
Practice practical, hands-on offensive penetration testing across beginner, intermediate, and advanced sections, including application-level exploits, windows vulnerabilities, escalation, and vm-based real-world scenarios.
Follow the course in a structured beginner-to-advanced sequence, practice with the instructor to gain certification skills, and unlock two additional modules after completion.
Learn web application security and assessment using standard practices. Explore injection, authentication, access control, misconfiguration, and cross-site scripting with manual testing and proxy-based scanners.
Walk through setting up burp proxy to intercept and analyze web traffic, install the burp certificate, and use intruder and repeater for payload testing on a target.
Learn to set up the open source zap proxy, configure your browser, intercept and analyze requests, spider and fuzz web apps, and run active scans for OSCP prep.
Install and configure the offensive security toolbox in a virtual box, download and import the toolbox appliance, and set up Windows environments to prep for OSCP-style penetration testing.
Master active and passive domain enumeration to collect domains, subdomains, name servers, and IP ranges for recon in offensive penetration testing and OSCP prep.
learn to perform subdomain enumeration using standalone scripts by setting up the required tools, configuring api keys, and enumerating domains to reveal subdomains and their ip addresses.
Demonstrates practical command execution to bypass security and gain a reverse shell by exploiting a vulnerable business application, using local host checks, one-line PSP payloads, and other command techniques.
Demonstrates local file inclusion exploitation to access sensitive files on a server, including password files, via application navigation, proxy setup, and scanner-driven discovery for oscp prep.
Explore local file inclusion techniques to read sensitive files and gain a shell on a remote server, using request interception and pass-through methods to execute external programs.
Master remote file inclusion to bypass control and gain a reverse shell, and configure the target to support this technique.
Discover remote file inclusion exploitation to access a server remotely and gain a reverse shell, including setting up a host, crafting payloads, and bypassing input validation via case sensitivity.
Explore bypassing file upload restrictions to plant a backdoor and gain a reverse shell on a vulnerable app, with hands-on exploitation for OSCP prep.
Learn to bypass a file upload restriction by intercepting and tampering requests with a proxy tool, changing content type and file name to upload a reverse shell for oscp prep.
Explore cross-site scripting exploitation to understand how malicious payloads can steal user credentials, revealing practical implications of XSS and credential theft in web applications for OSCP prep.
Learn XSS exploitation techniques to steal the session cookie and run automated scans with Burp and ZAP to identify vulnerabilities in a controlled environment for offensive penetration testing training.
Explore SQL injection fundamentals by navigating a database, listing databases and tables, and extracting user credentials, while contrasting manual and automated exploitation techniques.
Learn SQL injection techniques using SQLMap to enumerate databases, dump the database and tables, and extract user credentials, with emphasis on performing tests only with authorization to avoid legal trouble.
Install and configure OpenVAS, a free open source vulnerability scanner, and access its browser-based console to run scans and log in with credentials.
Configure and run an OpenVAS vulnerability assessment scan, create a scan task, define targets and IPs, monitor progress, and generate comprehensive reports with remediation guidance.
Install and run the Veil framework to generate payloads that bypass antivirus, and complete the setup for practical offensive penetration testing.
Exploitation using the beef framework demonstrates testing cross-site scripting and stored payload vulnerabilities in applications, showing how beef hooks and payload delivery can compromise targets.
Explore exploiting a Samba vulnerability with Metasploit, enumerate services with Nmap, test anonymous SMB login, configure a payload in the MSF console, and gain a Meterpreter session.
Explore exploitation with Metasploit by configuring the MSF console, selecting a payload, and triggering an interactive session against an IRCd vulnerability, showcasing practical steps for penetration testing.
Master Metasploit-driven privilege escalation by exploiting a distcc service, including service enumeration, exploit selection, payload delivery, and obtaining a shell on the target.
Install Empire PowerShell on the lab machine, follow the setup steps, and log in to explore exploitation features and post-exploitation workflows.
Explore Empire powershell-exploitation on Windows 10 level 1, setting up a listener, loading payloads, and gaining remote control to study credential access, privilege escalation, and golden ticket techniques.
This lecture demonstrates Empire PowerShell exploitation on Windows 10 level 2, covering payload creation, listener setup, privilege escalation, and post-exploitation credential access for OSCP prep.
Explore Empire PowerShell exploitation on Windows 10, building payloads via macros, establishing a reverse listener, and mastering privilege escalation, credential dumping, hashcat cracking, and golden tickets for OSCP prep.
Explore privilege escalation in Active Directory, from low-privileged shells to domain controller access, including password hashes, golden tickets, and defense strategies.
Explore a Drupal-based target in a hands-on offensive penetration testing scenario, enumerate services, identify a SQL injection vulnerability, gain admin access, and simulate post-exploitation in a vulnerable Drupal application.
Set up a lab environment, perform network scanning with nmap, enumerate ports, decode base64 credentials, and practice privilege escalation to obtain an interactive shell.
Demonstrates exploiting a vulnerable vm: port scanning, service enumeration, password cracking with Hydra, privilege escalation, and capturing flags for OSCP prep.
In this oscp prep lecture, practice exploitation: enumerate services, test anonymous login, analyze a web app, use ballbuster and wordlists to enumerate credentials, and perform privilege escalation to gain shells.
Navigate the sequoia vm to perform network discovery, port and service enumeration, and proxy-assisted exploitation. Gain foothold with default credentials, upload a payload, and extract data for OSCP prep.
Demonstrates an offensive penetration test on a vulnerable VM: scan ports, enumerate services, exploit via payload, gain root access, and enumerate credentials and backups.
Demonstrates a hands-on exploitation workflow on a vulnerable VM, including network scanning, service enumeration, credential discovery, and privilege escalation. Practice payload delivery and local file inclusion to access data.
In this course, you will learn how to exploit most of OWASP Top 10 vulnerabilities, Linux & Windows 10 OS to gain root access of servers This is designed to clear OSCP certification as well as those who want to excel in Cyber Security & Ethical Hacking Domain.
1. Running NMAP & other discovery tools.
2. Exploitation of OWASP Top 10 vulnerabilities and compromise user account,Dump Databases,Deface user's application with real words scenarios
3. Penetration Testing with Kali Linux including Metasploit,AV Evasion,Gain access of a shell,Privilege Escalation & many more
4. Hacking Windows OS using Empire Powershell ,Run Mimikatz,Pass the Hash,Dumping NTLM hashes,Getting Golden Ticket,Kerbros Ticket
5. Exploitation of 10 vulnerable VMs with real world scenarios
6. Give jumpstart to your career by learning Offensive Penetration Testing from Beginner to Advance level. After completion of this course, you will develop an offensive security mindset and feel more confident with latest tools being used in penetration testing
7. 10 vulnerable VMs included in this course will give you real world scenario for a complete lifecycle of Offensive Penetration Testing touching multiple topics related to most exploited areas in the offensive security and penetration testing which will enhance your skills as a penetration tester.