Orientation removes friction that would otherwise eat into every later session — a student who knows where things are spends their attention on the material.
Goal: calibrate depth. Where students start determines where to add examples and where to skip.
| It is | It is not |
|---|---|
| The contract for the next 8 weeks | Filler — every minute here saves an hour later |
| How to find every artefact you will need | Just logistics — it sets the framing for every topic |
| Calibration of expectations | Negotiable — assessment criteria are fixed and public from day one |
ICT security testing is a professional discipline — not just "hacking", not just "pentesting", not just "running scanners".
The rhythm is: theory → labs → synthesis.
| Part | Topics | Theme |
|---|---|---|
| I — Foundations | 01–06 | Framing, standards, scope, legal, ethics |
| II — Methodologies | 07–13 | OSINT, SE, scanning, review, pentest, red, blue |
| III — Pentest in depth | 14–18 | Recon, exploit, privesc, web, kill chain |
| IV — From findings to value | 19–23 | Evidence, scoring, remediation, reporting |
| Access | Credentials & instructions in SETUP.md — read before the next session |
| Rules | This is the only authorised testing target for coursework |
| Tooling | Pre-installed in the lab; students may add tools — within scope |
| Help | Teams channel for platform bugs and conceptual questions |
Further practice platforms outside the course: HackTheBox, TryHackMe, PortSwigger Web Security Academy, OverTheWire, PicoCTF.
Give students the foundational knowledge and a first hands-on experience needed to participate meaningfully in ICT security testing work — whether they end up doing the testing, commissioning it, or defending against it.
A graduate of this module can:
That is the bar. Everything in the syllabus exists to support it.
Most security professionals have hands-on testing experience at some point, whether they stay in offensive work or move to defence, secure development, or governance.
What is the difference between "I know how this attack works" and "I am a security tester"?
A security tester operates inside a contract — scope, authorisation, legal cover. They produce evidence sufficient for client action and legal defensibility, and they write a report that drives remediation. They also communicate what they did not test. Knowing the attack is the easy part; the professional discipline around it is what the profession actually pays for.
SETUP.md before the next sessionNext: Topic 02 — The security testing landscape. Every later methodology will slot into the map introduced there.
SETUP.md and access the lab before the next session.