
Congratulations on taking the next step in your quest for a career as a pentester! Welcome to the introduction module!
My objective in this course is to guide you through your journey until you land your first penetration testing job. To achieve this goal, here are my suggestions to fully profit from this course.
Slow but consistent
Many students rush through the course to quickly learn as much as they can. Unfortunately, they either stop midway because they get burned out, lack discipline, or build weak skills that will bite them down the road. Don’t be one of them. Enjoy the journey! I suggest you sit for the course every day, for 1 hour. Depending on your duties, you might adapt the 1-hour rule accordingly. But no matter how long it is, make it consistent.
Watch the videos AND read the text content.
The course contains both text AND video content. Don’t skip the former! They both complement each other.
Do your homework and quizzes.
The course contains homework and quizzes throughout its content. Don’t skip them, they are a crucial part of the course! You will never become a successful penetration tester without hands-on experience, and the homework was designed to help you with that. Make sure you grasp the concepts before you move on.
Celebrate along the way
The course is structured around cornerstone modules. Every module and every lecture will get you one step closer to becoming a pentester. Don’t wait until the end of the course to celebrate your transformation. When you finish homework or complete a module, you should celebrate. You deserve it!
Two learning resources to get you going
I have spent countless hours on many learning websites. You don’t have to! You've paid for this course to avoid wasting your valuable time.
The only two hacking platforms I want you to start with are root-me and tryhackme.
Root-me
If you are an absolute beginner, I guarantee this website will keep you busy for a few months, but I will show you exactly what to do to reduce it to weeks.
This platform contains so many features. For now, you should only focus on the challenges. Root-me has a huge database of laser-focused challenges to understand a specific security vulnerability deeply. You do this by reading the provided documentation and solving hands-on problems. Once you solve a challenge, you earn points which will be helpful in the next module.
Tryhackme
Tryhackme is a recent player in the ethical hacking scene. When I started my career in cybersecurity around 2013, it did not exist yet. Like root-me, this platform is growing and already has so many features. But I want you to focus on rooms for now.
A room contains several tasks linked together in a way that helps you understand a specific topic. For instance, the room pentesting fundamentals explains important ethics and methodologies behind every pentest. The room Basic Pentesting walks you through a use case involving web hacking and privilege escalation. You don't have to solve anything. For now, I am just giving you examples.
Although many rooms require a paid subscription, the basic ones are free. Paying for the subscription is not a requirement. You have all you need for free.
I don't want to overwhelm you with too many websites; these two are more than enough to start building the foundation of your technical skills.
Why take notes?
Taking notes is essential in your learning process. So important that I include this lecture before ANY technical lesson. That's because I know how valuable they are down the road. There are at least two key benefits of taking notes.
We tend to forget quite quickly: I still have notes from when I started learning about security vulnerabilities years ago. Whenever I encounter something during a pentest mission, I don't have to redo the entire learning process and search for the resources I might not find. With my notes, I quickly get the necessary information and move on with my mission.
It will be helpful in the following module: Most of the notes you will take in this module will serve in the next one when we tackle how to build your authority. It would be a pity to redo all the work just to note how you solved the challenges.
It's a valuable habit: Taking notes will help you during your professional job because you would naturally take extensive notes during a pentest mission. This is extremely useful for the final report you will deliver to your client.
How to easily take notes?
Okay, now that you know the importance of taking notes, this video will explain how to easily take them as you go through this module (or even after finishing this course). Taking notes should be second nature to you all the time.
Your study strategy
This lecture provides a well-defined but less-strict plan to continue learning the fundamental skills. If you don't know what HTTP or an IP is, I suggest you go back to the previous lecture before you continue with this one.
I encourage you to post your progress and questions in the Discord channel, its sole purpose is to provide you with the support, the inspiration, and the encouragement you need throughout this journey.
Root-me
Start with the most straightforward challenges on root-me to boost your confidence, learn simpler topics, and lay a strong foundation. Here is a list I recommend you start with but feel free to deviate as much as you see fit, depending on your current technical level and curiosity.
