
Penetration Tester — career path
StationX Intermediate
The offensive career: find and prove weaknesses before an attacker does. Security+ as the baseline, then the hacking courses employers look for, then PenTest+ to certify it.
The path
Step 1 — Security foundation
The baseline every offensive job advert asks for.
follows a certification path
Learn
- PathFollow the CompTIA Security+ (SY0-701) path — the certification almost every pentest role lists first
Step 2 — Hacking foundations
The attacker mindset, the toolkit and a first full hack, end to end.
2 courses
Learn
- CourseEthical Hacking - Hands-On Training - Part I 🔒 StationX Unlimited
20 sections · 74 lectures
- Course Overview 1
- Building Your Virtual Lab Environment Using VirtualBox 8
- Section: Troubleshooting VirtualBox 4
- Section: Passive Reconnaissance 6
- Active Scanning with Nmap 8
- Section: Scanning for Vulnerabilities Using Nessus 3
- Scanning for Vulnerabilities Using OpenVAS 2
- Section: Exploiting Microsoft Windows 3
- Section: MSFVENOM 5
- Section: Exploiting Linux 5
- Section: Social Engineering 1
- Section: BASH Scripting for Pentesters 2
- Section: Password Cracking 3
- Section: Pentesting Wireless Networks 5
- Section: Web Based Application Attacks 4
- Section: Browser Exploitation Framework (BeEF) 2
- Section: Remaining Anonymous 3
- Capture the Flag Walkthrough - Mr. Robot 4
- Capture the Flag Walkthrough – Stapler 4
- Audio Version of Training 1
- CourseLearn Ethical Hacking From Scratch 🔒 StationX Unlimited
27 sections · 146 lectures
- Training Overview 2
- 1. Course Introduction 3
- 2. Setting up a Hacking Lab 6
- 3. Linux Basics 3
- 4. Network Hacking 5
- 5. Network Hacking - Pre Connection Attacks 4
- 6. Network Hacking - Gaining Access - WEP Cracking 5
- 7. Network Hacking - Gaining Access - WPA / WPA2 Cracking 5
- 8. Network Hacking - Gaining Access - Security 2
- 9. Network Hacking - Post Connection Attacks 1
- 10. Network Hacking - Post-Connection Attacks - Information Gathering 5
- 11. Network Hacking - Post Connection Attacks - MITM Attacks 16
- 12. Network Hacking - Detection & Security 4
- 13. Gaining Access To Computers 1
- 14. Gaining Access - Server Side Attacks 9
- 15. Gaining Access - Client Side Attacks 6
- 16. Gaining Access - Client Side Attacks - Social Engineering 20
- 17. Gaining Access - Hacking Outside The Local Network 4
- 18. Post Exploitation 7
- 19. Website Hacking 2
- 20. Website Hacking - Information Gathering 7
- 21. Website Hacking - File Upload, Code Execution & File Inclusion Vulns 6
- 22. Website Hacking - SQL Injection Vulnerabilities 11
- 23. Website Hacking - Cross Site Scripting (XSS) Vulnerabilities 5
- 24. Website Hacking - Discovering Vulnerabilities Automatically 5
- 25. Bonus Section 1
- Audio Version of Training 1
Step 3 — Network attacks
Scan, enumerate and break into networks, wired and wireless.
2 courses
Learn
- CourseThe Complete Nmap Ethical Hacking Course: Network Security Assessment 🔒 StationX Unlimited
15 sections · 57 lectures
- Training Overview 2
- Introduction to the Course 4
- Nmap Cheat Sheet 1
- How to Install Nmap 3
- Nmap Basics, Target Specification & Port States 5
- Nmap Discovery and Ping Scanning 5
- Nmap Scan Techniques 5
- Nmap Port Specification, Service, Version & OS Detection 4
- Nmap Scripting Engine (NSE) 6
- Nmap Performance, Firewall and IDS Evasion 4
- Nmap Output and Extras 4
- Zenmap 4
- How Criminal Black Hats Use Nmap with Hacking Infrastructures 2
- Wrap up 2
- Preview 6
- CourseLearn Network Hacking From Scratch (WiFi & Wired) 🔒 StationX Unlimited
15 sections · 69 lectures
- Training Overview 2
- Section 0. 1
- Section 1. Preparation - Setting Up The Lab 8
- Section 2. Network Basics 4
- Section 3. Pre-Connection Attacks 4
- Section 4. Gaining Access 1
- Section 5. Gaining Access - WEP Cracking 6
- Section 6. Gaining Access - WPA/WPA2 Cracking 8
- Section 7. Gaining Access - Security & Mitigation 2
- Section 8. Post Connection Attacks 3
- Section 9. Post Connection Attacks - Information Gathering 3
- Section 10. Post Connections Attacks - Man In The Middle Attacks (MITM) 17
- Section 11. Post Connection Attacks - Gaining Full Control Over Devices On The Same Network 7
- Section 12. ARP Poisonning Detection & Security 2
- Audio Version of Training 1
Step 4 — Web application attacks
Work the OWASP Top Ten with Burp in hand.
