Intermediate · 12 weeks
Ethical Hacking & Penetration Testing
Hands-on offensive security, in twelve weeks.
- Live online, from anywhere
- 12 weeks
- A 2-hour live class every Monday
- 4 hours a week
- Next cohort: 15 January 2027
Who it’s for
- Future pentesters. You want a serious, hands-on route into penetration testing.
- Security+ or PenTest+ holders. You have the theory and want deep practical work.
- Bug bounty hunters. You want structured fundamentals behind your hunting.
Who it isn’t for
- You’ve never used Linux or a command line: start with Introduction to Cybersecurity.
- You want an exam-prep course: CompTIA PenTest+ is built around the exam.
- You want to test systems you don’t have permission to test. We teach the opposite.
Before you start: Comfortable on the command line, and the basics of networking (IP addresses, ports, protocols). Security+ level knowledge, or Introduction to Cybersecurity, is the right starting point.
What you’ll build
A full multi-network penetration test with live report delivery. The report becomes the centrepiece of your portfolio.
Curriculum
11 modules, 12 weeks
Twelve weeks from networking fundamentals to compromising a full lab enterprise: web applications, Active Directory, internal networks and privilege escalation. Every attack happens in our own lab, against systems built to be broken into.
01The pentester’s toolkit and Linux
- Kali Linux
- Bash scripting
- tmux, SSH and pivoting basics
- Setting up your lab
02Networking and protocol attacks
- TCP/IP for testers
- Packet crafting with Scapy
- ARP, DNS and DHCP attacks
- Man-in-the-middle techniques
03Reconnaissance and OSINT
- Passive and active recon
- Subdomain discovery
- Search engine and Shodan techniques
- Mapping the attack surface
04Vulnerability analysis
- Nessus, OpenVAS and Nuclei
- Manual verification
- Triage of false positives
- Risk scoring
05Exploitation
- The Metasploit framework
- Manual exploitation
- Payloads with msfvenom
- Antivirus evasion basics
06Web application testing
- The OWASP Top 10, hands-on
- A Burp Suite workflow
- SQLi, XSS, SSRF and IDOR
- Authentication bypass
07Active Directory
- Enumeration with BloodHound
- Kerberoasting and AS-REP roasting
- Pass-the-hash and pass-the-ticket
- Domain compromise
08Privilege escalation
- Linux
- Windows
- Misconfigurations and known CVEs
- LinPEAS and WinPEAS
09Wireless and physical
- WPA2 and WPA3 attacks
- Evil twin access points
- USB drop attacks
- Badge cloning basics
10Reporting
- Reports clients actually use
- CVSS scoring
- Executive summaries
- Re-test workflows
11Capstone
- A multi-network engagement
- Web, AD and privilege escalation combined
- Live report delivery
- Client debrief
Get the full syllabus
Every module, lab and tool as a one-page PDF. Enter your email and it downloads straight away.
How you learn
A week on the track
Live classes
A 2-hour live class every Monday. The time is confirmed when you enrol.
Mentor hours
Small-group office hours with a practising security engineer, every week
Labs
A hands-on lab every week
Tools
Kali Linux, Burp Suite, Metasploit, Nmap, BloodHound, Impacket
Two kinds of lab: guided labs in our cloud environment, with nothing to install, and some virtual-machine work on your own laptop. We help you set the virtual machines up.
- MonLive class2-hour instructor-led session with real-world examples
- TueGuided labHands-on lab in our cloud environment
- WedMentor hoursSmall-group office hours with a practising security engineer
- ThuSolo challengeA timed challenge to lock in the week’s concepts
- FriCTF FridayTeam capture-the-flag with a leaderboard

$ nmap -sV -Pn 10.10.20.0/24Nmap scan report for dc01.lab.learncyber (10.10.20.10)88/tcp open kerberos-sec Microsoft Windows Kerberos389/tcp open ldap Microsoft Windows AD LDAP445/tcp open microsoft-ds$ GetUserSPNs.py lab.learncyber/analyst -request[*] 3 service accounts with SPNs found$ hashcat -m 13100 tickets.txt wordlist.txtsvc_backup: cracked (weak password)
Exam and certificate
There’s no external exam built in. You finish with a LearnCyber certificate of completion and a full penetration test report for your portfolio. Many of the skills overlap with certifications such as OSCP or PNPT, which are set by other organisations.
Certificate, not certification
You receive a LearnCyber certificate of completion. It proves you completed the track, and employers can check it online. A certification is awarded by an exam body such as CompTIA.
What you’ll need
- Laptop
- A laptop with at least 8 GB of RAM and a stable internet connection
- Internet
- A connection that can hold a video call; every class is recorded if yours drops
- Time
- 4 hours a week, including the 2-hour live class
Who teaches
Taught by Hackrowd Technology’s working penetration testers, the team that does this work for clients.
Offensive security
Penetration tests of web apps, APIs, networks and Active Directory for client organisations.
Security operations
SOC work: monitoring, detection and incident response.
Governance and audit
GRC programmes and ISO 27001 audits.
After the track
- Step 1
Train
Live classes, labs and your capstone.
- Step 2
Internship
A three-month internship after the training.
- Step 3
Certificate and letter
A certificate of completion employers can verify, and a recommendation letter.
Admissions
Three steps to your seat
- Step 1Join a free webinar
Meet an instructor and ask anything first.
- Step 2Apply
A short questionnaire, not a test, so we can recommend the right track.
- Step 3Reserve your seat
Pay in full or in instalments. Your place is confirmed when the payment clears.
Questions
Is there a job guarantee?
No. No reputable school can guarantee you a job, and we won’t pretend to. What you do get: hands-on labs, a portfolio piece you can show an employer, and CV and interview coaching.
Is this legal?
Yes. Everything happens in our isolated lab, or against targets built to be attacked with permission. Testing anything you aren’t authorised to test is against our code of conduct.
Do I need programming skills?
You need to be comfortable on the command line. Some Python or Bash helps; we teach what you need.
Will this prepare me for OSCP?
It covers much of the ground OSCP tests. OSCP is set and certified by OffSec, not by us.
What’s the time commitment?
4 hours a week, including the 2-hour live class on Monday.
Ready to start Ethical Hacking & Penetration Testing?