Course Overview

Securing and testing modern infrastructures requires the right combination of tools and techniques, and this course provides a hands-on approach to mastering them. From reconnaissance to post-exploitation, you will learn how ethical hackers and penetration testers approach real-world environments. The course emphasizes practical application, ensuring you can confidently use industry-standard tools to identify and exploit vulnerabilities in both Windows and Linux systems. 

This course begins with building your lab environment using VirtualBox and installing various operating systems including Kali Linux, Windows, and Metasploitable3. You will then progress into reconnaissance and scanning with Nmap, OpenVAS, and Shodan before moving to enumeration and information gathering using tools like WinPEAS, DNSRecon, and recon-ng. Exploitation techniques are covered with MSFvenom, Netcat, and Metasploit, followed by persistence methods and post-exploitation tactics. The course also explores Windows privilege escalation, password attacks using Hydra, Medusa, and Mimikatz, and concludes with wireless and network attacks, WAF detection, and OWASP ZAP scanning. 

By the end, you will gain practical penetration testing skills, master essential tools, and build confidence to identify, exploit, and secure vulnerabilities effectively. 

What You Will Learn

  • Build a complete penetration testing lab with VirtualBox, Kali Linux, Windows, and vulnerable systems.
  • Perform reconnaissance and vulnerability scanning using Nmap, OpenVAS, and Shodan.
  • Enumerate and gather system information with tools like WinPEAS, Recon-ng, and DNSRecon.
  • Exploit vulnerabilities with Metasploit, MSFvenom, SQLmap, and advanced attack techniques.
  • Execute post-exploitation, privilege escalation, credential attacks, and wireless/network penetration methods.

Program Curriculum

  • Installing Oracle VirtualBox on Windows 10_11
  • Installing the VirtualBox Extension Pack
  • Creating a Virtual Install of Kali Linux
  • Creating a Virtual Install of Windows 10
  • Creating a Virtual Install of Metasploitable3 (W2k08)
  • Creating a Virtual Install of Server 2016
  • Chapter 1 Quiz

  • Nmap Service and Open Port Scan
  • Nmap Host Detection
  • Nmap NSE for Windows Services
  • Installing OpenVAS Using Docker
  • Vulnerability Scanning with OpenVAS
  • Using Shodan to Find Exposed Systems
  • Creating a Bash Script for Scanning Vulnerable Ports
  • Chapter 2 Quiz

  • Banner Grabbing & Service Fingerprinting
  • Local Enumeration with WinPEAS
  • Credential Dumping with netsh (Wi-Fi)
  • Recon-ng for Windows Infrastructure
  • Enumerate DNS Records Using DNSRecon
  • Chapter 3 Quiz

  • Use MSFvenom to Create a Reverse TCP Payload
  • Use MSFvenom to Create an HTTPS Payload
  • Use MSFvenom to Create Hidden Bind TCP Payload
  • HTML Smuggling Attack
  • Exploiting SQL Injection on Windows Sqlmap
  • Exploiting the UNIX_Linux rlogin Vulnerability
  • Exploiting VSFTPD v2.3.4 Using Metasploit
  • Pentesting with Netcat
  • Chapter 4 Quiz

  • Persistent Backdoor Using Service Persistence
  • Remote Access via PowerShell Reverse Shell
  • Launch an Automated Meterpreter Session
  • Disable UAC on Windows using PowerShell
  • Chapter 5 Quiz

  • Disable UAC on Windows 10 Using PowerShell
  • Verify Windows Privilege Escalation Unquoted Service Path
  • Windows Privilege Escalation - Unquoted Service Path
  • Chapter 6 Quiz

  • Password Cracking with Hydra
  • Password Cracking with Medusa
  • Password Cracking with Mimikatz
  • Brute-Forcing Windows Services (RDP/SMB)
  • Brute Force the SMB Password
  • Advanced Password Hacking Techniques with Metasploit
  • Chapter 7 Quiz

  • Quickly Transfer Files Using Python's SimpleHTTPServer
  • Web Application Firewall Detection Using WAFW00F
  • Spoof Fake TCP IP Packets Using Hping3
  • Perform a Vulnerability Scan Using OWASP ZAP Attack Proxy
  • Exploiting HTTP PUT
  • Chapter 8 Quiz
Load more modules

Instructor

Cliff Krahenbill Krahenbill

Cliff Krahenbill has worked in technology since 1998 as a Microsoft Support Technician, Microsoft Certified Trainer, technology support specialist, Senior Network Technology Consultant, IT Auditor, and now owner of CLK Technology Solutions in Tucson, Arizona. His expertise includes network infrastructure design, support, and security.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Fastest Way to Level Up Your Cybersecurity Skills

Invest in your future with flexible subscription plans that give you access to the world’s largest online cybersecurity course library. Whether you're exploring cybersecurity courses for beginners or advancing your expertise,
access in-demand courses, practical labs, and CTF challenges designed to support continuous learning.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Build your cybersecurity skills with 900+ bite-sized courses and curated learning paths designed for continuous learning.

$ 69.00
Billed monthly or $599.00 billed annually

What is included

  • 880+ Premium Short Courses
  • 70+ Structured Learning Paths
  • Validation of Completion with all courses and learning paths
  • New Courses added every month
Early Access Offer

Pro +

Develop real-world cybersecurity skills through hands-on labs and CTF challenges designed for practical learning.

$ 79.00
Billed monthly or $699.00 billed annually

Everything in Pro, Plus:

  • 1600+ Hands-on lab exercises with guided instructions
  • 150+ CTF Challenges with detailed walkthroughs
  • New Hands-on Labs and Challenges added every month

Related Courses

1 of 50