2 courses
Learn
- CourseLearn Website Hacking / Penetration Testing From Scratch 🔒 StationX Unlimited
21 sections · 103 lectures
- Training Overview 2
- Section 0: Course Introduction 1
- Section 1: Preparation - Creating a Hacking Lab 6
- Section 2. Preparation - Linux Basics 4
- Section 3. Website Basics 2
- Section 4. Information Gathering 9
- Section 5. File Upload Vulnerabilities 6
- Section 6. Code Execution Vulnerabilities 3
- Section 7. Local File Inclusion Vulnerabilities (LFI) 2
- Section 8. Remote File Inclusion Vulnerabilities (RFI) 4
- Section 9. SQL Injection Vulnerabilities 2
- Section 10. SQL Injection Vulnerabilities - SQLi In Login Pages 4
- Section 11. SQL injection Vulnerabilities - Extracting Data From The Database 4
- Section 12. SQL injection Vulnerabilities - Advanced Exploitation 11
- Section 13. XSS Vulnerabilities 6
- Section 14. XSS Vulnerabilities - Exploitation 14
- Section 15. Insecure Session Management 5
- Section 16. Brute Force & Dictionary Attacks 3
- Section 17. Discovering Vulnerabilities Automatically Using Owasp ZAP 2
- Section 18. Post Exploitation 12
- Audio Version of Training 1
- CourseLearn Burp Suite, the Nr. 1 Web Hacking Tool 🔒 StationX Unlimited
4 sections · 12 lectures
- Training Overview 2
- Setup 3
- The Tool 6
- Congrats! 1
Step 5 — Privilege escalation and Active Directory
Go from a foothold to domain admin — the part interviews probe hardest.
2 courses · 24 labs
Learn
- CourseThe Complete Pentesting & Privilege Escalation Course 🔒 StationX Unlimited
10 sections · 63 lectures
- Training Overview 2
- Introduction 2
- Bandit 14
- Wakanda 5
- Mr. Robot 6
- Fristi Leaks 5
- Linux Privilege Escalation 14
- Windows Privilege Escalation 10
- Arctic 4
- Closing 1
- CourseActive Directory with Windows Server 2016 🔒 StationX Unlimited
7 sections · 62 lectures
- Training Overview 2
- Introduction 1
- Install and Configure AD DS 16
- Managing and Maintaining AD DS 16
- Create and Manage Group Policy 10
- Implement AD Certificate Services 8
- Implement Identity Federation and Access Solutions 9
Practise
- Labs+Active Directory Domain Services — 24 labs 🔒 StationX Labs+
- Add and Manage Domain Controllers [Guided]
- Back Up Active Directory and SYSVOL [Guided]
- Can You Configure Active Directory in a Complex Environment? [Advanced]
- Can You Configure an Active Directory Domain Services Infrastructure? [Advanced]
- Can You Create and Manage Active Directory Users and Groups? [Advanced]
- Can You Implement and Manage Group Policy? [Advanced]
- Can You Maintain an Active Directory Domain Services Database? [Advanced]
- Can You Manage Active Directory Domain Services? [Expert]
- Can You Manage Active Directory Password Policy Settings, Account Lockout Policy Settings, Fine-Grained Password Policies, and Delegated Management? [Advanced]
- Can You Manage an Active Directory Domain Services Environment? [Expert]
- Configure Domain and Local Password Policy Settings [Guided]
- Configure Group Policy Processing [Guided]
- Configure Group Policy Settings and Preferences [Guided]
- Configure Multiple User Principal Name Suffixes [Guided]
- Configure a Forest Trust Relationship [Guided]
- Create and Manage Group Policy Objects [Guided]
- Delegate Password Settings Management [Guided]
- Deploy and Configure a Read-Only Domain Controller [Guided]
- Manage Active Directory Groups [Guided]
- Manage Active Directory Sites [Guided]
- Manage Active Directory Users [Guided]
- Manage Organizational Units [Guided]
- Perform an Offline Defragmentation of the Active Directory Database [Guided]
- Restore Objects in Active Directory [Guided]
Step 6 — Scripting for testers
Write the tools instead of waiting for them.
1 course
Learn
- CourseLearn Python & Ethical Hacking From Scratch 🔒 StationX Unlimited
21 sections · 194 lectures
- Training Overview 2
- Section 1: Introduction 13
- Section 2: Writing a MAC Address Changer - Python Basics 13
- Section 3: MAC Changer - Algorithm Design 7
- Section 4: Programming a Network Scanner 16
- Section 5: Writing an ARP Spoofer 12
- Section 6: Writing a Packet Sniffer 8
- Section 7: Writing a DNS Spoofer 8
- Section 8: Writing a File Interceptor 7
- Section 9: Writing a Code Injector 14
- Section 10: Bypassing HTTPS 4
- Section 11: Writing an ARP Spoof Detector 3
- Section 12: Writing Malware 10
- Section 13: Writing Malware - Keylogger 8
- Section 14: Writing Malware - Backdoors 22
- Section 15: Writing Malware - Packaging 15
- Section 16: Website / Web Application Hacking 3
- Section 17: Website Hacking - Writing a Crawler 9
- Section 18: Writing a Program To Guess Login Information 3
- Section 19: Writing a Vulnerability Scanner 16
- Audio Version of Training 1
Step 7 — Certify it
The methodology, the labs and the report — proven in an exam.
follows a certification path
Learn
- PathFollow the CompTIA PenTest+ (v3) path — the hands-on labs for every stage above live on this path
Where this leads
- Offensive Security Certified Professional (OSCP) — Advanced
- Certified Ethical Hacker (CEH) — Intermediate
Advanced · after the job
The AI-Driven Penetration Tester
Senior roles are going to the people who can direct AI to build security solutions. When you're working in the role and ready for that step, the AI Master's Program is where it's taught — an advanced, application-only programme.
See the AI Master's Program →Application-only. A separate programme for when you're ready.