Skip to main content
CYB-0330ExpertCurrent Intake
XEHP

XEHP: Xcademia Ethical Hacker Practitioner

10-Day Instructor-Led Programme

The XEHP Certification Programme is the practitioner standard for ethical hackers who demonstrate real offensive capability across network, web, cloud, and active directory environments. Assessed on Day 10 by a senior practitioner through a supervised simulated engagement. No MCQs. No exam anxiety. No question bank to memorise.

Duration

10 Days

Price

$7,495

XEHP: Xcademia Ethical Hacker Practitioner
Duration
10 Days
Complete in 10 days
Learning Style
Mentor-led, practical and scenario-based
Guided walkthroughs, real-world examples, and applied skills for the workplace.

Course Overview

Modern organisations face adversaries who do not follow a textbook. The penetration tester who can only replicate what a certification study guide describes is not the practitioner organisations need. XEHP is built for professionals who want to demonstrate genuine offensive capability, methodically, ethically, and professionally, across the full attack surface of a modern enterprise.

Across ten instructor-led days, participants build competency across the complete penetration testing lifecycle: from OSINT and reconnaissance through network infrastructure exploitation, active directory attacks, web and API security testing, cloud penetration, container security, advanced evasion, and professional engagement reporting. Where CEH v13 covers 20 modules across 5 days then sends candidates alone to a 125-question multiple choice exam, XEHP puts a senior practitioner in the room for all 10 days and evaluates actual work on Day 10.

On Day 10, participants conduct a scoped simulated engagement against a realistic enterprise target. The senior practitioner observes methodology, tooling decisions, and report quality. A Practitioner Assessment Report is issued alongside the XEHP certificate. Aligned with PTES, MITRE ATT&CK v14, OWASP Top 10 2025, NCSC CHECK methodology, NIST SP 800-115, and DoD 8140.

Hands-On Learning

Live lab engagements every day covering network scanning, active directory exploitation, web application and API hacking, cloud misconfiguration testing, container escapes, and evasion against defensive tooling.

Mentor-Led Sessions

Mentor-led sessions mapping real adversary tradecraft to MITRE ATT&CK v14, covering professional engagement report writing, CVSS risk rating, and executive communication of findings.

Career-Ready Skills

Demonstrate practitioner-level offensive security capability across network, web, cloud, and active directory environments, evidenced by a signed Practitioner Assessment Report that employers can verify publicly.

Learning Outcomes

Design and execute structured penetration testing engagements using PTES and NIST SP 800-115 from scoping through final report delivery

Exploit network infrastructure, active directory environments, web applications, and APIs using current offensive tooling in authorised environments

Implement active directory attack techniques including Kerberoasting, Pass-the-Hash, DCSync, and lateral movement

Assess cloud platform misconfigurations across AWS, Azure, and GCP using cloud-native offensive tools

Produce professional penetration testing reports with executive summaries, CVSS-rated findings, and remediation recommendations

Communicate engagement findings clearly to both technical teams and non-technical leadership at professional standard

Prerequisites

1

Minimum 12 months in an IT or security role with hands-on technical exposure to networks and systems

2

Working knowledge of TCP/IP networking, Windows and Linux operating systems at administrator level

3

Basic familiarity with at least one scripting language: Python, Bash, or PowerShell

Detailed Syllabus

Organized by professional domains with comprehensive coverage

Topics Covered:
  • PTES and NIST SP 800-115: engagement lifecycle from pre-engagement through reporting
  • Scoping, rules of engagement, and authorisation documentation requirements
  • Black, grey, and white box engagement models: when to use each and what each reveals
  • Cyber Kill Chain and MITRE ATT&CK v14 framework overview for attack planning
  • Ethical and legal boundaries for authorised testing: Computer Misuse Act 1990 and equivalent
Stage 5Final Capstone

XEHP: Xcademia Ethical Hacker Practitioner — Capstone Project

On Day 10, participants receive a scoped simulated target environment representing a realistic enterprise network. They conduct a full penetration test using the methodology and tooling covered across Days 1 to 9. The senior practitioner observes work at key points, reviews methodology decisions, and assesses the final engagement report for professional standard. The XEHP certificate and Practitioner Assessment Report are issued together on passing standard.

