Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Ethical hacking field manual
Learn what tool to use, when, how, and why.
Deep lessons, decision flows, command recipes, ATT&CK/OWASP maps, finding writer, comparisons, roadmaps, and a progress tracker — built to turn curiosity into operator judgment.
276
Tools cataloged
36
Deep lessons
3
Decision flows
23
Command recipes
Decision coach
Guided flows: home /24, web app, credentials — ordered checklists with tool links.
Command builder
Target type + phase → safe example commands with placeholders and RoE warnings.
Deep curriculum
16 modules with teach-through sections, mistakes, defender views, and drills.
ATT&CK / OWASP
Filter techniques and Top 10 categories; jump to tools and modules.
Finding writer
Form → Markdown export. Practice the deliverable, not just the exploit.
Case file
Scope, plan, findings, and purple notes in one local engagement you can export.
Operator bench
CVSS, subnet math, hash identification, JWT structure, and port crib — in the browser.
ATT&CK board
Taught techniques by tactic, with a one-click detection log on the case file.
Featured operator tools
Start with these staples — then explore the full directory.
Nmap
The definitive network mapper for host discovery, ports, and service/version detection.
Burp Suite
Industry-standard intercepting proxy for web/app security testing.
Nuclei
Template-based vulnerability scanner with huge community template set.
Impacket
Python collection for Windows network protocols (SMB, WMI, Kerberos, etc.).
Hashcat
GPU-accelerated password recovery tool supporting hundreds of hash types.
BloodHound / SharpHound / AzureHound
Maps Active Directory attack paths using graph theory.
Metasploit Framework
Modular exploitation framework with payloads, auxiliaries, and post modules.
Wireshark / tshark
World-class packet capture and protocol analysis tool.
Curriculum at a glance
Sequential modules designed like a professional onboarding path.
Mindset, Law & Ethics
Authorization is the only difference between testing and crime.
Networking & Linux Fluency
Tools change. Packets and processes do not.
Reconnaissance & OSINT
Quiet mapping beats loud guessing.
Scanning & Enumeration
Depth beats breadth once you know what is alive.
Web Application Hacking
Most real engagements still start and end in the browser.
Credentials, Passwords & Initial Access
Access is often a password problem wearing an exploit costume.
Internal Networks & Active Directory
Where professional pentests become real.
Privilege Escalation & Post-Exploitation
Foothold is the beginning, not the trophy.
Cloud, Containers & Modern Surfaces
The perimeter is an IAM policy and a misconfigured role.
Wireless & Adjacent Surfaces
RF is real-world scope: own the network or do not touch the air.
Reporting, Risk & Professional Practice
If the report is weak, the exploit did not matter.
Purple Team & Defensive Awareness
The best operators know how their attacks look from the other chair.
Identity, SSO & Entra ID
Cloud identity is a trust protocol, not a domain controller.
API Authorization & BOLA
A valid login is not permission to open every record.
CI/CD & Secret Exposure
A secret in git history is still a secret, and still a credential.
Mobile App Assessment
Read the app you were given. Practice on apps that were built to be broken.
Decide → recipe → lab → find → report
Use the decision coach when you are stuck choosing tools. Build commands. Run a playbook. Write the finding. Mark progress. That is how judgment compounds.