⚠️ Authorized practice only. Every technique here is for use inside isolated environments, or on systems you own or are explicitly authorized to test.

Curriculum

Phase 1 · Fundamentals

Networking, Linux, scripting, web basics.

Networking Fundamentals Beginner

TCP/IP, the OSI model, ports and protocols — the bedrock of everything.

Linux Fundamentals Beginner

Shell, filesystem, permissions — a hacker's home turf.

Web Basics Beginner

HTTP, headers, cookies — the vocabulary of web security.

Phase 4 · Advanced

Active Directory ranges, evasion, reporting.

Active Directory Range Expert

A multi-host isolated network: domain controller, workstation, attacker box.

Phase 5 · AI Security new

LLM attack surface, prompt injection, agency.

LLM Attack Surface Intermediate

Why prompts can't be parameterised, and where the real risk lives.

Insecure Output Handling Advanced

Model output is untrusted input. Match the sink to the classic bug class.

Phase 6 · Blue Team new

Log analysis, detection engineering, DFIR.

Log Analysis Beginner

Frequency, pattern and pacing — turning a wall of text into a finding.

Detection Engineering Intermediate

Rules that survive tool churn: behaviour over indicators.

Incident Response & DFIR Intermediate

Order of volatility, containment trade-offs, defensible timelines.