Skip to contentExploitQuest

The curriculum

Learn

Start anywhere. Threat modelling first is the honest recommendation — everything downstream depends on knowing who you are hiding from. Or follow a path, which is an order to take them in — or start from a scenario if you have a specific worry rather than a subject. If you want one specific thing rather than a course, every chapter is listed on its own.

Courses
11
Lessons
104
Exams
10
Foundation1h

Introduction to ExploitQuest

Start here. In three short chapters you will meet everything the platform can do — a real terminal you type into, questions that pay XP, hands-on challenges, and the credential at the end — by using each one, not reading about it.

  • 7 lessons
  • 1 exam
Foundation6h

Anonymity & OpSec

Anonymity & OpSec

Practical self-defence for people who are not security professionals and do not intend to become them. Threat modelling first, tools second — because the tool you need depends entirely on who you are hiding from.

  • 19 lessons
  • 3 labs
  • 1 exam
Foundation4h

The Attacker's Playbook

How people actually get hacked — the whole attack, from the reconnaissance before anyone touches you to the extortion at the end, told as one story through real breaches. Every stage is paired with the thing that stops it, usually early and cheaply.

  • 8 lessons
  • 2 labs
Easy6h

Linux Fundamentals

Linux & Systems

The operating system almost all of the internet runs on, taught from the first command. Free, and the ground every later course stands on.

Expects Introduction to ExploitQuest

  • 12 lessons
  • 3 labs
  • 1 exam
Medium8h

Web Application Security

Web Security

How web applications actually break, and how to stop yours breaking the same way. Every attack is paired with its defence, and every attack is run against something genuinely vulnerable rather than described.

Expects Introduction to ExploitQuest

  • 18 lessons
  • 7 labs
  • 1 exam
Medium6h

VPS & Self-Hosting

Linux & Systems

You deployed something to a server. Now learn to defend it. SSH keys, a firewall that denies by default, fail2ban banning the ones who keep coming back, patching that actually happens, and backups you have really restored — each taught by watching an attack, then stopping it.

Expects Linux Fundamentals

  • 9 lessons
  • 3 labs
  • 1 exam
Medium5h

Digital Forensics & Incident Response

Forensics & IR

Somebody is in your server, or your site is defaced, and the first thing you want to do is the thing that destroys the evidence. This is what to do instead: preserve, find the entry, build the timeline, find what they left to get back in, and answer honestly whether data was taken.

Expects Linux Fundamentals, VPS & Self-Hosting

  • 8 lessons
  • 2 labs
  • 1 exam
Medium6h

Secure Coding

Secure Coding

Not a vulnerability taxonomy. The habits that stop you writing the bug in the first place — parameterised queries, contextual encoding, authorization at the boundary, secrets with no fallbacks — each one taught with the check that enforces it and the incident that caused it to be written.

Expects Web Application Security

  • 8 lessons
  • 5 labs
  • 1 exam
Medium4h

AI Code Security

Secure Coding

You are shipping code you did not write. This is how to review it: the bugs models actually produce, the packages they invent that attackers then register, what happens when a model with tools reads attacker-controlled text, and why the confident, idiomatic, plausible version gets reviewed least carefully.

Expects Secure Coding

  • 5 lessons
  • 1 lab
  • 1 exam
Easy4h

Reconnaissance

Network Security

The four tools every assessment starts with, one module each. What each one actually asks, how to read its output rather than memorise its flags, and — for every one of them — what the scan looks like from the other end.

Expects Linux Fundamentals

  • 6 lessons
  • 1 exam
Medium4h

Cracking & Brute Force

Network Security

How passwords actually fall — offline against a stolen hash at a hundred billion guesses a second, online against a live login at four. Which hashes crack instantly and which never do, why the difference is the algorithm rather than the password, and what genuinely stops each attack.

Expects Linux Fundamentals

  • 4 lessons
  • 1 exam