All roadmaps
Advanced5 projects

Penetration Testing

Think like an attacker, document like a professional.

17+

completed

~14.5h

total time

5

projects

Part 1·Beginner·2.5h·17+ learners

Reconnaissance and Footprinting

Practice the passive and active recon that opens every real engagement — WHOIS, DNS, certificate transparency, and Nmap discovery.

Start
Part 2·Intermediate·3h·15+ learners

Web App Vulnerability Scanning

Stand up OWASP Juice Shop locally, then scan it with directory brute-forcing, Nikto, and OWASP ZAP's automated scanner.

Start
Part 3·Intermediate·3.5h·13+ learners

Exploiting Common Web Vulnerabilities

Manually exploit SQL injection and automate it with sqlmap, trigger stored XSS and an IDOR chain in Juice Shop.

Start
Part 4·Advanced·3.5h·11+ learners

Privilege Escalation Techniques

Take a low-privilege shell on a misconfigured Linux VM and escalate to root using manual enumeration, linPEAS, and GTFOBins.

Start
Part 5·Intermediate·2h·9+ learners

Writing a Penetration Test Report

Turn the roadmap's findings into a real PTES-structured report with CVSS-scored findings and an executive summary.

Start