Training · Pentest · Web · Mobile · Network · AD · Cloud

Real targets. Real exploits. Real engagement letters.

A pentest programme that trains the five surfaces a working pentester actually gets scoped against. Real exploits, run on lab-isolated targets. The rules of engagement, write-ups, and re-test discipline a paying client expects — not an afterthought bolted on at the end. It finishes on a single 24-hour multi-surface capstone.

The training gap

Most pentest certifications teach one path. A real engagement scopes you against five.

Most certifications still teach one kind of target — a Linux box, a buffer overflow, a local privilege escalation — and grade you on it in isolation. That was a reasonable model fifteen years ago, when a perimeter was a perimeter. It isn't the job any more. A single engagement letter today will routinely name a web application, its mobile client, the flat network sitting behind it, the Active Directory that authenticates all of it, and the cloud tenant it runs on — and expect you to be credible on every one of them, inside the same scope and the same report.

Three ways that gap shows up

01

Single-surface certifications

You pass on a network track, you walk into a web-app scope. You pass on a web track, the engagement letter names "the corporate AD environment". The mismatch is structural.

02

Cloud and AD left out

Cloud-pentest content is barely covered in the canonical certifications. Active-Directory attack chains live almost entirely in community write-ups, not curricula.

03

Engagement discipline left to chance

Scoping, rules of engagement, evidence handling, and writing for the person who actually reads the report. This is half the job, and it is the half most training leaves you to figure out on your first real engagement — usually the hard way.

Five surfaces

Five surfaces. One curriculum. Every cohort member operates in all five.

Each surface gets a three-week module. Five modules make fifteen weeks; week sixteen is a 24-hour multi-surface capstone — one engagement letter scoped across at least three of the five surfaces at once.

Five pentest surfaces: web, mobile, network, Active Directory, cloud. Each shows representative techniques and reference frameworks. WEB · OWASP Top 10 · API · GraphQL · JWT · OAuth abuse · SSRF · IDOR · SSTI REF OWASP WSTGMOBILE · iOS + Android · app static + dynamic · TLS pinning bypass · reverse engineering REF OWASP MASTGNETWORK · recon · enumeration · service exploitation · pivoting · tunnels · evasion · LotL REF PTESAD · Kerberos attacks · ACL · DACL abuse · BloodHound paths · domain escalation REF MITRE TA0006CLOUD · IAM abuse paths · misconfig · public S3 · container · k8s escape · cross-tenant REF CSA · MITRE Cloud3 WEEKS × 5 SURFACES · 24-HR MULTI-SURFACE CAPSTONE IN WEEK 16ROE + REPORTING DISCIPLINE DRILLED EVERY WEEK

What you do on the programme

Less reading. More owning.

Exploit OWASP Top 10 from byte level

IDOR, SSRF, SSTI, deserialisation, OAuth abuse, JWT confusion — written by hand against real lab apps. Not Burp button-clicks.

Reverse and exploit a mobile app

Static and dynamic analysis on iOS and Android. TLS pinning bypass. Local-storage extraction. Native-library RE. Build the attacker workflow you will actually use on an engagement.

Move through a flat enterprise network

Recon, service enumeration, exploitation, pivoting, tunnelling — without tripping the EDR you would meet in production. Living-off-the-land where it matters.

Take a domain

Kerberoasting. AS-REP roasting. ACL abuse. BloodHound graph reasoning. Privilege escalation from a low-priv user to Domain Admin — and learn what the SOC saw on the way.

Compromise the cloud

AWS IAM-policy abuse paths. Azure managed-identity escapes. GCP service-account chaining. Container and k8s escape. The fastest-changing attack surface and the one you will be scoped against.

Write the engagement letter you will receive

Every module ends in a real pentest report — executive summary, technical narrative, risk-ranked findings, retest scope, evidence pack. Reports are what clients actually pay for, and the one skill self-taught testers almost never practise.

Sample week · Active Directory · week 10 of 16

The week a low-priv user becomes Domain Admin.

A representative AD week. By Friday, you have walked an AD attack path from a single phished domain user account to full domain dominance — and, more importantly, you can explain every hop to the blue team in the debrief.

