EC-Council CEH v13 Study Roadmap
Last updated: March 30, 2026
Domain Weight Distribution
Week-by-Week Study Plan
Modules 1-2: Information Security fundamentals, Ethical Hacking methodology, Cyber Kill Chain
Modules 3-4: Footprinting & Reconnaissance — OSINT, DNS, Whois, social media recon
Modules 5-6: Scanning Networks — Nmap, host discovery, port scanning, OS fingerprinting
Module 7: Enumeration — NetBIOS, SNMP, LDAP, NTP, DNS zone transfers
Module 8: Vulnerability Analysis — Nessus, OpenVAS, vulnerability scoring, CVE databases
Modules 9-10: System Hacking — Password attacks, privilege escalation, rootkits, steganography
Modules 11-12: Malware Threats & Sniffing — Trojans, viruses, Wireshark, ARP poisoning
Modules 13-14: Social Engineering & DoS — Phishing, pretexting, DDoS tools, botnets
Modules 15-16: Session Hijacking & IDS/Firewall Evasion — Token theft, tunneling, fragmentation
Modules 17-18: Web Servers & Web Apps — Directory traversal, OWASP Top 10, XSS, CSRF
Module 19: SQL Injection — Union-based, blind, time-based, error-based, sqlmap
Modules 20-21: Wireless & Mobile Hacking — WPA cracking, evil twin, Android/iOS exploits
Modules 22-23: IoT/OT & Cloud — SCADA, MQTT, AWS/Azure attacks, container security, cryptography
Full Review: Practice exams, Weak areas, Lab exercises, Exam logistics
Free Resources
Related Tools
EC-Council CEH v13 Study Guide
Complete exam objectives and domain breakdown
✅Study Tracker
Track objective completion with progress dashboard
💰Cost Calculator
Total cost breakdown and ROI analysis
🧪Practice Quiz
Test your knowledge with free practice questions
FixTheVuln Store
Get the EC-Council CEH v13 Study Planner
Fillable PDF with 14-week schedule, domain trackers, flashcard templates, and progress tracking.
Get the Study Planner — $5.99