6-Month Program · Authorised Penetration Testing
Ethical Hacking
32 hands-on modules · 24 tools & platforms · 140+ hours of training · Penetration-testing methodology and vulnerability assessment taught for legitimate, authorised security work. Covers reconnaissance, scanning, vulnerability assessment and professional reporting, built entirely around isolated lab environments and industry-standard methodology such as PTES and OWASP.
Last updated: 27 August 2026
Quick answer
Skill Training Institute's Ethical Hacking course is a 6-month, 32-module, 140+ hour classroom and online program in Alpha-1, Greater Noida that teaches authorised penetration testing and vulnerability assessment on isolated lab machines, following PTES and OWASP methodology. It is beginner-friendly (no prior IT or networking background required), includes 4 portfolio projects and weekly practical assessments, and ends with 100% Placement Assist for roles such as junior penetration tester, vulnerability analyst and security consultant.
Who this course is for
Built for students, IT professionals and career-switchers who want dedicated, focused training in authorised penetration testing and vulnerability assessment — no prior security experience needed, every core concept is taught from the ground up with a strong emphasis on legality and ethics.
By the end you'll follow a full penetration testing methodology — reconnaissance, scanning, vulnerability assessment and authorised exploitation in isolated lab environments — and deliver a professional findings report the way a client-facing security consultant does.
Legal & ethical framing: every technique in this course is practised only in isolated, authorised lab environments that you own or that the institute provides. The course begins with cyber law and rules of engagement, and testing on any system without explicit written authorisation is never taught or permitted.
1Program structure
Four phases over 24 weeks — from legal foundations and methodology, through reconnaissance and scanning, to vulnerability assessment, authorised exploitation and professional reporting.
| Phase | Modules | Focus |
|---|---|---|
| Phase 1 — Foundations & Legal Framework | 01–08 | Ethics, cyber law, networking refresher, Kali Linux and penetration testing methodology |
| Phase 2 — Reconnaissance & Scanning | 09–16 | Active/passive recon, OSINT, network scanning and enumeration |
| Phase 3 — Vulnerability Assessment & Authorised Exploitation | 17–24 | Vulnerability analysis, web app testing, authorised exploitation in isolated labs |
| Phase 4 — Reporting & Career Readiness | 25–32 | Professional report writing, red/blue team concepts and a client-ready portfolio |
2Full curriculum — all 32 modules
Click any phase to expand its modules, or open a module directly for a detailed description.
Phase 1Foundations & Legal FrameworkModules 01–08Ethics, cyber law, networking refresher, Kali Linux and penetration testing methodology+
01Introduction to Ethical Hacking & Types of Hackers+
Understanding the ethical hacker's role and how authorised testing differs from malicious hacking.
02Cyber Laws, Ethics & Rules of Engagement+
Covering relevant cyber law, professional ethics and the written authorisation every engagement requires.
03Networking Refresher for Penetration Testers+
Revisiting core networking concepts — TCP/IP, ports and protocols — from a tester's perspective.
04Linux & Kali Linux Fundamentals+
Getting comfortable with the Linux command line and the Kali Linux testing distribution.
05Setting Up an Authorised Penetration Testing Lab+
Building an isolated, legal home lab with intentionally vulnerable target machines to practise on.
06Penetration Testing Methodologies (PTES, OWASP, NIST)+
Learning industry-standard methodologies that structure every professional penetration test.
07Passive Information Gathering & OSINT Basics+
Collecting publicly available information about an authorised target without touching its systems.
08Scoping, Rules of Engagement & Client Authorisation+
Defining engagement scope, timelines and authorisation documents before any testing begins.
Phase 2Reconnaissance & ScanningModules 09–16Active/passive recon, OSINT, network scanning and enumeration+
09Active Reconnaissance Techniques+
Moving from passive to active recon within an authorised scope to map a target's presence.
10DNS, WHOIS & Network Footprinting+
Using DNS and WHOIS records to build a footprint of a target organisation's infrastructure.
11Scanning Networks with Nmap+
Discovering live hosts, open ports and running services on an authorised network with Nmap.
12Service & Version Enumeration+
Identifying service versions and configurations to narrow down likely vulnerabilities.
13Vulnerability Scanning with Nessus & OpenVAS+
Running automated vulnerability scans against lab targets and interpreting the results.
14Web Application Reconnaissance & Nikto+
Mapping a web application's structure and surface-level weaknesses before deeper testing.
15Social Engineering Awareness & the SET Toolkit+
Understanding social engineering as an authorised test vector and how organisations defend against it.
16Wireless Network Reconnaissance+
Surveying wireless networks in a lab setting to understand common wireless weaknesses.
Phase 3Vulnerability Assessment & Authorised ExploitationModules 17–24Vulnerability analysis, web app testing, authorised exploitation in isolated labs+
17Vulnerability Analysis & CVSS Scoring+
Prioritising discovered vulnerabilities using CVSS severity scoring, the way real assessments do.
18Web Application Testing: OWASP Top 10+
Testing lab web applications against the OWASP Top 10 categories of common vulnerabilities.
19SQL Injection Testing with SQLmap+
Identifying and validating SQL injection issues on intentionally vulnerable lab applications.
