Twenty modules, real Docker labs, and a timed final built to match the 312-50 exam.
April 8, 2025
Certified Ethical Hacker is one of the most recognized names in offensive security certification. It is issued by EC-Council, the current version is v13, and the exam code is 312-50.
The HackRange course follows all twenty official modules and adds the part most CEH study material is missing, which is doing the attacks yourself in a real environment instead of reading about them.
It assumes nothing. If you have never opened a terminal or looked at a packet capture, the first modules start there and build up in small steps.
That is unusual for CEH material, which often assumes a working system administrator. The tradeoff is that the early modules will feel slow if you already have that background, and you can move through them quickly.
Each module comes with a hands on lab in a disposable environment: an attack machine on one side and a deliberately vulnerable target on the other. It is yours for the length of the lab and wiped clean afterwards.
You scan real services, crack real password hashes, exploit a real web application, capture real traffic, and take an Android application apart. Nothing is a simulation of a tool. It is the tool.
The attack side is Kali Linux, which is the same distribution used on paid engagements, with the same versions of Nmap, Wireshark, Burp Suite, Metasploit, and Hashcat.
The course follows the official structure: introduction to ethical hacking, footprinting and reconnaissance, scanning networks, enumeration, vulnerability analysis, system hacking, malware threats, sniffing, social engineering, denial of service, session hijacking, evading IDS and firewalls and honeypots, hacking web servers, hacking web applications, SQL injection, wireless networks, mobile platforms, IoT and OT, cloud computing, and cryptography.
Each one is broken down on our CEH module guide, with what you learn and what the lab asks you to do.
Module 1 spends real time on scope, rules of engagement, and written authorization, and it is not a formality. The difference between a penetration tester and a criminal is a signed document.
The module also covers the laws and standards that apply, which vary by country and by industry. In the United States the Computer Fraud and Abuse Act is the one that matters most, and it does not care whether you meant well.
Every lab in this course runs against targets we own and provide. Nothing in it should ever be pointed anywhere else. That is covered further in what penetration testing actually is.
Every module ends with a quiz plus a short things to know summary aimed at the exam. Those summaries exist because CEH asks a fair number of definition and terminology questions, and the labs alone will not prepare you for those.
The course then has two full length 125 question timed practice exams and a timed final in the same style as 312-50. Sitting a timed exam is its own skill, and doing it three times before the real thing removes most of the surprise.
CEH Engage is a full engagement from first scan to root, run end to end without module by module hand holding.
This is where the course finds out whether you learned techniques or learned methodology. The capstone does not tell you which module applies. You have a target and a scope, and you work.
The honest answer is that it depends on where you are. CEH is widely recognized by human resources departments and appears in many job listings and in some government requirements, which makes it useful for getting through filters.
It is a multiple choice exam, so on its own it proves knowledge rather than skill. Practical certifications such as OSCP prove more about hands on ability and cost more effort. Many people do CEH first and then move on. Our certification roadmap lays out the sequence and the price of each step.
The course is 137 lessons across twenty modules, plus a capstone, two practice exams, and a timed final. Progress and scores are tracked in the learning management system.