Ethical Hacker Scope and Sequence (Version 1.0)

In this course, learners develop ethical hacking and penetration testing skills that build a foundation for success in the cybersecurity industry. With the support of video and rich interactive media, participants learn, apply, and practice ethical hacking skills in meaningful ways through a series of realistic hands-on lab experiences.

The course also includes many opportunities for learners to practice what they are learning as they are learning it. Learning by doing is the most powerful way to build new skills and knowledge.
The Ethical Hacker course includes the following features:

- 34 labs support the independent acquisition of knowledge and ethical hacking skills.

- 86 practice activities provide opportunities for self-assessment and identification of learning deficits.

- 10 modules of content cover important topics that enable students to face ethical hacking challenges.

- Assessments include 10-chapter exams, a final exam, and a skills-based assessment.

70 hours
10 days 70 hrs
Greek
6 - 16

code:ECCOUNCIL.CEHV6

  • Objectives

    • Describe ethical hacking and penetration testing concepts, terminology, and common methodologies/frameworks.
    • Explain legal, ethical, and professional considerations (authorization, scope boundaries, documentation, and responsible disclosure).
    • Explain reconnaissance, vulnerability scanning concepts, and how to interpret typical scan outputs and risk implications.
    • Explain common social engineering techniques, physical attack vectors, and methods of influence used to elicit user participation.
    • Explain common network, wireless, web application, cloud, mobile, and IoT attack surfaces and associated vulnerability types (including OWASP Top 10 categories).
    • Describe post-exploitation concepts including persistence, lateral movement, detection avoidance, and enumeration at a high level.
    • Describe the purpose, structure, and key components of a penetration testing report and related stakeholder communications.
    • Describe common penetration testing tool categories and basic scripting/code analysis concepts used in security testing.
    • Plan and scope a penetration test by producing preliminary documents (e.g., rules of engagement, scope/plan) aligned to organizational requirements.
    • Perform passive and active reconnaissance to identify potential targets, services, and exposed information within an authorized scope.
    • Execute vulnerability scans and analyze results to prioritize likely exploitable findings.
    • Apply basic social engineering and physical-security testing concepts in safe, authorized, simulated scenarios.
    • Demonstrate exploitation approaches for common wired and wireless network vulnerabilities in a controlled lab environment.
    • Use web application testing tools to identify and validate common application vulnerabilities (e.g. injection, authentication/authorization flaws, XSS, CSRF, SSRF, file inclusion).
    • Demonstrate basic testing approaches for cloud, mobile, and IoT scenarios using research-driven attack vectors and lab activities.
    • Perform post-exploitation tasks in a lab, including establishing a foothold, maintaining persistence, and conducting enumeration/lateral movement activities as appropriate.
    • Plan and scope a penetration test by producing preliminary documents (e.g., rules of engagement, scope/plan) aligned to organizational requirements.
    • Perform passive and active reconnaissance to identify potential targets, services, and exposed information within an authorized scope.
    • Execute vulnerability scans and analyze results to prioritize likely exploitable findings.
    • Apply basic social engineering and physical-security testing concepts in safe, authorized,
  • Topics

    Module 1: Introduction to Ethical Hacking and Penetration Testingo

    Module objective: Explain the importance of methodological ethical

    Ethical Hacking and Penetration Testing

    Hacking and penetration testing.

    1.1 Understanding Ethical Hacking and Penetration Testing

    Objective: Explain the importance of ethical hacking and penetration testing.

    1.2 Exploring Penetration Testing Methodologies.

    Objective: Explain different penetration testing methodologies and frameworks.

    1.3 Building Your Own Lab.

    Objective: Configure a virtual machine for your penetration testing learning experience.

    Module 2: Planning and Scoping a Penetration Testing Assessment

    Module objective: Create penetration testing preliminary documents.

    2.1 Comparing and Contrasting Governance, Risk, and Compliance Concepts.

    Objective: Explain the role of governance, risk, compliance, and environmental factors in planning penetration testing.

    2.2 Explaining the Importance of Scoping and Organizational or Customer Requirements.

    Objective: Create a penetration test scope and plan document that addresses organizational requirements for penetration testing services.

    2.3 Demonstrating an Ethical Hacking Mindset by Maintaining Professionalism and Integrity.

    Objective: Create your personal code of conduct to provide professionalism and integrity in your ethical hacking practice.

    Module 3: Information Gathering and Vulnerability Scanning

    Module objective: Perform information gathering and vulnerability scanning activities.

    3.1 Performing Passive Reconnaissance.

    Objective: Perform passive reconnaissance activities.

    3.2 Performing Active Reconnaissance.

    Objective: Perform active reconnaissance activities.

