Security, taught by doing
Learn to disappear. Learn to break things. Ethically.
How people get found online and how to stay private. How attacks actually work, and how to run them yourself — in a sandbox built for it, never on anyone else. Read a lesson, practise in a real shell, solve a lab, then sit an exam and earn a credential anyone can verify.
A real shell — type help, or ls. More at Practice.
- No account needed to read anything
- No email address, at any tier
- No tracking, so no cookie banner
How it works
Learn
Lessons that talk to you — a mentor, a learner asking the questions you would ask, and real terminal output beside the explanation. Not a reference page you skim once and close.
Browse the courses →02Practise
A real shell in your browser, and hands-on labs where the flag is generated for you alone — so a shared answer is simply wrong, and solving it means you solved it.
See the labs →03Prove
A timed exam, one question at a time, no going back. Pass and you get a signed credential that anyone can verify — without an account, and without us telling them anything else about you.
What the exam covers →Where to start
Introduction to ExploitQuest
Start here. In three short chapters you will meet everything the platform can do — a real terminal you type into, questions that pay XP, hands-on challenges, and the credential at the end — by using each one, not reading about it.
Anonymity & OpSec
Practical self-defence for people who are not security professionals and do not intend to become them. Threat modelling first, tools second — because the tool you need depends entirely on who you are hiding from.
The Attacker's Playbook
How people actually get hacked — the whole attack, from the reconnaissance before anyone touches you to the extortion at the end, told as one story through real breaches. Every stage is paired with the thing that stops it, usually early and cheaply.
Linux Fundamentals
The operating system almost all of the internet runs on, taught from the first command. Free, and the ground every later course stands on.
Web Application Security
How web applications actually break, and how to stop yours breaking the same way. Every attack is paired with its defence, and every attack is run against something genuinely vulnerable rather than described.
VPS & Self-Hosting
You deployed something to a server. Now learn to defend it. SSH keys, a firewall that denies by default, fail2ban banning the ones who keep coming back, patching that actually happens, and backups you have really restored — each taught by watching an attack, then stopping it.
Digital Forensics & Incident Response
Somebody is in your server, or your site is defaced, and the first thing you want to do is the thing that destroys the evidence. This is what to do instead: preserve, find the entry, build the timeline, find what they left to get back in, and answer honestly whether data was taken.
Secure Coding
Not a vulnerability taxonomy. The habits that stop you writing the bug in the first place — parameterised queries, contextual encoding, authorization at the boundary, secrets with no fallbacks — each one taught with the check that enforces it and the incident that caused it to be written.
AI Code Security
You are shipping code you did not write. This is how to review it: the bugs models actually produce, the packages they invent that attackers then register, what happens when a model with tools reads attacker-controlled text, and why the confident, idiomatic, plausible version gets reviewed least carefully.
Reconnaissance
The four tools every assessment starts with, one module each. What each one actually asks, how to read its output rather than memorise its flags, and — for every one of them — what the scan looks like from the other end.
Cracking & Brute Force
How passwords actually fall — offline against a stolen hash at a hundred billion guesses a second, online against a live login at four. Which hashes crack instantly and which never do, why the difference is the algorithm rather than the password, and what genuinely stops each attack.
Why this is different
Attack, then defend
You cannot defend against something you have never seen, so lessons show how the attack works before the countermeasure — in a sandbox, with the rules stated, and never pointed at anyone who did not ask for it.
Threat modelling first
Hiding from an advertiser and hiding from an abusive ex are different problems with different answers. Almost every guide skips this, which is why people buy things that do not help.
Nothing is for sale but access
No affiliate links in any lesson. When we score a tool, the rubric is published and you can run it yourself.