WEEK 07

Ethical Hacking I — Methodology

Operational scenario

The fictional client wants a web-app assessment next week. Nothing happens until scope and signatures are in place.

Week completion
0%
~10 hours this week
Assessment: Knowledge check 7; ROE rubric
Deliverable: Approved ROE + authorization
Learning objectives
  • Scope an engagement
  • Write rules of engagement and authorization
  • Run recon and enumeration
Classroom topics
  • Scoping
  • ROE
  • Written authorization
  • Recon & enumeration
  • Vulnerability discovery & validation
Standards · vocabulary
PTES-style flowNIST SP 800-115 concepts
ROECVECVSSCWERCE
Open glossary
Competency demonstrated: Scopes and authorizes a test correctly.

Four-mode learning matrix

~1.5 h
Physical hands-on lab

Set up an isolated target VM; confirm no external reachability.

~2 h
Docker container lab

Lab 8 — Identify an intentionally vulnerable web app.

~0.5 h
AR/VR immersive scenario

Penetration-tester role: plan an authorized assessment. Role: Penetration tester.

No headset? Desktop planning worksheet. Printed and mobile versions are also available.

Individual technical assignment

Complete an ROE + authorization for a lab target.

Team exercise

Peer-review each other's scope for safety gaps.

Required hardware
  • Kali VM
  • Metasploitable / Juice Shop
  • Isolated vSwitch
Required software
  • Kali Linux
  • Nmap
  • OWASP Juice Shop
Workplace application

In real engagements the ROE and authorization letter are your legal protection — testers are fired and prosecuted without them.

Docker progression step
L8 Identifying an intentionally vulnerable web application

Fingerprint webapp; list three candidate weaknesses with CWE IDs. Week 10: patch and re-test.

Open the Docker range
Lab evidence to collect
Safety controls — confirm before starting
Controls practiced this week
Vulnerability & patch managementPenetration testing & control validation
See the full crosswalk