
Ethical Hacking Course
Master offensive security from the ground up with hands-on techniques used by professional penetration testers. This course covers every phase of ethical hacking — reconnaissance, exploitation, post-exploitation, and reporting — against realistic targets. Build the skills employers and clients actually pay for.
What you will learn:
You will learn how to conduct authorised penetration tests across networks, web applications, Active Directory environments, and wireless infrastructure. The course covers passive and active reconnaissance, vulnerability scanning, exploitation with Metasploit, privilege escalation on both Windows and Linux, and credential harvesting. You will also test web applications for injection flaws, authentication weaknesses, and advanced vulnerabilities like SSRF and insecure deserialization. Supplementary modules introduce cloud security testing, social engineering, scripting automation, and red team operations. Every topic is grounded in real attacker techniques mapped to professional engagement standards.
How you study in practice Ethical Hacking Course
How you practise Ethical Hacking Course
For companies looking to train their teams
With Dedika for Businesses, the course includes exercises and examples tailored to your own business and the specific needs of your company.
Course content
8 Chapters • 39 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsFoundations of Ethical Hacking
Foundations of Ethical Hacking
Lesson 1 • Core Networking Concepts for Hackers
Reviews TCP/IP, DNS, HTTP, and routing fundamentals required for all attack techniques. Bridges general networking knowledge to offensive security application.
Lesson 2 • Setting Up a Safe Lab Environment
Guides students through building an isolated virtual lab for all hands-on exercises. Ensures no real-world systems are exposed during practice.
Lesson 3 • Defining Ethical Hacking and Its Scope
Covers the distinction between ethical hacking, penetration testing, and malicious hacking. Anchors the chapter by framing professional purpose and authorised boundaries.
Lesson 4 • Legal and Ethical Frameworks
Examines consent requirements, liability exposure, and professional codes of conduct. Students learn to operate within enforceable boundaries before touching any system.
Lesson 5 • Hacking Methodology Overview
Introduces the five-phase penetration testing lifecycle used throughout the course. Provides a repeatable framework students apply in every subsequent chapter.
Chapter 2HideHide detailsSee detailsReconnaissance and Open-Source Intelligence
Reconnaissance and Open-Source Intelligence
Lesson 1 • Passive Reconnaissance Techniques
Teaches intelligence gathering without touching target infrastructure. Establishes the safest first phase of any engagement.
Lesson 2 • Active Reconnaissance Methods
Covers direct probing techniques that interact with target systems within authorised scope. Bridges passive intelligence to hands-on scanning in the next chapter.
Lesson 3 • Reconnaissance Automation and Tooling
Demonstrates scripting and tool chaining to accelerate information gathering at scale. Students build repeatable recon workflows for professional engagements.
Lesson 4 • Open-Source Intelligence Frameworks
Introduces structured OSINT methodologies and tooling for aggregating public data. Students learn to correlate disparate data points into actionable intelligence.
Chapter 3HideHide detailsSee detailsScanning, Enumeration, and Vulnerability Analysis
Scanning, Enumeration, and Vulnerability Analysis
Lesson 1 • Service and OS Fingerprinting
Identifies running services, versions, and operating systems on discovered hosts. Feeds directly into vulnerability matching in later sections.
Lesson 2 • Network Enumeration Techniques
Extracts users, shares, and configurations from network services within scope. Provides the detailed target data needed for targeted exploitation.
Lesson 3 • Vulnerability Scanning and Analysis
Uses automated scanners to match discovered services against known vulnerability databases. Students learn to interpret, validate, and prioritise scanner output.
Lesson 4 • Host Discovery and Port Scanning
Teaches techniques to identify live hosts and open ports across a target network. Forms the first active footprint of the attack surface.
Lesson 5 • Manual Vulnerability Verification
Validates scanner findings through manual testing to confirm exploitability. Prevents wasted effort on false positives during the exploitation phase.
Chapter 4HideHide detailsSee detailsExploitation Fundamentals
Exploitation Fundamentals
Lesson 1 • Client-Side Exploitation Techniques
Covers attacks that target end-user applications rather than server services. Expands the attack surface understanding beyond network-facing services.
Lesson 2 • Exploit Development Concepts
Explains how exploits work at a conceptual level, including memory corruption and logic flaws. Gives students the mental model needed to select and adapt exploits.
Lesson 3 • Exploiting Common Service Vulnerabilities
Applies exploitation techniques to frequently vulnerable services such as SMB, FTP, and web servers. Reinforces framework skills with realistic target scenarios.
Lesson 4 • Exploit Chaining and Pivoting Basics
Demonstrates combining multiple vulnerabilities to reach deeper network segments. Prepares students for the post-exploitation and lateral movement chapters ahead.
