Penetration Testing — Professional Pentest
A complete penetration testing course, from the legal planning of an engagement all the way to the report delivered to the client. The path follows the real progression of a mandate: you first learn to scope, then to reconnoiter, then to exploit, and finally to report.
Free course on sign-up
Access is free. It only asks for an account, so your progress and your certificate stay attached to your identity. Sign-in is done through a link sent by email, with no password to create.
What you will be able to do
- Scope an engagement with a legally defensible Rules of Engagement document.
- Run passive then active reconnaissance without needlessly tripping the defenses.
- Identify, qualify and exploit system, network and application vulnerabilities.
- Escalate your privileges, pivot across the network and exfiltrate data discreetly.
- Adapt the techniques to modern environments: cloud, mobile, IoT.
- Write a professional report with findings, evidence and actionable recommendations.
How to earn your certificate
- Work through the 13 technical modules, in order. Each module ends with a "Mark this lesson as complete" button that feeds your progress.
- Complete the three labs (Lab 1 in week 6, Lab 2 in week 9, Lab 3 in week 13).
- Once the 16 lessons are validated, take the final quiz. Passing score: 70%. The quiz can be retaken as many times as needed.
- A verifiable certificate is issued to you, with a unique code. Anyone can confirm its authenticity on the public page /certificate.
Legal framework
The techniques taught must be applied only to systems you own or for which you hold written authorization (RoE, contract). Any use outside this framework is illegal.
Course outline
| # | Module | Deliverables |
|---|---|---|
| 1 | Introduction & Kali environment | VM ready |
| 2 | Planning and Rules of Engagement | Simulated RoE |
| 3 | Information gathering (OSINT) | Target profile |
| 4 | Active reconnaissance & network scanning | Network map |
| 5 | Vulnerability research | Prioritized list |
| 6 | Social engineering | Lab 1 submitted |
| 7 | Web vulnerabilities (OWASP Top 10) | — |
| 8 | Automation & Metasploit | Lab 2 submitted |
| 9 | Privilege escalation | — |
| 10 | Lateral movement & exfiltration | — |
| 11 | Cloud, mobile & IoT security | — |
| 12 | Report & recommendations | Lab 3 submitted |
| 13 | Offensive code analysis | — |
Ready? Open the first module in the side menu.