Free Online Course · Self-paced

Ethical Hacking & Penetration Testing Tutorial (Hands-On)

Free, hands-on ethical hacking and penetration testing tutorial - lab setup, reconnaissance, password cracking, phishing, web/mobile pentesting, MITM attacks, and exploitation frameworks. 80+ practical lessons.

  • 89 parts
  • ~656 min total
  • Beginner to Advanced
  • Updated May 2026
Ethical Hacking & Penetration Testing Tutorial (Hands-On)
By Last updated

Disclaimer: every technique in this tutorial is presented for authorized testing, defensive research, and education in controlled environments. Never run these against systems you do not own or have explicit, written permission to test - laws in most jurisdictions treat unauthorized access as a criminal offense regardless of intent.

This tutorial is built for people who want to learn offensive security the way it is actually practiced: a real lab, real tools, and real attack chains. We start with lab setup (multiple Kali distros, Metasploitable targets, VPN/proxy isolation), then walk through the full kill chain - reconnaissance, vulnerability scanning, password cracking, phishing, web/mobile/wireless attacks, exploitation, and post-exploitation forensics.

Every chapter is a self-contained module, but if you are new to penetration testing the order matters: lab setup first, then reconnaissance, then attacks, then forensics. Click Start the course to begin with the pentest lab setup chapter.

What you'll learn

  • Set up a fully-isolated penetration testing lab on any host OS
  • Run reconnaissance and OSINT using industry-standard tools
  • Crack passwords, run brute-force attacks, and generate custom wordlists
  • Launch and analyze phishing campaigns ethically (red-team training)
  • Pentest web applications, mobile apps, and wireless networks
  • Use Metasploit, BeEF, Burp Suite, and other major exploitation frameworks
  • Perform digital forensics on disk images and memory dumps

Prerequisites

  • Solid Linux command-line skills (cd, grep, ssh, package management)
  • Basic networking knowledge (TCP/IP, ports, DNS, HTTP)
  • A workstation that can run virtual machines (8 GB RAM minimum)
  • Legal warning: only run these techniques against systems you own or have explicit written permission to test

