Introduction to Ethical Hacking FOUNDATION

Understanding offensive security, legal boundaries, methodologies, and building a safe lab environment.

โš–๏ธ Understanding Ethical Hacking vs. Malicious Hacking

๐Ÿ›ก๏ธ Ethical Hacking

  • Authorized by the system owner (written scope & permission).
  • Goal: identify & fix vulnerabilities before attackers exploit them.
  • Follows a code of conduct (e.g., do no harm, report all findings).
  • Also called white-hat or penetration testing.
  • Works with defenders and often shares findings transparently.

๐Ÿ’€ Malicious Hacking

  • Unauthorized access โ€” no permission or legal right.
  • Goal: steal data, disrupt, or cause harm for profit, ideology, or ego.
  • Often uses illegal means and hides tracks.
  • Also called black-hat or cracker.
  • Victimizes individuals, companies, and critical infrastructure.
๐Ÿ”‘ Key differentiator: Legal authorization & intent. Ethical hackers operate within the law and a strict ethical framework; malicious hackers do not.

๐Ÿ‘ค Roles of an Ethical Hacker

Penetration Tester Simulates attacks on networks, apps, and physical controls to find weaknesses.
Red Teamer Focuses on adversary emulation, stealth, and bypassing detection (full-scope attack).
Security Analyst Monitors, triages, and responds to threats; often works alongside ethical hackers.
Vulnerability Assessor Scans and identifies known vulnerabilities, then prioritizes remediation.
Bug Bounty Hunter Independently finds bugs in exchange for rewards via legitimate platforms.
Security Consultant Advises clients on best practices, compliance, and risk reduction.

โšก Ethical hackers must be trustworthy, detail-oriented, and continuous learners. They often hold certifications and follow strict reporting standards.

๐Ÿ“œ Legal and Ethical Aspects (Laws, Certifications, Compliance)

โš–๏ธ Key Laws & Regulations

  • CFAA (US) โ€“ Computer Fraud and Abuse Act: prohibits unauthorized access.
  • GDPR (EU) โ€“ Data protection; hacking without consent may violate privacy.
  • HIPAA (US) โ€“ Health data security; strict penalties for breaches.
  • PCI DSS โ€“ Payment card industry standard; requires penetration testing.
  • Cybercrime laws โ€“ Most countries criminalize unauthorized access.

Always get written permission before testing any system.

๐Ÿ“œ Certifications & Compliance

  • CEH โ€“ Certified Ethical Hacker (EC-Council).
  • OSCP โ€“ Offensive Security Certified Professional (hands-on).
  • GPEN โ€“ GIAC Penetration Tester.
  • CISSP โ€“ More managerial, but respected for security governance.
  • CompTIA PenTest+ โ€“ Vendor-neutral penetration testing.

Compliance frameworks: ISO 27001, NIST, SOC 2 โ€“ often require regular penetration tests.

โš ๏ธ Ethical duty: Report all discovered vulnerabilities promptly and confidentially. Never exfiltrate real data or cause disruption.

๐Ÿงช Penetration Testing Methodologies

Structured frameworks ensure thorough, repeatable, and professional testing.

OSSTMM Open Source Security Testing Methodology Manual. Focuses on scientific metrics, operational security, and covers networks, physical, human, and wireless.
PTES Penetration Testing Execution Standard. Seven phases: pre-engagement, intel gathering, threat modeling, vuln analysis, exploitation, post-exploitation, reporting.
NIST SP 800-115 Technical Guide to Information Security Testing. Emphasizes planning, discovery, attack, and reporting; widely used in government & compliance.

๐Ÿ“‹ Typical phases (PTES aligned)

1. Pre-engagement 2. Intelligence Gathering 3. Threat Modeling 4. Vulnerability Analysis 5. Exploitation 6. Post-Exploitation 7. Reporting

๐Ÿงฐ Setting Up a Hacking Lab

A safe, isolated environment for practicing offensive security without legal or ethical risks.

๐Ÿ–ฅ๏ธ Virtual Machines (VMs)

  • Hypervisors: VirtualBox (free), VMware Workstation, Hyper-V.
  • Isolation: Use host-only or internal network adapters.
  • Snapshots: Revert to clean state after each exercise.
  • Recommended VMs: Kali Linux, Metasploitable2, Windows 10/11 (evaluation), DVWA.

๐Ÿ‰ Kali Linux & Metasploit

  • Kali Linux: Debian-based distro with 600+ preinstalled tools (Nmap, Burp Suite, Wireshark).
  • Metasploit Framework: Exploitation framework โ€” msfconsole, modules, payloads, Meterpreter.
  • Lab targets: Metasploitable2, OWASP Broken Web Apps, VulnHub VMs.

โš™๏ธ Example lab network (host-only)

Attacker VM (Kali)
IP: 192.168.56.10/24
Tools: nmap, msfconsole, hydra, burp
Target VM (Metasploitable2)
IP: 192.168.56.20/24
Vulnerable services: FTP, SSH, HTTP, SMB

๐Ÿ’ก Always keep your lab disconnected from the internet (host-only adapter) to avoid accidental exposure.


100% legal authorization required
7 PTES phases (industry standard)
600+ tools preinstalled in Kali Linux
3 core methodologies: OSSTMM, PTES, NIST