The Web-Server category: This is your go-to category for web application penetration testing. As a pentester, most of the missions will revolve around web applications. That’s why I suggest you start with this category. You will learn the HTTP protocol basics, how the web server handles and responds to client requests, and the different server-side vulnerabilities you should know.
The Web - Client category: This category contains knowledge related to the other side of web applications, the web browser, also known as the client. Here, you will find the vulnerabilities on the web browser, not the server. For example, you learned about cross-site scripting in the previous lecture. Well, so many challenges here will make you feel very comfortable exploiting them, and then some!
The App - Script category: I recommend it to learn about vulnerabilities present in services you will typically find in your future pentest engagements after you gain remote code execution on a target system. These challenges aim to teach you the skills required to elevate your privileges on the host running the vulnerable service.
Aim to solve all easy and medium challenges on your own. For each category, start from the lowest difficulty, and work your way up. For every challenge, you have a sub-title explaining your objective. Further down, you will find resources to help you solve the challenge.
It is crucial to get into the habit of learning from such documents earlier in your learning process. It is a must-have skill for any serious professional penetration tester.
Sometimes, the resources don’t provide specific directions to solve the problem, which often happens in real life. That’s why, if you still can’t progress after reading through them, don’t hesitate to surf through the forum. More often, you will find your direction there. If you’re still stuck, there is the IRC channel where you can directly ask your question and have some help in real-time. When you DM someone, clearly state where you are stuck and what things you tried. Otherwise, you might get an unsatisfying answer.
If you feel comfortable in these categories, you can optionally tackle the App-System category for buffer overflows, Cryptanalysis to learn how to exploit vulnerabilities and misconfigurations in many encryption algorithms.
Your study strategy
This lecture provides a well-defined but less-strict plan to continue learning the fundamental skills. If you don't know what HTTP or an IP is, I suggest you go back to the previous lecture before you continue with this one.
I encourage you to post your progress and questions in the Discord channel, its sole purpose is to provide you with the support, the inspiration, and the encouragement you need throughout this journey.
(This lecture is optional)
On TryHackme, you can learn from free rooms using the search feature, but since they are not categorized, you won’t know, at your current level, what rooms to choose from.
If you are willing to pay for a tryhackme subscription, I recommend focusing on the learning paths. These are a combination of free and paid rooms dedicated to teaching a broader topic. In case of penetration testing, I recommend enrolling into the following learning paths:
JR penetration tester
Web fundamentals
Once you gain the fundamental skills with these learning paths, you will know what rooms to choose next from the search feature.
The fun begins now!
Solving individual challenges brings joy and achievement; you have certainly experienced the feeling. But let me tell you that the next type of challenge will bring you even more adrenaline. I still remember my first challenge of this kind; I was hooked!
Now that you have the foundation technical knowledge thanks to the hands-on atomic challenges, it’s time to tackle boot2root challenges.
As the name suggests, these are machines you boot, and the objective is to acquire the highest privileges. Under Windows, you have to gain SYSTEM privileges. In Linux systems, the goal is to become root.
With Boot2root challenges, you will combine the skills you have learned and develop the right methodology for your next pentest job.
Many websites are offering boot2root machines nowadays. When I started my journey as an ethical hacker, the most famous one was Vulnhub. You had to download the virtual machine, install it, configure it, and finally start hacking it. But today, things have become much easier. You don’t need to deploy anything locally. Besides, you get to pick the machine that serves your specific learning needs.
Setting up your VPN
Before you can attack a boot2root machine on TryHackMe, you have to access it via a VPN, which allows you to establish a secure connection to the subnet that hosts the machine, as if you had booted it locally.
Don’t worry; I am not talking about Third-party VPN services you typically use to connect from different countries. You don’t have to purchase any of them. This video will explain how to establish a VPN connection and start hacking your target machine.
You may have come across these challenges when you explored TryHackme’s rooms. They allow you to deploy and hack a machine remotely and are composed of many tasks to guide you through the journey. You can search for specific terms, such as web, and filter based on difficulty.