    3.3 Understanding the Art of Performing Vulnerability Scans.

    Objective: Perform vulnerability scans.

    3.4 Understanding How to Analyze Vulnerability Scan Results.

    Objective: Analyze the results of reconnaissance exercises

    Module 4: Social Engineering Attacks

    Module objective: Explain how social engineering attacks succeed.

    4.1 Pretexting for an Approach and Impersonation.

    Objective: Explain how pretexting is used in social engineering attacks.

    4.2 Social Engineering Attacks.

    Objective: Explain different types of social engineering attacks.

    4.3 Physical Attacks.

    Objective: Explain different types of physical attacks.

    4.4 Social Engineering Tools.

    Objective: Explain how social engineering attack tools facilitate attacks.

    4.5 Methods of Influence.

    Objective: Explain how social engineering a tacks enlist user participation.

    Module 5: Exploiting Wired and Wireless Networks

    Module objective: Explain how to exploit wired and wireless network vulnerabilities.

    5.1 Exploiting Network-Based Vulnerabilities.

    Objective: Explain how to exploit network-based vulnerabilities.

    5.2 Exploiting Wireless Vulnerabilities.

    Objective: Explain how to exploit wireless vulnerabilities.

    Module 6: Exploiting Application-Based Vulnerabilities

    Module objective: Explain how to exploit application-based vulnerabilities.

    6.1 Overview of Web Application-Based Attacks for Security Professionals and the OWASP Top 10.

    Objective: Explain common web application attacks.

    6.2 How to Build Your Own Web Application Lab

    Objective: Describe common web application testing tools.

    6.3 Understanding Business Logic Flaws.

    Objective: Explain how business logic flows enable attackers to exploit web applications.

    6.4 Understanding Injection-Based Vulnerabilities.

    Objective: Use tools to conduct injection attacks.

    6.5 Exploiting Authentication-Based Vulnerabilities.

    Objective: Use tools to exploit authentication-based vulnerabilities.

    6.6 Exploiting Authorization-Based Vulnerabilities.

    Objective: Explain how authorization-based vulnerabilities are exploited.

    6.7 Understanding Cross-Site Scripting (XSS) Vulnerabilities.

    Objective: Explain cross-site scripting vulnerabil

    Module 7: Cloud, Mobile, and IoT Security

    Module objective: Explain how to exploit cloud, mobile, and IoT security vulnerabilities.

    7.1 Researching Attack Vectors and Performing Attacks on Cloud Technologies.

    Objective: Explain how to attack cloud technologies.

    7.2 Explaining Common Attacks and Vulnerabilities Against Specialized Systems.

    Objective: Explain common attacks against specialized systems.

    Module 8: Performing Post-Exploitation Techniques

    Module objective: Explain how to perform postexploitation activities.

    8.1 Creating a Foothold and Maintaining Persistence After Compromising a System.

    Objective: Explain how to create a foothold and maintain persistence after compromising a system.

    8.2 Understanding How to Perform Lateral Movement, Detection Avoidance, and Enumeration.

    Objective: Explain how to perform lateral movement, detection avoidance, and enumeration.

    Module 9: Reporting and Communication

    Module objective: Create a penetration testing report.

    9.1 Comparing and Contrasting Important Components of Written Reports.

    Objective: Describe the major components of a written pentest report.

    9.2 Analyzing the Findings and Recommending the Appropriate Remediation Within a Report.

    Objective: Recommend appropriate remediation based on the findings of a pentesting campaign.

    9.3 Explaining the Importance of Communication During the Penetration Testing Process.

    Objective: Explain the components necessary for communications during the pentest process.

    9.4 Explaining Post-Report Delivery Activities.

    Objective: Explain necessary processes to complete the pentesting engagement.

    Module 10: Tools and Code Analysis

    Module objective: Classify pentesting tools by use case.

    10.1 Understanding the Basic Concepts of Scripting and Software Development.

    Objective: Analyze code for pentesting use.

    10.2 Understanding the Different Use Cases of Penetration Testing Tools and Analyzing Exploit Code.

    Objective: Classify pentesting tools by their primary use cases.

  • Participants

    This course is intended for

    - Entry-level cybersecurity professionals seeking an introduction to ethical hacking and penetration testing through structured, hands-on labs

    - IT professionals transitioning into cybersecurity, such as help desk, network/system administrators, and junior engineers who want offensive-security fundamentals

    - Junior security operations / blue-team practitioners (SOC analysts, incident responders) who want to better understand attacker tactics and improve defensive thinking

    - Security practitioners new to penetration testing who need an end-to-end methodology covering scoping, reconnaissance, exploitation, and reporting

  • Methodology

    Lecture, discussion, demonstration and practice.

  • Other Details

    Good Knowledge of computers and Internet