Offensive Security, Defensive Security

CA305: Enterprise Pen-Testing

Course authored by:

Perparim Mjeku, Rinor Shehu, Altin Gashi

31 Hours of Instruction

Includes lectures, guest speakers, and Q&A sessions

Hands-on
labs

10 Labs

Live Online or On-Demand Access

Join weekly synchronous sessions or access all material and recorded lectures anytime

Intermediate to Expert Level

Advancing from solid fundamentals to mastery-level expertise

Course Materials

Available after purchase

Course Overview

Enterprise penetration testing is not about running tools it is about simulating real adversaries against complex environments and proving where defenses fail. The four-section structure builds practical capability in assessing large-scale infrastructures through structured offensive testing. You will work through core phases including reconnaissance, vulnerability analysis, and exploitation across black-box, gray-box, and white-box methodologies. The course emphasizes internal network testing and adversary emulation to reflect real-world attack paths. Techniques such as OSINT, scanning, and enumeration are applied to uncover and validate weaknesses. You will also develop clear reporting, documentation, and responsible disclosure practices aligned with professional standards. Expect hands-on execution and high expectations by the end, you will be able to conduct enterprise-level penetration tests and deliver actionable security insights.

What You’ll Learn

Develop the ability to simulate real-world attacks and evaluate enterprise security through structured penetration testing practices

  • Understand enterprise penetration testing concepts and methodologies
  • Differentiate between penetration testing and vulnerability assessments
  • Perform reconnaissance using passive and active information gathering techniques
  • Identify attack surfaces through scanning, enumeration, and analysis
  • Apply black-box, gray-box, and white-box testing approaches
  • Exploit vulnerabilities to demonstrate real-world impact
  • Conduct internal network penetration testing scenarios
  • Document findings and deliver actionable security reports

Business Takeaways

Understand how proactive security testing reduces risk exposure and strengthens enterprise defense strategies

  • Identify and remediate vulnerabilities before attackers exploit them
  • Improve risk management through realistic attack simulations
  • Strengthen security posture across networks, systems, and applications
  • Support compliance with industry security standards and regulations
  • Enhance decision-making with evidence-based security insights
  • Reduce financial and reputational impact of potential breaches
  • Promote a security-aware culture across the organization
  • Enable continuous improvement through regular testing and assessment

Syllabus: 4 Sections to Transformation

The CA305 program places you in the mindset of an advanced attacker, focusing on how enterprise environments are mapped, targeted, and exploited. It spans everything from reconnaissance and intelligence gathering to adversary emulation and real-world attack simulation.

syllabus overview

Justify Training to Your Manager

section 1

FOUNDATIONS: ENTERPRISE PENTESTING & DATA RISK

Develop a clear understanding of enterprise environments and why they are high-value targets.
Examine how data breaches occur and why penetration testing is critical for modern organizations.

TOPICS COVERED

  • Enterprise penetration testing concepts and objectives.
  • Corporate data exposure and breach impact (financial, operational, reputational).
  • Types of penetration testing (black-box, gray-box, white-box).
  • Penetration testing vs vulnerability assessment.
  • Enterprise security goals and business alignment.

LABS

  • Cookie manipulation
  • Windows iexpress

section 2

RECONNAISSANCE: INFORMATION GATHERING & FOOTPRINTING

Transition into intelligence collection techniques used before any attack begins.
Learn how attackers and testers gather data to map targets and identify entry points.

TOPICS COVERED

  • Digital reconnaissance concepts and importance.
  • Passive vs active reconnaissance.
  • OSINT sources (social media, job sites, public records).
  • Tools: WHOIS, dig, Google dorking, Shodan, Nmap.
  • DNS enumeration and information leakage.

LABS

  • Using BloodHound
  • Mapping APT with MITRE Navigator

section 3

ADVERSARY EMULATION & ATTACK SIMULATION

Adopt the mindset of real attackers by simulating advanced threat behaviors.
Focus on structured attack planning and understanding persistent threats.

TOPICS COVERED

  • Adversary emulation concepts and benefits.
  • MITRE ATT&CK and threat modeling.
  • Advanced Persistent Threats (APT) characteristics.
  • Attack planning and engagement strategy.
  • Memory-based attacks and buffer overflow basics.

LABS

  • Setup and Usage of CALDERA
  • Invoke Obfuscation
  • ByPass UAC

section 4

EXECUTION: SYSTEM EXPLOITATION & ENTERPRISE HARDENING

Apply techniques in real environments while understanding system-level security controls.
Explore enterprise systems and how defenders harden infrastructure against attacks.

TOPICS COVERED

  • Linux enterprise systems (Red Hat / Fedora basics).
  • System configuration and tuning.
  • Network connectivity and system setup.
  • SELinux concepts and enforcement.
  • Hardening systems against exploitation.

LABS

  • Powershell Empire
  • Impacket toolkit and GodPotato tool
  • LOLBAS & LOLBins

Course Schedule
& Pricing

Looking for Group Purchase Options? See below

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Frequently Asked Questions

Mission-critical information for prospective operatives

What is enterprise penetration testing and how is it different from basic pentesting?

The book explains that enterprise penetration testing is a structured process used to assess the security of large, complex environments by simulating real-world attacks. Unlike basic testing, it evaluates the entire organization, including networks, systems, and processes, to understand the overall security posture and potential impact of a breach.

According to the book, modern organizations operate in highly interconnected environments with increasing volumes of sensitive data, making them prime targets for sophisticated attackers. Enterprise penetration testing is critical because it proactively identifies vulnerabilities before they can be exploited, helping reduce the risk and impact of real-world breaches.

The book describes the process as a structured lifecycle that includes reconnaissance, exploitation, post-exploitation, and reporting. This mirrors how real attackers operate, allowing organizations to understand not just individual vulnerabilities, but how they can be chained together into a full compromise.

The book clearly distinguishes the two by explaining that vulnerability assessments identify potential weaknesses using automated tools, while penetration testing goes further by actively exploiting those weaknesses to confirm their impact. This makes penetration testing more realistic and valuable for understanding actual risk.

The book emphasizes that the report is the primary deliverable of a penetration test. A well-written report translates technical findings into business impact and provides clear remediation steps, ensuring that organizations can understand the risks and take effective action to improve security.

0
    Your Cart
    Your cart is empty