Skip to content

Ethical Hacking Mastery Path

Mastery Path
BOOTCAMP

Ethical hacking is the practice of finding security weaknesses the way an attacker would — but with written permission, inside an agreed scope, and with the goal of getting them fixed. The skill that separates a professional from someone who just runs tools is not knowing one more exploit; it is knowing what you are allowed to touch, how to prove impact without causing harm, and how to write it up so the finding actually gets remediated. This course teaches the full workflow, and it teaches it the only way that is legal to practise: against targets you own or are explicitly authorized to test.

Authorization is the whole job

Every technique here is for systems you own or have written permission to test. Running any of it against a system you do not have explicit authorization for is a crime in most countries (in the United States, the Computer Fraud and Abuse Act; in the UK, the Computer Misuse Act 1990; in India, the Information Technology Act, 2000 §43 & §66). There is no "I was just learning" exemption. Level 1 shows you how to build an isolated lab so you can practise everything in this course without ever touching a system you do not own.

Level 1 builds the foundation: what authorization and scope actually mean, how to stand up an isolated practice lab, the penetration-testing lifecycle, the Linux command line a tester leans on, networking seen through a tester's eyes, passive OSINT, active scanning with Nmap, service enumeration, and how CVEs and CVSS work — ending with a full recon-and-enumeration pass over your own lab range. Level 2 is web application testing against deliberately vulnerable practice apps (DVWA, OWASP Juice Shop): the testing mindset, intercepting proxies, injection and SQL injection, XSS, broken authentication, broken access control and IDOR, SSRF and file-upload flaws, misconfiguration and vulnerable components, and API testing — ending with a structured assessment of Juice Shop. Level 3 moves to infrastructure in the lab: vulnerability scanning and validation, exploitation fundamentals with Metasploit, password attacks on hashes you generate, Linux and Windows privilege escalation, Active Directory attack paths, pivoting, wireless testing on your own access point, and authorized phishing simulation — ending with an internal network pentest. Level 4 is the professional craft: post-exploitation and evidence handling, writing the report, scoping and rules of engagement, threat modeling, cloud and mobile testing basics, how red teaming and bug bounty differ from a pentest, certifications and careers, the law and responsible disclosure — and a capstone that runs a complete engagement end to end.

Every lesson has a How It Actually Works section — why a SYN scan needs no full handshake, what a prepared statement changes at the database so injection fails, how a set-uid binary becomes a privilege-escalation path, why an NTLM hash is enough to authenticate without ever cracking it, how a reverse shell's bytes traverse your lab network.

This course pairs with the broader Cybersecurity Mastery Path, which covers defence, blue-team operations, forensics, SOC and governance. Where the two touch (networking, OWASP, pentest methodology), this course stays on the hands-on offensive-testing side and links across rather than repeating.

Honest about what runs

This is a conceptual-plus-lab course written to be safe and legal. Commands against your own lab (Nmap against 127.0.0.1, hashing and cracking a password you generated, a local web app) are shown as real, reproducible steps. Anything that needs infrastructure this course can't legally or practically spin up — a cloud account, a real Active Directory forest, a wireless radio, a paid scanner like Nessus — is described faithfully and labelled as set up in your own lab; this course never fabricates tool output, version numbers or benchmarks, and says plainly when a step is something you must run in your own environment.

How the program is organized

Level Focus Modules What you can do after
1 · Foundations & Legal Lab Authorization, lab, recon, scanning, enumeration 10 Legally stand up a lab and map a target you own
2 · Web Application Testing OWASP flaws in practice apps, proxies, APIs 10 Run a methodical web app assessment and write findings
3 · Infrastructure & Network Exploitation, privesc, AD, pivoting, wireless, SE 10 Carry an internal network test from foothold to report
4 · Professional Practice Reporting, scoping, cloud/mobile, law, careers 10 Run a full authorized engagement professionally

Each level has 9 teaching modules plus a hands-on project (module 10), for 40 lessons total.

How to use this site

  • Start at Level 1, module 1, and build the lab first. Do not skip the lab — it is what makes the rest of the course legal to practise.
  • Type the commands yourself against your own lab. Reading a scan is not the same as running one and reading the output.
  • Keep notes as you go. Level 4 teaches reporting, but good notes start on lesson one — every professional engagement is only as good as its evidence trail.
  • Respect scope at all times, including in your own lab, so the habit is automatic when a real engagement has a narrow one.

More from the Mastery Path series

Free, structured, module-wise training across 81 other languages, platforms and disciplines:

Languages

Web Frameworks

Mobile

Testing & QA

Security

Cloud Platforms

Data & Analytics

AI / ML / LLM

Embedded Systems

Leadership & Management

Professional Skills

Careers & Interviews

Process & APIs

Infrastructure & Ops