What you'll gain

🛡️
Learn authorized, legal, ethical penetration testing — and write the report

Ethical hacking is one of the most in-demand skills in technology — but also one of the most misunderstood, and one where a single wrong step is a crime. This course is the honest foundations playbook for authorized, legal, ethical penetration testing, built around one bright line stated on the first page and repeated on every module: you only ever test systems you own or have explicit written authorization to test, because unauthorized access is a crime — in Nigeria under the Cybercrimes Act 2015, and under equivalents elsewhere. This is orientation and capacity-building for legal, defensive work — not instructions for unauthorized hacking, not a job or income guarantee, and not legal advice — and it never targets a real system or teaches you to attack anyone. You learn what a penetration test actually is (an authorized, simulated attack to find weaknesses before a real attacker does and report them to be fixed, so the difference between an ethical hacker and a criminal is authorization, scope, ethics and intent), and the engagement lifecycle (pre-engagement scoping and signed authorization, reconnaissance, scanning and enumeration, vulnerability analysis, careful in-scope exploitation, post-exploitation, reporting, and re-test), where scope is a fence you never cross and "do no harm" is a rule. You learn the foundations you need first (networking, Linux, the command line, how web apps work, the OWASP Top 10), the standard industry tools (Kali, Nmap, Burp Suite, Metasploit and more) with the rule that the tool is neutral and the authorization is everything, and the legal labs where you actually practise (TryHackMe, Hack The Box, the PortSwigger Web Security Academy, deliberately-vulnerable machines in your own lab, CTFs, and bug bounties within scope) — never on a system you do not own or are not authorized to test. Then the heart of the course and its namesake: writing the report — the real product — with an executive summary for management and findings each carrying a risk rating, evidence, impact and remediation. You learn the ethics code and responsible disclosure (report privately, reasonable time, never exploit or extort), the career path and recognised certifications, and the classic mistakes and the scams — hire-a-hacker services, cert mills, and "pay me or I release it" extortion — with a red-flag grammar. Two Nigerians travel with you: Tunde, learning on legal labs toward his first authorized engagement, and Nkechi, cross-training into web-app testing and responsible bug bounty. Where a law, tool or certification could not be fixed, the course tells you to confirm it live and that this is not legal advice. This is orientation and capacity-building for legal, ethical, authorized security work — never a licence to attack anyone, and never a guarantee of a job.

🎓
A certificate that proves it

Pass a real exam and earn a publicly verifiable certificate employers trust.

🔁
Practice until it sticks

Unlimited practice mode + spaced-repetition flashcards, then unlimited exam retakes.

♾️
Lifetime access

Keep the lessons and every future update to this course, forever.

What you'll cover

10 modules · 20 lessons · timed certification exam

1. Start here — authorization is everything 2 lessons

What this course is (and is not), and what a penetration test actually is.

  • What this course is — and what it is not · 12 min
  • What a penetration test actually is · 11 min
2. The authorization and legal bright line 2 lessons

The rule the course rests on, and the law behind it.

  • The authorization bright line · 12 min
  • The law behind the line · 11 min
3. The engagement lifecycle 2 lessons

The professional phases, and scope and rules of engagement.

  • The penetration-test lifecycle · 12 min
  • Scope and rules of engagement · 11 min
4. The work 2 lessons

Reconnaissance, scanning and analysis, and careful in-scope exploitation.

  • Reconnaissance, scanning and analysis · 12 min
  • Careful, in-scope exploitation · 11 min
5. Tools and legal labs 2 lessons

The standard tools, and the legal labs where you actually learn.

  • The standard tools · 12 min
  • The legal labs where you learn · 11 min
6. The report — the real product 2 lessons

Why the report is the product, and the anatomy of a finding.

  • The report is the product · 12 min
  • The anatomy of a finding · 11 min
7. Ethics and responsible disclosure 2 lessons

The non-negotiable ethics code, and how to report a real-world find.

  • The ethics code · 12 min
  • Responsible disclosure · 10 min
8. The career and the foundations 2 lessons

The path and certifications, and the fundamentals you need first.

  • The career path · 11 min
  • The foundations you need first · 10 min
9. Mistakes and scams 2 lessons

The classic mistakes, and the scams that make this field dangerous to get wrong.

  • The classic mistakes · 11 min
  • The scams and the filter · 11 min
10. The honest museum and your capstone 2 lessons

The hard truths to keep, and a plan you can defend.

  • The honest museum — hard truths to keep · 10 min
  • Your capstone — a plan you can defend · 12 min

Frequently asked

Is the certificate verifiable?

Yes. Every certificate carries a unique ID and a cryptographic signature. Anyone — an employer or a client — can confirm it instantly on our public verification page, with no login.

Who teaches this course?

A vetted expert author — Sankofa Skills Studio. Every expert course is reviewed and fact-checked before publication, and the author earns a revenue share on your enrolment.

How long do I have access?

Lifetime. Once you enrol you keep access to the lessons, practice mode and flashcards — including future updates to this course.

What happens if I don't pass the exam first time?

You can retake it — up to 5 attempts, with a 12-hour wait between attempts. Practice mode is unlimited, so rehearse with the same verified question bank until you're ready.

Can my team enrol together?

Yes. Talk to us about group and organisation rates — certifying a whole team is faster and cheaper than one at a time.