← Back to the catalogue
Domain 05 . Security

Penetration Testing

70
Hours of teaching
Advanced
Level
8
Modules
Classroom . Online . Hybrid
Mode
Course overview

A professional penetration testing course covering methodology, exploitation depth and client reporting. The course works to a formal methodology PTES and OWASP — from scoping and rules of engagement through exploitation, lateral movement and evidence collection. Active Directory attack paths and API testing are given full modules.

Assessment is a complete client-style report on a multi-host lab, defended in a debrief session.

Who it is for
  • Security analysts moving into offensive roles
  • Ethical hacking course graduates
  • SOC and blue team staff cross-training
  • Consultants delivering assessments
Prerequisites
Ethical hacking fundamentals, networking, Linux and basic scripting.
How it runs
Learn → Practise → Build → Experience → Demonstrate, ending in a capstone. Delivered by practitioners from the engineering bench, in Madurai, Coimbatore and online.
Final project
Full Penetration Test Report and Debrief

Programme sheet

The printed sheet carries the full module breakdown, labs, project work and certification path. Fees, dates and formats for the next intake are confirmed by the education team on enquiry.

Learning outcomes

01
Scope an engagement and agree rules of engagement.
02
Enumerate and exploit hosts systematically.
03
Move laterally and escalate inside a domain.
04
Test web applications and APIs to OWASP standards.
05
Collect evidence without damaging systems.
06
Rate findings with CVSS and business impact.
07
Write and present a client-quality report.

Module structure

8 modules
Module 01

Methodology and Scoping

PTES . Scope and exclusions . Time-boxing . OWASP testing guide . Legal agreements
Module 02

Infrastructure Enumeration

Network mapping . Service fingerprinting . Attack surface documentation
Tools — Nmap, CrackMapExec, NetExec
Module 03

Exploitation

Public exploits . Payload handling . Shell stabilisation . Manual exploitation . Antivirus considerations
Tools — Metasploit, msfvenom
Module 04

Post-Exploitation

Local enumeration . Persistence . Privilege escalation . Pivoting
Tools — LinPEAS, WinPEAS, Mimikatz, Cleanup
Module 05

Active Directory Attacks

Domain enumeration . AS-REP roasting . ACL paths . Kerberoasting . Delegation abuse . Domain persistence
Tools — BloodHound, Impacket
Module 06

Web and API Testing

Authentication flaws . Injection . Business logic . IDOR . JWT handling . Rate limiting
Tools — Burp Suite, Postman
Module 07

Cloud and Container Notes

IAM abuse . Metadata services . Secret exposure
Module 08

Reporting and Debrief

Evidence handling . Executive summary . Technical detail . Remediation plan . Retest cycle

Assessment & certification

Module assignments and labs
25%
Internal assessments
15%
Mini projects
20%
Final project and review
40%

Learners who complete all modules, submit the final project and clear the review receive a course completion certificate from Kaizen Infinities Private Limited. Project work is documented for the learner's portfolio, and interview preparation is included in the closing sessions.

Career outcomes . Roles this programme prepares for
Penetration TesterRed Team OperatorSecurity ConsultantApplication Security AnalystOffensive Security Engineer
Enquire or apply →Programme sheet (PDF)Institutions can commission a cohort

Also in Security