Lesson 5 • Using Exploitation Frameworks
Introduces Metasploit as the primary exploitation framework for structured attack execution. Students learn module selection, payload configuration, and session management.
Chapter 5HideHide detailsSee detailsPost-Exploitation and Privilege Escalation
Post-Exploitation and Privilege Escalation
Lesson 1 • Post-Exploitation Goals and Methodology
Defines objectives after initial access: data identification, persistence, and lateral movement. Frames all subsequent sections within professional engagement goals.
Lesson 2 • Credential Harvesting and Lateral Movement
Extracts credentials from memory, files, and registries to move across the network. Connects privilege escalation outcomes to broader network compromise.
Lesson 3 • Persistence and Backdoor Techniques
Establishes reliable re-entry mechanisms that survive reboots and user logoffs. Students understand attacker persistence to better advise defensive teams.
Lesson 4 • Windows Privilege Escalation
Covers techniques to elevate from standard user to SYSTEM on Windows hosts. Builds on exploitation skills using misconfigurations and token abuse.
Lesson 5 • Linux Privilege Escalation
Teaches escalation from low-privilege shell to root on Linux systems. Covers SUID binaries, sudo misconfigurations, and kernel exploits.
Chapter 6HideHide detailsSee detailsWeb Application Penetration Testing
Web Application Penetration Testing
Lesson 1 • Web Application Reconnaissance
Maps application structure, technologies, and entry points before active testing. Applies recon skills from earlier chapters to the web application context.
Lesson 2 • Authentication and Session Attacks
Tests login mechanisms, session tokens, and access control implementations for weaknesses. Directly impacts confidentiality and authorization integrity of applications.
Lesson 3 • Cross-Site Scripting and CSRF
Demonstrates reflected, stored, and DOM-based XSS alongside cross-site request forgery. Teaches client-side attack vectors that compromise end users.
Lesson 4 • Advanced Web Vulnerabilities
Explores SSRF, XXE, insecure deserialization, and broken access control. Prepares students for complex, chained web application attack scenarios.
Lesson 5 • Injection Vulnerabilities
Covers SQL injection, command injection, and LDAP injection attack and detection. Represents the highest-impact vulnerability class in web application testing.
Chapter 7HideHide detailsSee detailsNetwork and Infrastructure Attacks
Network and Infrastructure Attacks
Lesson 1 • Firewall and IDS Evasion
Demonstrates techniques to bypass perimeter controls and avoid detection during engagements. Prepares students for realistic environments with active defenses.
Lesson 2 • Active Directory Attacks
Targets Active Directory authentication, delegation, and trust relationships for domain compromise. Represents the most common enterprise attack path in real engagements.
Lesson 3 • VPN and Remote Access Attacks
Tests VPN configurations and remote access services for authentication and implementation flaws. Addresses the expanded attack surface of remote work environments.
Lesson 4 • Wireless Network Penetration Testing
Tests WPA2 and enterprise wireless networks for authentication and encryption weaknesses. Extends the attack surface to physical and wireless perimeters.
Lesson 5 • Network Protocol Attacks
Exploits weaknesses in ARP, DNS, and routing protocols to intercept or redirect traffic. Builds on networking fundamentals from Chapter 1 with offensive application.
Chapter 8HideHide detailsSee detailsReporting, Remediation, and Professional Delivery
Reporting, Remediation, and Professional Delivery
Lesson 1 • Building a Professional Pentest Practice
Addresses scoping, pricing, contracts, and continuous skill development for practitioners. Prepares students to operate as independent or employed security professionals.
Lesson 2 • Remediation Guidance and Validation
Provides actionable fix recommendations for each vulnerability class covered in the course. Includes retesting methodology to confirm remediation effectiveness.
Lesson 3 • Engagement Debrief and Client Handoff
Covers the final meeting, evidence handling, and data destruction after an engagement. Ensures professional closure and protects both client and tester.
Lesson 4 • Penetration Test Report Structure
Defines the components of a professional pentest report from executive summary to technical appendix. Establishes the deliverable standard for all student assessments.
Lesson 5 • Communicating Risk to Stakeholders
Teaches translation of technical severity into business impact language for non-technical audiences. Bridges the gap between hacker findings and executive decision-making.
Your valid completion certificate
This course is for you:
IT support technician: ready to pivot into offensive security roles.
Networking professional: wants to apply infrastructure knowledge to attack scenarios.
Computer science student: building practical skills beyond academic coursework.
Career changer: drawn to cybersecurity and committed to learning it properly.
Junior sysadmin: seeking credentials and hands-on skills for security advancement.
Bug bounty hobbyist: needs a structured methodology to improve finding quality.
What our students say
Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos help a lot with learning.

Top trainings
FAQs
Who is Dedika?
Is the certificate valid in Pakistan?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















