Introduction & Kali — Concepts
Before you launch a single tool, two things have to be in place: the attacker's head and the stage. Without the stage (an isolated lab), the head is useless: you end up in front of a judge. Without the head, the stage is useless too: you fire off random commands and nothing falls.
Everything taught here applies exclusively to machines you own, or ones you have written authorization for (RoE, contract, bug bounty). Scanning a site you have no permission to touch is already an offense in most jurisdictions. This course teaches you how to attack. The law teaches you where.
What you will be able to do after this lesson
- Explain in your own words what a penetration test is, and why it is not an audit.
- Tell vulnerability, exploit, and impact apart — the three words everyone mixes up.
- Adopt an attacker's mindset: start from the target, not from the tool.
- Name the major phases of an attack (the famous kill chain), so you always know where you are.
- Understand why Kali Linux exists, and what it concretely gives you.
1. Why this job exists
A company has built an application, a network, a cloud infrastructure. It believes the whole thing is secure because nobody has tried to break it. That is exactly why you get paid: to try to break it before a real bad actor does.
The penetration tester is the legal burglar. The client hands you the key, asks you to try getting in through the window, the chimney, the mailbox, the neighbor's kid, the cleaning crew — and then to tell the whole story, with evidence, so the holes can be plugged.
A pentest is worth nothing for its number of flaws found. It is worth something for:
- The evidence you bring back (screenshots, logs, extracted files).
- The reproducibility: the client must be able to redo the step after remediation.
- The recommendations: what gets done Monday morning to close the hole.
A report with no evidence is gossip. Gossip does not close a ticket.
Definition — a shell, a word we will use ten times per lesson
A shell is an interface that accepts commands and hands them to the operating system to execute. When you open a terminal on your computer and type ls, you are inside a shell.
For an attacker, "getting a shell" on a remote machine means exactly one thing: being able to type commands on that machine as if you were sitting in front of it. This is the first real milestone of an attack. Until you have a shell, you have nothing. Once you have one, everything becomes possible: reading files, trying to escalate privileges, jumping to another machine.
Two flavors come back throughout the course. A bind shell, where the target opens a port and waits for you to connect: simple but loud, a firewall sees it. A reverse shell, where the target reaches out to you from inside: far more common in practice, because most firewalls let outbound traffic leave without looking twice.
2. The three cousins everyone confuses
| Discipline | What you do | The question you answer |
|---|---|---|
| Audit | You read the docs, interview people, look at the configs. | Is this compliant with the policy / the standard? |
| Pentest | You attack, within a limited scope, over a limited time. | Can we get in, and how far? |
| Red team | You simulate a real, stealthy attacker with business objectives. | How long before we get detected, and would we have been? |
The audit runs through the interview box. The pentest runs through the exploit box. The red team runs through the defense evasion box — and often the social engineering box.
You learn the pentest, with regular openings toward the red team in the advanced modules (8 through 11).
Definition — the purple team, and why the word keeps coming back
Red team and blue team have long stood for offense and defense. Purple team is not a third team: it is the moment when the two work together. In practice the attacker runs a technique and lets the defense know; the defense checks whether its SIEM caught it. If not, they tune the rules and replay. Repeat for every technique in the MITRE ATT&CK catalog.
The value is twofold. The defense learns what slips past today and how to catch it tomorrow. The attacker learns which techniques are loud and which slip through — indispensable for a future stealthy engagement. A real two-week purple team exercise is worth more than a yearly pentest whose report lands weeks after the consultants have left.
Further reading — audit and pentest are complementary, not competing
An ISO 27001 audit checks that the password policy is written and enforceable. It says nothing about its actual strength: if the document requires "12 characters minimum" but half of the estate still allows eight, the auditor will not see it.
That is exactly where the pentest fills the gap: it tries to break that policy with real password attacks, and reports the share of accounts that fell. The two approaches lean on each other — an audit without a pentest can certify an organization that is still trivial to compromise, and a pentest without an audit finds ten holes without explaining why they exist.
3. Vulnerability, exploit, impact — stop mixing them up
Three words. Three different things. Confusing the three means writing a report the client will throw away.
Vulnerability: a weakness. A piece of code, a config, a default password. On its own, it does nothing.
Exploit: the concrete move that turns the weakness into access. The code, the command, the click that proves the thing.
Impact: the business consequence of the exploit. It is never a CVSS score. It is "with this, I read the entire customer database" or "with this, I take production down for three days."
An example to burn the distinction in:
- Vulnerability: the web server runs a version vulnerable to
CVE-2021-41773(Apache path traversal). - Exploit: I run
curlwith a traversing path and pull/etc/passwd. - Impact: the credentials of a service account were sitting in a
.envfile in the same folder, and I got the connection to the production database.
