Offensive Security

CA305: Enterprise Pen-Testing

Course authored by:

Drinor Selmanaj, Perparim Mjeku, Rinor Shehu, Altin Gashi

31 Hours of Instruction

Includes lectures, guest speakers, and Q&A sessions

Hands-on
labs

10 Labs

Live Online or On-Demand Access

Join weekly synchronous sessions or access all material and recorded lectures anytime

Intermediate to Expert Level

Advancing from solid fundamentals to mastery-level expertise

Prerequisite

  • CA401 Linux Operations
  • CA403 Windows Security
  • CA402 Network Security

Course Overview

Real attackers don't stop at the perimeter — they move through it. This course builds practical capability in assessing large-scale infrastructures through structured offensive testing across black-box, gray-box, and white-box methodologies. You work through reconnaissance, vulnerability analysis, and exploitation with emphasis on internal network testing and adversary emulation. By the end, you can conduct enterprise-level penetration tests and deliver actionable security insights.

What You’ll Learn

* Perform reconnaissance using passive and active information gathering techniques
* Identify attack surfaces through scanning, enumeration, and vulnerability analysis
* Apply black-box, gray-box, and white-box testing methodologies
* Exploit vulnerabilities to demonstrate real-world impact
* Document findings and deliver structured, actionable security reports

Business Takeaways

* Identify and remediate vulnerabilities before attackers exploit them
* Strengthen security posture across networks, systems, and applications
* Support compliance with industry security standards and regulations
* Reduce financial and reputational impact of potential breaches

Syllabus: 4 Sections to Transformation

The CA305 program places you in the mindset of an advanced attacker, focusing on how enterprise environments are mapped, targeted, and exploited. It spans everything from reconnaissance and intelligence gathering to adversary emulation and real-world attack simulation.

syllabus overview

Justify Training to Your Manager

section 1

FOUNDATIONS: ENTERPRISE PENTESTING & DATA RISK

Develop a clear understanding of enterprise environments and why they are high-value targets.
Examine how data breaches occur and why penetration testing is critical for modern organizations.

TOPICS COVERED

  • Enterprise penetration testing concepts and objectives.
  • Corporate data exposure and breach impact (financial, operational, reputational).
  • Types of penetration testing (black-box, gray-box, white-box).
  • Penetration testing vs vulnerability assessment.
  • Enterprise security goals and business alignment.

LABS

  • Cookie manipulation
  • Windows iexpress

section 2

RECONNAISSANCE: INFORMATION GATHERING & FOOTPRINTING

Transition into intelligence collection techniques used before any attack begins.
Learn how attackers and testers gather data to map targets and identify entry points.

TOPICS COVERED

  • Digital reconnaissance concepts and importance.
  • Passive vs active reconnaissance.
  • OSINT sources (social media, job sites, public records).
  • Tools: WHOIS, dig, Google dorking, Shodan, Nmap.
  • DNS enumeration and information leakage.

LABS

  • Using BloodHound
  • Mapping APT with MITRE Navigator

section 3

ADVERSARY EMULATION & ATTACK SIMULATION

Adopt the mindset of real attackers by simulating advanced threat behaviors.
Focus on structured attack planning and understanding persistent threats.

TOPICS COVERED

  • Adversary emulation concepts and benefits.
  • MITRE ATT&CK and threat modeling.
  • Advanced Persistent Threats (APT) characteristics.
  • Attack planning and engagement strategy.
  • Memory-based attacks and buffer overflow basics.

LABS

  • Setup and Usage of CALDERA
  • Invoke Obfuscation
  • ByPass UAC

section 4

EXECUTION: SYSTEM EXPLOITATION & ENTERPRISE HARDENING

Apply techniques in real environments while understanding system-level security controls.
Explore enterprise systems and how defenders harden infrastructure against attacks.

TOPICS COVERED

  • Linux enterprise systems (Red Hat / Fedora basics).
  • System configuration and tuning.
  • Network connectivity and system setup.
  • SELinux concepts and enforcement.
  • Hardening systems against exploitation.

LABS

  • Powershell Empire
  • Impacket toolkit and GodPotato tool
  • LOLBAS & LOLBins

Course Schedule
& Pricing

Looking for Group Purchase Options? See below

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Frequently Asked Questions

Mission-critical information for prospective operatives

What is enterprise penetration testing and how is it different from basic pentesting?

The book explains that enterprise penetration testing is a structured process used to assess the security of large, complex environments by simulating real-world attacks. Unlike basic testing, it evaluates the entire organization, including networks, systems, and processes, to understand the overall security posture and potential impact of a breach.

According to the book, modern organizations operate in highly interconnected environments with increasing volumes of sensitive data, making them prime targets for sophisticated attackers. Enterprise penetration testing is critical because it proactively identifies vulnerabilities before they can be exploited, helping reduce the risk and impact of real-world breaches.

The book describes the process as a structured lifecycle that includes reconnaissance, exploitation, post-exploitation, and reporting. This mirrors how real attackers operate, allowing organizations to understand not just individual vulnerabilities, but how they can be chained together into a full compromise.

The book clearly distinguishes the two by explaining that vulnerability assessments identify potential weaknesses using automated tools, while penetration testing goes further by actively exploiting those weaknesses to confirm their impact. This makes penetration testing more realistic and valuable for understanding actual risk.

The book emphasizes that the report is the primary deliverable of a penetration test. A well-written report translates technical findings into business impact and provides clear remediation steps, ensuring that organizations can understand the risks and take effective action to improve security.