Module objectives
CTF
This is where the rest of the course turns into something you do. A capture-the-flag box and a scoped penetration test follow the same loop: map the target, find the way in, take a foothold, then escalate to full control. This module walks that loop end to end and keeps the legal line in view throughout.
By the end you will be able to:
- Place any action in the right engagement phase, from reconnaissance to reporting, and explain why authorisation and rules of engagement come first.
- Run reconnaissance and read nmap output: port states, service mappings and the scan-type flags worth memorising.
- Match the right tool to the job across capture, web testing, exploitation and credential attacks.
- Spot Linux privilege escalation routes from sudo, SUID, cron and file-permission evidence, and name the technique.
The exam is practical: ten artifacts off a target box, graded in your browser. Get seven of ten and the certificate is yours.