Skip to content

Latest commit

 

History

21 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Ethical Hacking — Hands-On Lab Knowledge Base

Ethical Hacking — Hands-On Lab Knowledge Base

MIT 19 modules level hands-on standards

19 practical topic guides for learning offensive security and its defensive controls. Follow the workflow: understand the goal → review the commands → practise in an isolated lab → capture evidence → assess the defence. Built from a university ethical-hacking course, with credited student examples.

Commands depend on tool versions, target configuration and lab permissions. These guides are not a claim that every exercise has been reproduced on every current platform. Start with the isolation checks below; never substitute a public target for a missing lab.

New here? → Start with the lab setup guide, build your safe lab, then work the modules in order.

⚠️ Ethics and scope. Everything here is for a lab you own or are authorised in writing to test. Learning to attack is how you learn to defend — keep it legal.


The map

New scenario-led series: From Scope to Security Evidence starts with rules of engagement and includes a worked finding-to-risk example. The first lesson is a desk exercise, not a request to scan a target.

The attack lifecycle and how the modules map to it

What every module gives you

Each module folder is a self-contained lab guide with the same shape, so you always know where to look:

  • The goal — what this phase achieves and where it fits in the lifecycle.
  • Concepts that matter — the ideas you actually need, tightly.
  • A command cheat-sheet — the real commands for that phase, grouped and commented. This is the part you'll come back to.
  • Walk it in your lab — a step-by-step run against a named safe target (Metasploitable, DVWA, Juice Shop…).
  • What good looks like — how you know it worked, and what to capture.
  • Detection & defence — the blue-team view of every attack.
  • Common junior mistakes — the traps, called out.

The modules

Core lifecycle — work these in order:

# Module In one line
02 Reconnaissance Map the target's surface from public data before you touch it.
03 Scanning Find live hosts, open ports, and the service versions behind them.
04 Enumeration Make each service tell you its users, shares and secrets.
05 Vulnerability Assessment Turn versions into ranked, verified findings — not scanner noise.
06 System Hacking Gain access, escalate privilege, evidence the impact. (full student lab included)

Specialised attack surfaces:

# Module In one line
13 Hacking Web Servers Attack the server layer — version, config, exposed files.
14 Hacking Web Applications The OWASP Top 10, hands-on. (full student lab included)
15 SQL Injection Read a database through unsafe queries — by hand, then automated, then fixed.
16 Wireless Attacks Capture and crack Wi-Fi handshakes; rogue APs and defences.
17 Mobile Security Decompile apps, intercept their APIs, find the stored secrets.
18 IoT & OT Security Firmware secrets, default creds, and the safety rules of industrial gear.
19 Cloud Security Misconfigurations and identity — where real cloud breaches happen.

Cross-cutting skills:

# Module In one line
07 Malware Threats Analyse malicious code safely; build an IOC list.
08 Sniffing Read traffic on the wire and see why a switch won't save you.
09 Social Engineering The human attack surface — and how to run an authorised awareness test.
10 Denial of Service How availability is attacked at every layer, and absorbed.
11 Session Hijacking Steal or forge the token — and test whether logout really logs out.
12 Evading IDS, Firewalls & Honeypots How detection works, how it's evaded, and how to close the gap.
20 Cryptography Break how crypto is used — weak hashes, bad modes, misconfigured TLS.

A realistic learning path

  • Week 1–2: Modules 02–05 — the "find the way in" phase (recon → scanning → enumeration → vuln assessment).
  • Week 3–4: Module 06 + 08, 11, 12 — access, sniffing, sessions, evasion.
  • Week 5–6: Modules 13–15 — web servers, web apps, SQLi (the highest-demand skills).
  • Week 7+: Modules 16–20 + 07, 09, 10 — wireless, mobile, IoT, cloud, crypto, malware, social, DoS.

Worked examples — real student labs

Two modules include a full class lab write-up produced by their student groups — report, commands, and step-by-step screenshots — kept exactly as submitted, as worked examples of the phase:

That work belongs to its authors and is credited to them.

Credits, licensing & trademarks

  • Instructional content, module guides and diagrams: © Abdullah Bin Zarshaid — free to reuse for learning under the MIT License, with attribution.
  • Student lab reports: remain the work of their named authors (CY201 course), credited in each module.
  • Trademarks: "CEH" and "Certified Ethical Hacker" are trademarks of EC-Council. This is an independent educational resource organised around publicly known domain names; it reproduces no EC-Council courseware and is not affiliated with or endorsed by EC-Council.

If this helped you, a ⭐ helps other learners find it.

About

19 ethical-hacking topic guides: isolated practice, assessment evidence and defensive controls, with credited student examples.

Topics

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors