Penetration Testing
Professional-level course
A penetration-testing course that opens with methodology and moves to the tools - Nmap, Burp Suite, Metasploit and the OWASP Top 10 - against targets built for the purpose in the lab. Graduates can plan an engagement, gather intelligence, exploit a weakness, escalate privileges and move laterally across an Active Directory domain, and write a report a client can act on.
- Registration
- Waiting list
- Duration
- 32 academic hours
- Format
- In personHybrid
- Level
- Professional
- Certification
- SpotAcademy certificate of completion
- Language
- Hebrew, course materials in English
- For organisations
- By arrangement - at the academy or hybrid
What you will be able to do
- Scope an engagement and agree rules of engagement before any testing begins.
- Enumerate a target with Nmap and map its attack surface.
- Find and exploit web-application flaws using Burp Suite and the OWASP Top 10.
- Gain a foothold with public exploits and Metasploit, then escalate privileges on Linux and Windows.
- Enumerate and attack an Active Directory domain and move laterally through it.
- Write a penetration-test report with evidence and remediation a client can act on.
The syllabus
8 modules over 32 academic hours. Open a module for its topics.
- The phases of a penetration test
- Scoping and rules of engagement
- Documentation and evidence expectations
- Passive and active reconnaissance
- Host and service discovery with Nmap
- Enumeration of common services
- Vulnerability scanning and analysis
- The OWASP Top 10
- Intercepting and manipulating traffic with Burp Suite
- Injection, authentication and access-control flaws
- File upload and SSRF
- Finding and adapting public exploits
- The Metasploit Framework and payloads
- Client-side and password attacks
- Gaining an initial foothold
- Linux privilege escalation
- Windows privilege escalation
- Credential harvesting
- Enumerating escalation paths
- Enumerating an Active Directory domain
- The assumed-compromise scenario
- Lateral movement and pass-the-hash
- Domain privilege escalation
- Port forwarding and tunnelling
- Pivoting between network segments
- Persistence and cleanup
- Collecting evidence
- Writing the technical report
- Evidence and remediation guidance
- A 24-hour style challenge lab
- Mapping to OSCP+, PenTest+ PT0-003 and CEH v13
Who it is for
Who takes this course, and what you need before the first session.
Security engineers and analysts moving into offensive work.
IT and system people who want to test their own environments.
Anyone preparing for OSCP, PenTest+ or CEH.
Prerequisites
The course requires a working grasp of Linux and the command line, familiarity with TCP/IP networking and, ideally, some Python or scripting.
The exam and the certification
The course prepares for several recognised certification exams in offensive security. OffSec PEN-200 leads to a 24-hour practical exam that on passing issues both OSCP and OSCP+ (three standalone machines and one Active Directory set); CompTIA PenTest+ in the PT0-003 version (up to 90 questions, 165 minutes); and EC-Council CEH v13 - the 312-50 knowledge exam (125 questions, 4 hours) alongside CEH Practical. The exams are sat in English with the vendor; OSCP does not expire, and OSCP+ is valid for three years.
The certification
SpotAcademy certificate of completion
CompTIA PenTest+
PT0-003: up to 90 questions including performance-based items, 165 minutes, passing score 750 on a 100-900 scale; three-year renewal cycle. Booked through Pearson VUE.
OffSec OSCP
A 24-hour proctored practical exam, sat after OffSec's own PEN-200 course. Passing issues both OSCP, which does not expire, and OSCP+, valid three years.
EC-Council CEH
CEH v13: exam 312-50, 125 questions, four hours, at a test centre or remotely proctored. CEH Practical is a separate six-hour exam; holding both gives CEH Master.
The labs
Practice runs from the lab's Kali Linux against a range of vulnerable targets built for the purpose - Linux and Windows servers and a full Active Directory domain. Participants scan, exploit web and system flaws, escalate privileges and move laterally through the domain, and finish with a 24-hour-style challenge and a written report.
Two ways to take the course
The waiting list for the next open cohort, or an intensive format for a team - which a team can have on its own dates, whatever the open cohorts are doing.
The next cohort
The next cohort is in planning - 32 academic hours at the academy in Shoham. A hybrid option is available, with part of the sessions remote. Join the waiting list and you hear the dates first; the list is also what decides which course opens next.
For your team
An intensive format, by arrangement - at the academy in Shoham, or hybrid with part of the sessions remote. Small groups, and a syllabus adjusted to your equipment and environment.
Related courses
SOC Analyst, Tier 1-2
A course that trains a SOC analyst to work the SIEM on Splunk - reading alerts, triaging and enriching them, and handling an incident from the first sign to closure. Graduates can tell a real incident from a false positive, investigate it and pass it on to Tier 2, and sit prepared for the Splunk, CompTIA and Microsoft SOC certification exams.
Explore Foundation Opening soonPython for network and security automation
A hands-on Python course that teaches enough to automate the daily work of a network or security team - device configuration, log parsing and API calls - written and run in class. Graduates write scripts that talk to Splunk, to Microsoft Sentinel and to network gear, and arrive prepared for the Python Institute PCEP and PCAP exams.
Explore Foundation Opening soonLinux Administration
Linux administration from the first shell prompt to a running server - the command line, users and permissions, storage, services, networking and shell scripts - on Linux servers of your own in the lab. You leave able to build a Linux server, maintain it and troubleshoot it, with the material of the LPIC-1 and CompTIA Linux+ exams covered.
Explore