Assessed by a senior Xcademia practitioner

Framework Alignment

This course is mapped directly onto the standards your organisation already answers to. No invented frameworks, no proprietary jargon.

  • PTES

    Global

    Penetration Testing Execution Standard: primary methodology framework throughout all domains

  • NIST SP 800-115

    Global

    Technical Guide to Information Security Testing: engagement scoping and documentation standards

  • MITRE ATT&CK v14

    Global

    All techniques mapped to ATT&CK tactic and technique IDs throughout the programme

  • OWASP Top 10 2025

    Global

    Web application security testing domain fully aligned to current 2025 edition

  • OWASP API Top 10

    Global

    API security testing domain aligned to OWASP API Top 10 throughout

  • NCSC CHECK

    Global

    UK government approved penetration testing: XEHP aligns to CHECK scoping and reporting principles supporting Direct Award

  • NIST CSF 2.0

    Global

    Identify and Protect functions: vulnerability assessment and attack surface management outcomes

  • DoD 8140

    Global

    US defence workforce framework: offensive operations and exploitation analyst role categories

Skills You'll Gain

Master these in-demand skills through hands-on practice

Network penetration testingActive directory exploitationWeb application hackingAPI security testingCloud penetration testing (AWS/Azure/GCP)MITRE ATT&CK v14 mappingVulnerability analysis and chainingEngagement report writingContainer and Kubernetes security testingEvasion techniquesSocial engineering simulationOSINT tradecraft

Career Progression

A clear view of the roles this programme supports, what typically comes next, and where learners progress over time

Penetration TesterRed Team OperatorSecurity ConsultantVulnerability AssessorOffensive Security EngineerApplication Security Engineer
Flexible Delivery Options

Ways to Learn

Choose the learning format that works best for you and your team

Book Now

Live Online

Instructor-Led Training

Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.

10 Days
Small cohorts
  • Live instructor interaction (real-time)
  • Trainer-led walkthroughs and real examples
  • Guided resources and session notes provided
  • Structured Q&A and practical discussion

Price per person

$7,495+ VAT

Group enrolments and early planning options available.

All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.

Premium Training Option

Prefer a Faster, Personalised Route into IT?

Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.

Personalised XEHP: Xcademia Ethical Hacker Practitioner learning plan
Tailored to your pace and goals
Live 1-to-1 sessions
With an experienced mentor
Real-world troubleshooting
Practice, not just exam theory
Flexible scheduling
To fit around work, study, or family

"Many learners choose 1-to-1 when they want understanding, not memorisation."

Exam & Certification Information

Everything you need to know about the certification exams

Xcademia Certification Programme

Xcademia Certification Programme

On successful completion of XEHP: Xcademia Ethical Hacker Practitioner, learners are assessed on the final day through a supervised practitioner scenario. Three outcomes are possible, Certificate Awarded, Certificate Deferred, or Not Awarded. The Practitioner Assessment Report and certificate are issued together. Verified at xcademia.com/verify.

Certificate Awarded

Assessed competent on the final day.

Certificate Deferred

Resit available on a future cohort.

Not Awarded

Attendance record issued. Reassessment possible.

Frequently Asked Questions

Everything you need to know about this course

CEH v13 is 5 days of training followed by 125 multiple choice questions. XEHP is 10 instructor-led days ending in a supervised real engagement on Day 10. The practitioner observes your methodology and produces a signed assessment report. Employers see what you demonstrated, not a test percentage. CEH costs over $2,800 with renewal fees every 3 years. XEHP is one price, all in, no renewal fees.

Share:

Ready to Start Your Learning Journey?

Take the next step in your professional development

Digital certificate upon completion
Comprehensive course materials
Expert instructor support
Flexible learning options