Course Overview

Penetration testing, often called pentesting, is a crucial discipline in cybersecurity, focusing on identifying and addressing vulnerabilities before malicious actors exploit them. As organizations increasingly rely on digital infrastructure, the need for skilled professionals who can simulate real-world attacks has grown. Pentesting Fundamentals for Beginners is designed to introduce newcomers to the core principles and practices of penetration testing, helping them build a strong technical foundation and understanding of the methodologies used by ethical hackers.

This course begins with setting up a virtual lab environment using VirtualBox, including installations of Kali Linux, Windows 10, Metasploitable 2 and 3, and OWASP systems. It then moves into the critical documentation required for professional engagements, such as Scoping, SOWs, and NDAs. Students are introduced to major penetration testing frameworks like MITRE ATT&CK, NIST, and PTES. Practical hands-on sessions cover network discovery using Nmap, vulnerability scanning with OpenVAS, information gathering techniques, reverse shells, privilege escalation strategies, and OWASP Top 10 mitigation practices. The course also delves into web application testing using tools like Burp Suite and SQLmap, compiling exploit code for different platforms, and scripting techniques using Python and PowerShell.

By completing this course, learners will gain the essential skills to conduct fundamental penetration tests, analyze vulnerabilities, and develop a structured, professional approach to cybersecurity testing.

What You Will Learn

  • The fundamentals of ethical hacking.
  • Identify security tools and ethical hacking techniques
  • Identify and exploit web application vulnerabilities.
  • Identify the appropriate documentation for starting and finalizing a pentest.
  • Correct reporting procedures.
  • Analyze threats and vulnerabilities within context of ethical hacking.
  • Identify the appropriate pentesting framework for meeting the needs of a specific client.
  • Identify the appropriate exploit for a given vulnerability.

Program Curriculum

  • Create a Virtual Install of Kali Linux
  • Create a Virtual Install of Windows 10
  • Create a Virtual Install of Metasploitable2 Using VirtualBox
  • Create a Virtual Install of Metasploitable3 Using VirtualBox
  • Create a Virtual Install of OWASP
  • Taking a Snapshot of Your Current Configuration
  • $7 Million Cybersecurity Scholarship by EC-Council
  • Chapter 1 Quiz

  • Scoping the Engagement
  • Statement of Work (SOW) Document
  • Rules of Engagement (ROE) Document
  • Master Service Agreement (MSA), NDA
  • Pentesting Final Report
  • Chapter 2 Quiz

  • Overview of MITRE ATT&CK framework
  • Overview of the NIST Pentesting Framework
  • Overview of the Penetration Testing Execution Standard (PTES)
  • Chapter 3 Quiz

  • Introduction to Nmap
  • Nmap Service and Open Port Scan
  • Nmap OS Detection
  • Nmap Service and Version Detection
  • Nmap Host Discovery
  • Nmap Scripting Engine (NSE)
  • Analyzing Nmap Results
  • Chapter 4 Quiz

  • Perform a Vulnerability Scan Using OpenVAS
  • Chapter 5 Quiz

  • Using Banner Grabbing to Aid in Reconnaissance
  • Enumerating Windows 10 Using WinPEAS
  • Chapter 6 Quiz

  • Creating a Persistent Backdoor Using Service Persistence
  • Create a Windows Reverse Shell Using PowerShell
  • Launch a Graphic Console Window Using SSH and XTERM
  • Chapter 7 Quiz

  • Window 7/10 Privilege Escalation Using UAC Bypass
  • Verify Windows Privilege Escalation: Unquoted Service Path
  • Windows Privilege Escalation Unquoted Service Path
  • Chapter 8 Quiz

  • Overview of OWASP Top 10
  • Assemble Fake TCPIP Packets Using Hping3
  • Identify Active Network Hosts and Services Using Nmap
  • Perform a Vulnerability Scan Using OWASP Zed Attack Proxy
  • Chapter 9 Quiz

  • Configuring Burp Suite as a Proxy
  • Web Application Firewall Detection Using WAFW00F
  • Perform a SQL Injection Attack Using Sqlmap
  • Exploit Vulnerable Web Applications Using Command Injection
  • Exploiting HTTP PUT Method
  • Brute Forcing WordPress Password
  • Chapter 10 Quiz

  • Compiling Exploit Code for Linux Using GCC
  • Prepare a Windows OVA file for Your Virtual Lab Environment
  • Cross Compiling Windows Exploits Using Mingw-w64
  • Chapter 11 Quiz

  • Local File Inclusion Using Kali Web Shells PHP Scripts
  • File Transfer Using HTTP and PowerShell’s WebClient Object
  • Python3 SimpleHTTPServer
  • String Slicing Using Python
  • Disable Windows 10 UAC Using PowerShell
  • Chapter 12 Quiz
Load more modules

Instructor

Cliff Krahenbill Krahenbill

Cliff Krahenbill has worked in technology since 1998 working as a Microsoft Support Technician, a Microsoft Certified Trainer, a technology support specialist, a Senior Network Technology Consultant, an IT Auditor and most recently as the owner and operator of his own technology firm, CLK Technology Solutions located in Tucson Arizona. Cliff's expertise in technology focuses on designing, building, supporting network infrastructures, and network security.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Choose the Pro Plan That Fits Your Learning Journey

Invest in your future with flexible Pro subscription plans. Whether you're starting your cybersecurity journey or expanding your expertise, choose the membership duration that works for you and gain access to our complete learning platform.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Ideal for continuous learning, offering extensive resources with 900+ courses and diverse Learning Paths to enhance your skills.

$ 599.00
Billed annually or $69.00 billed monthly

What is included

  • Access to 900+ Premium Short Courses
  • 70+ Structured Learning Paths
  • Validation of Completion with All Courses and Learning Paths
  • New Courses Added Every Month
Early Access Offer

Pro +

Experience immersive learning with Practice Labs and CTF Challenges for comprehensive skill-building.

$ 699.00
Billed annually or $79.00 billed monthly

Everything in Pro and

  • 500+ Practice Labs with Guided Instructions
  • 400+ CTF Challenges with Detailed Walkthroughs
  • New Practice Labs and Challenges Added Every Month

Related Courses

1 of 50