PEN-200: Penetration Testing with Kali Linux
Gain expertise in penetration testing topics, including XSS, SQL Injection, privilege escalation, Active Directory and AWS exploitation Be professionally recognized for life as an...
- Gain expertise in penetration testing topics, including XSS, SQL Injection, privilege escalation, Active Directory and AWS exploitation
- Be professionally recognized for life as an OffSec Certified Professional (OSCP) and gain your 3-year OSCP+
Get Course Details & Pricing
Our advisor will reach out within 24 hours
Enquiry Received!
Thank you! One of our training advisors will contact you within 24 hours with full details and a personalised quote.
The Penetration Testing with Kali Linux (PEN-200) course is OffSec’s essential training program for aspiring penetration testers. The course teaches learners how to identify and exploit real-world vulnerabilities across computers, network security, web applications, and basic cloud environments. Emphasizing hands-on, practical learning, PEN-200 provides the core technical skills and mindset required to simulate offensive information security operations—and defend against them. It’s a critical resource for those pursuing roles such as security analyst, security specialist, or certified ethical hacker.
PEN-200 covers a wide range of topics and attack techniques, including:
- Providing an introduction to cybersecurity and an effective learning strategy to help you get started
- Performing enumeration and information gathering, including vulnerability scanning
- Understanding encryption and cryptography
- Utilizing perimeter attacks in web security and client-side attacks, where we go into depth in the commonly seen vulnerabilities such as XSS, Command Injection, Directory Traversal, File Uploads, and SQL Injection. We also cover password attacks and touch on Anti-Virus Evasion
- Performing Windows and Linux privilege escalation and lateral movements, including pivoting and tunneling techniques
- Using Active Directory, attacking Active Directory authentication, and lateral movement in Active Directory
- Enumerating and attacking AWS cloud infrastructure
- Learning how to use commonly used tools and commands in penetration testing, such as Nmap, Metasploit, Burp Suite, Hydra, Nessus, sqlmap, and Shellter
PEN-200 is organized into 20+ modules. Most modules have companion videos for the visually inclined learners. Most modules have hands-on labs to help learners practice the concept and theory taught in that module. After mastering each of the techniques and skills taught in all modules, learners can move on to the 9 challenge labs to practice a combination of skills in one lab, mimicking the real-world penetration test engagement. To help learners get ready for their OSCP+ exam, three challenge labs are designed to closely replicate the OSCP+ exam environment.
PEN-200 is suitable for those wishing to embark on a professional pen testing career, or wanting to learn skills possessed by pen testers. Before taking this course, we do suggest having hands-on practical knowledge of Linux and Windows administration, networking, and network scripting.
The PEN-200 course is ideal for:
- Infosec professionals transitioning into penetration testing
- Pen testers seeking an industry-recognized pentesting certification
- Those interested in a penetration testing career path
- Security professionals
- Network administrators
- Other technology professionals
While there are no formal prerequisites, it is strongly recommended that you have:
- A solid understanding of TCP/IP networking
- Reasonable Windows and Linux administration experience
- Familiarity with basic Bash and/or Python scripting
Up to 40 (ISC)² CPE credits.
Master the core concepts, technologies, and best practices that form the bedrock of information security, providing a solid foundation for your pen testing journey
Learn how web applications function, what their underlying technologies are, and the architectural weaknesses that create common web security attack vectors
Explore the techniques behind common web attacks, injection flaws, session hijacking, and the essential strategies to stop them
Exploit vulnerabilities in web browsers, browser extensions, and client-side technologies to compromise user systems and gain access
Identify and exploit misconfigurations and vulnerabilities in Windows systems to gain admin-level access and more control within a network security framework
Introduction and Enumeration Understand the structure of Active Directory, learn to enumerate users, groups, trusts, and sensitive configurations using tools like BloodHound and PowerView to identify attack paths
Exploit weaknesses in Active Directory authentication mechanisms (Kerberos, NTLM, etc) to compromise credentials and gain unauthorized access
Course Pricing Options
Choose the package that best fits your learning goals and professional background
Self Paced Learning - 90 Days Access
Access for 90 days to Full e-learning on demand in English + Labs + exam voucher
Self Paced Learning - 365 Days Access
Access for 365 days to Full-elearning on demand in English + Labs + exam voucher
Send Course Enquiry
Fill out the form and we will get back to you within 24 hours
Why Choose Profice?
Italy's Leading Training Partner with a Proven Track Record
Official Partner
Authorized Training Partner delivering official certified curriculum
Expert Instructors
Certified professionals with 10+ years of real-world experience
Hands-on Labs
Real-world projects and 24/7 lab environment access
95% Pass Rate
Industry-leading certification exam success rate
Job Assistance
Dedicated placement support with 500+ hiring partners
Lifetime Support
Ongoing mentorship and community access after course completion
Ready to Transform Your Career?
Join thousands of professionals who achieved their certification goals with Profice.