Initializing

Back to courses
CPPJ// Professional · Offensive

Professional Junior Pentesting Course

Learn professional pentesting by hacking a real corporate network: 7 Windows and Linux servers spread across two subnets you must compromise and pivot through. It closes with a hands-on 24-hour exam against a network you've never seen.

$199 USD7 serversProfessional
CPPJ — Professional Junior Pentesting Course

What you'll be able to do

Not "you'll learn about" — when you finish, you execute. Every outcome is a real technique you can demonstrate.

Compromise an Active Directory

From zero access to Domain Admin on the Windows perimeter Domain Controller.

Pivot into an internal network

Turn a compromised host into a springboard, set up tunnels and reach a subnet that was unreachable.

Land RCE on real apps

Remote code execution on Java web apps, CMS platforms and enterprise services.

Escalate privileges

Root/SYSTEM on Linux and Windows by abusing sudo, SUID, services and dangerous configs.

Escape containers

Break out of misconfigured Docker containers and jump from the container to the real host.

Report like a professional

Document an end-to-end intrusion and rate the criticality of every finding.

A corporate network across two subnets

The lab simulates a real company: two segmented subnets with Windows and Linux servers. There's no shortcut into the internal network — you have to pivot.

THE PERIMETER · 10.10.x.0/24THE INTERNAL NETWORK · 10.10.y.0/24↓ Pivoting ↓Pivot pointSpartanOpsPunto de pivoteFortalezaWindows · EasyPunto de pivoteImprentaLinux · EasyPunto de pivoteCetroWindows · MediumPunto de pivoteLinkLinux · HardAngelLinux · MediumLavaLinux · HardFantasmaLinux · Hard
Stage 1 · 10.10.x.0/24

The perimeter

4servers
Reachable directly from your SpartanOps

The network's exposed services: Active Directory, web apps, CMS and file services. The way in — and any of its 4 hosts becomes your springboard into the internal network.

Stage 2 · 10.10.y.0/24

The internal network

3servers
Unreachable directly — ONLY via pivoting from a Stage 1 host

The deep services only visible from the inside: enterprise apps, containers and internal services. The protected segment.

Pivoting

The lab is a one-way cascade enforced by network rules: your SpartanOps only reaches Subnet 1; Subnet 2 is closed. The only way to touch Angel, Lava and Fantasma is to pivot — you compromise any of the four perimeter hosts, turn it into a springboard, set up a tunnel, and only then does the internal network 'appear'. This is exactly what happens in a real internal pentest.

The 7 servers you'll hack

These aren't toy labs: it's a full corporate network. 7 Windows and Linux servers across two subnets. You breach the perimeter, pivot inward and keep hacking all the way to the last host.

Fortaleza
Easy

Your first breach on the Windows perimeter: get in through a misconfigured service and become local admin. Entry point and springboard into the internal network.

WindowsPivot point
Imprenta
Easy

A service with anonymous access leaks the keys to the kingdom: from a forgotten credential to root, and your first bridge into the protected subnet.

LinuxPivot point
Cetro
Medium

Compromise the Domain Controller: from zero access to Domain Admin, then use the owned DC as your pivot into the second subnet.

WindowsPivot point
Link
Hard

Chain a series of web flaws all the way to RCE and escalate through a dangerous sudo config. The final perimeter challenge before you cross subnets.

LinuxPivot point
↓ Pivoting ↓
Angel
Medium

Now inside the internal network: exploit a shared network resource, abuse a misconfigured container and crack the host hash offline to take your first target after the pivot.

Linux
Lava
Hard

RCE on a Java web app, PATH-hijacking privesc and a Docker container escape: three jumps to root on the real host.

Linux
Fantasma
Hard

Authentication bypass, discovery of hidden internal services and insecure deserialization in an enterprise app. The final challenge of the internal network.

Linux

The environment is already set up

Your attack machine and your target network, provisioned and ready. Zero setup: open your browser and start hacking.

SpartanOps: your attack machine

SpartanOps is your attack machine, your base of operations. A professional cloud operator station, provisioned just for you, with the full pentesting arsenal already installed and tuned. Launch it from your browser —nothing to install, no VPN, no Kali to set up— and you're already attacking. We build the environment; you focus on breaking into the servers.

A real training ground

A Training Zone is a full simulation of a corporate network: Windows and Linux servers across segmented subnets, with the same structure you would face in a real internal pentest. A controlled lab environment —built and managed by us— where you practice the end-to-end intrusion, from the perimeter to the internal network, with nothing to set up or maintain.

What's included

Everything you need to go from zero to operational.

+15 hours of pre-recorded content

Video lessons at your own pace, to watch and replay as many times as you need.

+140 pages of theory PDF

The written theory behind every module, to study and look up without the video.

7-server Training Zone

A Windows and Linux corporate network across two segmented subnets.

SpartanOps attack machine

A dedicated cloud operator station, ready from your browser.

24h exam + Diploma

A hands-on exam against a fresh network and a verifiable diploma (Certifier).

Discord community

Exclusive group with students and the instructor.

90 days to activate your lab

Activate whenever you want within those 90 days; from then on you get 30 days of lab. The exam can be taken from the day of purchase.

A complete attack campaign

The curriculum follows a real attack chain: from reconnaissance to full domain compromise.

4Phases
21+Modules
108+Lessons
7Servers
01
1.1Reconnaissance and mapping of the corporate network6
1.2Exploiting exposed services and leaked credentials5
1.3Hacking web applications and CMS platforms7
1.4Windows privilege escalation5
1.5Linux privilege escalation5
1.6Active Directory intrusion: from zero access to Domain Admin8
1.7Chaining web vulnerabilities all the way to RCE7
02
2.1Corporate network segmentation and why Stage 2 is unreachable4
2.2Turn a compromised host into a springboard: tunnels and port forwarding6
2.3Recon through the pivot (why ICMP/UDP won't cross the tunnel)4
2.4Reverse shells and callbacks across a segmented network5
03
3.1Enumerating internal services not exposed to the Internet5
3.2RCE on enterprise Java applications6
3.3Exploiting insecure object deserialization5
3.4DNS enumeration and discovery of hidden internal hosts4
3.5Container security and Docker escapes6
3.6Credential looting and offline password cracking5
3.7Advanced escalation: from the container to the real host5
04
4.1Methodology for a time-boxed engagement3
4.2End-to-end intrusion: foothold, pivoting and escalation on Linux and Windows4
4.3Exfiltrating flags and documenting the compromise3

The exam: 24 hours, 2 servers, a network you've never seen

24h2 servers

The course closes with a hands-on 24-hour exam, separate from the lab's 7 servers, against a corporate network you've never seen. Two hard servers across two different subnets that force you to pivot: you compromise the first, turn it into your springboard and jump into the second subnet to take the second. You exfiltrate 4 flags (initial access and full control on each server) and, on passing, earn your CPPJ certification. It's not a certificate of attendance: it's proof you can do the job.

4 flags · initial access and full control on each server

1
Server 1
Stage 1
Hard
2
Server 2
Stage 2
Hard

Get certified and learn from the instructor

Professional Junior Pentesting Certification
Certifier· Diploma digital verificable y firmado.
GE

Gerardo Eliasib

Instructor

Fundador de Spartan-Cybersecurity. Enseña ciberseguridad ofensiva con vulnerabilidades y escenarios del mundo real.

// Start today

Hack your first network this month

Buy today and activate your lab when you're ready, within the activation period. Payment and access are handled on the Academy.

$199 USD

One-time payment · Labs included · Certificate included