Ethical Hacking & Penetration Testing Course
Learn ethical hacking through authorised, hands-on penetration testing of networks, web apps and APIs with professional reporting.
Talk to an advisor on WhatsApp
How you will learn
What you will learn, module by module
Assess vulnerabilities and conduct authorised penetration testing using professional methodologies. Progress from Ethics, Scope and Penetration Testing Methodology to Penetration Testing Capstone through guided labs, assessed projects, and portfolio evidence.
01Module 1 · 5 hoursEthics, Scope and Penetration Testing MethodologyCreate a professional rules-of-engagement and test plan for an authorised lab target.
- Authorization
- Rules of engagement
- Scope
- Evidence
- Reporting
- Attack lifecycle
- Legal/ethical boundaries
- Tools and platforms
- Kali Linux lab, documentation templates
- Portfolio evidence
- Pen-test engagement plan
- Assessment
- Scope review
02Module 2 · 8 hoursReconnaissance and Attack Surface MappingMap the attack surface of a deliberately vulnerable lab environment.
- Passive/active recon
- DNS
- Subdomains
- Technology fingerprinting
- Exposed services
- Metadata
- OSINT principles
- Tools and platforms
- Nmap, Amass/Subfinder concepts, browser tools
- Portfolio evidence
- Attack-surface map
- Assessment
- Recon lab
03Module 3 · 10 hoursScanning, Enumeration and Vulnerability ValidationEnumerate hosts/services and validate high-priority findings without destructive actions.
- Port/service discovery
- Version detection
- Enumeration
- Vulnerability scanning
- False positives
- Manual validation
- Prioritisation
- Tools and platforms
- Nmap, lab vulnerability scanner
- Portfolio evidence
- Validated vulnerability report
- Assessment
- Technical lab
04Module 4 · 10 hoursNetwork and Host Exploitation ConceptsExploit safe intentionally vulnerable hosts in a controlled lab and document remediation.
- Authentication weaknesses
- Insecure services
- Misconfiguration
- Privilege escalation concepts
- Lateral movement concepts
- Credential hygiene
- Post-exploitation boundaries
- Tools and platforms
- Metasploitable/HTB-style lab, Linux/Windows VMs
- Portfolio evidence
- Host exploitation case report
- Assessment
- Lab practical
05Module 5 · 12 hoursWeb Application Security and OWASP RisksTest a deliberately vulnerable web app, reproduce issues and recommend fixes.
- HTTP
- Sessions
- Input validation
- Injection
- XSS
- Access control
- SSRF concepts
- Tools and platforms
- Burp Suite Community/OWASP ZAP, vulnerable web lab
- Portfolio evidence
- Web security findings portfolio
- Assessment
- Web pentest report
06Module 6 · 10 hoursAuthentication, API and Cloud-Native Attack SurfaceAssess a vulnerable REST API for authorization and input-validation issues.
- JWT/OAuth concepts
- API authorization
- Rate limits
- IDOR/BOLA
- Secrets
- Container/cloud misconfig concepts
- API testing methodology
- Tools and platforms
- Burp/ZAP, Postman/curl, API lab
- Portfolio evidence
- API penetration test report
- Assessment
- API security lab
07Module 7 · 8 hoursExploitation Workflow, Evidence and RemediationComplete an end-to-end exploit-to-remediation validation workflow in a lab.
- Exploit selection
- Safe proof-of-concept
- Shell hygiene
- Data minimization
- Evidence capture
- Cleanup
- Risk rating
- Tools and platforms
- Kali, lab targets, reporting tools
- Portfolio evidence
- Evidence-backed remediation package
- Assessment
- Practical checkpoint
08Module 8 · 18 hoursPenetration Testing CapstoneConduct a full authorised penetration test against a multi-service lab and present findings to a mock client.
