Every subject, on its own
Chapters
A chapter is one subject, taught properly, in about half an hour. If you came here to learn a specific thing rather than to take a whole course, start here — every one is readable without an account.
60 chapters across 11 courses
What This Is
The promise the platform makes, and how a lesson actually works.
Foundation3 lessons · 6 minThe Shell Is Real
Not a screenshot of a terminal — a terminal. Watch one, build a command, then do it yourself.
Foundation2 lessons · 3 minEarning Your Place
XP, streaks and shields, and the labs, exams and signed credential the whole platform builds toward.
Foundation2 lessons · 4 minFoundations
The question every other decision depends on, and the vocabulary to answer it honestly.
Anonymity & OpSec · Anonymity & OpSec
Foundation4 lessons · 16 minWho Is Actually Attacking You
"Hackers" is not one thing. An automated scanner, a ransomware crew and a nation-state want different things, can do wildly different things, and are stopped by wildly different things. Knowing which one is aimed at you is where every sensible decision starts.
Foundation1 lesson · 4 minReconnaissance
Before anyone touches your systems, they read. Attackers assemble a picture of you from what is already public — your domains, your staff, your leaked passwords, the metadata in your own documents — and most of it, you gave away without noticing.
Foundation1 lesson · 3 minThe Browser
The single application that leaks the most about you, and the handful of choices that decide how much.
Anonymity & OpSec · Anonymity & OpSec
Foundation4 lessons · 16 minAccounts & Identity
How people are actually found — not by broken encryption, but by the account they forgot and the password they reused.
Anonymity & OpSec · Anonymity & OpSec
Foundation4 lessons · 13 minInitial Access
The way in is almost never the dramatic one. Ranked by how often each actually starts a breach, the front doors are a phished click, a reused password, an unpatched box, and a trusted supplier — in roughly that order, which is not the order the films taught you.
Foundation1 lesson · 4 minPersistence
Getting in is the expensive part, so a serious attacker makes sure they never have to do it again. Persistence is the quiet business of leaving a way back — a new account, a scheduled task, a stolen token — that survives a reboot, a password change, and often the clean-up itself.
Foundation1 lesson · 3 minPrivate Messaging
The most practical privacy decision most people make daily — which app carries their conversations, and what "encrypted" actually buys them.
Anonymity & OpSec · Anonymity & OpSec
Foundation3 lessons · 12 minPrivilege Escalation
Attackers rarely land where they want to be. They land as a nobody — a single low-privilege account — and climb. Privilege escalation is that climb, and it usually runs on the things a tired administrator left lying around, not on a clever exploit.
Foundation1 lesson · 3 minThe Bug Between Two Features
A real forum, two features that both worked exactly as designed, and a person who became locatable.
Anonymity & OpSec · Anonymity & OpSec
Foundation4 lessons · 10 minLateral Movement
One compromised laptop is not one compromised laptop. It is a place to stand while reaching for the next machine, and the next, until the attacker holds the whole network. Lateral movement is why a small foothold becomes an organisation-wide emergency.
Foundation1 lesson · 3 minExfiltration And Extortion
The end of the story is where the attacker gets paid. They take the data out, and then they turn it into leverage — sold, ransomed, or held over you with the threat of a leak. Understanding the payday is how you make yourself a bad investment.
Foundation1 lesson · 3 minThe Whole Chain, Defended
Walk back through the whole attack and something hopeful appears: the attacker had to win every round, and you only have to win one. The links break earliest and cheapest near the start — which is where a handful of ordinary habits stop most of the story before it begins.
Foundation1 lesson · 4 minThe Terminal
The text prompt that looks intimidating and turns out to be the most honest interface a computer has.
Linux Fundamentals · Linux & Systems
Easy3 lessons · 10 minPipes and Filters
The idea that makes the command line more than a list of commands — small tools that each do one thing, joined into something none of them could do alone.
Linux Fundamentals · Linux & Systems
Easy3 lessons · 12 minPermissions
Who is allowed to read, change, or run each file — the model that keeps a multi-user system from being a free-for-all, and the power that comes with root.
