Roadmaps / Ethical Hacking
🎯
advanced Roadmap #9

Ethical Hacking

Learn to think and operate like a professional penetration tester. This roadmap covers the complete pentest lifecycle — from passive OSINT through active exploitation, privilege escalation on Linux and Windows, persistence, and writing a professional report.

📚 19 lessons ⏱ ~40h 📊 advanced

Create a free account to track your progress and unlock all features.

Get Started Free Sign In
Reconnaissance Nmap Metasploit Exploitation Privilege Escalation Post-Exploitation Reporting Social Engineering Kali Linux

📋 Lessons (19 total)

1
Ethical Hacking Methodology & Passive Reconnaissance Easy prereq required

Master the ethical hacking engagement lifecycle and passive reconnaissance — OSINT, Google dorking, Shodan, theHarvester, and intelligence gathering without touching the target.

⏱ 55m
2
OSINT Deep Dive: Advanced Recon Tooling Hard

Go beyond intro-depth OSINT: certificate transparency logs, Amass, Maltego's transform model, Recon-ng, and metadata extraction as passive attack-surface mapping.

⏱ 65m
3
Active Reconnaissance & Network Scanning Medium prereq required

Actively probe targets with Nmap, Nessus, and enumeration tools to discover open ports, services, OS fingerprints, and vulnerabilities — building a complete attack surface map.

⏱ 60m
4
Exploitation Fundamentals with Metasploit Hard prereq required

Master the Metasploit Framework for vulnerability exploitation — searching, selecting, configuring, and launching exploits, generating payloads with msfvenom, and managing sessions.

⏱ 70m
5
Linux Privilege Escalation Hard prereq required

Escalate from a low-privilege shell to root on Linux using SUID binaries, sudo misconfigurations, cron jobs, weak file permissions, capabilities, and kernel exploits.

⏱ 70m
6
Windows Privilege Escalation Hard prereq required

Escalate privileges on Windows systems using service misconfigurations, unquoted service paths, DLL hijacking, token impersonation, and AlwaysInstallElevated — from low-privilege user to SYSTEM.

⏱ 70m
7
Password Attacks: Cracking, Spraying & Pass-the-Hash Hard prereq required

Master offline password cracking with hashcat and John the Ripper, online brute force with Hydra, credential stuffing, and Windows-specific attacks like pass-the-hash and pass-the-ticket.

⏱ 65m
8
Social Engineering & Phishing Medium prereq required

Understand and simulate social engineering attacks — spear phishing, pretexting, vishing, and physical attacks — to evaluate human security controls and train employee awareness.

⏱ 55m
9
Network Attacks & Man-in-the-Middle Hard prereq required

Execute network-level attacks — ARP poisoning, MITM traffic interception with Wireshark, Responder for credential capture, and network protocol exploitation.

⏱ 65m
10
Active Directory Fundamentals Medium

Learn the AD hierarchy, GPOs, LDAP, and the Kerberos/NTLM authentication protocols that the next lesson's attacks (Kerberoasting, DCSync, Golden Ticket) all build on.

⏱ 65m
11
Active Directory Attacks Hard prereq required

Attack Windows Active Directory environments using BloodHound enumeration, Kerberoasting, AS-REP roasting, DCSync, Pass-the-Ticket, and Golden Ticket attacks.

⏱ 75m
12
Wireless Security & Attacks Medium prereq required

Attack Wi-Fi networks — capture and crack WPA2 handshakes, perform evil twin attacks, exploit WPS, and probe for insecure enterprise authentication.

⏱ 60m
13
Buffer Overflow Fundamentals Hard prereq required

Understand and exploit classic stack-based buffer overflows — memory layout, EIP control, bad characters, shellcode generation, and exploit development with GDB and pwndbg.

⏱ 75m
14
Capstone Lab: Buffer Overflow to Shell expert

Chain every step from Buffer Overflow Fundamentals into one working exploit: fuzzing, offset discovery, bad characters, a JMP ESP redirect, and final shellcode delivery.

⏱ 90m
15
Pivoting & Lateral Movement Hard prereq required

Move through segmented networks using port forwarding, dynamic SOCKS proxies, chisel tunnels, and ProxyChains — reaching hosts that aren't directly accessible from the attacker machine.

⏱ 65m
16
Pentest Reporting & Documentation Easy prereq required

Write professional penetration testing reports — executive summaries, technical findings, CVSS scoring, remediation recommendations, and evidence documentation that deliver real value to clients.

⏱ 50m
17
Red Team Operations & OPSEC Hard prereq required

Understand advanced red team operations — simulating sophisticated adversaries with C2 frameworks, OPSEC techniques, detection evasion, and adversary simulation using MITRE ATT&CK.

⏱ 70m
18
eJPT Certification Practice Exam Hard

A 30-question practice set covering the practical syllabus areas of INE's eJPT (eLearnSecurity Junior Penetration Tester) certification.

⏱ 60m
19
OSCP-style PWK Practice Exam expert

A 30-question practice set covering the practical methodology areas of OSCP/PWK-style penetration testing: enumeration, buffer overflow, privesc, AD attacks, and web attacks.

⏱ 65m
🎯

Pentest Methodology

  1. 1 Reconnaissance
  2. 2 Scanning & Enumeration
  3. 3 Exploitation
  4. 4 Post-Exploitation
  5. 5 Reporting
⚠️ Only test systems you have explicit written permission to test.

Recommended Before

Complete earlier roadmaps in the sequence for best results.

View all roadmaps →

What You'll Learn

  • Conduct full penetration test engagements
  • Use Nmap, Metasploit, and Kali tools
  • Perform OSINT and passive reconnaissance
  • Escalate privileges on Linux and Windows
  • Write professional pentest reports
  • Understand legal and ethical boundaries