Choose your language
Ethical Hacking Course
More than 20 lakh learners worldwide

Ethical Hacking Course

4.9

Master offensive security from the ground up with hands-on techniques used by professional penetration testers. This course covers every phase of ethical hacking — reconnaissance, exploitation, post-exploitation, and reporting — against realistic targets. Build the skills employers and clients actually pay for.

Dedika for businesses

What you will learn:

You will learn how to conduct authorised penetration tests across networks, web applications, Active Directory environments, and wireless infrastructure. The course covers passive and active reconnaissance, vulnerability scanning, exploitation with Metasploit, privilege escalation on both Windows and Linux, and credential harvesting. You will also test web applications for injection flaws, authentication weaknesses, and advanced vulnerabilities like SSRF and insecure deserialization. Supplementary modules introduce cloud security testing, social engineering, scripting automation, and red team operations. Every topic is grounded in real attacker techniques mapped to professional engagement standards.

How you study in a practical way Ethical Hacking Course

How you practise Ethical Hacking Course

For companies looking to train their teams

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course content

8 Chapters • 39 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Ethical Hacking

  • Lesson 1 • Core Networking Concepts for Hackers

    Reviews TCP/IP, DNS, HTTP, and routing fundamentals required for all attack techniques. Bridges general networking knowledge to offensive security application.

  • Lesson 2 • Setting Up a Safe Lab Environment

    Guides students through building an isolated virtual lab for all hands-on exercises. Ensures no real-world systems are exposed during practice.

  • Lesson 3 • Defining Ethical Hacking and Its Scope

    Covers the distinction between ethical hacking, penetration testing, and malicious hacking. Anchors the chapter by framing professional purpose and authorised boundaries.

  • Lesson 4 • Legal and Ethical Frameworks

    Examines consent requirements, liability exposure, and professional codes of conduct. Students learn to operate within enforceable boundaries before touching any system.

  • Lesson 5 • Hacking Methodology Overview

    Introduces the five-phase penetration testing lifecycle used throughout the course. Provides a repeatable framework students apply in every subsequent chapter.

Chapter 2See details

Reconnaissance and Open-Source Intelligence

  • Lesson 1 • Passive Reconnaissance Techniques

    Teaches intelligence gathering without touching target infrastructure. Establishes the safest first phase of any engagement.

  • Lesson 2 • Active Reconnaissance Methods

    Covers direct probing techniques that interact with target systems within authorised scope. Bridges passive intelligence to hands-on scanning in the next chapter.

  • Lesson 3 • Reconnaissance Automation and Tooling

    Demonstrates scripting and tool chaining to accelerate information gathering at scale. Students build repeatable recon workflows for professional engagements.

  • Lesson 4 • Open-Source Intelligence Frameworks

    Introduces structured OSINT methodologies and tooling for aggregating public data. Students learn to correlate disparate data points into actionable intelligence.

Chapter 3See details

Scanning, Enumeration, and Vulnerability Analysis

  • Lesson 1 • Service and OS Fingerprinting

    Identifies running services, versions, and operating systems on discovered hosts. Feeds directly into vulnerability matching in later sections.

  • Lesson 2 • Network Enumeration Techniques

    Extracts users, shares, and configurations from network services within scope. Provides the detailed target data needed for targeted exploitation.

  • Lesson 3 • Vulnerability Scanning and Analysis

    Uses automated scanners to match discovered services against known vulnerability databases. Students learn to interpret, validate, and prioritise scanner output.

  • Lesson 4 • Host Discovery and Port Scanning

    Teaches techniques to identify live hosts and open ports across a target network. Forms the first active footprint of the attack surface.

  • Lesson 5 • Manual Vulnerability Verification

    Validates scanner findings through manual testing to confirm exploitability. Prevents wasted effort on false positives during the exploitation phase.

Chapter 4See details

Exploitation Fundamentals

  • Lesson 1 • Client-Side Exploitation Techniques

    Covers attacks that target end-user applications rather than server services. Expands the attack surface understanding beyond network-facing services.

  • Lesson 2 • Exploit Development Concepts

    Explains how exploits work at a conceptual level, including memory corruption and logic flaws. Gives students the mental model needed to select and adapt exploits.

  • Lesson 3 • Exploiting Common Service Vulnerabilities

    Applies exploitation techniques to frequently vulnerable services such as SMB, FTP, and web servers. Reinforces framework skills with realistic target scenarios.

  • Lesson 4 • Exploit Chaining and Pivoting Basics

    Demonstrates combining multiple vulnerabilities to reach deeper network segments. Prepares students for the post-exploitation and lateral movement chapters ahead.

  • Lesson 5 • Using Exploitation Frameworks

    Introduces Metasploit as the primary exploitation framework for structured attack execution. Students learn module selection, payload configuration, and session management.

Chapter 5See details

Post-Exploitation and Privilege Escalation

  • Lesson 1 • Post-Exploitation Goals and Methodology

    Defines objectives after initial access: data identification, persistence, and lateral movement. Frames all subsequent sections within professional engagement goals.

  • Lesson 2 • Credential Harvesting and Lateral Movement

    Extracts credentials from memory, files, and registries to move across the network. Connects privilege escalation outcomes to broader network compromise.

  • Lesson 3 • Persistence and Backdoor Techniques

    Establishes reliable re-entry mechanisms that survive reboots and user logoffs. Students understand attacker persistence to better advise defensive teams.

  • Lesson 4 • Windows Privilege Escalation

    Covers techniques to elevate from standard user to SYSTEM on Windows hosts. Builds on exploitation skills using misconfigurations and token abuse.

  • Lesson 5 • Linux Privilege Escalation

    Teaches escalation from low-privilege shell to root on Linux systems. Covers SUID binaries, sudo misconfigurations, and kernel exploits.

Chapter 6See details

Web Application Penetration Testing

  • Lesson 1 • Web Application Reconnaissance

    Maps application structure, technologies, and entry points before active testing. Applies recon skills from earlier chapters to the web application context.

  • Lesson 2 • Authentication and Session Attacks

    Tests login mechanisms, session tokens, and access control implementations for weaknesses. Directly impacts confidentiality and authorization integrity of applications.

  • Lesson 3 • Cross-Site Scripting and CSRF

    Demonstrates reflected, stored, and DOM-based XSS alongside cross-site request forgery. Teaches client-side attack vectors that compromise end users.

  • Lesson 4 • Advanced Web Vulnerabilities

    Explores SSRF, XXE, insecure deserialization, and broken access control. Prepares students for complex, chained web application attack scenarios.

  • Lesson 5 • Injection Vulnerabilities

    Covers SQL injection, command injection, and LDAP injection attack and detection. Represents the highest-impact vulnerability class in web application testing.

Chapter 7See details

Network and Infrastructure Attacks

  • Lesson 1 • Firewall and IDS Evasion

    Demonstrates techniques to bypass perimeter controls and avoid detection during engagements. Prepares students for realistic environments with active defenses.

  • Lesson 2 • Active Directory Attacks

    Targets Active Directory authentication, delegation, and trust relationships for domain compromise. Represents the most common enterprise attack path in real engagements.

  • Lesson 3 • VPN and Remote Access Attacks

    Tests VPN configurations and remote access services for authentication and implementation flaws. Addresses the expanded attack surface of remote work environments.

  • Lesson 4 • Wireless Network Penetration Testing

    Tests WPA2 and enterprise wireless networks for authentication and encryption weaknesses. Extends the attack surface to physical and wireless perimeters.

  • Lesson 5 • Network Protocol Attacks

    Exploits weaknesses in ARP, DNS, and routing protocols to intercept or redirect traffic. Builds on networking fundamentals from Chapter 1 with offensive application.

Chapter 8See details

Reporting, Remediation, and Professional Delivery

  • Lesson 1 • Building a Professional Pentest Practice

    Addresses scoping, pricing, contracts, and continuous skill development for practitioners. Prepares students to operate as independent or employed security professionals.

  • Lesson 2 • Remediation Guidance and Validation

    Provides actionable fix recommendations for each vulnerability class covered in the course. Includes retesting methodology to confirm remediation effectiveness.

  • Lesson 3 • Engagement Debrief and Client Handoff

    Covers the final meeting, evidence handling, and data destruction after an engagement. Ensures professional closure and protects both client and tester.

  • Lesson 4 • Penetration Test Report Structure

    Defines the components of a professional pentest report from executive summary to technical appendix. Establishes the deliverable standard for all student assessments.

  • Lesson 5 • Communicating Risk to Stakeholders

    Teaches translation of technical severity into business impact language for non-technical audiences. Bridges the gap between hacker findings and executive decision-making.

Certification

Your valid completion certificate

This course is for you:

  • IT support technician: ready to pivot into offensive security roles.

  • Networking professional: wants to apply infrastructure knowledge to attack scenarios.

  • Computer science student: building practical skills beyond academic coursework.

  • Career changer: drawn to cybersecurity and committed to learning it properly.

  • Junior sysadmin: seeking credentials and hands-on skills for security advancement.

  • Bug bounty hobbyist: needs a structured methodology to improve finding quality.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content that I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way of presentation and video transcription, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos help a lot in learning.
André Felipe
André FelipePrompt Engineering Student

Top qualifications

FAQs

Who is Dedika?

Is the certificate valid in India?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course