The curriculum
Learn
Start anywhere. Threat modelling first is the honest recommendation — everything downstream depends on knowing who you are hiding from. Or follow a path, which is an order to take them in — or start from a scenario if you have a specific worry rather than a subject. If you want one specific thing rather than a course, every chapter is listed on its own.
- Courses
- 11
- Lessons
- 104
- Exams
- 10
Introduction to ExploitQuest
Start here. In three short chapters you will meet everything the platform can do — a real terminal you type into, questions that pay XP, hands-on challenges, and the credential at the end — by using each one, not reading about it.
- 7 lessons
- 1 exam
Anonymity & OpSec
Anonymity & OpSec
Practical self-defence for people who are not security professionals and do not intend to become them. Threat modelling first, tools second — because the tool you need depends entirely on who you are hiding from.
- 19 lessons
- 3 labs
- 1 exam
The Attacker's Playbook
How people actually get hacked — the whole attack, from the reconnaissance before anyone touches you to the extortion at the end, told as one story through real breaches. Every stage is paired with the thing that stops it, usually early and cheaply.
- 8 lessons
- 2 labs
Linux Fundamentals
Linux & Systems
The operating system almost all of the internet runs on, taught from the first command. Free, and the ground every later course stands on.
Expects Introduction to ExploitQuest
- 12 lessons
- 3 labs
- 1 exam
Web Application Security
Web Security
How web applications actually break, and how to stop yours breaking the same way. Every attack is paired with its defence, and every attack is run against something genuinely vulnerable rather than described.
Expects Introduction to ExploitQuest
- 18 lessons
- 7 labs
- 1 exam
VPS & Self-Hosting
Linux & Systems
You deployed something to a server. Now learn to defend it. SSH keys, a firewall that denies by default, fail2ban banning the ones who keep coming back, patching that actually happens, and backups you have really restored — each taught by watching an attack, then stopping it.
Expects Linux Fundamentals
- 9 lessons
- 3 labs
- 1 exam
Digital Forensics & Incident Response
Forensics & IR
Somebody is in your server, or your site is defaced, and the first thing you want to do is the thing that destroys the evidence. This is what to do instead: preserve, find the entry, build the timeline, find what they left to get back in, and answer honestly whether data was taken.
Expects Linux Fundamentals, VPS & Self-Hosting
- 8 lessons
- 2 labs
- 1 exam
Secure Coding
Secure Coding
Not a vulnerability taxonomy. The habits that stop you writing the bug in the first place — parameterised queries, contextual encoding, authorization at the boundary, secrets with no fallbacks — each one taught with the check that enforces it and the incident that caused it to be written.
Expects Web Application Security
- 8 lessons
- 5 labs
- 1 exam
AI Code Security
Secure Coding
You are shipping code you did not write. This is how to review it: the bugs models actually produce, the packages they invent that attackers then register, what happens when a model with tools reads attacker-controlled text, and why the confident, idiomatic, plausible version gets reviewed least carefully.
Expects Secure Coding
- 5 lessons
- 1 lab
- 1 exam
Reconnaissance
Network Security
The four tools every assessment starts with, one module each. What each one actually asks, how to read its output rather than memorise its flags, and — for every one of them — what the scan looks like from the other end.
Expects Linux Fundamentals
- 6 lessons
- 1 exam
Cracking & Brute Force
Network Security
How passwords actually fall — offline against a stolen hash at a hundred billion guesses a second, online against a live login at four. Which hashes crack instantly and which never do, why the difference is the algorithm rather than the password, and what genuinely stops each attack.
Expects Linux Fundamentals
- 4 lessons
- 1 exam