
Explore exploitation fundamentals from vulnerability discovery to payload delivery, mastering shellcode, staged versus stageless payloads, encoding, and exploit categories across RCE, LPE, and web and client-side exploits.
Master metasploit framework architecture and core workflow, including six module types, MSF console navigation, database integration, pivoting, and evidence capture for GPEN style exams.
Master the full attack surface of network services, from smb and rdp to ssh and web services. Learn vulnerability mechanics, practical tooling, and validation before exploitation for real engagements.
Master post-exploitation with netcat and socat for reliable shells and file transfers, and learn techniques like reverse and bind shells, TLS, and DNS tunneling.
Master password attack methodology and hash types, distinguishing online and offline attacks. Identify and crack NT/NTLM, LM, and Kerberos hashes using Hashid and Hash Identifier for rapid command-line cracking.
Explore NTLM relay attacks and the full relay chain, including SMB signing states, ntlmrelayx configuration, LDAP relay, and multi-target scenarios, with post-auth capabilities like SAM dumps and SOCKS proxies.
Explore Windows privilege escalation across services, registry abuse, and token abuse. Learn detection commands and exploitation workflows with WinPEASE and PowerUP.
Explore how Active Directory forms the backbone of enterprise identity, authentication, and access control across forests, domains, trees, and OUs, including trusts, delegation, and modern hardening controls.
Explore active directory enumeration using PowerView, LDAP queries, and CrackMapExec to map users, groups, trusts, and ACLs, enabling targeted Kerberoasting and privilege escalation.
Master Kerberos authentication flow from as-req to ap-rec, detailing as-rep, tgt, tgs, and spns, and explore kerberoasting, golden and silver tickets, pac, and delegation risks.
Explore how DC sync enables full domain compromise via NTDS.DIT extraction and domain hash dumping, including Kerberos keys and golden tickets, plus the required rights and tools.
Explore ADCS attack surfaces from ESC1 to ESC8 using CertiPy, learning template misconfigurations, CA ACLs, and web enrollment abuse to chain certificates into domain admin access.
The GIAC Penetration Tester (GPEN) certification is one of the most respected offensive security credentials in the world. Held by elite penetration testers, red teamers and security professionals across government, defense and enterprise, it validates your ability to conduct real-world penetration tests using industry best-practice techniques and methodologies. With over 41,000 active job postings referencing GPEN and average salaries exceeding $117,000 per year, this certification directly impacts your career trajectory.
The problem is that there is no serious instructor-led GPEN preparation course on the market. Until now.
This course is the most comprehensive GPEN exam preparation resource available anywhere online. Built around the official 2026 GIAC exam objectives and fully aligned to the SEC560 Enterprise Penetration Testing curriculum, it delivers over 31 hours of structured, in-depth instruction across every topic you will be tested on — nothing is skipped, nothing is surface-level.
The course covers all three official GPEN exam domains in full depth.
Domain 1 takes you through penetration testing methodology, legal frameworks, scoping, rules of engagement, passive and active reconnaissance, OSINT, DNS attacks, network scanning with Nmap, NSE scripting, vulnerability scanning and service enumeration.
Domain 2 covers initial access and exploitation, Metasploit and Meterpreter, msfvenom payload generation, password attacks with Hydra, Hashcat and John the Ripper, LLMNR poisoning with Responder, NTLM relay attacks with ntlmrelayx, IPv6 DNS takeover with mitm6, post-exploitation, Windows and Linux privilege escalation, credential harvesting with Mimikatz, pivoting and tunneling, and data exfiltration.
Domain 3 dives deep into Active Directory attacks including BloodHound and SharpHound, Kerberoasting, AS-REP roasting, Pass-the-Hash, Pass-the-Ticket, Golden Ticket and Silver Ticket forgery, DCSync, NTDS.dit extraction, Active Directory Certificate Services exploitation covering ESC1 through ESC8 with Certipy, Azure and Entra ID password spraying, token abuse, RBAC privilege escalation, managed identity attacks, hybrid identity exploitation, command and control frameworks including Sliver and Empire, persistence mechanisms, AMSI bypass, EDR evasion and professional penetration test reporting.
The course closes with two full-length mock examinations built to the exact format, difficulty and scenario style of the real GPEN exam. These are not simple quiz banks — each mock is a complete 82-question exam with detailed explanations for every answer, designed to simulate the pressure and question logic of the actual GIAC testing environment so you walk in on exam day with full confidence.