What makes hacking ethical
Hacking means finding ways to make systems do things their designers did not intend. Ethical hacking uses the same knowledge and skills to make systems safer, and it rests on three things:
- Permission: explicit, written authorisation from the owner of every system involved, before any testing.
- Purpose: the aim is to find and fix weaknesses, not to steal, damage or embarrass.
- Responsibility: staying within the agreed scope, protecting any data seen, causing no unnecessary harm, and reporting findings to people who can fix them.
Without permission, good intentions do not make hacking legal. In Kenya, the Computer Misuse and Cybercrimes Act, 2018 makes it an offence to get into a computer system without authorisation by getting round its security measures (section 14), including with intent to commit a further offence (section 15), and to interfere with (section 16) or intercept (section 17) computer systems or data without authorisation. Where the Act allows testing, it is testing that has been authorised. Saying you were "only testing" does not make unauthorised access lawful. Many other countries have similar laws.
Coordinated (sometimes called responsible) vulnerability disclosure applies when someone finds a weakness in a system they were not engaged to test, for example while using a public website: report it privately to the owner, give them reasonable time to fix it, and do not exploit it further or publish details that would help attackers. Finding a weakness by chance does not authorise you to probe it further: stop, write down what you saw, and report it. Many organisations now publish a vulnerability disclosure policy that explains how to report and what testing, if any, they allow, and the international standard ISO/IEC 29147 describes how organisations should receive and handle such reports. Some organisations also run bug bounty programmes that authorise and reward testing under stated rules.
How an attack unfolds
Real attacks follow recognisable stages. Defenders describe them in order to spot and interrupt them. A widely used public knowledge base, MITRE ATT&CK, catalogues the tactics and techniques attackers use, built from real-world attacks. In simplified form, and not always in this order, attacks commonly involve:
- Reconnaissance: learning about the target: its people, systems, suppliers and exposed services, often from public information.
- Initial access: getting a foothold, for example through a phishing email, stolen credentials or an unpatched internet-facing system.
- Execution and persistence: running malicious code and making sure access survives restarts and password changes.
- Privilege escalation: gaining higher permissions, such as administrator rights.
- Credential access: stealing usernames, passwords and session tokens (the digital pass a website issues after someone logs in) to act as legitimate users.
- Discovery and lateral movement: mapping the internal network and moving to other systems, often using legitimate administration tools to blend in.
- Command and control: keeping a communication channel open to compromised systems so the attacker can direct them.
- Collection and exfiltration: gathering valuable data and sending it out.
- Impact: the attacker's goal, such as encrypting systems for ransom (often after stealing data first and threatening to publish it, known as double extortion), stealing money, destroying data or disrupting services.
The full ATT&CK list for enterprise systems currently has 15 tactics, including hiding activity and disabling defences.
Two lessons follow for defenders. First, attacks take time: every stage is a chance to detect and stop them, but only if the right logs are collected, kept and reviewed. Second, defence in depth works: an attack usually needs several steps to succeed, and each layer of defence is another chance to block it or detect it before serious harm is done.
The common ways in
National and regional threat reports show that most attacks do not rely on rare, sophisticated techniques. They use a small number of common routes, again and again. For example, the European Union Agency for Cybersecurity's 2025 threat landscape found phishing (about 60% of the cases it observed) and the exploitation of vulnerabilities (about 21%) to be the leading ways in. The common routes are:
- Phishing and social engineering: tricking people into revealing passwords, approving logins, opening malicious attachments or making payments.
- Stolen or weak credentials: passwords reused from other breaches, guessed, bought from criminal markets or captured by malware, especially where there is no multi-factor authentication.
- Unpatched vulnerabilities: known flaws in internet-facing systems, such as remote access gateways, web applications and email servers, exploited before the fix is applied.
- Misconfiguration: cloud storage left open to the internet, default passwords, unnecessary services exposed, excessive permissions.
