All roadmaps
Advanced5 projects
Penetration Testing
Think like an attacker, document like a professional.
17+
completed
~14.5h
total time
5
projects
Part 1·Beginner·2.5h·17+ learners
Reconnaissance and Footprinting
Practice the passive and active recon that opens every real engagement — WHOIS, DNS, certificate transparency, and Nmap discovery.
Part 2·Intermediate·3h·15+ learners
Web App Vulnerability Scanning
Stand up OWASP Juice Shop locally, then scan it with directory brute-forcing, Nikto, and OWASP ZAP's automated scanner.
Part 3·Intermediate·3.5h·13+ learners
Exploiting Common Web Vulnerabilities
Manually exploit SQL injection and automate it with sqlmap, trigger stored XSS and an IDOR chain in Juice Shop.
Part 4·Advanced·3.5h·11+ learners
Privilege Escalation Techniques
Take a low-privilege shell on a misconfigured Linux VM and escalate to root using manual enumeration, linPEAS, and GTFOBins.
Part 5·Intermediate·2h·9+ learners
Writing a Penetration Test Report
Turn the roadmap's findings into a real PTES-structured report with CVSS-scored findings and an executive summary.
