All Twenty CEH v13 Modules Explained

What each of the twenty CEH modules covers, and what its lab asks you to do.

April 22, 2025

CEH v13 is organized into twenty modules that follow the shape of a real engagement, from gathering information about a target through to breaking its cryptography.

Here is what each one actually covers in the HackRange course.

Modules 1 to 5: Learning the Target

Module 1, Introduction to Ethical Hacking. What makes hacking ethical, the hacker spectrum and the threat actor types, the five phases and the cyber kill chain, scope and authorization, defensive controls, and the laws you cannot ignore.

Module 2, Footprinting and Reconnaissance. Doing your homework first. WHOIS and DNS as the public record of a company, search engines and Google dorking, and open source intelligence. The lab footprints a live target using only public information.

Module 3, Scanning Networks. Ports and the TCP handshake, host discovery and port scanning with Nmap, scan types, operating system fingerprinting, and evasion. The lab scans the target network properly rather than by running one command.

Module 4, Enumeration. Making the target talk. SMB, NetBIOS, and SNMP, then LDAP, SMTP, DNS, and NFS. Enumeration is where a list of open ports turns into usernames, shares, and versions.

Module 5, Vulnerability Analysis. Finding weaknesses, the scanning tools, and CVSS scoring with the important follow up: verifying a finding and prioritizing it. The lab asks you to find and rate, not just find.

Modules 6 to 9: Getting In and Staying In

Module 6, System Hacking. Password attacks, privilege escalation, maintaining access, and covering tracks with log manipulation, hidden files, and rootkits. The lab is break in and take over.

Module 7, Malware Threats. The malware zoo of viruses, worms, trojans, and the rest, how malware spreads and hides, and how to analyze it safely. The lab builds and analyzes a payload in an isolated environment.

Module 8, Sniffing. How sniffing works with switches and promiscuous mode, active sniffing techniques including MAC flooding and ARP poisoning, then Wireshark and tcpdump and the defenses. The lab captures cleartext credentials, which is the moment encryption stops being an abstract idea.

Module 9, Social Engineering. Hacking the human, the playbook of phishing and pretexting, and the defenses. The lab clones a login page and harvests credentials, inside the range only.

Grid of all twenty CEH version 13 modules from introduction to ethical hacking through cryptography.
The Twenty CEH Modules

Modules 10 to 12: Availability, Sessions, and Evasion

Module 10, Denial of Service. Attacking availability, then the techniques: floods, amplification, and slow attacks. The lab knocks over a server safely so you can watch resource exhaustion happen.

Module 11, Session Hijacking. Stealing the login rather than the password, network level hijacking, and the toolkit. The lab forges a session token, which explains a lot about why session management is written the way it is.

Module 12, Evading IDS, Firewalls, and Honeypots. What each control actually does, firewall types and web application firewalls, honeypot detection, and evasion. The lab contrasts a loud scan with a quiet one and shows what each looks like from the defender's side.

Modules 13 to 15: The Web

Module 13, Hacking Web Servers. Configuration mistakes, information leaks, WebDAV, and patch management. The lab takes a web server from banner to shell.

Module 14, Hacking Web Applications. The web application attack surface and the OWASP Top 10, then the big vulnerability classes including cross site scripting, injection, and insecure direct object references. The lab exploits a real application.

Module 15, SQL Injection. How it works, then the harder variants: blind, error based, and web application firewall evasion. The lab bypasses a login and dumps a database, which is worth doing once by hand before you ever reach for an automated tool.

Modules 16 to 18: Wireless, Mobile, and the Physical World

Module 16, Hacking Wireless Networks. Wireless concepts and the encryption history from WEP through WPA3, Bluetooth, enterprise Wi-Fi, and the toolkit. The lab cracks a WPA2 handshake captured in the range.

Module 17, Hacking Mobile Platforms. The Android and iOS attack surface, mobile malware, mobile device management, and the mobile pentest methodology. The lab takes an Android application apart.

Module 18, IoT and OT Hacking. Hacking the physical world, the IoT methodology, firmware analysis, and operational technology protocols. OT matters more every year because the consequences are physical rather than financial.

Modules 19 and 20: Cloud and Cryptography

Module 19, Cloud Computing. Shared responsibility and the new perimeter, cloud attack techniques, and container security. The lab audits a cloud account, and it overlaps with Week 12 of the mentorship.

Module 20, Cryptography. The difference between encoding, hashing, and encryption, which trips up a startling number of people. Then public key infrastructure, TLS, and encryption in practice, followed by cryptographic attacks. The lab breaks weak crypto.

Then the Capstone and the Exams

CEH Engage runs a full engagement start to root with no module structure to lean on. After that come two 125 question timed practice exams and the timed final.

The course keeps the exam material and the lab material separate on purpose, because they test different things. See the course overview for how the whole thing fits together.

Learn This at HackRange

Twenty modules, 137 lessons, real labs for each, and full length timed practice exams before you sit the real one.