Skip to content

Level 3 · Infrastructure & Network Testing

Level 2 stayed inside one web app. Level 3 takes on hosts and networks: scanning them for weaknesses, gaining an initial foothold through a known-vulnerable service, escalating from a limited account to full control, moving through a network, and understanding how Windows domains fall. Everything here runs against machines you build in the lab from Level 1 — intentionally vulnerable VMs such as Metasploitable and retired practice boxes.

The emphasis is on understanding why each step works, not on memorising commands. A foothold is a known CVE met with a public module; privilege escalation is a misconfiguration; lateral movement is reused credentials. Once you see the pattern, the specific tool matters less.

Modules

  1. Vulnerability Scanning & Validation — automated scanners, their false positives, and manual validation.
  2. Exploitation Fundamentals & Metasploit — what an exploit is, payloads and shells, driven through the Metasploit Framework in the lab.
  3. Password Attacks & Cracking — hashing, wordlists, and cracking hashes you generate yourself with Hashcat and John.
  4. Linux Privilege Escalation — SUID binaries, sudo rules, cron and capabilities.
  5. Windows Privilege Escalation — services, tokens, and unquoted paths.
  6. Active Directory Attack Paths — how a domain is enumerated and why it falls: Kerberos, hashes and trust.
  7. Pivoting & Lateral Movement — using one foothold to reach a network you otherwise couldn't.
  8. Wireless Network Testing — Wi-Fi security, WPA2/WPA3, and testing your own access point.
  9. Social Engineering & Authorized Phishing Simulation — the human layer, and running a phishing simulation inside an authorized scope.
  10. Project — Internal Network Pentest — foothold to domain, documented at every step.