School of Cybersecurity · Intermediate–Advanced

Ethical Hacking & Penetration Testing Course

Learn ethical hacking through authorised, hands-on penetration testing of networks, web apps and APIs with professional reporting.

Talk to an advisor on WhatsApp
Ethical Hacking & Penetration Testing course illustration at Brightnest AI Academy
Ethics, Scope and Penetration Testing MethodologyReconnaissance and Attack Surface MappingScanning, Enumeration and Vulnerability ValidationNetwork and Host Exploitation Concepts
Kali Linux labdocumentation templatesNmapAmassSubfinder concepts
Duration11–13 weeks81 hours
Batch startsConfirm with admissionsOpen for registration
Learning formatLive mentor-led instruction, guided labs, assignments, feedback and project reviewsLive online / classroom
Curriculum8 modulesLabs and assessed capstone
Portfolio2 projectsPlus module evidence
LevelIntermediate–AdvancedCourse level
PathwayCybersecurity EngineerRelated career pathway

How you will learn

Live instructor-led sessions that connect concepts to real workplace decisions.
Guided labs and workshops in every module.
Assignments, checkpoints and practical feedback.
Portfolio documentation, demonstrations and capstone review.
Access to recordings and LMS resources according to the published batch policy.
Career preparation based on completed work and target roles.
Course curriculum

What you will learn, module by module

Assess vulnerabilities and conduct authorised penetration testing using professional methodologies. Progress from Ethics, Scope and Penetration Testing Methodology to Penetration Testing Capstone through guided labs, assessed projects, and portfolio evidence.

01Module 1 · 5 hoursEthics, Scope and Penetration Testing MethodologyCreate a professional rules-of-engagement and test plan for an authorised lab target.
Topics you will cover
  • Authorization
  • Rules of engagement
  • Scope
  • Evidence
  • Reporting
  • Attack lifecycle
  • Legal/ethical boundaries
Tools and platforms
Kali Linux lab, documentation templates
Portfolio evidence
Pen-test engagement plan
Assessment
Scope review
02Module 2 · 8 hoursReconnaissance and Attack Surface MappingMap the attack surface of a deliberately vulnerable lab environment.
Topics you will cover
  • Passive/active recon
  • DNS
  • Subdomains
  • Technology fingerprinting
  • Exposed services
  • Metadata
  • OSINT principles
Tools and platforms
Nmap, Amass/Subfinder concepts, browser tools
Portfolio evidence
Attack-surface map
Assessment
Recon lab
03Module 3 · 10 hoursScanning, Enumeration and Vulnerability ValidationEnumerate hosts/services and validate high-priority findings without destructive actions.
Topics you will cover
  • Port/service discovery
  • Version detection
  • Enumeration
  • Vulnerability scanning
  • False positives
  • Manual validation
  • Prioritisation
Tools and platforms
Nmap, lab vulnerability scanner
Portfolio evidence
Validated vulnerability report
Assessment
Technical lab
04Module 4 · 10 hoursNetwork and Host Exploitation ConceptsExploit safe intentionally vulnerable hosts in a controlled lab and document remediation.
Topics you will cover
  • Authentication weaknesses
  • Insecure services
  • Misconfiguration
  • Privilege escalation concepts
  • Lateral movement concepts
  • Credential hygiene
  • Post-exploitation boundaries
Tools and platforms
Metasploitable/HTB-style lab, Linux/Windows VMs
Portfolio evidence
Host exploitation case report
Assessment
Lab practical
05Module 5 · 12 hoursWeb Application Security and OWASP RisksTest a deliberately vulnerable web app, reproduce issues and recommend fixes.
Topics you will cover
  • HTTP
  • Sessions
  • Input validation
  • Injection
  • XSS
  • Access control
  • SSRF concepts
Tools and platforms
Burp Suite Community/OWASP ZAP, vulnerable web lab
Portfolio evidence
Web security findings portfolio
Assessment
Web pentest report
06Module 6 · 10 hoursAuthentication, API and Cloud-Native Attack SurfaceAssess a vulnerable REST API for authorization and input-validation issues.
Topics you will cover
  • JWT/OAuth concepts
  • API authorization
  • Rate limits
  • IDOR/BOLA
  • Secrets
  • Container/cloud misconfig concepts
  • API testing methodology
Tools and platforms
Burp/ZAP, Postman/curl, API lab
Portfolio evidence
API penetration test report
Assessment
API security lab
07Module 7 · 8 hoursExploitation Workflow, Evidence and RemediationComplete an end-to-end exploit-to-remediation validation workflow in a lab.
Topics you will cover
  • Exploit selection
  • Safe proof-of-concept
  • Shell hygiene
  • Data minimization
  • Evidence capture
  • Cleanup
  • Risk rating
Tools and platforms
Kali, lab targets, reporting tools
Portfolio evidence
Evidence-backed remediation package
Assessment
Practical checkpoint
08Module 8 · 18 hoursPenetration Testing CapstoneConduct a full authorised penetration test against a multi-service lab and present findings to a mock client.
Topics you will cover
  • Scope
  • Recon
  • Enumeration
  • Web/API/network testing
  • Evidence
  • Risk rating
  • Executive summary
Tools and platforms
Kali, Nmap, Burp/ZAP, lab environment
Portfolio evidence
Professional penetration testing report
Assessment
Capstone report and presentation
Applied portfolio

Projects you will build

2 portfolio projects plus module evidence

Portfolio project 1

Authorised Multi-Service Penetration Test

Test a vulnerable network/web/API lab and produce a client-style report.