Start with these two rooms. They are easy and have detailed tasks to get a feel of what to expect in this type of challenge:
Basic Pentesting: This is a classic exercise to learn the hacker's methodology on a boot2root machine.
h4cked: I recommend this CTF because it starts with an incident response exercise to explain how the attacker exploited the machine, then you get to replay the same steps to achieve the same outcome.
Once you have solved several challenges on try hack me, you will be ready to tackle boot2root VMs that don't have guiding tasks.
CTF all the day is a feature on root-me that allows you to boot a new machine in a new room or join another where players are already competing. The first one to root the machine wins.
CTF all the day doesn't require any VPN access; you just have to click on the join button.
You can choose among many famous vulnerable machines. Most of them were ported from Vulnhub. Although the choice is limited on root-me, most machines are classics that any future pentester should do.
Like Tryhackme, when you get stuck and exhaust all your possibilities, you can read the forum threads about the machines and portions of the available walkthroughs, either on the platform or online.
At this point, you are ready to tackle Hackthebox, a platform known for its abundance of boot2root machines of all kinds. I intentionally delayed this resource until you have the basic skills. In the past, you couldn't sign up until you solved a basic web challenge, but nowadays, it's not the case anymore.
Once you have an account, you might get overwhelmed by the number of resources available. Don’t worry; I’ve got you covered.
There are challenges, but their number is limited compared to root-me. Our focus will be on boot2root machines available for free for a limited period. Every Saturday, the oldest machine retires. You can still play with it if you pay for a VIP subscription, which costs 12$/month at the time of writing this lecture, but the free machines are enough.
Start with the easy machines, tackle Windows and Linux, and take plenty of notes and screenshots. We are going to need them in the next module.
Don't forget to ask questions on the private Discord channel, and share your progress to inspire and encourage other students!
Time to hack multiple machines
Once you feel comfortable pwning both Linux and Windows machines, you will be ready for the next step: Hacking an infrastructure composed of multiple machines.
The chances of being directly assigned to an internal pentest in your first pentester job will be slim.
You will probably start hacking a web application or an API or perform an external pentest.
However, demonstrating you can handle hacking a target composed of many machines and networks will give you a competitive advantage during job interviews and boost your career by participating in challenging and exciting pentest missions as soon as you land your first pentester job.
Hand-held labs with TryHackMe
This platform offers a set of networks you can hack following pre-defined tasks, just like you've seen with rooms. Some of them are free, others require a subscription or payment. Start with the following free networks:
Wreath: In this lab, you will practice the overall hacker methodology you learned in the previous lectures. From scanning to pivoting.
Breaching Active Directory: This lab will teach you the techniques of getting initial access to an Active Directory environment. Companies widely use Active Directory, and I highly encourage you to familiarize yourself with how to hack it.
Enumerating Active Directory: Always in AD, but you will practice different enumeration techniques this time. Enumeration is key in every pentest engagement, especially in Active Directory infrastructures.
Note that you need a 7-day streak to join these rooms. Otherwise, you must pay for a subscription to get instant access. To get free access, you must answer any question in any room every day for seven days. DO NOT answer later than 24 hours, or your streak will reset. ALL questions qualify for a streak, even those that don't require an answer!
When you finish them, you can optionally pay for the following networks.
Throwback: An Active Directory lab simulating a realistic corporate environment with several attack vectors you would expect to find in today’s organizations. You pay for either 30 or 45 days of access.
Holo: This lab simulates an external pentest that combines web attacks, pivoting and internal Active Directory attacks. It's available when you purchase a subscription.
Once you do the hand-held labs above, you can work autonomously on the following labs.
Free labs on Root-me
Root-me offers free labs, try out both versions of the Blue-box CTF on root-me. It's available in CTF all Day.
Also, try hacking the Sambox saga, which is available in CTF all the day as well.
Hackthebox
For an enterprise-like, entry-level difficulty network, try the dante pro lab on hackthebox. it's a great way to introduce yourself to hacking an entire lab. You also get a certificate of completion to add to your resume.
