Choose your language
Hands-On Hacking Course
Over 400,000 professionals on the platform
Exclusive for companies

Hands-On Hacking Course

Master real-world offensive security techniques through hands-on labs covering everything from reconnaissance to full domain compromise. You'll build a working hacker lab, exploit live vulnerabilities, and produce professional penetration test reports. This course is built for those who want practical skills that hold up in the field — not just theory.

Dedika for students

What your team will master:

  • Configure a fully isolated hacking lab with vulnerable VMs and snapshot workflows.

  • Perform passive OSINT, network scanning, and service enumeration to map attack surfaces.

  • Exploit web application vulnerabilities including SQL injection, XSS, SSRF, and broken authentication.

  • Execute man-in-the-middle attacks, capture credentials, and crack password hashes offline.

  • Escalate privileges on Windows and Linux systems using proven, real-world techniques.

  • Produce client-ready penetration test reports with risk ratings and remediation guidance.

How your team learns in practice Hands-On Hacking Course

How your team practices Hands-On Hacking Course

Professionals from these companies study at Dedika

ActemiumFR
Nunner LogisticsNL
GT Constructora GeotécnicaCR
Sydel StarBR
Metrô de São PauloBR
Aguas AndinasCL
DSMIN
MeridianbetRS
CDHCN

Course Content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Ethical Hacking

  • Lesson 1 • The Hacker Mindset and Ethics

    Defines offensive security roles, attacker motivations, and the ethical boundaries that separate authorized testing from criminal activity. Anchors all subsequent technical work in professional responsibility.

  • Lesson 2 • Introduction to Kali Linux and Core Tools

    Orients students to the Kali Linux filesystem, package management, and the essential toolset used throughout the course. Builds command-line fluency required for all later modules.

  • Lesson 3 • Core Networking Concepts for Hackers

    Reviews TCP/IP, DNS, HTTP, and routing fundamentals through an attacker's lens. Provides the protocol literacy needed to understand every subsequent exploitation technique.

  • Lesson 4 • Building a Safe Lab Environment

    Guides students through hypervisor setup, vulnerable VM deployment, and network isolation. A functional lab is the prerequisite for every hands-on exercise in the course.

  • Lesson 5 • Legal and Regulatory Foundations

    Surveys computer-crime statutes, authorization requirements, and contractual obligations that govern penetration testing engagements. Ensures students can identify legal risk before touching a target.

Chapter 2See details

Reconnaissance and Information Gathering

  • Lesson 1 • Network Scanning and Host Discovery

    Applies Nmap and similar tools to identify live hosts, open ports, and operating systems across a target network. Results form the foundation for service-level enumeration.

  • Lesson 2 • DNS and Domain Enumeration

    Demonstrates zone transfers, brute-force subdomain discovery, and DNS record analysis to map an organization's internet-facing footprint. Feeds directly into port scanning and service enumeration.

  • Lesson 3 • Organizing and Reporting Recon Data

    Structures collected intelligence into a target profile using mind maps, spreadsheets, and note-taking tools. Prepares students to translate raw data into actionable attack plans.

  • Lesson 4 • Service and Version Enumeration

    Extracts service banners, version strings, and configuration details from open ports to identify exploitable software. Bridges raw scan data to vulnerability identification.

  • Lesson 5 • Passive OSINT Techniques

    Covers search-engine dorking, WHOIS lookups, certificate transparency, and social-media profiling without touching target infrastructure. Establishes the intelligence baseline for active recon.

Chapter 3See details

Vulnerability Scanning and Analysis

  • Lesson 1 • Manual Vulnerability Verification

    Teaches techniques to confirm scanner findings without triggering exploits, reducing false positives before reporting. Reinforces the difference between detection and exploitation.

  • Lesson 2 • Vulnerability Scoring and Prioritization

    Applies CVSS scoring, asset criticality, and exploitability factors to rank vulnerabilities by business risk. Enables students to focus exploitation efforts on highest-impact targets.

  • Lesson 3 • Using Nessus and OpenVAS

    Provides hands-on configuration and execution of industry-standard scanners against lab targets. Students interpret raw scan output and export findings for analysis.

  • Lesson 4 • Web Application Vulnerability Scanning

    Introduces DAST tools such as Nikto and OWASP ZAP for automated web vulnerability discovery. Prepares students for the manual web exploitation techniques covered in later chapters.

  • Lesson 5 • Vulnerability Scanning Fundamentals

    Explains how scanners detect misconfigurations and known CVEs through credentialed and uncredentialed checks. Sets expectations for scanner accuracy and false-positive rates.

Chapter 4See details

Exploitation Fundamentals

  • Lesson 1 • Exploiting Common Network Services

    Targets vulnerable versions of SMB, FTP, and SSH services using both Metasploit modules and manual exploits. Reinforces the link between enumeration findings and exploit selection.

  • Lesson 2 • The Exploitation Lifecycle

    Maps the stages from vulnerability selection through payload delivery to session establishment. Provides a repeatable mental model applied in every subsequent exploitation exercise.

  • Lesson 3 • Metasploit Framework Mastery

    Covers the Metasploit console, module taxonomy, and option configuration for rapid exploit deployment. Students run their first successful exploit against a vulnerable lab service.

  • Lesson 4 • Post-Exploitation Basics

    Covers immediate post-shell actions: system enumeration, privilege checking, and persistence setup. Bridges initial access to the deeper post-exploitation chapter that follows.

