Certification

GIAC Penetration Tester (GPEN)

GIAC

Median earnings
Cost
Duration
Completion

The GIAC Penetration Tester (GPEN) certification validates a practitioner's ability to properly conduct a penetration test using best-practice techniques and methodologies. GPEN certification holders have the knowledge and skills to conduct exploits, engage in detailed environmental reconnaissance, and utilize a process-oriented approach to penetration testing projects.

hybridProgram details →

Skills taught

Use advanced methods to attack password hashes and authenticateObtain and attack password hashes and other password representationsUnderstand Azure applications and the attacks against them including federated and single sign-on environments and Azure AD authentication protocolsUnderstand Entra ID implementation fundamentals, common Entra ID attacks, and Azure authentication techniquesUnderstand the design, application, and use of Command and Control (C2) and common C2 frameworksUnderstand common Windows privilege escalation attacks and Kerberos attack techniques used to consolidate and persist administrative access to Active DirectoryDemonstrate the fundamental concepts of exploitation, data exfiltration from compromised hosts, and pivoting to exploit other hosts within a target networkDemonstrate the fundamental concepts associated with the exploitation phase of a penetration testUnderstand attacks against Active Directory including Kerberos attacksUse and configure the Metasploit Framework at an intermediate levelUnderstand types of password attacks, formats, defenses, and when to use each password attack variation and conduct password guessing attacksUnderstand common password hashes and formats for storing password dataDemonstrate the fundamental concepts associated with penetration testing and use a process-oriented approach to penetration testing and reportingUnderstand the fundamental concepts of reconnaissance and obtain high-level information about target organizations and networks including public contacts, IP address ranges, document formats, and supported systemsUse appropriate techniques to scan networks for targets and conduct port, operating system, and service version scans and analyze the resultsConduct vulnerability scans and analyze the results
← Browse credential pathways