Exploitation & Post-Exploitation
From first foothold to full domain compromise, all inside an authorized lab.
Tuition
$399
Advanced
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
10 hours
Estimated time
What you will be able to do
- Exploit common vulnerability classes in an isolated lab and explain the root cause behind each one.
- Confirm scope, permission, and rules of engagement before you touch a target, so every action stays authorized.
- Drive exploitation frameworks such as Metasploit safely, choosing payloads that fit the job instead of causing harm.
- Escalate from a low-privilege account to full control on both Windows and Linux hosts.
- Pivot across a network and reuse captured credentials to reach systems you could not touch directly.
- Demonstrate common persistence concepts and describe how defenders detect and remove them.
- Map and walk an Active Directory attack path from a single foothold to domain-wide control.
- Turn your lab activity into clear, evidence-backed findings a client can act on.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
Exploiting Vulnerability Classes with Frameworks
Start where an engagement really begins: turning a known weakness into a working foothold. You will study the vulnerability classes behind most findings, from memory-safety bugs to injection and dangerous misconfiguration, learn to read a Common Vulnerabilities and Exposures (CVE) entry well enough to reproduce the flaw in the lab, and then drive exploitation frameworks such as Metasploit while matching every exploit and payload to an authorized scope.
2 lessons · 5 quiz questions
- 02
Privilege Escalation on Windows and Linux
A foothold is rarely enough; most systems drop you in as a low-privilege user. In this module you will hunt for the misconfigurations, weak permissions, and stale software that let you climb to administrator or root. You will practice the main escalation paths on both Linux and Windows, so you are ready when you meet an unfamiliar host.
2 lessons · 5 quiz questions · assignment
- 03
Lateral Movement, Credentials, and Persistence
One machine is a starting point, not the goal. Here you will pivot deeper into a network, harvest and reuse credentials, and reach systems that were never exposed to you directly. You will map each move to the MITRE ATT&CK framework (Adversarial Tactics, Techniques, and Common Knowledge) and study how defenders detect persistence, so your findings explain both the attack and the fix.
2 lessons · 5 quiz questions
- 04
Active Directory Attack Paths
Most enterprise networks run on Active Directory, so this is where an engagement is often won or lost. You will enumerate a domain, use attack-path mapping tools to reveal the relationships that quietly connect users, groups, and machines, and follow a realistic route from one foothold to domain-wide control. You will finish by turning that path into an evidence-backed report a client can act on.
2 lessons · 5 quiz questions · assignment