20Authorised Exploitation Basics with Metasploit+
Using the Metasploit framework to validate vulnerabilities against isolated lab targets only.
21Password Attacks & Authentication Testing+
Testing authentication mechanisms for weak credential handling in a controlled lab environment.
22Privilege Escalation Concepts (Windows & Linux)+
Understanding common privilege escalation vectors and the misconfigurations behind them.
23Wireless & Network Penetration Testing+
Running an authorised wireless and internal-network penetration test in the lab.
24Post-Exploitation & Evidence Handling+
Documenting evidence responsibly and understanding post-exploitation reporting requirements.
Phase 4Reporting & Career ReadinessModules 25–32Professional report writing, red/blue team concepts and a client-ready portfolio+
25Report Writing: Findings, Risk & Executive Summaries+
Structuring a professional penetration test report for both technical and executive readers.
26Client Debrief & Remediation Recommendations+
Presenting findings to a client and writing clear, actionable remediation guidance.
27Red Team vs Blue Team Concepts+
Understanding how offensive (red team) and defensive (blue team) roles work together.
28Introduction to Bug Bounty Programs+
Learning how legitimate bug bounty platforms and responsible disclosure programs operate.
29Cloud Penetration Testing Basics+
Introducing authorised testing considerations specific to cloud-hosted environments.
30Certification Roadmap: CEH, OSCP & Beyond+
Mapping course learning to recognised certifications and planning your next steps.
31Building an Ethical Hacking Portfolio+
Curating lab reports and projects into a portfolio suitable for security analyst interviews.
32Capstone: Full Authorised Penetration Test & Report+
Running a complete penetration test on an authorised lab environment, end-to-end, with a final report.
324 tools & platforms you'll use
Everything is taught on real, industry-standard tools inside authorised lab environments — not simulations. Swipe or use the arrows to browse every category.
Gathering information about an authorised target before any active testing begins.
Finding and validating weaknesses on authorised, isolated lab targets.
Validating findings in isolated labs and turning results into a professional report.
4How each module is taught
Every module follows the same practical, real-engagement lens, entirely inside authorised lab environments.
Concept Walkthrough
Trainer explains the concept using a real-world, authorised testing scenario first, then the tool or workflow.
Live Along
You run the same scan, test or lab step by step, right alongside the trainer, on isolated targets only.
Hands-on Lab Exercise
An independent task applying the concept in a new authorised lab scenario.
Doubt Clearing
One-on-one help for anyone stuck, before the class moves to the next module.
Weekly Assessment
A short practical lab test every week so gaps are caught early, not at the end.
5Projects & portfolio
Four practical, portfolio-ready assessment projects across the full syllabus — the kind of work you'll show in interviews.
- Project 1. Passive & active reconnaissance report for an authorised lab target
- Project 2. Network vulnerability assessment with prioritised, CVSS-scored findings
- Project 3. Authorised web application penetration test in an isolated lab
- Project 4. Capstone: full authorised penetration test with a professional client report
6Assessment & certification
Weekly practical assessments covering reconnaissance, scanning, vulnerability assessment and lab exploitation workflows, with instructor review and feedback.
Final practical exam across all four phases, plus the capstone project used as your demonstrable, portfolio-ready proof of skill.
Certificate of completion, plus resume and portfolio support through our 100% Placement Assist program.
7Key terms explained
Short, plain-language definitions of the core terms used throughout this course.
- Ethical Hacking
- Authorised, legally sanctioned testing of computer systems to find security weaknesses before malicious attackers do.
- Penetration Testing
- A structured, authorised simulated attack on a system, network or application to evaluate its security, carried out under a defined scope and methodology.
- PTES
- Penetration Testing Execution Standard — an industry methodology that defines the phases of a professional penetration test, from scoping through reporting.
- OWASP Top 10
- A standard awareness document listing the ten most critical security risks to web applications.
- CVSS
- Common Vulnerability Scoring System — an open framework for rating the severity of security vulnerabilities on a standardised numeric scale.
- Vulnerability Assessment
- The process of identifying, classifying and prioritising security weaknesses in a system or network.
8Quick answers
Is this legal to learn?
Yes. Every technique is practised only on isolated lab machines you own or that the institute provides, and the course opens with cyber law, ethics and authorisation requirements before any tool is touched. Testing real systems without written authorisation is never taught or condoned.
Do I need prior IT or networking experience?
No prior experience is needed — networking, Linux and methodology fundamentals are taught from the ground up in Phase 1.
Do I need my own laptop for the labs?
A laptop that can run a virtual machine is recommended; institute lab computers with Kali Linux and all tools pre-installed are also available in class.
Will I test real, live systems?
No — all hands-on testing happens against isolated, intentionally vulnerable lab machines set up specifically for this course, never against production or third-party systems.
Are classes online, offline, or both?
Both. Offline batches run at our Alpha-1, Greater Noida campus; online live batches follow the same curriculum with the same trainers. Morning, evening and weekend timings are available.
What can I do after completing this course?
You'll be ready for junior penetration tester, vulnerability analyst and security consultant roles, with a client-ready portfolio, and can progress into advanced offensive security certifications with the same placement support.
Ready to see a class live?
Book a free, no-obligation demo class and sit in on a real authorised penetration testing lab before you decide anything.
