Skip to content

Level 1 · Foundations & Legal Lab

Before anyone runs a single scan, two things have to be true: the work must be authorized, and there must be a safe place to practise. Level 1 settles both, then teaches the opening moves of every engagement — reconnaissance, scanning and enumeration — against targets you build and own.

You will finish this level able to legally stand up an isolated lab, understand the lifecycle a professional test follows, drive the Linux command line a tester relies on, and map a target host from "I know its IP" to "I have a ranked list of its services and likely weak points."

Modules

  1. What Ethical Hacking Is — Authorization, Scope & the Law — the difference permission makes, scope, rules of engagement, and the laws you must know.
  2. Building a Legal, Isolated Practice Lab — host-only networking, intentionally vulnerable targets, and keeping the lab off the internet.
  3. The Penetration Testing Lifecycle — PTES and the OSSTMM, and the phases from pre-engagement to reporting.
  4. The Linux Command Line You'll Actually Use — the commands, pipes and text tools that carry a test.
  5. Networking Through a Tester's Lens — TCP/IP, ports, the handshake, and what each layer gives an attacker.
  6. Passive Reconnaissance & OSINT — gathering information without touching the target, and the scope rules that still apply.
  7. Active Scanning with Nmap — host discovery, port states, scan types, timing and NSE, run against your own lab.
  8. Service Enumeration — turning open ports into named, versioned services and a map of the attack surface.
  9. Vulnerabilities, CVE & CVSS — how weaknesses are named, scored and prioritised.
  10. Project — Recon & Enumeration of Your Lab Range — a full discovery pass written up as a findings worksheet.