Linux Fundamentals · Linux & Systems
Easy3 lessons · 12 minProcesses
Everything the computer is doing right now is a process. Seeing them, and starting and stopping them deliberately, is the last piece of a working footing.
Linux Fundamentals · Linux & Systems
Easy3 lessons · 11 minSQL Injection
The bug that comes from building a query out of string pieces. Where it comes from, what it lets somebody do, and the one-line habit that ends it.
Web Application Security · Web Security
Medium6 lessons · 15 minBroken Access Control
The application checks that you are logged in and forgets to check that the thing you asked for is yours. Where that gap comes from, what it hands over, and the check that has to happen on every object, every time.
Web Application Security · Web Security
Medium3 lessons · 8 minPath Traversal
A filename is a path, and a path can climb. When an application builds a file path out of something you typed, `..` walks it out of the folder it was meant to stay in — and reads whatever the process can.
Web Application Security · Web Security
Medium3 lessons · 6 minBroken Authentication
A session token is only as strong as the check that verifies it. When the verifier accepts a token that declares its own signature unnecessary, anyone can write themselves a token that says whatever they like.
Web Application Security · Web Security
Medium3 lessons · 7 minCross-Site Scripting
The other four bugs let you break the server. This one lets you run code in somebody else's browser, with their session, from a value the page rendered without escaping it. A comment field becomes a way to become the moderator.
Web Application Security · Web Security
Medium3 lessons · 9 minThe First Box
The minute a server has a public address, it is being tried — not by someone who chose you, but by machines trying everyone. The first hour of a box is about closing the doors those machines rattle: a real user, a key instead of a password, and an SSH daemon told to stop accepting the easy way in.
VPS & Self-Hosting · Linux & Systems
Medium1 lesson · 3 minDefault Deny
A firewall you can trust is one that blocks everything and then opens only the doors you can name out loud. The dangerous port is never the one you meant to open — it is the database, the admin panel, the debug server you forgot was listening.
VPS & Self-Hosting · Linux & Systems
Medium1 lesson · 3 minThe Ones Who Come Back
You cannot stop the internet from knocking, but you can make it expensive. A few failed logins is noise; the same address failing a hundred times is an attacker, and fail2ban reads that in the log and shuts the door on them — for an hour, and for the ones who keep coming back, for weeks.
VPS & Self-Hosting · Linux & Systems
Medium3 lessons · 6 minPatching That Happens
The vulnerability that takes your box is almost never a new one — it is an old, known, already-patched one that nobody applied. Patching that depends on you remembering is patching that does not happen, so you make it automatic, and you make sure it finishes the job by rebooting.
VPS & Self-Hosting · Linux & Systems
Medium1 lesson · 2 minThe Edge And Its Secrets
Two ways a well-run box gives itself away: a reverse proxy that leaks the real server behind it, and a secrets file sitting in the one place every scanner looks. Both are small, both are common, and both are closed by knowing where the edge of your box actually is.
VPS & Self-Hosting · Linux & Systems
Medium1 lesson · 3 minRestore, Then Watch
A backup you have never restored is a hope, not a backup — the restore is the exercise, not the copy. And a box nobody watches is one where the bad day is discovered by a customer. Both are about the day something goes wrong, prepared for on a day it has not.
VPS & Self-Hosting · Linux & Systems
Medium1 lesson · 3 minLocked Out
Everything at once, on a box that is being scanned as you work. The log fills with attempts; you close the doors one by one; and by the end the same stream of attackers is hitting a box that has nothing left to give them. Graded on what the box is, not what you remember.
VPS & Self-Hosting · Linux & Systems
Medium1 lesson · 2 minDo Not Destroy the Evidence
The first thing you want to do is the thing that makes the rest impossible.
Digital Forensics & Incident Response · Forensics & IR
Medium2 lessons · 7 minThe First Hour
Is it still happening, what is exposed, and what comes down before anything else.
Digital Forensics & Incident Response · Forensics & IR
Medium1 lesson · 3 minThe One Request That Worked
Finding the single line that mattered among a million that did not.