The client does not care about the CVE. What sticks is the database. That is what goes at the top of the report.
Definition — CVE, what this number is and what it is not
CVE, Common Vulnerabilities and Exposures, is a public catalog maintained by MITRE in the United States. Every publicly disclosed vulnerability gets an identifier of the form CVE-2021-41773: the year is the year of assignment, not of discovery. The catalog names the flaw, it does not fix it.
Three traps that cost beginners. A CVE does not imply that a public exploit exists: roughly one third of CVEs never have any published exploitation code. Not every CVE is severe: many apply only to rare configurations. And most importantly, a CVE on a component does not automatically affect your installation — if the faulty feature is not enabled, the vulnerable version is harmless. That is the first thing to demonstrate before writing "critical" in a report.
Definition — CVSS, the severity score and its limits
CVSS, Common Vulnerability Scoring System, assigns a score from 0 to 10 to a vulnerability. It aggregates the potential impact — confidentiality, integrity, availability — and the ease of exploitation — reachable over the network or only locally, with or without authentication, with or without user interaction.
This score is useful for sorting a pile of tickets. It is useless in a pentest report, and here is why. CVSS ignores your context. A flaw rated 9.8 on an isolated server with no sensitive data is less urgent than a flaw rated 6.5 on the gateway that protects your production. The report must say "with this flaw, an attacker gets access to this data", not "CVSS score 9.8". The score helps the client decide between two similar flaws; it never replaces your analysis.
4. The attacker's mindset
The systems engineer starts from the machine and asks "what am I running?". The attacker starts from the same point and asks "what sticks out?".
The five reflexes that make the difference:
- Always look at what is listening. An open port is a door. A door is a service. A service is a version. A version is a story of known bugs.
- Always look at what talks. Banners, HTTP headers, error messages — they tell you everything.
- Always look at what was forgotten. A
.gitfolder, abackup.sql, arobots.txt, a screenshot left in a public directory. Negligence is more common than a zero-day vulnerability. - Always chain. A single flaw is rarely critical. Two medium flaws chained together are a disaster. Look for the chain, not the flaw.
- Always doubt success. If it works on the first try, it may be a trap (honeypot). Check that the machine you hold is really the one you think it is.
"What the developer forgot to check is exactly where I get in."
Definition — the three states of a port, because you will read them in every report
A port is not just "open or closed": it has three states, and confusing the last two makes you miss real targets.
Open: something is listening and answers. That is what we look for.
Closed: the machine exists, it answered, but no service waits on that specific port. The target is alive, the port is simply unused.
Filtered: the machine did not answer — or answered only with an error message — because a firewall intercepted the packet upstream. You do not know whether the port is open or closed. That is valuable information: it means filtering is in place, so the service is probably sensitive and deliberately protected.
Nmap adds two rarer nuances. Unfiltered: the port answers but Nmap cannot conclude; common with certain scan types. Open|filtered: Nmap hesitates, often in UDP where the absence of an answer can mean either. You will learn to read these states in module 4.
Definition — root, Administrator, SYSTEM, what we want at the end
On Unix systems — Linux, macOS, BSD — the all-powerful account is called root. Its numeric ID is zero. It reads and writes every file, kills every process, loads and unloads kernel drivers.
On Windows the hierarchy is finer-grained. Administrator is the historic admin account, the one on the desktop. Above it, invisible to the user, sits SYSTEM — the identity under which Windows services themselves run, including those that manage authentication and security. A pentester prefers SYSTEM over Administrator: SYSTEM can read the password database (SAM) that even Administrator cannot open without tricks. That is why the module's walkthrough targets a SYSTEM shell directly.
A third level exists on machines joined to a Windows domain: Domain Admin. Compromising Domain Admin is equivalent to owning the whole directory — and, usually, the whole estate.
5. The kill chain — the map that keeps you from getting lost
An attack is not a single stroke of genius. It is a sequence of steps. The classic sequence, in seven stages:
- Reconnaissance — learn about the target without touching it (OSINT). Module 3.
- Active reconnaissance — port scanning, service enumeration. Module 4.
- Vulnerability research — correlate the versions you saw with known CVEs. Module 5.
- Initial exploitation — get the first shell. Modules 7 and 8.
- Privilege escalation — go from some account to
rootorSYSTEM. Module 9. - Lateral movement — hop from machine to machine, exfiltrate data. Module 10.
- Reporting — deliver the evidence, the recommendations, the timeline. Module 12.
