# Ethical Hacking and Offensive Security Essentials Course

Canonical URL: <https://www.graduateschool.edu/courses/ethical-hacking-and-offensive-security-essentials-course>

## Overview

This foundational course gives IT and security professionals a vendor-neutral grounding in ethical hacking, with no hosted lab required. It starts with authorization, scope, and the phases of a professional testing engagement.

Learners then work through reconnaissance, scanning and enumeration, vulnerability analysis, exploitation concepts, and common web application weaknesses. The course closes with writing findings that non-technical stakeholders can act on, preparing learners for hands-on penetration testing training.

## What you'll learn

- Distinguish ethical hacking from unauthorized access and identify what authorization and scope must cover before testing begins.
- Sequence the phases of the penetration testing lifecycle from planning through reporting.
- Compare established testing methodologies and select one appropriate to a given engagement.
- Apply open source intelligence techniques to gather information about a target within an authorized scope.
- Interpret network scan and enumeration output to identify points that warrant further investigation.
- Classify vulnerabilities by category and evaluate their severity using a standard scoring approach.
- Prioritize vulnerability findings by risk when time or resources are limited.
- Explain how an exploit converts a vulnerability into unauthorized access.
- Recognize common categories of attack techniques used in offensive security testing.
- Identify common web application weaknesses and match them to a vendor-neutral weakness reference.
- Describe common post-exploitation objectives and the scope boundaries that keep them authorized.
- Write a findings summary that a non-technical stakeholder can act on.
- Explain how remediation and retesting close the testing lifecycle.

## Curriculum

#### Module 1: Ethical Hacking Foundations: Law, Ethics, and Authorization

- Lessons: 
  - What Ethical Hacking Is and Is Not
  - Authorization, Scope, and Rules of Engagement
  - Relevant Laws and Professional Codes of Conduct

- Applied activity: Learners draft a one-page mock authorization and scope memo for a fictional engagement, using a provided template, and check it against a provided checklist of required elements.

#### Module 2: The Penetration Testing Lifecycle and Methodologies

- Lessons: 
  - Overview of the Testing Lifecycle: Planning Through Reporting
  - Comparing Testing Methodologies and Frameworks
  - Choosing an Approach for a Given Engagement

- Applied activity: Learners map a short case study engagement description onto the lifecycle phases and identify which methodology best fits, using a provided worksheet.

#### Module 3: Reconnaissance and Open Source Intelligence

- Lessons: 
  - Passive versus Active Reconnaissance
  - Open Source Intelligence (OSINT) Techniques and Tools
  - Documenting Reconnaissance Findings

- Applied activity: Learners perform an OSINT exercise on a provided fictional company profile using publicly available search techniques on their own machine, and record findings in a provided worksheet.

#### Module 4: Scanning and Enumeration Techniques

- Lessons: 
  - Network and Port Scanning Fundamentals
  - Service and Vulnerability Enumeration
  - Interpreting Scan Output

- Applied activity: Learners review an annotated sample scan report and identify which findings warrant further investigation, checking their answers against a provided key.

#### Module 5: Vulnerability Identification and Analysis

- Lessons: 
  - Vulnerability Categories and Common Weakness Types
  - Using Vulnerability Databases and Scoring
  - Prioritizing Findings for Risk

- Applied activity: Learners score three sample vulnerabilities using a public scoring reference and rank them by priority, comparing their ranking to a provided answer key.

#### Module 6: Exploitation Concepts and Common Attack Techniques

- Lessons: 
  - How Exploitation Turns a Vulnerability Into Access
  - Common Attack Technique Categories
  - Limits of Safe, Authorized Testing

- Applied activity: Learners review a narrated, screenshot-based walkthrough of a sample exploitation scenario against a test system and answer reflection questions about what made the exploit possible.

#### Module 7: Web Application Attack Fundamentals

- Lessons: 
  - The Web Application Attack Surface
  - Common Web Application Weaknesses
  - Recognizing Findings in a Web Application Report

- Applied activity: Learners review a sample, redacted web application finding report and match each finding to its weakness category, using a provided vendor-neutral weakness reference.

#### Module 8: Post-Exploitation, Reporting, and Remediation

- Lessons: 
  - Post-Exploitation Goals and Boundaries
  - Writing Findings for a Non-Technical Audience
  - Remediation and Retesting

- Applied activity: Learners rewrite a technical finding excerpt into a plain-language summary for a business stakeholder, using a provided before-and-after example as a model.

## Schedule
- Mar 17, 2027 – Mar 18, 2027 — Live Online
- Jun 9, 2027 – Jun 10, 2027 — Live Online
- Sep 1, 2027 – Sep 2, 2027 — Live Online

## Pricing

**Tuition:** $1049
