Choose your language
Ethical Hacking Course for Beginners
More than 2 million learners worldwide

Ethical Hacking Course for Beginners

Master the tools, techniques, and ethics that define professional penetration testing. This course takes you from foundational legal concepts to hands-on exploitation, reconnaissance, and reporting across networks, systems, and web applications. Whether you are launching a security career or formalising existing skills, you will build the structured mindset employers and clients demand.

Dedika for businesses

What you will learn:

  • Understand the legal boundaries, ethics, and professional standards governing authorised security testing.

  • Configure isolated lab environments and deploy vulnerable systems for safe, hands-on practice.

  • Conduct passive and active reconnaissance to build detailed intelligence profiles of target environments.

  • Perform vulnerability scanning and manual verification to produce prioritised exploitation roadmaps.

  • Exploit network services, web applications, and client-side vulnerabilities using industry-standard frameworks.

  • Produce professional pentest reports with clear risk ratings, evidence, and remediation guidance.

How you study in practice Ethical Hacking Course for Beginners

How you practise Ethical Hacking Course for Beginners

For companies looking to train their teams

With Dedika for Businesses, the course includes exercises and examples tailored to your own business and the specific needs of your company.

Click here

Course content

8 Chapters • 39 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Ethical Hacking

  • Lesson 1 • The Penetration Testing Lifecycle

    Introduces the five-phase pentest model from planning through reporting. Provides the structural map students will follow throughout the course.

  • Lesson 2 • Setting Up a Safe Lab Environment

    Guides students through building an isolated practice environment using virtualisation. Prevents accidental harm to live systems during skill development.

  • Lesson 3 • Professional Ethics and Conduct

    Defines codes of conduct, confidentiality obligations, and responsible disclosure norms. Builds the professional identity required for trusted security work.

  • Lesson 4 • Legal and Regulatory Foundations

    Covers computer crime statutes, authorisation requirements, and liability concepts. Ensures students understand consequences before touching any system.

  • Lesson 5 • Defining Ethical Hacking

    Contrasts ethical hacking with malicious hacking using intent, authorisation, and scope. Anchors the chapter's legal and professional context.

Chapter 2See details

Networking Concepts for Hackers

  • Lesson 1 • Packet Analysis with Traffic Capture Tools

    Teaches live and offline packet capture, filtering, and protocol dissection. Develops the skill of reading raw traffic to identify credentials and anomalies.

  • Lesson 2 • TCP/IP and the OSI Model

    Maps each OSI layer to real protocols and attack categories. Gives students a mental model for locating vulnerabilities within network stacks.

  • Lesson 3 • Common Protocols and Their Weaknesses

    Examines DNS, HTTP, FTP, SMTP, and SNMP from an attacker's perspective. Connects protocol design flaws to practical exploitation opportunities.

  • Lesson 4 • Network Devices and Segmentation

    Covers routers, switches, firewalls, and VLANs as both defences and attack targets. Prepares students to map network topology during reconnaissance.

Chapter 3See details

Reconnaissance and Information Gathering

  • Lesson 1 • Port and Service Scanning

    Teaches systematic port scanning to identify open services and running software. Produces the service inventory used in later vulnerability analysis.

  • Lesson 2 • Enumeration of Users and Shares

    Extracts usernames, groups, shares, and policies from network services. Feeds credential-based attacks in subsequent chapters.

  • Lesson 3 • Passive Reconnaissance Techniques

    Uses publicly available sources to gather target data without direct contact. Establishes the low-risk first phase of any engagement.

  • Lesson 4 • Organising and Documenting Findings

    Structures raw reconnaissance data into a usable target profile. Reinforces professional documentation habits introduced in Chapter one.

  • Lesson 5 • Active Reconnaissance Methods

    Introduces direct probing techniques that interact with target systems. Bridges passive intelligence to actionable network data.

Chapter 4See details

Vulnerability Analysis and Scanning

  • Lesson 1 • Prioritising Vulnerabilities for Exploitation

    Applies risk-based ranking to select the highest-value targets for exploitation. Connects vulnerability analysis output to the exploitation planning process.

  • Lesson 2 • Automated Vulnerability Scanning

    Configures and runs network and web vulnerability scanners against lab targets. Demonstrates how to interpret scanner output critically.

  • Lesson 3 • Web Application Vulnerability Basics

    Introduces the top web vulnerability classes including injection and broken authentication. Prepares students for the dedicated web chapter ahead.

  • Lesson 4 • Vulnerability Concepts and Classification

    Defines CVEs, CVSS scoring, and vulnerability categories. Gives students a shared language for communicating risk severity.

  • Lesson 5 • Manual Vulnerability Verification

    Validates scanner findings through manual testing to confirm exploitability. Reduces false positives before committing to exploitation attempts.

