What CEH v13 actually covers
CEH v13 is a comprehensive 20-module programme that takes you through every major phase and discipline of ethical hacking — from reconnaissance and footprinting through to cloud attacks, IoT exploitation, and AI-powered threats. The curriculum is built around the offensive mindset: you learn to think, act, and adapt like an attacker.
What distinguishes CEH from many certifications is that it requires learning real tools and real techniques. You are expected to know how to use Nmap, Metasploit, Wireshark, Burp Suite, SQLmap, and dozens of other industry-standard tools — not just their names, but how to apply them in real attack scenarios.
CEH v13 modules at a glance
The 20 modules progress through the complete ethical hacking lifecycle:
-
1–4Foundations & Reconnaissance — Introduction to ethical hacking, footprinting, scanning networks, and enumeration. Building the full picture of a target before attacking.
-
5–8Exploitation — Vulnerability analysis, system hacking (gaining access, escalating privileges, maintaining access), malware threats, and network sniffing.
-
9–12Advanced Attacks — Social engineering, denial of service, session hijacking, evading IDS/IPS/Firewalls, and web server attacks. All include hands-on Kali Linux labs.
-
13–16Web & Wireless — Web application hacking (OWASP Top 10, SQLi, XSS), SQL injection in depth, hacking wireless networks (WPA2, Evil Twin, Deauthentication). Lecture-based modules.
-
17–20Modern Attack Surfaces — Mobile platform security, IoT and OT hacking, cloud computing security, and the new v13 module: AI-powered ethical hacking. Covers how attackers use AI tools and how defenders detect AI-assisted attacks.
Who should pursue CEH v13?
CEH is well suited for:
- IT professionals (sysadmins, network engineers) transitioning into offensive security or penetration testing
- Security analysts who want to understand attacker techniques to improve detection and response
- Anyone targeting penetration tester, red team analyst, or security consultant roles
- Professionals in government, military, or defence where CEH is specifically listed as a required or preferred credential
EC-Council recommends 2 years of IT security experience, though this is not strictly enforced. Students with strong IT fundamentals (networking, operating systems) typically succeed in CEH training programmes without prior security experience, particularly when supported with hands-on labs.
The CEH examination
CEH v13 has two assessment formats:
- CEH Knowledge Exam: 125 multiple-choice questions over 4 hours. Tests theoretical knowledge across all 20 modules. Passing score is approximately 70% (varies by question version).
- CEH Practical Exam (optional): A 6-hour hands-on exam on a real lab environment. You are given targets and must find and exploit vulnerabilities to earn specific flags. Achieving both credentials earns the "CEH Master" designation — the highest CEH tier.
VAPTIC is an official EC-Council Authorised Training Centre offering CEH v13 with live instruction, real Kali labs, and small class sizes for personalised learning.