  1. Monday

    AD reconnaissance

    LDAP enumeration. SMB share triage. Service-account discovery. BloodHound ingestion. By end of day: a graph of the domain with the shortest path to DA flagged.

  2. Tuesday

    Kerberos attacks

    Kerberoasting. AS-REP roasting against pre-auth-disabled accounts. Offline cracking. Practical thresholds — what kind of service account is realistically crackable and what is not.

  3. Wednesday

    ACL and DACL abuse

    GenericAll, GenericWrite, WriteDACL, ForceChangePassword — the misconfigurations that make a DA path two hops shorter. Identify, exploit, document.

  4. Thursday

    Lateral movement and the blue-team trace

    Pass-the-hash, pass-the-ticket, overpass-the-hash. Each technique demonstrated alongside the EDR / SIEM events it generates. You learn the attack and the trace in the same hour.

  5. Friday morning

    Domain escalation capstone

    You receive a fresh, unbriefed AD lab and a single phished user account. You have 90 minutes to reach Domain Admin. Document the path.

  6. Friday afternoon

    Blue-team debrief

    A blue-team instructor walks the cohort through the telemetry generated during Friday's capstone. Each cohort member must explain which of their actions were noisiest — and why they made them anyway.

Tooling coverage

The open-source pentest toolchain — learned well past the cheat-sheet.

Web

Burp Suite, ZAP, sqlmap, nuclei, ffuf, gobuster — and writing your own Burp extensions for the cases the off-the-shelf tooling does not cover.

Mobile

Frida, Objection, MobSF, jadx, apktool, and Ghidra for iOS native libraries, with SSL Kill Switch for pinning — down to the custom Frida scripts you write when a target fights back.

Network

nmap, masscan, Metasploit, Impacket, Responder, Chisel, Ligolo-ng, evilginx for relay attacks.

Active Directory

BloodHound and SharpHound, mimikatz, Rubeus, Certify and Certipy, CrackMapExec, NetExec, and ldapdomaindump — the chain that turns one foothold into a domain.

Cloud

Pacu for AWS, Stormspotter and MicroBurst for Azure, ScoutSuite and Prowler across providers, cloudfox for IAM paths, and kubeaudit for Kubernetes.

Reverse + binary

Ghidra, x64dbg, radare2, and IDA Free for static work; gdb and pwndbg at runtime — plus ROP gadget hunting and symbolic execution where it earns its keep.

Reporting + evidence

A report template library — executive summary, technical narrative, risk ranking, retest scope — and the workflow to assemble a clean, defensible evidence pack behind every finding.

Rules of engagement

Scope-fence discipline, kill-switch protocols, customer-communication cadence, emergency-stop language — drilled in the classroom, not improvised on your first live engagement.

What you walk away with

A pentester who can take any of the five surfaces on day one.

Five-surface certification

A 24-hour multi-surface capstone in week 16. Pass to certify; the rubric mirrors the discipline of a real engagement.

Engagement-grade report portfolio

Five module reports plus your capstone report — proper format, written for the reader who signs it off, findings ranked the way a client expects. A portfolio you can put in front of an interviewer.

Adversary-emulation grounding

The kill-chain logs you produce feed straight into an AttackWiz BAS scenario (see Products) — so the offensive work you practise here and the continuous validation on the blue side speak one vocabulary.

Hiring pipeline access

The Cyberange consulting team, sovereign red-team cells, BFSI internal offensive teams, MSSP testing desks — reached through a referral pipeline, not another job portal.

Drilled against

  • CERT-In empanelment criteria
  • STQC certified-tester scheme
  • MITRE ATT&CK
  • PTES
  • OSSTMM
  • OWASP WSTG · MASTG · ASVS
  • NIST SP 800-115
  • CIS · CSA cloud benchmarks

Practice

"The exploit is the easy part. The engagement letter, the scope-fence, the rules of engagement, the kill switch, and the report are the discipline. Anyone can pop a shell. Far fewer can do it inside a scope and write a report that gets paid for."
Pentest Training · operating principleWhy the discipline around the exploit, not the exploit itself, is what separates a hobbyist from a professional.

Sixteen weeks. Five surfaces. One multi-surface capstone.

Weekend and weekday cohorts. Corporate cohorts on request. Workload is real — budget twelve to fifteen hours per week outside the cohort sessions.