Pen Testing Pathway

4.2

/

5

in partnership with

Default Title
Default Title
Default Title
Default Title
Default Title

What will you learn?

1. Engagement management
  • Planning and scoping: defining rules of engagement, testing windows, and target selection.
  • Legal and ethical compliance: ensuring authorization letters, mandatory reporting, and adherence to regulations.
  • Collaboration and communication: aligning with stakeholders through peer reviews, escalation paths, and risk articulation.
  • Penetration test reports: creating reports with executive summaries, findings, and remediation recommendations.
2. Reconnaissance and enumeration
  • Active and passive reconnaissance: gathering information using open-source intelligence (OSINT), network sniffing, and protocol scanning.
  • Enumeration techniques: performing DNS enumeration, service discovery, and directory enumeration.
  • Reconnaissance tools: using tools like Nmap, Wireshark, and Shodan for information gathering.
  • Script modification: customizing Python, PowerShell, and Bash scripts for reconnaissance and enumeration.
3. Vulnerability Discovery and Analysis
  • Vulnerability scans: conducting authenticated, unauthenticated, static application security testing (SAST) and dynamic application security testing (DAST).
  • Result analysis: validating findings, troubleshooting configurations, and identifying false positives.
  • Discovery tools: using tools like Nessus, Nikto, and OpenVAS for vulnerability discovery.
4. Attacks and exploits
  • Network attacks: performing VLAN hopping, on-path attacks, and service exploitation.
  • Authentication attacks: executing brute-force attacks, pass-the-hash, and credential stuffing.
  • Host-based attacks: conducting privilege escalation, process injection, and credential dumping.
  • Web application attacks: performing SQL injection, cross-site scripting (XSS), and directory traversal.
  • Cloud-based attacks: exploiting container escapes, metadata service attacks, and identity and access management (IAM) misconfiguration.
  • AI attacks: explaining prompt injection and model manipulation against artificial intelligence systems.
Live Tuition Sessions

Our tutors are all industry leading professionals with extensive experience in their field. Our tutors continue to operate and lead in their industries which keeps our curriculum and course content up to date and aligned with employers expectations. You will also have access to our online learning platform , where you can contact your tutor directly between sessions.

Accredited Courses

All of our courses include accredited qualifications. We are authorised partners of CompTIA, AWS, Microsoft and the Chartered Institute of Marketing (CIM). To enhance your learning experience, we have also partnered with a specialist, industry leading Penetration Testing company; North Green Security.

Job Interview Guarantee

Our team has a combined 30+ years of experience recruiting into the IT & Tech sector, with a sharp focus on early careers. Our network of employers and reputation in the industry enables us to guarantee an interview for everyone that completes their course and passes their exam. You will have full transparency over the recruitment process and the interview and job role will be specific to your skills and experience.

Flexible, Part Time, Online Learning Solutions

We strive to make our courses as accessible as possible. We have a range of part time, online delivery models to suit your current career and responsibilities. Whilst it's important for us to complete your qualification and fire up your career change as quickly as possible, we also want to fit in with your current schedule.

Interest Free Payment Plans

Our interest free, flexible payment plans are designed to make your career change as seamless as possible. If you don't want to pay in full, you can spread the cost over 3, 6, 9 or 12 interest free installments. There are no deposits, finance agreement or credit checks.

Exam Pass Rate
0 %
Learners on Programme
0 +
Interview Guarantee
0 %
Employer Network
0 +

Excellent