  • Lesson 5 • Client-Side Exploitation Techniques

    Demonstrates browser, document, and macro-based exploits that target end-user systems rather than servers. Introduces social-engineering delivery vectors used in phishing simulations.

Chapter 5See details

Web Application Hacking

  • Lesson 1 • Injection Attacks: SQL and Beyond

    Teaches manual and tool-assisted SQL injection, command injection, and LDAP injection against vulnerable applications. Students extract database contents and achieve OS-level command execution.

  • Lesson 2 • Authentication and Authorization Flaws

    Exploits weak passwords, broken access controls, insecure direct object references, and JWT vulnerabilities to escalate privileges within web applications. Directly applicable to real-world assessments.

  • Lesson 3 • Web Application Architecture for Attackers

    Maps client-server communication, authentication flows, and session management from an attacker's perspective. Establishes the technical context for every web vulnerability class that follows.

  • Lesson 4 • Advanced Web Exploitation Techniques

    Covers SSRF, XXE, file upload bypasses, and deserialization vulnerabilities that lead to remote code execution. Prepares students for complex, chained web attack scenarios.

  • Lesson 5 • Cross-Site Scripting and CSRF

    Demonstrates reflected, stored, and DOM-based XSS alongside cross-site request forgery to compromise user sessions and perform unauthorized actions. Covers both attack and impact validation.

Chapter 6See details

Network Attacks and Traffic Analysis

  • Lesson 1 • ARP Poisoning and MitM Attacks

    Executes ARP cache poisoning with Ettercap and Bettercap to position an attacker between hosts and intercept traffic. Demonstrates real-time credential theft and session hijacking.

  • Lesson 2 • Packet Capture and Traffic Analysis

    Uses Wireshark and tcpdump to capture, filter, and decode network traffic for credential and session data. Provides the analytical foundation for all active network attack techniques.

  • Lesson 3 • Password Cracking and Hash Analysis

    Applies Hashcat and John the Ripper with wordlists, rules, and mask attacks to crack captured hashes offline. Reinforces credential harvesting outcomes from the post-exploitation chapter.

  • Lesson 4 • Wireless Network Attacks

    Targets WPA2 handshake capture, PMKID attacks, and evil-twin access points to compromise wireless networks. Extends MitM skills to the wireless attack surface.

  • Lesson 5 • Tunneling and Covert Channels

    Demonstrates DNS tunneling, ICMP covert channels, and SSH port forwarding to exfiltrate data and bypass firewalls. Prepares students for advanced pivoting and C2 communication.

Chapter 7See details

Privilege Escalation and Post-Exploitation

  • Lesson 1 • Persistence and Defense Evasion

    Establishes covert persistence through scheduled tasks, registry run keys, and backdoored services while evading common defenses. Teaches students to maintain access across reboots.

  • Lesson 2 • Linux Privilege Escalation

    Identifies SUID binaries, cron job misconfigurations, writable paths, and kernel exploits that elevate a low-privilege shell to root. Builds systematic enumeration habits for Linux targets.

  • Lesson 3 • Active Directory Attacks

    Covers AS-REP roasting, DCSync, Golden Ticket, and domain trust abuse to achieve full Active Directory compromise. Represents the culmination of the privilege escalation chapter.

  • Lesson 4 • Windows Privilege Escalation

    Targets unquoted service paths, weak registry permissions, token impersonation, and AlwaysInstallElevated to gain SYSTEM on Windows hosts. Mirrors real-world Windows assessment workflows.

  • Lesson 5 • Credential Harvesting and Lateral Movement

    Extracts password hashes, plaintext credentials, and Kerberos tickets to move laterally across a network. Connects privilege escalation outcomes to domain-wide compromise.

Chapter 8See details

Penetration Testing Methodology and Reporting

  • Lesson 1 • Simulated Full-Scope Engagement

    Students execute a complete black-box penetration test against a multi-service lab environment from recon to report. Serves as the capstone assessment integrating all course competencies.

  • Lesson 2 • Engagement Planning and Scoping

    Defines rules of engagement, scope boundaries, communication protocols, and emergency contacts before testing begins. Prevents legal and operational incidents during real engagements.

  • Lesson 3 • Evidence Collection and Chain of Custody

    Establishes practices for timestamped screenshots, command logs, and hash-verified artifacts that support findings. Ensures findings are defensible and reproducible during client review.

  • Lesson 4 • Writing Professional Penetration Test Reports

    Structures executive summaries, technical findings, risk ratings, and remediation guidance into a polished deliverable. Translates technical exploitation outcomes into business-relevant language.

  • Lesson 5 • Structured Testing Methodologies

    Compares PTES, OWASP Testing Guide, and NIST SP 800-115 frameworks to provide a repeatable testing structure. Enables students to align their work with industry-recognized standards.

Certification

Your valid completion certificate

This course is for you:

  • Aspiring penetration tester: wants structured, lab-based training before pursuing certifications.

  • IT support technician: ready to shift from fixing systems to testing their defenses.

  • Computer science student: looking to build offensive security skills alongside academic coursework.

  • Cybersecurity analyst: seeking hands-on attack experience to strengthen their defensive perspective.

  • Career changer: motivated by security work and committed to building a new technical skill set.

  • CTF enthusiast: wants to move beyond puzzles and into professional assessment workflows.

Related courses

FAQ

Who is Dedika?

Is the certificate valid in United States?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course