Rules of engagement · evidence · findings · remediation · retest results
Portfolio project 2

Web and API Security Assessment

Assess authentication, authorization and input-handling weaknesses in a vulnerable application.

Burp/ZAP evidence · risk ratings · developer remediation guidance
Course value

Why this course

Ethical hacking requires explicit authorisation, controlled methodology, reproducible evidence, risk-based reporting, and verified remediation—not indiscriminate tool use.

The curriculum progresses from Ethics, Scope and Penetration Testing Methodology to Penetration Testing Capstone, with guided labs, assessments, and two portfolio projects: Authorised Multi-Service Penetration Test and Web and API Security Assessment.

Course fit

Who this course is for

Security learners and practitioners developing authorised offensive-security skills.

Intermediate–AdvancedCybersecurity Engineer
PrerequisitesLearners should understand networking, Linux/Windows, and cybersecurity fundamentals. All lab testing is conducted only in authorised environments.
Practical capabilities

What you will be able to do

  • Create a professional rules-of-engagement and test plan for an authorised lab target.
  • Map the attack surface of a deliberately vulnerable lab environment.
  • Enumerate hosts/services and validate high-priority findings without destructive actions.
  • Exploit safe intentionally vulnerable hosts in a controlled lab and document remediation.
  • Test a deliberately vulnerable web app, reproduce issues and recommend fixes.
  • Complete an end-to-end exploit-to-remediation validation workflow in a lab.
  • Conduct a full authorised penetration test against a multi-service lab and present findings to a mock client.
Tools and platforms

Technology you will use in this course

Kali Linux labdocumentation templatesNmapAmassSubfinder conceptsbrowser toolslab vulnerability scannerMetasploitableHTB-style labLinuxWindows VMsBurp Suite CommunityOWASP ZAPvulnerable web labBurpZAP
Career relevance

Cybersecurity Engineer

This course supports the development of skills relevant to roles such as Penetration Tester, Ethical Hacker, and Vulnerability Assessment Analyst. The strongest learner outcome is a portfolio that shows the problem, implementation, testing or evaluation, documentation and a clear explanation of decisions—not a certificate alone.

Course evidence and instruction

Academy advisor

Ranjeet Kumar

Advisor, Brightnest AI Academy · Innovation & Growth Leader

A technologist and data leader with 15+ years of experience applying data, artificial intelligence and machine learning to complex problems, scalable products and business growth.

What our learners say

Learner experience

The SOC project helped me practise alert triage, investigation notes, incident response and the professional reporting expected from analysts.
Arjun MehtaCybersecurity Learner · Security Operations Pathway

Industry and technology ecosystem

MicrosoftAmazon Web ServicesDeloitteTech MahindraTata Consultancy ServicesWipro
Course FAQs

Clear answers before you enrol

Learn ethical hacking through authorised, hands-on penetration testing of networks, web apps and APIs with professional reporting.

Is the Ethical Hacking & Penetration Testing course suitable for beginners?

This course progresses from intermediate to advanced level. Learners should understand networking, Linux/Windows, and cybersecurity fundamentals. All lab testing is conducted only in authorised environments.

What will I build during the course?

You will complete guided labs in every module and build two portfolio projects: Authorised Multi-Service Penetration Test and Web and API Security Assessment. Deliverables include working files or code, documentation, testing or evaluation evidence, and a final presentation.

Which tools and platforms are covered?

Key tools include Kali Linux lab, documentation templates, Nmap, Amass, Subfinder concepts, browser tools, lab vulnerability scanner, and Metasploitable. Additional platforms are introduced in relevant modules through practical tasks, and the toolset may evolve as industry practice changes.

How long does the course take?

The course includes approximately 81 guided learning hours across 8 modules, normally delivered over 11–13 weeks depending on batch intensity and learner practice time.

Which career paths can this course support?

The curriculum supports the development of skills relevant to roles such as Penetration Tester, Ethical Hacker, and Vulnerability Assessment Analyst. Career outcomes depend on prior experience, project quality, interview readiness and market conditions; employment is not guaranteed.

Will I receive mentor and career support?

The course includes live instruction, lab support, assignment feedback, project reviews and career preparation covering portfolio development, resume writing, LinkedIn profile improvement, and interview guidance.

Ready to start?

Ready to start your Ethical Hacking & Penetration Testing journey?

Review the full curriculum, experience a live class and confirm the right starting point before enrolling.

A-56, Sector-64, Noida, Uttar Pradesh – 201301