๐
Intermediate16 hours estimated
Penetration Tester
Think like an attacker to defend better. This path covers the structured methodology, core techniques, and reporting skills required for professional penetration testing.
๐ 4 topic areas๐ 13 curated resources๐ 10 quiz questions
What you'll cover
Reconnaissance & OSINT
Passive and active information gathering: DNS, WHOIS, certificate transparency, social media, and job postings.
Web Application Vulnerabilities
Master OWASP Top 10: SQL injection, XSS, IDOR, SSRF, authentication flaws, and more.
Privilege Escalation
Escalate from low-privilege access to root/SYSTEM on Linux and Windows systems.
๐๐๐๐
GTFOBins: Linux Privesc
Unix binaries that can bypass security restrictions
LOLBAS: Windows Privesc
Living Off The Land Binaries and Scripts for Windows
TryHackMe: Privilege Escalation
Hands-on labs for Linux and Windows privilege escalation
Sudo Privilege Escalation Lesson
How misconfigured sudo rules become root, and how to lock them down
Pentest Reporting
Write reports that executives and developers actually act on: executive summary, findings, risk ratings, and remediation guidance.
Knowledge Check
Path Summary
- Level
- Intermediate
- Estimated time
- 16 hours
- Topics
- 4
- Resources
- 13
- Quiz questions
- 10
- Passing score
- 70% (7/10)