跳到内容

FieldsCybersecurityPenetration Tester

Penetration Tester

Break into systems legally so attackers cannot do it first.

Career

Structure
8 modules, each ending in a milestone
Proof
Verified against real tasks from module 2
Ends in
A defended capstone and a high-assurance credential

Get early access

The journey

  1. Practised under observation

    1. The profession, the law and the engagement frameWhy this work is legal when it is done properly: the authorisation document, the engagement lifecycle, and the professional identity that comes before any technique.Practised under observation
      MilestoneUnderstands the mandate before the method

      The document that makes this work lawful is understood before any technique is, and the engagement you sell is the one that answers the client's actual question.

  2. From here, milestones are verified rather than practised.

    Verified against a real task

    1. Reconnaissance, enumeration and methodical coverageThe phase that decides an engagement's quality, with information gathered systematically, the attack surface enumerated completely, and coverage documented so that finding nothing means something.Verified against a real task
      MilestoneEnumerates completely, documents honestly

      What was not tested is written in the report next to what was, and anything outside the scope stays outside it.

    2. Exploitation and proving impactTurning a weakness into demonstrated consequence, with exploitation as a controlled professional act and the discipline to prove impact without causing it.Verified against a real task
      MilestoneProves impact, causes none

      Access is proven rather than taken, a single record is shown rather than a database, and the work stops the moment continuing would do real harm.

    3. Web application and API testingWhere most engagements happen: application testing at professional depth, business logic tested where scanners cannot reach, and findings written for the developers who must fix them.Verified against a real task
      MilestoneTests the application, including what scanners cannot

      A flaw in what the application is for is found by reasoning about its purpose, and the write-up lets a developer reproduce it without ever contacting you.

    4. Network, infrastructure and cloud testingThe enterprise engagement, from foothold to objective, with cloud estates tested for the misconfigurations that dominate real breaches and lateral movement demonstrated under control.Verified against a real task
      MilestoneFoothold to impact, under control

      The path from a foothold to the objective is narrated as reasoning rather than as a sequence of tools, the routes that failed are recorded as coverage rather than hidden, and every system touched is left as it was found.

    5. Reporting and remediationThe actual deliverable: findings written so they get fixed, severity assessed honestly, and the debrief that turns a report into remediation.Verified against a real task
      MilestoneWrites the report that gets it fixed

      Someone non-technical reads the summary and states the business risk correctly, and a severity is neither inflated for effect nor lowered for comfort.

    6. Advanced engagements and specializationBeyond the standard test: red-team operations, purple teaming, social engineering under strict ethics, and the specialisations this seat grows into.Verified against a real task
      MilestoneRuns the advanced engagement, chooses the right one

      Recommending the engagement a client did not ask for is part of the job, and a simulation that would humiliate an employee is refused rather than delivered.

    7. The Penetration Tester in the professionThe professional identity: integrity under commercial pressure, the client relationship, and a career built on trust rather than on cleverness.Verified against a real task
      MilestoneTrusted with the keys

      Every client is told what the timeline can actually cover, an invitation to look at one more system is refused and re-scoped on paper, and the finding somebody wants removed stays in the report.

    1. Capstone

      A professional engagement, end to end

      A complete penetration testing engagement for a realistic client in an instructor-provided authorised environment, worked under observation with documented authorisation throughout, from scoping and rules of engagement through systematic enumeration and validated exploitation to the report, the debrief, the retest and the professional layer of the seat.

      Defence

      You walk an instructor through your own engagement: what authorised this test and what would have made it a crime, what you did not test and whether your report says so, a finding you proved without taking anything, and a finding you almost inflated and why you did not. The credential is not awarded if you cannot account for your own work.

    2. Credential

      High-assurance credential

      Evidence that you can run an authorised engagement end to end and write the report that gets the problem fixed. It is held on a clean professional-conduct record, and a scope violation at any point forfeits it. It does not claim seniority, and it does not oblige any employer to accept it.

      See how proof works

What is not live yet

The desktop app, consent-based observation, scoring, and credentials are in development. Nothing here implies they are live yet.

Get early access