
Hands-On Hacking Course
Master real-world offensive security techniques through hands-on labs covering everything from reconnaissance to full domain compromise. You'll build a working hacker lab, exploit live vulnerabilities, and produce professional penetration test reports. This course is built for those who want practical skills that hold up in the field — not just theory.
What you will learn:
Configure a fully isolated hacking lab with vulnerable VMs and snapshot workflows.
Perform passive OSINT, network scanning, and service enumeration to map attack surfaces.
Exploit web application vulnerabilities including SQL injection, XSS, SSRF, and broken authentication.
Execute man-in-the-middle attacks, capture credentials, and crack password hashes offline.
Escalate privileges on Windows and Linux systems using proven, real-world techniques.
Produce client-ready penetration test reports with risk ratings and remediation guidance.
How you study in practice Hands-On Hacking Course
How you practise Hands-On Hacking Course
For businesses looking to train their team
With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.
Course content
8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsFoundations of Ethical Hacking
Foundations of Ethical Hacking
Lesson 1 • The Hacker Mindset and Ethics
Defines offensive security roles, attacker motivations, and the ethical boundaries that separate authorised testing from criminal activity. Anchors all subsequent technical work in professional responsibility.
Lesson 2 • Introduction to Kali Linux and Core Tools
Orients students to the Kali Linux filesystem, package management, and the essential toolset used throughout the course. Builds command-line fluency required for all later modules.
Lesson 3 • Core Networking Concepts for Hackers
Reviews TCP/IP, DNS, HTTP, and routing fundamentals through an attacker's lens. Provides the protocol literacy needed to understand every subsequent exploitation technique.
Lesson 4 • Building a Safe Lab Environment
Guides students through hypervisor setup, vulnerable VM deployment, and network isolation. A functional lab is the prerequisite for every hands-on exercise in the course.
Lesson 5 • Legal and Regulatory Foundations
Surveys computer-crime statutes, authorisation requirements, and contractual obligations that govern penetration testing engagements. Ensures students can identify legal risk before touching a target.
Chapter 2HideHide detailsSee detailsReconnaissance and Information Gathering
Reconnaissance and Information Gathering
Lesson 1 • Network Scanning and Host Discovery
Applies Nmap and similar tools to identify live hosts, open ports, and operating systems across a target network. Results form the foundation for service-level enumeration.
Lesson 2 • DNS and Domain Enumeration
Demonstrates zone transfers, brute-force subdomain discovery, and DNS record analysis to map an organisation's internet-facing footprint. Feeds directly into port scanning and service enumeration.
Lesson 3 • Organising and Reporting Recon Data
Structures collected intelligence into a target profile using mind maps, spreadsheets, and note-taking tools. Prepares students to translate raw data into actionable attack plans.
Lesson 4 • Service and Version Enumeration
Extracts service banners, version strings, and configuration details from open ports to identify exploitable software. Bridges raw scan data to vulnerability identification.
Lesson 5 • Passive OSINT Techniques
Covers search-engine dorking, WHOIS lookups, certificate transparency, and social-media profiling without touching target infrastructure. Establishes the intelligence baseline for active recon.
Chapter 3HideHide detailsSee detailsVulnerability Scanning and Analysis
Vulnerability Scanning and Analysis
Lesson 1 • Manual Vulnerability Verification
Teaches techniques to confirm scanner findings without triggering exploits, reducing false positives before reporting. Reinforces the difference between detection and exploitation.
Lesson 2 • Vulnerability Scoring and Prioritisation
Applies CVSS scoring, asset criticality, and exploitability factors to rank vulnerabilities by business risk. Enables students to focus exploitation efforts on highest-impact targets.
Lesson 3 • Using Nessus and OpenVAS
Provides hands-on configuration and execution of industry-standard scanners against lab targets. Students interpret raw scan output and export findings for analysis.
Lesson 4 • Web Application Vulnerability Scanning
Introduces DAST tools such as Nikto and OWASP ZAP for automated web vulnerability discovery. Prepares students for the manual web exploitation techniques covered in later chapters.
Lesson 5 • Vulnerability Scanning Fundamentals
Explains how scanners detect misconfigurations and known CVEs through credentialed and uncredentialed checks. Sets expectations for scanner accuracy and false-positive rates.
Chapter 4HideHide detailsSee detailsExploitation Fundamentals
Exploitation Fundamentals
Lesson 1 • Exploiting Common Network Services
Targets vulnerable versions of SMB, FTP, and SSH services using both Metasploit modules and manual exploits. Reinforces the link between enumeration findings and exploit selection.
Lesson 2 • The Exploitation Lifecycle
Maps the stages from vulnerability selection through payload delivery to session establishment. Provides a repeatable mental model applied in every subsequent exploitation exercise.
Lesson 3 • Metasploit Framework Mastery
Covers the Metasploit console, module taxonomy, and option configuration for rapid exploit deployment. Students run their first successful exploit against a vulnerable lab service.
Lesson 4 • Post-Exploitation Basics
Covers immediate post-shell actions: system enumeration, privilege checking, and persistence setup. Bridges initial access to the deeper post-exploitation chapter that follows.
Lesson 5 • Client-Side Exploitation Techniques
Demonstrates browser, document, and macro-based exploits that target end-user systems rather than servers. Introduces social-engineering delivery vectors used in phishing simulations.