Syllabus

10 chapters · 89 lessons · ~656 min of reading

  1. 1 Set Up Your Lab 18 lessons
    1. Part 1 Create a Kali Linux bootable USB 6 min read
    2. Part 2 Install Kali Linux in VirtualBox 9 min read
    3. Part 3 Install Kali Linux on Apple M1 with UTM 8 min read
    4. Part 4 Install Kali Linux on Android 8 min read
    5. Part 5 Install Kali Linux on Raspberry Pi 5 min read
    6. Part 6 Dual boot Ubuntu and Kali Linux 10 min read
    7. Part 7 Dual boot Windows 10 and Linux 8 min read
    8. Part 8 Install Kali Linux apps on Ubuntu 8 min read
    9. Part 9 Manage Kali Linux repositories 9 min read
    10. Part 10 Pentest lab setup (Kali, Metasploitable, DVWA) 8 min read
    11. Part 11 Learn hacking using Metasploitable 2 14 min read
    12. Part 12 Install the CAINE forensics VM 6 min read
    13. Part 13 Install airmon-ng on Kali Linux 7 min read
    14. Part 14 Install Pyrit on Kali Linux 7 min read
    15. Part 15 Install Gobuster on Ubuntu 8 min read
    16. Part 16 Set up ProxyChains on Kali Linux 9 min read
    17. Part 17 Install Tor Browser on Linux 7 min read
    18. Part 18 Install Tor Browser on Rocky Linux 6 min read
  2. 2 Reconnaissance and OSINT 13 lessons
    1. Part 19 Complete Shodan tutorial 7 min read
    2. Part 20 OSINT with the Mitaka browser extension 5 min read
    3. Part 21 OSINT automation with SpiderFoot 5 min read
    4. Part 22 OSINT with the InfoOze tool 9 min read
    5. Part 23 Automated pentesting with Nettacker 10 min read
    6. Part 24 Banner grabbing techniques 9 min read
    7. Part 25 DNS enumeration 13 min read
    8. Part 26 Subdomain enumeration tools 7 min read
    9. Part 27 Find hidden endpoints with fuzzing 8 min read
    10. Part 28 SMTP enumeration 10 min read
    11. Part 29 How doxing works (and how to defend against it) 6 min read
    12. Part 30 Track an IP address using an image 5 min read
    13. Part 31 Use canary tokens for breach detection 6 min read
  3. 3 Password Cracking and Brute Force 8 lessons
    1. Part 32 Crack password hashes 7 min read
    2. Part 33 John the Ripper password cracker 14 min read
    3. Part 34 Generate custom wordlists 10 min read
    4. Part 35 SSH brute-force attack 11 min read
    5. Part 36 Brute-force web forms 5 min read
    6. Part 37 Postgres brute-force attack 10 min read
    7. Part 38 VNC brute-force attack 5 min read
    8. Part 39 Bypass an Android lock screen 5 min read
  4. 4 Phishing and Social Engineering 11 lessons
    1. Part 40 Social engineering attack types explained 7 min read
    2. Part 41 Social Engineering Toolkit (SET) phishing 5 min read
    3. Part 42 Install the Gophish phishing framework 8 min read
    4. Part 43 Create a phishing campaign with Gophish 5 min read
    5. Part 44 Run phishing simulations with FiercePhish 6 min read
    6. Part 45 Snapchat phishing simulation 5 min read
    7. Part 46 Social media phishing with Zphisher 5 min read
    8. Part 47 Phishing simulations with SocialFish 5 min read
    9. Part 48 Lockphish v2 PIN phishing attack 5 min read
    10. Part 49 Browser-in-the-browser (BitB) phishing 4 min read
    11. Part 50 Analyze phishing emails with TheHive (TheHive Phish) 5 min read
  5. 5 Web Application Pentesting 11 lessons
    1. Part 51 DVWA - Damn Vulnerable Web Application 6 min read
    2. Part 52 Install DVWA on Kali Linux 13 min read
    3. Part 53 SQL injection on DVWA 6 min read
    4. Part 54 Install OWASP Juice Shop 13 min read
    5. Part 55 Burp Suite proxy tutorial 9 min read
    6. Part 56 Fuzzing tools for web app pentesting 11 min read
    7. Part 57 Bypass CSRF protection 7 min read
    8. Part 58 Local File Inclusion (LFI) attack 6 min read
    9. Part 59 Web cache deception attack 5 min read
    10. Part 60 WordPress vulnerability scanning with WPScan 12 min read
    11. Part 61 Set up a WordPress reverse shell 6 min read
  6. 6 Network Attacks (WiFi, MITM, DoS) 7 lessons
    1. Part 62 WiFi password attack techniques (WPA/WPA2) 7 min read
    2. Part 63 WPA2 WiFi honeypot tutorial 7 min read
    3. Part 64 Evil twin WiFi attack 6 min read
    4. Part 65 Man-in-the-middle via ARP spoofing 8 min read
    5. Part 66 MITM attacks with Xerosploit 6 min read
    6. Part 67 Change your MAC address on Linux 7 min read
    7. Part 68 DDoS attack example (in your own lab) 7 min read
  7. 7 Exploitation Frameworks 7 lessons
    1. Part 69 Metasploit tutorial 12 min read
    2. Part 70 BeEF browser exploitation framework 6 min read
    3. Part 71 Reverse shell cheat sheet 13 min read
    4. Part 72 Encode payloads with Shellter 8 min read
    5. Part 73 Embed a payload in a PDF 6 min read
    6. Part 74 Undetectable Windows payload with TechnoLogger 5 min read
    7. Part 75 Windows remote access trojan (RAT) walkthrough 6 min read
  8. 8 Mobile Pentesting 7 lessons
    1. Part 76 Set up an Android pentesting lab 6 min read
    2. Part 77 APKHunt - Android app pentesting 9 min read
    3. Part 78 Mobile Security Framework (MobSF) walkthrough 5 min read
    4. Part 79 Embed a payload in an APK file 7 min read
    5. Part 80 Obfuscate Android payloads with APKBleach 5 min read
    6. Part 81 Hack Android with the Ghost framework 5 min read
    7. Part 82 Remote Android management with L3MON 6 min read
  9. 9 Digital Forensics and Defense 6 lessons
    1. Part 83 Create a forensic disk image with FTK Imager 6 min read
    2. Part 84 Analyze memory dumps with Volatility 8 min read
    3. Part 85 Android forensics with Andriller 5 min read
    4. Part 86 Detect rootkits and malware with rkhunter 6 min read
    5. Part 87 Steganography - hide messages in images 8 min read
    6. Part 88 Encrypt a USB drive with VeraCrypt 7 min read
  10. 10 Project Management 1 lesson
    1. Part 89 Manage pentest projects with Cervantes 5 min read
Deepak Prasad

R&D Engineer

Founder of GoLinuxCloud with more than 15 years of expertise in Linux, Python, Go, Laravel, DevOps, Kubernetes, Git, Shell scripting, OpenShift, AWS, Networking, and Security. With extensive experience, he excels across development, DevOps, networking, and security, delivering robust and efficient solutions for diverse projects.

  • Go (programming language)
  • Python (programming language)
  • DevOps
  • Computer Security
  • Cloud Computing
  • Kubernetes
  • Linux
  • Ansible (software)