Digital Forensics & Incident Response · Forensics & IR
Medium1 lesson · 2 minBuilding the Timeline
When it started, what happened in order, and what has been cleaned.
Digital Forensics & Incident Response · Forensics & IR
Medium1 lesson · 3 minWhere They Hid To Come Back
Cleaning the defacement and not the persistence means it happens again on Thursday.
Digital Forensics & Incident Response · Forensics & IR
Medium1 lesson · 3 minWas Data Taken
The hardest question, and how to answer it honestly rather than reassuringly.
Digital Forensics & Incident Response · Forensics & IR
Medium1 lesson · 3 minGetting Back, and Writing It Down
Which backup is safe, what to rebuild rather than clean, and the report that is the actual deliverable.
Digital Forensics & Incident Response · Forensics & IR
Medium1 lesson · 3 minNever Build a Query as a String
The one rule with no exceptions, and why every escaping-by-hand approach has failed.
Secure Coding · Secure Coding
Medium1 lesson · 3 minEncoding Is Contextual
HTML, attribute, JavaScript and URL are four different problems with four different answers.
Secure Coding · Secure Coding
Medium1 lesson · 3 minAuthorization at the Boundary
Decided in one place, never in the interface. A hidden button is not an access control.
Secure Coding · Secure Coding
Medium1 lesson · 3 minSecrets Have No Fallbacks
A default secret is the same as no secret, and it is the one that ships.
Secure Coding · Secure Coding
Medium1 lesson · 3 minThe Packages You Did Not Choose
Lockfiles, audits, typosquats, and the transitive dependency nobody read.
Secure Coding · Secure Coding
Medium1 lesson · 2 minCryptography You Should Not Write
Passwords, comparisons, and the difference between an identifier and a secret.
Secure Coding · Secure Coding
Medium1 lesson · 3 minWhat Your Errors and Uploads Give Away
What the user sees against what the log holds, and why a filename is not a name.
Secure Coding · Secure Coding
Medium1 lesson · 3 minReading Your Own Code
What to look for, in what order, and why rate limiting is a security control.
Secure Coding · Secure Coding
Medium1 lesson · 3 minReviewing Code You Did Not Write
What to check first, and why "it passes the tests" is the weakest signal you have.
AI Code Security · Secure Coding
Medium1 lesson · 3 minThe Package That Was Never Real
Models invent package names. Attackers read the same models and register them.
AI Code Security · Secure Coding
Medium1 lesson · 3 minWhen the Model Has Tools
Injection stops being a text problem the moment the reader can act.
AI Code Security · Secure Coding
Medium1 lesson · 3 minWhat You Pasted Into the Box
A context window is a place your secrets can go, and it is not one you control.
AI Code Security · Secure Coding
Medium1 lesson · 3 minThe Confident Wrong Answer
Plausible, idiomatic, subtly broken — and reviewed less carefully because it looks good.
AI Code Security · Secure Coding
Medium1 lesson · 3 minnmap
Host discovery, port states, and what "filtered" actually means.
Reconnaissance · Network Security
Easy2 lessons · 3 min- Easy1 lesson · 2 min
whois
What a registry holds, how stale it is, and why it is not the machine.
Reconnaissance · Network Security
Easy1 lesson · 3 minffuf
Content discovery, filtering by response, and why the interesting result is the anomaly.
Reconnaissance · Network Security
Easy2 lessons · 5 minhashcat
Offline cracking against a stolen hash, and why the algorithm decides everything.
Cracking & Brute Force · Network Security
Medium1 lesson · 2 minjohn
When a tiny list built from the account beats a million generic words.
Cracking & Brute Force · Network Security
Medium1 lesson · 2 minhydra
Online brute force, and why it is mostly a way to get rate-limited.
Cracking & Brute Force · Network Security
Medium1 lesson · 2 minWhat Actually Stops Them
A memory-hard hash, rate limiting on both axes, and a constant-time comparison.
Cracking & Brute Force · Network Security
Medium1 lesson · 3 min