Chapter 5See details

System Exploitation Techniques

  • Lesson 1 • Exploiting Common Service Vulnerabilities

    Targets unpatched services such as SMB, RDP, and FTP in lab scenarios. Demonstrates how known CVEs translate into active sessions.

  • Lesson 2 • Maintaining Access and Persistence

    Demonstrates how attackers establish persistence after initial compromise. Teaches detection of persistence mechanisms for defensive awareness.

  • Lesson 3 • Exploitation Frameworks and Workflow

    Introduces modular exploitation frameworks, their architecture, and standard workflow. Provides the operational foundation for all hands-on exploitation exercises.

  • Lesson 4 • Client-Side Exploitation

    Exploits vulnerabilities in browsers, documents, and email clients to compromise endpoints. Introduces social engineering as a technical delivery mechanism.

  • Lesson 5 • Password Attacks and Credential Exploitation

    Covers brute-force, dictionary, and hash-cracking techniques against real credential stores. Connects enumeration findings to credential-based access.

Chapter 6See details

Web Application Hacking

  • Lesson 1 • Business Logic and API Vulnerabilities

    Identifies flaws in application workflow assumptions and insecure API endpoints. Addresses vulnerability classes that automated scanners frequently miss.

  • Lesson 2 • Authentication and Session Attacks

    Targets weak login mechanisms, insecure tokens, and session fixation vulnerabilities. Builds on credential attack concepts from Chapter five.

  • Lesson 3 • Injection Attacks

    Covers SQL, command, and LDAP injection with hands-on exploitation in lab apps. Demonstrates how unsanitised input leads to data exfiltration and system compromise.

  • Lesson 4 • Cross-Site Scripting and CSRF

    Exploits reflected, stored, and DOM-based XSS alongside cross-site request forgery. Connects client-side attacks to session hijacking and account takeover.

  • Lesson 5 • Web Application Architecture Review

    Maps client-server interactions, APIs, and data flows to identify attack entry points. Grounds all subsequent web techniques in architectural understanding.

Chapter 7See details

Post-Exploitation and Privilege Escalation

  • Lesson 1 • Post-Exploitation Goals and Methodology

    Defines attacker objectives after foothold establishment including data access and lateral movement. Frames post-exploitation within the authorised pentest lifecycle.

  • Lesson 2 • Lateral Movement Techniques

    Uses harvested credentials and trust relationships to pivot across network segments. Illustrates how attackers expand from a single host to domain-wide access.

  • Lesson 3 • Privilege Escalation on Linux Systems

    Targets SUID binaries, cron jobs, and weak sudo rules to escalate to root. Demonstrates platform-specific escalation paths alongside Windows techniques.

  • Lesson 4 • Privilege Escalation on Windows Systems

    Identifies and exploits misconfigured services, tokens, and registry keys to gain SYSTEM-level access. Builds on exploitation skills from Chapter five.

  • Lesson 5 • Covering Tracks and Log Manipulation

    Examines how attackers remove evidence and why defenders must protect log integrity. Reinforces the importance of centralised logging as a countermeasure.

Chapter 8See details

Reporting and Remediation Guidance

  • Lesson 1 • Writing Clear Technical Findings

    Structures individual findings with description, evidence, impact, and remediation steps. Ensures findings are reproducible and actionable by development teams.

  • Lesson 2 • Communicating Risk to Stakeholders

    Translates technical severity into business impact language for non-technical audiences. Bridges the gap between security findings and executive decision-making.

  • Lesson 3 • Pentest Report Structure and Standards

    Defines the components of a professional pentest report from executive summary to appendices. Establishes the quality standard expected in commercial engagements.

  • Lesson 4 • Remediation Guidance Best Practices

    Provides actionable, specific remediation advice aligned to each vulnerability class. Positions the ethical hacker as a trusted advisor rather than just an attacker.

  • Lesson 5 • Debrief and Client Engagement

    Covers the post-report debrief meeting, Q&A facilitation, and follow-up retest scoping. Completes the full engagement lifecycle introduced in Chapter one.

Certification

Your valid completion certificate

This course is for you:

  • IT support technician: ready to pivot toward a more specialized and higher-paying security role.

  • Computer science student: seeking practical offensive security skills beyond what coursework typically covers.

  • Network administrator: wanting to understand attacker techniques to better defend managed infrastructure.

  • Career changer from a non-technical field: motivated by strong interest in cybersecurity as a profession.

  • Junior developer: aiming to understand how insecure code gets exploited in real-world scenarios.

  • Hobbyist CTF player: looking to formalize self-taught skills into a structured, career-ready methodology.

What our students say

Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos help a lot with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQs

Who is Dedika?

Is the certificate valid in Pakistan?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course