This repository contains all labs for the Phase 2 Cybersecurity and Ethical Hacking Internship. Labs cover ethical hacking, penetration testing, vulnerability scanning, social engineering, post-exploitation techniques, forensics, and more. Each course has its own directory with detailed lab instructions and tools.
- Immersive Cybersecurity Labs: Designed for active participation from both students and instructors, offering practical exercises that mimic real-world cyber threats.
- Kali Linux as the Core Environment: All exercises are built around Kali Linux, providing students with hands-on experience using the industry’s leading penetration testing platform.
- Comprehensive Learning Support: Each lab is equipped with detailed documentation, PowerPoint slides, relevant files, and screenshots for enhanced understanding and visual learning.
- Broad Scope of Cybersecurity Topics: Covers a wide array of ethical hacking and cybersecurity domains, such as reconnaissance, vulnerability assessment, network exploitation, social engineering, and post-exploitation techniques.
- Free and Open-Source Resources: The labs leverage openly available tools and technologies, making them accessible to everyone without any financial investment.
- Continuous Development: Backed by ongoing contributions from cybersecurity experts, with regular updates to ensure labs remain relevant and reflect current trends in cybersecurity.
- Integrated Forensic Intelligence: Labs include practical tasks based on real-world digital forensic investigations, providing students with exposure to modern cybercrime scenarios and data analysis.
For questions, feedback, or to inform us of your use of these materials, please contact us at resources@aivtic.org.ng. Your input is invaluable to the growth of this repository!
| Lab Number | Activity Name | Status |
|---|---|---|
| Lab 1.1.3 | Lab - Researching PenTesting Careers | Mandatory |
| Lab 1.2.4 | Practice - Types of Penetration Tests | Mandatory |
| Lab 1.2.6 | Lab - Compare Pentesting Methodologies | Mandatory |
| Lab 1.3.4 | Practice - Requirements and Guidelines for Penetration Testing Labs | Mandatory |
| Lab 1.3.6 | Lab - Deploy a Pre-Built Kali Linux Virtual Machine (VM) | Mandatory |
| Lab 1.3.7 | Lab - Investigate Kali Linux |
| Lab Number | Activity Name | Status |
|---|---|---|
| Lab 2.1.4 | Practice - Regulations | Mandatory |
| Lab 2.1.8 | Practice - Legal Concepts | Mandatory |
| Lab 2.1.9 | Lab - Compliance Requirements and Local Restrictions | Mandatory |
| Lab 2.2.3 | Practice - Rules of Engagement | Mandatory |
| Lab 2.2.5 | Practice - Target List and In-Scope Assets | Mandatory |
| Lab 2.2.8 | Practice - Strategy: Unknown vs. Known Environment Testing | Mandatory |
| Lab 2.2.9 | Lab - Pre-Engagement Scope and Planning | Mandatory |
| Lab 2.2.10 | Lab - Create a Pentesting Agreement | Mandatory |
| Lab 2.3.2 | Practice - Demonstrate an Ethical Hacking Mindset | Mandatory |
| Lab 2.3.3 | Lab - Personal Code of Conduct | Mandatory |
| Lab Number | Activity Name | Status |
|---|---|---|
| Lab 4.1.2 | Practice - Pretexting / Impersonation | Mandatory |
| Lab 4.2.7 | Practice - Pivot Attack | Mandatory |
| Lab 4.2.8 | Practice - Social Engineering Attacks | Mandatory |
| Lab 4.3.6 | Practice - Physical Attacks | Mandatory |
| Lab 4.4.4 | Practice - Browser Exploitation Framework | Mandatory |
| Lab 4.4.6 | Practice - Call Spoofing Tools | Mandatory |
| Lab 4.4.7 | Lab - Explore the Social Engineering Toolkit (SET) | Mandatory |
| Lab 4.4.8 | Lab - Using the Browser Exploitation Framework (BeEF) | Mandatory |
| Lab 4.5.2 | Practice - Methods of Influence | Mandatory |
| Lab 4.6.3 | Quiz - Social Engineering Attacks | Mandatory |
| Lab Number | Activity Name | Status |
|---|---|---|
| Lab 5.1 | Practice - Windows Name Resolution and SMB Attacks | Mandatory |
| Lab 5.2 | Lab - Scanning for SMB Vulnerabilities with enum4linux | Mandatory |
| Lab 5.3 | Lab - On-Path Attacks with Ettercap | Mandatory |
| Lab Number | Activity Name | Status |
|---|---|---|
| Lab 6.1 | Practice Lab 1: Practice - The HTTP Protocol | Mandatory |
| Lab 6.2 | Lab 2: Web Sessions Security Enhancement | Mandatory |
| Lab 6.3 | Lab 3: Web Vulnerability Scanning using OWASP Broken Web Applications VM | Mandatory |
| Lab 6.4 | Lab 4 - Using the GVM Vulnerability Scanner | Mandatory |
| Lab 6.5 | Lab 5 Practice - Understanding Business Logic Flaws | Mandatory |
| Lab 6.6 | Practice 6 - SQL Injection Attacks | Mandatory |
| Lab 6.7 | Lab 7- Injection Attacks | Mandatory |
| Lab 6.8 | Practice Lab 8 - Parameter Pollution | Mandatory |
| Lab 6.9 | Lab 9 - Insecure Direct Object Reference (IDOR) Vulnerabilities | Mandatory |
| Lab 6.9.1 | Lab 10 - Reflected Cross-Site Scripting (XSS) Attacks | Mandatory |
| Lab 6.7.1 | Lab 12 - Use the OWASP Web Security Testing Guide | Mandatory |
| Lab 6.7.2 | Final Practice Quiz - Performing Post-Exploitation Techniques | Mandatory |
| Lab Number | Activity Name | Status |
|---|---|---|
| Lab 7.1 | Lab 1: Reverse and Bind Shells in Post-Exploitation Techniques | Mandatory |
| Lab 7.2 | Post-Exploitation using Legitimate Utilities and Living-off-the-Land | Mandatory |
| Lab 7.3 | Lab 3: Horizontal Privilege Escalation via URL Manipulation (Real Test) | Mandatory |
| Lab 7.4 | Lab 4: Covering Your Tracks and Exfiltrating Data Using Steganography | Mandatory |
| Lab 7.5 | Practice: Reflection Questions | Mandatory |