Skip to contentExploitQuest

The curriculum

Learn

Start anywhere. Threat modelling first is the honest recommendation — everything downstream depends on knowing who you are hiding from. Or follow a path, which is an order to take them in — or start from a scenario if you have a specific worry rather than a subject. If you want one specific thing rather than a course, every chapter is listed on its own.

Courses
11
Lessons
104
Exams
10
Medium6h

Secure Coding

Secure Coding

Not a vulnerability taxonomy. The habits that stop you writing the bug in the first place — parameterised queries, contextual encoding, authorization at the boundary, secrets with no fallbacks — each one taught with the check that enforces it and the incident that caused it to be written.

Expects Web Application Security

  • 8 lessons
  • 5 labs
  • 1 exam
Medium4h

AI Code Security

Secure Coding

You are shipping code you did not write. This is how to review it: the bugs models actually produce, the packages they invent that attackers then register, what happens when a model with tools reads attacker-controlled text, and why the confident, idiomatic, plausible version gets reviewed least carefully.

Expects Secure Coding

  • 5 lessons
  • 1 lab
  • 1 exam