- Scope
- Recon
- Enumeration
- Web/API/network testing
- Evidence
- Risk rating
- Executive summary
- Tools and platforms
- Kali, Nmap, Burp/ZAP, lab environment
- Portfolio evidence
- Professional penetration testing report
- Assessment
- Capstone report and presentation
Projects you will build
2 portfolio projects plus module evidence
Authorised Multi-Service Penetration Test
Test a vulnerable network/web/API lab and produce a client-style report.
Rules of engagement · evidence · findings · remediation · retest resultsWeb and API Security Assessment
Assess authentication, authorization and input-handling weaknesses in a vulnerable application.
Burp/ZAP evidence · risk ratings · developer remediation guidanceWhy this course
Ethical hacking requires explicit authorisation, controlled methodology, reproducible evidence, risk-based reporting, and verified remediation—not indiscriminate tool use.
The curriculum progresses from Ethics, Scope and Penetration Testing Methodology to Penetration Testing Capstone, with guided labs, assessments, and two portfolio projects: Authorised Multi-Service Penetration Test and Web and API Security Assessment.
Who this course is for
Security learners and practitioners developing authorised offensive-security skills.
What you will be able to do
- Create a professional rules-of-engagement and test plan for an authorised lab target.
- Map the attack surface of a deliberately vulnerable lab environment.
- Enumerate hosts/services and validate high-priority findings without destructive actions.
- Exploit safe intentionally vulnerable hosts in a controlled lab and document remediation.
- Test a deliberately vulnerable web app, reproduce issues and recommend fixes.
- Complete an end-to-end exploit-to-remediation validation workflow in a lab.
- Conduct a full authorised penetration test against a multi-service lab and present findings to a mock client.
Technology you will use in this course
Cybersecurity Engineer
This course supports the development of skills relevant to roles such as Penetration Tester, Ethical Hacker, and Vulnerability Assessment Analyst. The strongest learner outcome is a portfolio that shows the problem, implementation, testing or evaluation, documentation and a clear explanation of decisions—not a certificate alone.
Course evidence and instruction
Ranjeet Kumar
Advisor, Brightnest AI Academy · Innovation & Growth LeaderA technologist and data leader with 15+ years of experience applying data, artificial intelligence and machine learning to complex problems, scalable products and business growth.
Learner experience
The SOC project helped me practise alert triage, investigation notes, incident response and the professional reporting expected from analysts.
Industry and technology ecosystem
Clear answers before you enrol
Learn ethical hacking through authorised, hands-on penetration testing of networks, web apps and APIs with professional reporting.
Is the Ethical Hacking & Penetration Testing course suitable for beginners?
This course progresses from intermediate to advanced level. Learners should understand networking, Linux/Windows, and cybersecurity fundamentals. All lab testing is conducted only in authorised environments.
What will I build during the course?
You will complete guided labs in every module and build two portfolio projects: Authorised Multi-Service Penetration Test and Web and API Security Assessment. Deliverables include working files or code, documentation, testing or evaluation evidence, and a final presentation.
Which tools and platforms are covered?
Key tools include Kali Linux lab, documentation templates, Nmap, Amass, Subfinder concepts, browser tools, lab vulnerability scanner, and Metasploitable. Additional platforms are introduced in relevant modules through practical tasks, and the toolset may evolve as industry practice changes.
How long does the course take?
The course includes approximately 81 guided learning hours across 8 modules, normally delivered over 11–13 weeks depending on batch intensity and learner practice time.
Which career paths can this course support?
The curriculum supports the development of skills relevant to roles such as Penetration Tester, Ethical Hacker, and Vulnerability Assessment Analyst. Career outcomes depend on prior experience, project quality, interview readiness and market conditions; employment is not guaranteed.
Will I receive mentor and career support?
The course includes live instruction, lab support, assignment feedback, project reviews and career preparation covering portfolio development, resume writing, LinkedIn profile improvement, and interview guidance.
Ready to start your Ethical Hacking & Penetration Testing journey?
Review the full curriculum, experience a live class and confirm the right starting point before enrolling.
