Penetration Testing & Ethical Hacking (PEN-200 / OSCP) | Ingress Academy
Create account & apply
NETWORK SECURITY & ETHICAL HACKING · INTERMEDIATE LEVEL

Penetration Testing & Ethical Hacking (PEN-200 / OSCP)

Pentest (PEN-200 / OSCP) is a 4-month hands-on cybersecurity training program focused on penetration testing and ethical hacking. Participants learn Linux and Windows privilege escalation, web application security testing, network pivoting, Active Directory exploitation, and OSCP-style attack techniques through practical labs and real-world scenarios. The program prepares learners for the OffSec OSCP certification and professional penetration testing roles.

Intermediate16 weeks128 hoursOn-site
Your selected course will be carried into Ingress Portal.
YOUR LEVEL
BeginnerIntermediateAdvancedExpert
WHAT YOU WILL BE ABLE TO DO

The skills you will have by the end of this course.

  • Upon successful completion of this program, participants will be able to:
  • Conduct reconnaissance and enumeration using industry-standard tools and techniques.
  • Identify and exploit common vulnerabilities in Linux, Windows, and web applications.
  • Perform privilege escalation on Linux and Windows systems.
  • Use tunneling and pivoting techniques to access internal networks.
  • Assess and exploit Active Directory environments.
  • Apply penetration testing methodologies in real-world scenarios.
  • Document findings and create professional penetration testing reports.
  • Prepare for the OffSec OSCP (PEN-200) certification exam with confidence.
CONDENSED SYLLABUS

See the structure without reading a textbook.

Modules stay collapsed for quick scanning. Open any module to inspect its topics.

01Public Exploit + İlk Shell1 lesson+

SearchSploit, Exploit-DB, GitHub-dan exploit tapmaq. Python/Bash exploit uyğunlaşdırma. Reverse shell növləri. Shell stabilization (pty, stty).

02Linux Privilege Escalation I1 lesson+

LinPEAS ilə enum. sudo -l + GTFOBins. SUID binaries. Cron job abuse. Insecure file permissions.

03Linux Privilege Escalation II + Şifrə Kırma1 lesson+

Capabilities, NFS misconfig, kernel exploit axtarışı. Credential harvesting (history, config faylları). John + Hashcat, zip2john, ssh2john (raport Target No1-2 əsaslı).

04Windows Privilege Escalation I1 lesson+

WinPEAS ilə enum. Service binary hijacking, unquoted service paths, DLL hijacking. icacls, sc qc, accesschk.

05Windows Privilege Escalation II1 lesson+

Token impersonation (SeImpersonatePrivilege). PrintSpoofer / GodPotato. Scheduled tasks, registry autoruns. Credential harvesting (SAM, Sticky Notes). xp_cmdshell → PrintSpoofer zənciri (raport Target No4).

06Port Forwarding & SSH Tunneling1 lesson+

SSH -L (local), -R (remote), -D (dynamic/SOCKS5). Proxychains konfiqurasiyası. socat relay. Daxili şəbəkəyə çatmaq niyə lazımdır.

07Chisel + Fayl Transfer1 lesson+

Chisel reverse SOCKS5 tunnel (raport Target No4 tam axışı). netsh portproxy, plink.exe. Fayl transfer metodları: certutil, Python HTTP server, SMB share.

08Veb Əsasları + Burp Suite + Directory Enum1 lesson+

HTTP/HTTPS — request/response, metodlar, status kodlar. Burp Suite: Intercept, Repeater, Intruder. gobuster ilə directory/file enum. Veb servis fingerprinting.

09SQL Injection — Manual1 lesson+

SQL əsasları, manual aşkarlama. UNION-based, Error-based, Blind (time-based). MSSQL xp_cmdshell ilə OS command execution (raport Target No4). SQLmap OSCP-də qadağandır — hər şey Burp Repeater ilə manual.

10File Upload + LFI/RFI + Command Injection1 lesson+

File upload bypass (Content-Type, extension). PHP webshell. LFI — /etc/passwd, log poisoning ilə RCE. Command injection operatorları (;, &&, |, backtick).

11Real OSCP-style Veb Hədəflər1 lesson+

WordPress plugin zəifliyi (gobuster + CVE). Default credentials. zip2john + exiftool + credential spray (raport Target No2 tam axışı). Veb shell → stable shell → privesc vektoru.

12Active Directory Enum + Autentifikasiya1 lesson+

AD strukturu (Domain, DC, OU, GPO, Trust). NTLM + Kerberos axışı. net / PowerView ilə manual enum (user, group, SPN, share). BloodHound giriş.

13Kerberoasting, AS-REP Roasting, Pass-the-Hash1 lesson+

Kerberoasting: SPN→TGS→hashcat (-m 13100). AS-REP Roasting: pre-auth disabled→hash. Pass-the-Hash: impacket-psexec / evil-winrm. BloodHound attack path analizi.

14Lateral Movement + DCSync1 lesson+

psexec, wmiexec, smbexec, evil-winrm. CrackMapExec ilə credential spray. secretsdump: SAM, LSA, NTDS dump. Domain Admin ilə DC-yə psexec (raport Target No5 tam axışı).

15Mock OSCP + İmtahan Strategiyası1 lesson+

OSCP formatı: 3 standalone (60pt) + AD set (40pt). Zaman strategiyası. Stuck olduqda nə etmək. Bonus bal (+10pt lab report). Mock imtahan: AD set + 2 standalone.

16Mühit + Port Skanı1 lesson+

Kali Linux quraşdırma, VPN, lab mühiti. Nmap flagları (-p-, -A, -sV, NSE). SMB enum (enum4linux, smbclient).

UPCOMING GROUPS

Choose the cohort you can actually attend.

Only current, open groups are shown.

STARTS

To be announced

On-site
Schedule
To be announced
Format
On-site
Duration
16 weeks · 128 hours
Language
Confirm with advisor
Join the next cohort waitlist
CONTEXTUAL PROOF
“The program helped me connect individual skills into the way real teams design, build and deliver software.”

See real graduate stories from the Ingress community.

Explore graduate results
APPLICATION THROUGH INGRESS PORTAL

Your course stays selected while you create your account.

We use one Portal account for applications, assessments and future learning progress. You will not need to email your details or select the training again.

Questions first? Talk to an advisor
  1. 01

    Create or sign in to your Portal accountYour contact details stay connected to one student profile.

  2. 02

    Confirm your application detailsPenetration Testing & Ethical Hacking (PEN-200 / OSCP) is preselected.

  3. 03

    Submit your applicationThe admissions team receives it immediately and can follow up from the Portal.

SELECTED TRAININGPenetration Testing & Ethical Hacking (PEN-200 / OSCP)On-site

Continue in Ingress Portal Already registered? The Portal will let you sign in instead.