About this track
A penetration test is not a single trick — it is a disciplined process. You do not start by firing exploits; you start by agreeing, in writing, on what you are allowed to touch. From there the work follows a predictable lifecycle: reconnaissance, scanning and enumeration, vulnerability analysis, exploitation, post-exploitation, and finally the deliverable. This track follows that lifecycle phase by phase.
It is the offensive counterpart to the fundamentals modules. Where Network Security taught you how traffic moves, here you scan it for a way in. Where Web Application Security taught you what XSS is, here you chain it into an engagement. Many phases reuse labs you have already met — the port-scanning lab, the SQL-injection suite, the WPA2 handshake crack — now framed as steps in one continuous attack story.
Authorized testing only. Everything here is taught for defensive understanding and for legal, authorized engagements — the kind performed under a signed scope against systems you own or have explicit written permission to test. The first phase covers exactly where that line is.
The engagement, phase by phase
How this connects to the fundamentals
This track does not replace the fundamentals modules — it weaponizes them. Each phase leans on material you can study in depth elsewhere on the site: