Pentesting Fundamentals

This room teaches the ideas behind penetration testing, the ethics, the rules, and the methods, before you ever touch a hacking tool. It’s about 30 minutes of reading plus one short drag-and-drop exercise at the end. Let’s go through it task by task, in plain English.

Task 01: What is Penetration Testing?

A penetration test (or pentest) is a legal, ethically-driven attempt to find and test the security weaknesses of a system, using the same tools and techniques a real attacker would, but with permission. Think of it like a security audit: you’re checking how well the defences actually hold up.

Why it matters: there are over 2,200 cyber attacks every day, roughly one every 39 seconds, so it’s far better to find your weak spots yourself than to let an attacker find them first.

Read me!

No answer needed

Task 02: Penetration Testing Ethics

The golden rule of ethical hacking is permission. Before any testing starts, you agree on:

  • Scope, exactly what you are (and aren’t) allowed to test.
  • Rules of Engagement (ROE), the document that defines how the engagement will be carried out: what’s allowed, what’s off-limits, and how things are reported.

Hackers are often grouped by “hat” colour:

HatWho they are
White HatThe good guys, stay within the law and use their skills to help.
Grey HatUse their skills for good, but don’t always stay within the law.
Black HatCriminals, malicious intent, breaking in to cause harm or for profit.

Task 2, Questions and Answers

You are given permission to perform a security audit on an organisation; what type of hacker would you be?

White Hat

You have permission and good intent, that’s a white hat.

You attack a target without any permission, what type of hacker would you be?

Black Hat

What document defines how a penetration testing engagement should be carried out?

Rules of Engagement

Task 03: Penetration Testing Methodologies

A methodology is just the set of steps a tester follows. A good one fits the target, you wouldn’t test a network the same way you test a website. Most methodologies share these general stages:

  1. Information Gathering, collect public information about the target (OSINT). No scanning yet.
  2. Enumeration / Scanning, discover the apps and services that are running.
  3. Exploitation, use the weaknesses you found to get in.
  4. Privilege Escalation, expand your access (horizontally = another user at the same level; vertically = a higher level, like an admin).
  5. Post-exploitation, pivot to other machines, gather more, cover your tracks, and write the report.

A few industry frameworks worth knowing:

  • OSSTMM, focuses on networks and telecommunications.
  • OWASP, focuses on web applications.
  • NIST Cybersecurity Framework, broad standards for managing cyber risk.
  • NCSC CAF, aimed at critical-infrastructure organisations.

Task 3, Questions and Answers

What stage of penetration testing involves using publicly available information?

Information Gathering

If you wanted to use a framework for pentesting telecommunications, what framework would you use? (acronym)

OSSTMM

What framework focuses on the testing of web applications?

OWASP

Task 04: Black box, White box, Grey box Penetration Testing

How much you know about the target decides your testing style:

  • Black-Box, you get no inside information. You poke at it like a normal user, so a lot of time goes into information gathering and enumeration.
  • Grey-Box, you get some information. This is the most popular choice for pentests; the limited knowledge saves time, especially on well-hardened targets.
  • White-Box, you get full knowledge, including the source code. It’s the most thorough (you can validate the entire attack surface) but also the most time-consuming.

Task 4, Questions and Answers

You are asked to test an application but are not given access to its source code, what testing process is this?

Black Box

You are asked to test a website, and you are given access to the source code, what testing process is this?

White Box

Task 05: Practical, ACME Penetration Test

The final task is a quick hands-on exercise. Click View Site, then drag each action onto the correct pentest stage (Information Gathering → Enumeration → Exploitation → Privilege Escalation → Post-exploitation) for the fictional company “ACME”. Put the stages in the right order and you’ll complete the engagement and earn the flag:

THM{PENTEST_COMPLETED}

Wrap-up

That’s the whole room. The big takeaways:

  • A pentest is authorised hacking, permission and a clear scope come first.
  • Stay a white hat, and write the limits into the Rules of Engagement.
  • Follow a methodology (gather → enumerate → exploit → escalate → post-exploit) and pick a framework that fits the target (OWASP for web apps, OSSTMM for networks).
  • Choose black / grey / white box depending on how much you know going in.

Next in the path, you’ll start using the actual tools. Happy (ethical) hacking! 🛡️