This intermediate, challenge-only project brings reconnaissance, network mapping, and vulnerability triage into one staged external attack surface assessment. You will turn evidence from Whois, DNS, Nmap, Nikto, and Searchsploit into concise artifacts that another analyst could reuse.
The environment is deliberately contained: the organization, DNS zone, hosts, and services are simulated locally. The emphasis is on choosing and applying the right commands, preserving useful evidence, and justifying remediation order—not on attacking real systems.
What You Will Learn
- Query a local Whois service and extract an administrative contact cleanly
- Enumerate MX records and exposed subdomains with
digand a DNS zone transfer - Consolidate passive reconnaissance findings into a readable target dossier
- Discover responding hosts from an approved scope with Nmap ping-scan mode
- Record selected open TCP ports in reusable grepable Nmap output
- Fingerprint a key SSH service with Nmap version detection
- Correlate an Apache version and Nikto finding with a Searchsploit reference
- Rank remediation priorities and assemble an evidence-based assessment report
Who This Course Is For
This course is for learners who have already practiced command-line reconnaissance, Nmap scanning, and basic vulnerability assessment and now want an independent review project. It suits aspiring security analysts, penetration testers, and defenders who want to connect discovery evidence to remediation decisions.
Prerequisites: Comfortable working in a Linux shell; familiarity with Whois and DNS queries, Nmap host/port/version scans, basic web vulnerability scanning, and interpreting public exploit references.
Learning environment: An Ubuntu 22.04 LabEx VM with local simulated Whois and DNS services, loopback-hosted network targets, a local Apache-like web target, and tools including dig, Nmap, Nikto, and Searchsploit.
Frequently Asked Questions
Is this a guided beginner course?
No. It consists of three challenge-based assessments and expects you to combine skills learned earlier. Each challenge defines the required evidence and deliverables, but you must construct the commands and workflow yourself.
Will I scan real companies or Internet hosts?
No. The fictional examplecorp.internal domain, Whois and DNS services, scoped hosts, and web target are provided locally on loopback addresses. The work is contained within the training VM.
Will I exploit the Apache vulnerability?
No. You identify the simulated Apache 2.4.49 version, find its path-traversal and remote-code-execution reference in Searchsploit, and use that evidence for prioritization. The course does not ask you to run the exploit.
What will I produce during the assessment?
You will create a reconnaissance dossier, a network map combining live-host, port, and service evidence, and a priority report that compares the Apache exposure with a missing X-Frame-Options header.