You already have a strong start.
Believe it or not, you have already started building your reputation from the beginning of this course. How? Every platform we discussed in the previous module implements a gamification system. You earned points and badges while you were solving challenges. And you can tell others about your progress by sharing your profile page.
Don’t forget to test the URL in an incognito window before sharing it. You don’t want your future potential employers to land on a dead link.
Additionally, you can share your social accounts on these hacking platforms to make it easier for potential employers to learn more about you and hopefully reach out to you. LinkedIn, GitHub, and Twitter are great for this purpose. Once you have a running website, add it there as well. We will talk about your website in the next lecture.
Why having your website is crucial?
One of the best ways to boost your reputation and increase your authority is by having your personal website where you document write-ups of machines or labs you have pwned, some cool techniques you have learned, or just explain how a vulnerability can be exploited in your own way.
A website showcases your writing style. This is, sadly, a valuable soft skill that most candidates overlook. Part of your future pentest missions will include writing a professional report destined for the top management and the technical people working for your customers. If you don’t know how to write good reports, your website is a great way to develop this skill.
Before landing my job as a pentester, I have written many reports in almost all my job interviews. And nowadays, I systematically ask candidates to write a professional report in the job interview process. And let me tell you that very few candidates pass the bar. Trust me; you will have a considerable competitive advantage when you can write good professional reports.
To give a more professional feel to your website, I recommend you buy a domain of your own. It could be yourfullname.com. Then, you can use it instead of yourgithubusername.github.io.
Why solve challenges with others?
Working in a team has three benefits:
If you love interacting with people, being in a group encourages you to spend more time hacking and honing your hacking skills more quickly.
It's a great way to build your professional network. Plus, you can receive endorsements or recommendations from your colleagues.
You will have experience working in a team of hackers even if you are not a professional pentester yet. This is a great experience to highlight during job interviews because it proves you can work in a team and bring value. If you are an introvert, this might push you out of your comfort zone, but the community around this course is what will ease the experience for you.
How to do that?
One word: CTFs!
Capture The Flags are hacking puzzles designed to test your technical skills. During your progress, you collect proofs called flags, which are typically a series of unique strings found in files or databases.
CTFs are a great opportunity to make friends and acquire new knowledge that you can share on your blog in the form of write-ups.
There are so many online CTF competitions around the globe that come in different flavors.
In Jeopardy-like CTFs, you are presented with various challenges in different categories, such as web, crypto, cracking, binary exploitation, etc. This is the most famous genre.
In Attack-Defense CTFs, every team has its vulnerable servers and services. Teams must attack other team's servers while protecting their own from being hacked.
CTF time
You can find such CTFs on ctftime. The video of the lecture shows how you can use the website.
Another type of CTF challenge is organized by companies that seek to hire pentesters. What’s cool about them is that you get a chance for an interview once you solve the CTF. You can find these CTFs on hackthebox’s Fortresses.
If you are competitive in games, I suggest you try the battlegrounds. It's a set of competitive games played against two teams. You can either play Attack/Defend, where you get root access to your machines to secure them while attacking the opponent's lab, or play the Race to the Top style, where each team will attack one lab and get the root flag.
Learn more about it on the knowledge base.
King of the Hill is a competitive CTF where you play alone against others to get root, maintain access to the target machine, and find hidden flags. You prevent others from accessing by patching the vulnerabilities you exploited. Whoever has the highest score after 60 minutes wins.
This video demonstrates is a continuation of the King of the Hill session started in the previous video. It contains some key moments in the challenge. However, it was loosely edited because I want you to see what a real hacking session looks like.
Form teams of 2, 3, or 4 players from students in the course. It's a great way to get to know each other and learn while playing. Then:
Participate in one CTF on ctftime.org,
Play one CTF in hackthebox battlegrounds,
If you prefer playing alone, you can still do that in Tryhackme's King of the Hill or CTFtime.
Either way, publish a write-up on your website for each challenge you solve and share it with your network on Linkedin, Twitter, and Discord.