Chapter 5HideHide detailsSee detailsWeb Application Hacking
Web Application Hacking
Lesson 1 • Injection Attacks: SQL and Beyond
Teaches manual and tool-assisted SQL injection, command injection, and LDAP injection against vulnerable applications. Students extract database contents and achieve OS-level command execution.
Lesson 2 • Authentication and Authorisation Flaws
Exploits weak passwords, broken access controls, insecure direct object references, and JWT vulnerabilities to escalate privileges within web applications. Directly applicable to real-world assessments.
Lesson 3 • Web Application Architecture for Attackers
Maps client-server communication, authentication flows, and session management from an attacker's perspective. Establishes the technical context for every web vulnerability class that follows.
Lesson 4 • Advanced Web Exploitation Techniques
Covers SSRF, XXE, file upload bypasses, and deserialisation vulnerabilities that lead to remote code execution. Prepares students for complex, chained web attack scenarios.
Lesson 5 • Cross-Site Scripting and CSRF
Demonstrates reflected, stored, and DOM-based XSS alongside cross-site request forgery to compromise user sessions and perform unauthorised actions. Covers both attack and impact validation.
Chapter 6HideHide detailsSee detailsNetwork Attacks and Traffic Analysis
Network Attacks and Traffic Analysis
Lesson 1 • ARP Poisoning and MitM Attacks
Executes ARP cache poisoning with Ettercap and Bettercap to position an attacker between hosts and intercept traffic. Demonstrates real-time credential theft and session hijacking.
Lesson 2 • Packet Capture and Traffic Analysis
Uses Wireshark and tcpdump to capture, filter, and decode network traffic for credential and session data. Provides the analytical foundation for all active network attack techniques.
Lesson 3 • Password Cracking and Hash Analysis
Applies Hashcat and John the Ripper with wordlists, rules, and mask attacks to crack captured hashes offline. Reinforces credential harvesting outcomes from the post-exploitation chapter.
Lesson 4 • Wireless Network Attacks
Targets WPA2 handshake capture, PMKID attacks, and evil-twin access points to compromise wireless networks. Extends MitM skills to the wireless attack surface.
Lesson 5 • Tunneling and Covert Channels
Demonstrates DNS tunnelling, ICMP covert channels, and SSH port forwarding to exfiltrate data and bypass firewalls. Prepares students for advanced pivoting and C2 communication.
Chapter 7HideHide detailsSee detailsPrivilege Escalation and Post-Exploitation
Privilege Escalation and Post-Exploitation
Lesson 1 • Persistence and Defence Evasion
Establishes covert persistence through scheduled tasks, registry run keys, and backdoored services while evading common defences. Teaches students to maintain access across reboots.
Lesson 2 • Linux Privilege Escalation
Identifies SUID binaries, cron job misconfigurations, writable paths, and kernel exploits that elevate a low-privilege shell to root. Builds systematic enumeration habits for Linux targets.
Lesson 3 • Active Directory Attacks
Covers AS-REP roasting, DCSync, Golden Ticket, and domain trust abuse to achieve full Active Directory compromise. Represents the culmination of the privilege escalation chapter.
Lesson 4 • Windows Privilege Escalation
Targets unquoted service paths, weak registry permissions, token impersonation, and AlwaysInstallElevated to gain SYSTEM on Windows hosts. Mirrors real-world Windows assessment workflows.
Lesson 5 • Credential Harvesting and Lateral Movement
Extracts password hashes, plaintext credentials, and Kerberos tickets to move laterally across a network. Connects privilege escalation outcomes to domain-wide compromise.
Chapter 8HideHide detailsSee detailsPenetration Testing Methodology and Reporting
Penetration Testing Methodology and Reporting
Lesson 1 • Simulated Full-Scope Engagement
Students execute a complete black-box penetration test against a multi-service lab environment from recon to report. Serves as the capstone assessment integrating all course competencies.
Lesson 2 • Engagement Planning and Scoping
Defines rules of engagement, scope boundaries, communication protocols, and emergency contacts before testing begins. Prevents legal and operational incidents during real engagements.
Lesson 3 • Evidence Collection and Chain of Custody
Establishes practices for timestamped screenshots, command logs, and hash-verified artefacts that support findings. Ensures findings are defensible and reproducible during client review.
Lesson 4 • Writing Professional Penetration Test Reports
Structures executive summaries, technical findings, risk ratings, and remediation guidance into a polished deliverable. Translates technical exploitation outcomes into business-relevant language.
Lesson 5 • Structured Testing Methodologies
Compares PTES, OWASP Testing Guide, and NIST SP 800-115 frameworks to provide a repeatable testing structure. Enables students to align their work with industry-recognised standards.
Your valid completion certificate
This course is for you:
Aspiring penetration tester: wants structured, lab-based training before pursuing certifications.
IT support technician: ready to shift from fixing systems to testing their defences.
Computer science student: looking to build offensive security skills alongside academic coursework.
Cybersecurity analyst: seeking hands-on attack experience to strengthen their defensive perspective.
Career changer: motivated by security work and committed to building a new technical skill set.
CTF enthusiast: wants to move beyond puzzles and into professional assessment workflows.
What our students say
Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast and simple to use. The diversity of content and complementary videos really help with learning.

Top qualifications
FAQ
Who is Dedika?
Is the certificate valid in the United Kingdom?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















