WEEK 07
Ethical Hacking I — Methodology
Operational scenario
The fictional client wants a web-app assessment next week. Nothing happens until scope and signatures are in place.
Week completion
0%
~10 hours this week
Assessment: Knowledge check 7; ROE rubric
Deliverable: Approved ROE + authorization
Learning objectives
- Scope an engagement
- Write rules of engagement and authorization
- Run recon and enumeration
Classroom topics
- Scoping
- ROE
- Written authorization
- Recon & enumeration
- Vulnerability discovery & validation
Standards · vocabulary
PTES-style flowNIST SP 800-115 concepts
ROECVECVSSCWERCE
Open glossaryCompetency demonstrated: Scopes and authorizes a test correctly.
Four-mode learning matrix
~1.5 h
Physical hands-on lab
Set up an isolated target VM; confirm no external reachability.
~2 h
Docker container lab
Lab 8 — Identify an intentionally vulnerable web app.
~0.5 h
AR/VR immersive scenario
Penetration-tester role: plan an authorized assessment. Role: Penetration tester.
No headset? Desktop planning worksheet. Printed and mobile versions are also available.
Individual technical assignment
Complete an ROE + authorization for a lab target.
Team exercise
Peer-review each other's scope for safety gaps.
Required hardware
- Kali VM
- Metasploitable / Juice Shop
- Isolated vSwitch
Required software
- Kali Linux
- Nmap
- OWASP Juice Shop
Workplace application
In real engagements the ROE and authorization letter are your legal protection — testers are fired and prosecuted without them.
Docker progression step
L8 Identifying an intentionally vulnerable web application
Open the Docker rangeFingerprint webapp; list three candidate weaknesses with CWE IDs. Week 10: patch and re-test.
Lab evidence to collect
Safety controls — confirm before starting
Controls practiced this week
Vulnerability & patch managementPenetration testing & control validation
See the full crosswalkReflection & rubric for week 7 Modes tracked: 0/5