Pular para o conteúdo principal

Penetration Testing — Professional Pentest

A complete penetration testing course, from the legal planning of an engagement all the way to the report delivered to the client. The path follows the real progression of a mandate: you first learn to scope, then to reconnoiter, then to exploit, and finally to report.

Free course on sign-up

Access is free. It only asks for an account, so your progress and your certificate stay attached to your identity. Sign-in is done through a link sent by email, with no password to create.

What you will be able to do

  • Scope an engagement with a legally defensible Rules of Engagement document.
  • Run passive then active reconnaissance without needlessly tripping the defenses.
  • Identify, qualify and exploit system, network and application vulnerabilities.
  • Escalate your privileges, pivot across the network and exfiltrate data discreetly.
  • Adapt the techniques to modern environments: cloud, mobile, IoT.
  • Write a professional report with findings, evidence and actionable recommendations.

How to earn your certificate

  1. Work through the 13 technical modules, in order. Each module ends with a "Mark this lesson as complete" button that feeds your progress.
  2. Complete the three labs (Lab 1 in week 6, Lab 2 in week 9, Lab 3 in week 13).
  3. Once the 16 lessons are validated, take the final quiz. Passing score: 70%. The quiz can be retaken as many times as needed.
  4. A verifiable certificate is issued to you, with a unique code. Anyone can confirm its authenticity on the public page /certificate.
Legal framework

The techniques taught must be applied only to systems you own or for which you hold written authorization (RoE, contract). Any use outside this framework is illegal.

Course outline

#ModuleDeliverables
1Introduction & Kali environmentVM ready
2Planning and Rules of EngagementSimulated RoE
3Information gathering (OSINT)Target profile
4Active reconnaissance & network scanningNetwork map
5Vulnerability researchPrioritized list
6Social engineeringLab 1 submitted
7Web vulnerabilities (OWASP Top 10)
8Automation & MetasploitLab 2 submitted
9Privilege escalation
10Lateral movement & exfiltration
11Cloud, mobile & IoT security
12Report & recommendationsLab 3 submitted
13Offensive code analysis

Ready? Open the first module in the side menu.