- Third parties: compromising a supplier, service provider or software update to reach many organisations at once.
Knowing the common ways in tells defenders where effort pays most: phishing-resistant multi-factor authentication, fast patching of internet-facing systems, secure configuration, least privilege, supplier security, and staff who know how to spot and report manipulation. Public lists of vulnerabilities known to be exploited in real attacks, such as the Known Exploited Vulnerabilities catalogue published by the US Cybersecurity and Infrastructure Security Agency, help teams decide which patches to apply first; it is US-run but useful everywhere.
Thinking like an attacker to defend
Defenders use attacker thinking in several structured ways:
- Threat modelling: before building or changing a system, asking four questions: what are we working on, what can go wrong, what are we going to do about it, and did we do a good enough job? One widely used prompt, STRIDE, considers spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege.
- Attack surface management: keeping an up-to-date view of everything the organisation exposes to the internet, because attackers scan for it continuously.
- Detection engineering: writing detections for the techniques attackers actually use, mapped to knowledge bases such as MITRE ATT&CK, and testing that they fire.
- Penetration testing and red teaming: authorised simulated attacks that show where defences fail.
- Purple teaming: attackers (red) and defenders (blue) working together, so each simulated technique is checked against detection and response, and gaps are identified and closed, often during the exercise itself.
The mindset matters as much as the methods. Attackers look for the easiest path, not the most interesting one; they chain small weaknesses; and they take advantage of assumptions, such as "that system is internal, so it is safe". Defenders who ask "how would I get in?" find the gaps that checklists miss.
Building the skills safely
Ethical hacking skills are in demand, and they can be learned legally and safely.
- Foundations first: networking, operating systems, how web applications work, and basic programming or scripting. Understanding how systems work is what makes it possible to see how they fail.
- Practise only on systems you own or are authorised to test: build a home laboratory with virtual machines, or use training platforms and deliberately vulnerable applications designed for learning.
- Capture the flag (CTF) competitions: legal challenges where participants solve security puzzles; many are free and beginner-friendly, and some are run in Kenya by universities, student clubs and government bodies.
- Study defence as well as attack: detection, incident response and secure design. The best testers understand what defenders see.
- Recognised training and certifications can structure learning and help with employment; choose them by the skills they test, not only by name.
- Follow the rules: read and respect the scope of any programme, never test real systems without written permission, and report what you find responsibly.
In Kenya, cyber incidents can be reported to the National Kenya Computer Incident Response Team – Coordination Centre (National KE-CIRT/CC), hosted by the Communications Authority of Kenya.
The skills are the same on both sides. What makes someone an ethical hacker is the choice to use them with permission, for protection, and within the law.
Ten questions
Answer all ten questions, then check your answers. You need 9 out of 10 to pass and receive a certificate. If you score less, you will see which answers were right and wrong, and then go through the course again before you retake the check. Your answers, progress and times are kept only in this browser.
Your answers
Your certificate of completion
Enter your name as you want it to appear, then save the certificate as a PDF. In the print window, choose Save as PDF. A certificate is issued once per completion of the course.
Saolix does not record who takes this course, so it cannot verify these certificates. The certificate confirms completion of a free self-paced course and is not an accredited qualification.
Sources
The official documents this course relies on. Laws and guidance change, so check the current version.
- MITRE ATT&CK · MITRE
- MITRE ATT&CK Enterprise tactics · MITRE
- ENISA Threat Landscape 2025 · European Union Agency for Cybersecurity
- ISO/IEC 29147:2018 Vulnerability disclosure · International Organization for Standardization
- Known Exploited Vulnerabilities Catalog · US Cybersecurity and Infrastructure Security Agency
- OWASP Threat Modeling Cheat Sheet · OWASP Foundation
- Computer Misuse and Cybercrimes Act, 2018 (No. 5 of 2018) · Kenya Law
- National KE-CIRT/CC · Communications Authority of Kenya