Reconnaissance
The four tools every assessment starts with, one module each. What each one actually asks, how to read its output rather than memorise its flags, and — for every one of them — what the scan looks like from the other end.
Not yet reviewed
Before you start
- Linux Fundamentalsabout 6h
This course expects those first. Nothing is locked — sign in and it will say where you stand.
Host discovery, port states, and what "filtered" actually means.
- Attack
- Telemetry
- Fix
- Detection
2 lessons · 1 hands-on · 3 min
Record types, delegation, and what a zone gives away for free.
One-sided — A DNS query is answered by a resolver, and the target's own servers may never see it. There is nothing reliable to detect, and saying so is more useful than a telemetry beat that would not fire.
1 lesson · 1 hands-on · 2 min
What a registry holds, how stale it is, and why it is not the machine.
One-sided — A whois lookup queries a registry, not the target. There is nothing in the target's logs to detect and nothing for it to defend — which is exactly what makes it the first thing an attacker does, and is worth saying rather than inventing a defensive beat for.
1 lesson · 1 hands-on · 3 min
Content discovery, filtering by response, and why the interesting result is the anomaly.
- Attack
- Telemetry
- Fix
- Detection
2 lessons · 1 hands-on · 5 min
Exam
Timed, and it issues a credential anyone can verify. Practice quizzes are untimed; this one is not.