This homework will take time to achieve, but it's worth the effort. This will give you the professional experience to put in your future resume and boost your confidence during job interviews.
Create an account on github.com if you don't have one yet, then sign up to huntr.dev.
Read 3 to 5 reports from the hacktivity every day.
Watch these videos from the platform on how to find bugs in open-source projects.
Keep an eye on thehacktivity for unpatched vulnerabilities, and try to fix them. Note the CVE IDs to include in your future resume.
Once familiar with the ecosystem, start hunting for bugs and record CVEs for your future resume.
Remember, you shouldn't rush through this homework. It is meant to be done over time. Continue with the course, but don't forget to progress in the homework everyday. Consistence is key!
Write your CV using the guidelines you have just learned. To push things even further, upload your CV to resumeworded.com, and make enhancements based on their feedback.
To find a penetration testing job, there are many websites available at your disposal. You must know about them all. That will increase your chances of finding your next pentest job.
I will start with the ones you are already familiar with from this course. You guessed it, root-me and Hackthebox.
Root-me
If you live in Europe, particularly in France or the Benelux area (Belgium, Nederlands Luxembourg), you can find offers listed by known cyber security players. Since you already have a reputation on this website, getting noticed and getting your foothold on the interview process should be straightforward.
The downside is that only a few offers are listed.
To apply for a job offer, you should at least have 100 reputation points, which is not a problem if you have followed the steps in module 1 of this course. Then, you have to fill up your professional information, such as uploading the CV you have just written.
In the brief biography field, tell a compelling story about your journey in cybersecurity. Try answering the questions: What do you currently do? Why are you looking for a pentester job? Briefly mention the three best achievements you are proud of the most.
In your education degree field, even if you don’t have a cybersecurity-related career, highlight the motivations that drove you to switch to this industry in the Education degree explanation field. I know pentesters who were lawyers in the past and others who were web designers. So, don't underestimate yourself. If you have been following the roadmap of this course, I guarantee you have what it takes for the job.
In the experience level explanation field, highlight the greatest achievements you barely touched upon previously. Even if your only experience has been this course so far, you’d have plenty of things to show from the previous modules. Things like your website containing write-ups about the CTFs you had solved, your certifications, your profile pages on the hacking platforms, and, why not, your profile on a bug bounty platform with some public bugs you found.
In the professional aspiration explanation field, list your goals in the short and medium terms. Here are some examples:
Short-term goal: "I want to practice my skills on real-world targets through different pentest missions, such as external, internal, and web."
Medium-term goal: "In five years, I want to move to a senior position and focus on advanced areas, such as exploit development and red teaming." You can also think of a managerial career where you might become a team leader, then a cybersecurity manager. You can also think of switching sides from offensive to defensive. It’s up to you.
Once you have filled up the professional and personal data, you can apply for available open positions.
You are then asked to write a paragraph for each application: That's your motivation letter. This is where you will apply the knowledge you gained from the previous section and write one that stands out.
Hackthebox also has a job board feature, with more offers across a wider range of countries. You can apply filters and view more info about the job and the company. Your level in the platform determines if you are eligible for a job, but if you have worked hard in module 1, you should be a Pro Hacker by now, which will give you access to almost, if not all, the job offers.
When you want to apply for a job offer, simply fill up your information and link your CV URL from your website or an upload service, such as transfer.sh or your Google Drive, and you should be good to go. You will see the list of job offers you applied to in the dedicated tab.
To be visible to employers seeking a pentester, tick the “Open to exploring new job opportunities” option to become visible.
If you don’t know what LinkedIn is, you should stop this video right now and sign up to linkedin.com, then fill up your profile with your experience so far, including your certifications, any awards, such as the badges you earned from the hacking platforms, and make sure you toggle "Open to finding a new job." That way, LinkedIn makes your profile visible to potential offers.
You can hunt for penetration testing jobs on LinkedIn using the search feature. It allows you to look for jobs in a company, jobs that have a certain title, skill, etc. You can choose any place worldwide and filter the results based on your specific needs.