Every module of this course answers one step. Whenever you get lost on an engagement, come back to this list: it tells you where you are, and what is missing.
Further reading — where the kill chain comes from, and why MITRE ATT&CK replaced it
The Cyber Kill Chain was formalized in 2011 by Lockheed Martin. It transposed onto cyber the military reasoning already applied to destroying a physical target: Find, Fix, Track, Target, Engage, Assess. Its strength is pedagogical — it is linear, memorable in a minute — but its weakness surfaced with use: a real attack is not linear. It loops. The attacker returns to reconnaissance after an initial foothold, changes axis, drops one chain to try another.
MITRE ATT&CK, first published in 2013, replaces the line with a matrix. The columns are the broad categories — Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact. Each column holds several concrete techniques, each with a unique identifier such as T1078. That granularity lets a defender say "I have rules for this identifier, none for that one".
In this course we start from the kill chain because it serves as a narrative thread, but ATT&CK vocabulary appears as early as module 4. A good pentester moves between both.
6. Why Kali, and not Ubuntu
Kali Linux is a Debian distribution stuffed with offensive tools. We could have installed all of them by hand on an Ubuntu. We do not, for three reasons:
- It is all there, right away. Nmap, Metasploit, Burp Suite, John the Ripper, Hashcat, Wireshark, Bloodhound, Impacket — more than 600 tools preinstalled and up to date.
- The updates go the right way. The
kali-rollingchannel pushes recent offensive versions. On an Ubuntu LTS, Nmap can be a year behind on its NSE scripts. - The community knows what you are doing. Hit a snag? You search "kali nmap segfault" and find the answer in thirty seconds. On a generic distribution, nobody will understand your problem.
Kali is not "an OS for hackers." It is a toolbox with an operating system wrapped around it. You store nothing on it, you never open it to the public network, and you rebuild it from a snapshot the moment it starts acting strange.
Definition — a rolling distribution, and why it changes a tester's life
A rolling distribution publishes updates continuously, with no fixed numbered release. You update on a Monday, packages are in the state they were that Monday; you update again two months later, they have moved on. There is no Kali 2023.4 you install for two years before reinstalling — there is a permanent stream.
At the opposite end, Ubuntu LTS ships a release every two years and barely moves afterward, except for backported security fixes. That is a sensible choice for a production server, where stability wins. For an attacker it is a handicap: an exploit signature added to Metasploit last week will reach your Ubuntu only after a backporting cycle, often never.
The trade-off of the rolling model is real: an update can break a tool overnight. That is why you take a VirtualBox snapshot after each successful update, and only return to it after testing the new version in a spare environment.
Definition — a virtual machine snapshot
A snapshot is a recording of a virtual machine's complete state at a given moment: disk contents, RAM contents, simulated hardware configuration. VirtualBox and VMware store that state next to the main virtual disk as a differential file — only the blocks that changed since the snapshot are copied, which makes the operation fast even for a VM of dozens of gigabytes.
Two uses in pentesting. The first is defensive: before installing a shady tool or executing a suspicious binary, take a snapshot; if the VM misbehaves, one click brings it back. The second is experimental: on the lab's target machine, take a snapshot called base-vulnerable before the first exploitation. You can then replay the same attack indefinitely, which is essential to verify a remediation or to teach someone else. Without a snapshot, a destroyed target does not replay.
7. The confusions that cost time
Fix them now, before they bite you in week 5.
| What people often say... | The right notion |
|---|---|
| "I found a CVE" | A CVE is an identifier. You find a vulnerability, which may correspond to a CVE. |
| "I hacked it" | No, you exploited a vulnerability. The word hack says nothing precise. |
| "It is malicious code" | An exploit is not malware. An exploit triggers a flaw. Malware does something bad once it is in place. |
| "Nmap found me a flaw" | No, Nmap sees ports and versions. You make the link with the vulnerability. |
| "The port is closed" | A port can be closed (the service says no), filtered (a firewall intercepts), or open (someone is listening). Three states, three stories. |
| "Metasploit hacked the machine" | Metasploit delivers an exploit and manages the session. It does not think for you. |
8. What to remember
- A pentest is scoped, authorized, measured. Without that frame, it is no longer a pentest, it is a crime.
- The value of a pentest is in the evidence and the recommendations, not in the number of findings.
- Vulnerability, exploit, impact: three words, three things. Stop mixing them.
- The attacker looks at what sticks out, what talks, what was forgotten, and then chains.
- The kill chain always tells you where you are.
- Kali is your toolbox. Not your desk, not your safe.
Next lesson: we install Kali, run the first scan, and watch a machine fall — inside a lab locked up tight.