Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Ethical Hacking Offensive Penetration Testing
Rating: 3.5 out of 5(119 ratings)
1,612 students

Ethical Hacking Offensive Penetration Testing

Practical Hands on Offensive Penetration Testing OSCP - Beginner to Advance
Last updated 10/2025
English

What you'll learn

  • Set up your environment for performing penetration testing with Kali Linux
  • Enumerate/scan systems with Netdiscover, Nmap, Dirb, Nikto, etc.
  • Practical Ethical Hacking & Offensive Penetration Testing
  • Exploitation of OWASP Top 10 Web Application Attacks ( SQL Injection,XSS,LFI & RFI,Command Injection etc.
  • Perform remote exploitation of systems
  • Take a Walkthrough of Burp Suite,OWASP ZAP, OpenVAS VA scanner
  • Exploitation of Linux Vulnerabilities (SAMBA exploit,IRC,distscc,etc)using netcat & metasploit
  • Exploitation of Windows 10 using Empire Powershell (Creating Payload using MS Word & Excel with Empire)
  • Attacking & Defending Active Directory
  • Detailed Walkthrough of Exploitation of 10 Intentionally Vulnerable Machine close to Real World Scenarios

Course content

3 sections39 lectures12h 13m total length
  • Introduction1:03

    Practice practical, hands-on offensive penetration testing across beginner, intermediate, and advanced sections, including application-level exploits, windows vulnerabilities, escalation, and vm-based real-world scenarios.

  • How to Make best out of this course0:58

    Follow the course in a structured beginner-to-advanced sequence, practice with the instructor to gain certification skills, and unlock two additional modules after completion.

  • A Walk-through of Web Application Security3:46

    Learn web application security and assessment using standard practices. Explore injection, authentication, access control, misconfiguration, and cross-site scripting with manual testing and proxy-based scanners.

  • A Walk-through of Burp Proxy12:45

    Walk through setting up burp proxy to intercept and analyze web traffic, install the burp certificate, and use intruder and repeater for payload testing on a target.

  • A Walk-through of ZAP Proxy9:46

    Learn to set up the open source zap proxy, configure your browser, intercept and analyze requests, spider and fuzz web apps, and run active scans for OSCP prep.

  • Installation & Configuration6:41

    Install and configure the offensive security toolbox in a virtual box, download and import the toolbox appliance, and set up Windows environments to prep for OSCP-style penetration testing.

  • Active & Passive Domain Enumeration - Collecting IP details13:02

    Master active and passive domain enumeration to collect domains, subdomains, name servers, and IP ranges for recon in offensive penetration testing and OSCP prep.

  • Sub Domain Enumeration using standalone scripts3:23

    learn to perform subdomain enumeration using standalone scripts by setting up the required tools, configuring api keys, and enumerating domains to reveal subdomains and their ip addresses.

  • Command Execution - Bypass security and gain reverse shell11:56

    Demonstrates practical command execution to bypass security and gain a reverse shell by exploiting a vulnerable business application, using local host checks, one-line PSP payloads, and other command techniques.

  • Local File Inclusion - Getting Sensitive files from a server14:34

    Demonstrates local file inclusion exploitation to access sensitive files on a server, including password files, via application navigation, proxy setup, and scanner-driven discovery for oscp prep.

  • Local File Inclusion- Gaining a shell from remote server7:06

    Explore local file inclusion techniques to read sensitive files and gain a shell on a remote server, using request interception and pass-through methods to execute external programs.

  • Remote File Inclusion - Bypass control and gain reverse shell4:15

    Master remote file inclusion to bypass control and gain a reverse shell, and configure the target to support this technique.

  • Remote File Inclusion Part - Exploit server remotely and gain reverse shell10:23

    Discover remote file inclusion exploitation to access a server remotely and gain a reverse shell, including setting up a host, crafting payloads, and bypassing input validation via case sensitivity.

  • File Upload - Bypass File restriction - Upload Backdoor -Gain Reverse Shell21:52

    Explore bypassing file upload restrictions to plant a backdoor and gain a reverse shell on a vulnerable app, with hands-on exploitation for OSCP prep.

  • File Upload - Bypass File Restriction - Ulpoad backoor-Gain reverse shell -Level10:49

    Learn to bypass a file upload restriction by intercepting and tampering requests with a proxy tool, changing content type and file name to upload a reverse shell for oscp prep.

  • XSS Exploitation - Stealing Victim Credentials8:36

    Explore cross-site scripting exploitation to understand how malicious payloads can steal user credentials, revealing practical implications of XSS and credential theft in web applications for OSCP prep.

  • XSS Exploitation - Defacing Websites - Stealing Credentails of All Website Users16:57
  • XSS Exploitaton - Stealing Session Cookie -Running Automated scan using Burp&ZAP9:35

    Learn XSS exploitation techniques to steal the session cookie and run automated scans with Burp and ZAP to identify vulnerabilities in a controlled environment for offensive penetration testing training.

  • SQL Injection - Navigating in Database & Basic Concepts5:58

    Explore SQL injection fundamentals by navigating a database, listing databases and tables, and extracting user credentials, while contrasting manual and automated exploitation techniques.

  • SQL Injection - Exploiting using SQLMap -Dumping Database - Dumping Tables-User14:52

    Learn SQL injection techniques using SQLMap to enumerate databases, dump the database and tables, and extract user credentials, with emphasis on performing tests only with authorization to avoid legal trouble.

Requirements

  • Basic IT knowledge
  • Some prior exposure to the basics of Kali Linux
  • Prior hands-on experience with penetration testing/ethical hacking will be beneficial but not necessary

Description

In this course, you will learn how to exploit most of OWASP Top 10  vulnerabilities, Linux & Windows 10 OS to gain root access of servers This is designed to clear OSCP certification as well as those who want to excel in Cyber Security & Ethical Hacking Domain.

1. Running NMAP & other discovery tools.

2. Exploitation of OWASP Top 10 vulnerabilities and compromise user account,Dump Databases,Deface user's application with real words scenarios

3. Penetration Testing with Kali Linux including Metasploit,AV Evasion,Gain access of a shell,Privilege Escalation & many more

4. Hacking Windows OS using Empire Powershell ,Run Mimikatz,Pass the Hash,Dumping NTLM hashes,Getting Golden Ticket,Kerbros Ticket

5. Exploitation of 10 vulnerable VMs with real world scenarios

6. Give jumpstart to your career by learning Offensive Penetration Testing from Beginner to Advance level. After completion of this course, you will develop an offensive security mindset and feel more confident with latest tools being used in penetration testing

7.  10 vulnerable VMs included in this course will give you real world scenario for a complete lifecycle of Offensive Penetration Testing touching multiple topics related to most exploited areas in the offensive security and penetration testing which will enhance your skills as a penetration tester.

Who this course is for:

  • Aspirants who are seeking carrear in information Seucurity,Information Security professional,Cyber Security Professional,Cyber Security Enthusiasts,IT Security.
  • Beginner in Cyber Security,Aspiring OSCP Certification,Aspiring Ethical Hackers