Curriculum

Path from curious beginner to capable operator

Twelve modules with deep teach-through sections, key concepts, common mistakes, defender views, checklists, and practice drills. Work in order if you are new; jump ahead only when foundations are solid.

12 modules
28 lessons
163 deep sections

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

Foundation · 2 modules
Operator · 4 modules
Advanced · 4 modules
Professional · 2 modules
01

Mindset, Law & Ethics

Foundation

Authorization is the only difference between testing and crime.

Before any tool, master the rules of engagement, legal boundaries, professional ethics, and how to build a safe home lab. Experts start here every career — and revisit often.

Open module
3 lessons15 sections~150 min5 outcomes
02

Networking & Linux Fluency

Foundation

Tools change. Packets and processes do not.

Become dangerous with the fundamentals: TCP/IP, DNS, HTTP, Linux processes, permissions, and shell pipelines. This module is what lets you understand tool output instead of memorizing flags.

Open module
3 lessons17 sections~185 min5 outcomes
03

Reconnaissance & OSINT

Operator

Quiet mapping beats loud guessing.

Learn passive and active reconnaissance: OSINT, subdomain discovery, certificate transparency, and building an attack surface inventory without rushing to exploits.

Open module
2 lessons11 sections~115 min5 outcomes
04

Scanning & Enumeration

Operator

Depth beats breadth once you know what is alive.

Host discovery, port scanning, service enumeration, and the discipline of turning scan spam into a prioritized target list — always within written authorization.

Open module
2 lessons12 sections~135 min5 outcomes
05

Web Application Hacking

Operator

Most real engagements still start and end in the browser.

OWASP-focused web testing: application mapping, injection classes, content discovery, APIs, and modern workflows with Burp and manual reasoning. Practice only on authorized labs and in-scope targets.

Open module
3 lessons18 sections~185 min5 outcomes
06

Credentials, Passwords & Initial Access

Operator

Access is often a password problem wearing an exploit costume.

Offline cracking methodology, intelligent wordlists and rules, careful online authentication testing, and how credential weaknesses become initial access — taught for authorized labs and scoped engagements only.

Open module
2 lessons12 sections~125 min5 outcomes
07

Internal Networks & Active Directory

Advanced

Where professional pentests become real.

Windows estates, Active Directory attack paths, NTLM, Kerberos, BloodHound, relays, and intentional pivoting — taught exclusively for lab use and authorized engagements. Build GOAD or similar before applying techniques on client networks.

Open module
3 lessons18 sections~200 min5 outcomes
08

Privilege Escalation & Post-Exploitation

Advanced

Foothold is the beginning, not the trophy.

Linux and Windows privilege escalation methodology, situational awareness, credential harvesting concepts, and controlled post-exploitation that supports objectives without chaos. Authorized labs and scoped engagements only.

Open module
2 lessons12 sections~140 min5 outcomes
09

Cloud, Containers & Modern Surfaces

Advanced

The perimeter is an IAM policy and a misconfigured role.

Modern estates live in shared responsibility models: cloud control planes, object storage, serverless, and Kubernetes clusters. This module teaches how operators map cloud attack surfaces, abuse common identity and configuration failures, and assess containers and orchestrators without treating them as magic black boxes. Every technique assumes authorized lab or client scope only.

Open module
2 lessons12 sections~135 min5 outcomes
10

Wireless & Adjacent Surfaces

Advanced

RF is real-world scope: own the network or do not touch the air.

Wireless assessments demand strict authorization, careful RF hygiene, and deep understanding of 802.11 authentication, encryption, and client behavior. This module covers lab-only Wi-Fi attack learning paths, evidence standards, and home/AP hardening plus operator OPSEC so you never confuse “interesting signal” with legal permission. Practice only on networks and hardware you own or are explicitly contracted to test.

Open module
2 lessons12 sections~125 min5 outcomes
11

Reporting, Risk & Professional Practice

Professional

If the report is weak, the exploit did not matter.

Clients buy risk reduction and decision-quality narratives, not shell trophies. This module trains you to write findings that survive scrutiny, rate severity with context, structure methodologies that are repeatable, and operate as a professional who can retest, debrief, and protect client data. Strong reporting is a technical skill equal to exploitation.

Open module
2 lessons12 sections~125 min5 outcomes
12

Purple Team & Defensive Awareness

Professional

The best operators know how their attacks look from the other chair.

Purple teaming closes the loop between offensive proof and defensive improvement. This module teaches you to view your own techniques through telemetry, collaborate without ego, and build basic detection-engineering habits using logs, rules, and lab environments. The goal is not to become a full-time SOC analyst overnight — it is to make every offensive finding more valuable by pairing it with visibility and response insight.

Open module
2 lessons12 sections~125 min5 outcomes