Back to portfolio

eJPT Certification Applied Research

Enterprise Penetration Testing Labs & Network Exploitation

A sustained body of hands-on work carried out across authorized, simulated laboratory networks while preparing for and completing the eJPT certification — treating each lab as a small engagement with a scope, a method and written findings.

Context
eJPT preparation
Environment
Authorized labs
Role
Solo practitioner
Status
Completed
01

Overview

The work centred on practising a complete assessment workflow against intentionally vulnerable hosts inside authorized lab environments rather than on isolated tool usage.

Each lab was approached as a miniature engagement: define the scope, enumerate what is reachable, assess what is weak, validate a limited number of findings, and record the reasoning behind every step.

02

Approach

  • 01Scope first — only in-scope, simulated lab targets were touched, with the boundaries written down before starting.
  • 02Recon and enumeration were kept deliberately slow, so that later conclusions rested on observed evidence instead of assumptions.
  • 03Findings were categorised by weakness class and reachability before any exploitation was attempted.
  • 04Validation stayed minimal and purposeful; the goal was confirming impact, not collecting shells.
  • 05Every lab ended with notes: what worked, what failed, and what a defender would have seen.
03

Methodology

Mapping the authorized lab scope — host discovery, service exposure and surface notes before any interaction.

Interrogating identified services to build an accurate picture of versions, shares and reachable endpoints.

Correlating findings with known weakness classes and separating noise from what is actually exploitable.

Validating a small number of findings in simulated lab targets to confirm real impact rather than theory.

Studying privilege escalation fundamentals, persistence concepts and clean documentation of the path taken.

All activity performed in authorized, simulated lab environments.

04

Tools

  • Kali Linux
  • Nmap
  • Wireshark
  • Linux
05

Technical Areas

  • Reconnaissance
  • Enumeration
  • Vulnerability Assessment
  • Network Analysis
  • Privilege Escalation Fundamentals
06

Key Learnings

  • Enumeration quality determines everything downstream — most dead ends came from rushing this stage.
  • Reading traffic in Wireshark made abstract protocol theory concrete, especially around authentication and service behaviour.
  • Tools are interchangeable; the methodology is the transferable skill.
  • Documentation is part of the technical work, not an afterthought — an unreproducible finding has little value.
  • Working strictly inside authorized environments builds the professional habits expected of a security practitioner.

All activity described here was performed in authorized, simulated lab environments. No production systems were involved.

Visit GitHub