Linkedin supports reminders that you can configure to receive notifications with new job offers that match your criteria.
Indeed.com is also another resource for finding penetration testing job offers. I find it a bit harder to use since you must manually choose the right website that matches your country. However, it has fine-grained search filters that can give you subtle hints about the job you are looking for. For instance, you can filter by salary range, which is taken from current results, giving you an idea about your salary expectations, more on that in the next module.
Although the search results are limited compared to Linkedin, I found my first penetration testing job on indeed. You never know where it sticks, so better take all the chances.
Indeed supports alert notifications as well.
Glassdoor also allows you to search for jobs, as we have seen with LinkedIn and Indeed.
I use Glassdoor to find more information about a company I am interested in. Things like the salary range, the interview process, and the working environment are based on the opinions of other users. Because there is no way you can confirm a user has worked in a certain company, or because it depends on the honesty of the ex-employee, the results are sometimes misleading. So you should take the results with a big spoonful of salt.
Say you found a job offer that corresponds to your needs but don't know much about the company. Glassdoor might have the answer. Generally, you will find a great deal of data if the company is famous, but a few results to nothing if you search for a less-known company.
Glassdoor also supports notifications.
Although you should prioritize career growth when choosing your first pentest job, you don’t want to be underpaid. After all, you are providing value to your employer’s customers, which should be compensated fairly.
The question: “What is your salary expectation” is generally brought up early in the interview process, typically during the first call with HR or the hiring agency. It’s essential to know how to answer it beforehand. Otherwise, you risk being rejected early if your salary expectations don’t overlap with the company’s range.
Here are some strategies you may use to answer this question.
Delay the answer
Suppose you don’t know the salary range in your area. In that case, I suggest you delay the answer by saying something like this: “I’d like to know more about the job responsibilities and the company’s benefits before deciding on the salary range.”
With this answer, you can go through the interview and demonstrate your value before asking for a salary.
Bear in mind that they might insist on giving them a salary range at the beginning to know whether there is an overlap before wasting anyone’s time during the interviews. That’s why I highly recommend you research beforehand and provide a salary range, as we will see in the next section.
Do your research
Before answering the question: “What is your salary expectation?”, you should look for the salary range in your area and the company. We saw in the previous module that you can filter job offers by salary range on LinkedIn, Glassdoor, and Indeed. I will demonstrate how to search for salary ranges using different websites in this video.
Provide a range based on your research
Once you have a range, I suggest you increase the lower bound somewhere near the average. If you get accepted for the job, companies typically offer you the lower bound plus a minor amount to fall into the range you asked for. Besides, having a high lower bound allows you to be more flexible when negotiating a common ground.
Ask for the range of the position.
One of the great ways to gain some insights about the company's salary range is to simply…ask for it! Your reply might be: “I am sure the company XYZ has a budget for this job offer. It would be very helpful if you could share a range.”
Stop wasting your valuable time scouring the internet, wondering if you are on the right track. I have spent years gathering the relevant knowledge you need to gain confidence and help you sign your first penetration testing job. It's all right here in this one course, waiting for you to harness its full potential.
Join me, pentester and Team Leader Abdessamad Dhassi, as I walk you through every practical step to help you land your first penetration testing job, in your free time, from scratch! From the basics of security vulnerabilities all the way to negotiating your salary, this pragmatic class will provide you with the skills you will need to jump-start your career with the dream job you've always wanted.
In this super-efficient crash course, we will cover:
Hard skills you should acquire, and how to start practicing them right now on selected challenges online,
You will learn and apply proven techniques to stand out among other candidates,
Search for the right pentester job,
Tips and tricks to get the confidence you need to ace any job interview,
Learn how to negotiate a good salary.
You don’t need any prior knowledge about ethical hacking. The only thing I require from you is dedication.
This course is NOT for you if you can identify with the following:
You want quick and easy magic tips to become a hacker
You intent to use this knowledge to do harm or hack systems you don't own
While the course offers a well-defined roadmap to acquire the essential skills to secure your initial position as a pentester, this course does not guarantee job placement.