Tracks Curriculum
Operational offense syllabus — explore core concepts, preview challenge nodes, and infiltrate real servers.
Linux and shell fundamentals. Navigation, permissions, processes, encoding, network, SSH keys, port scanning, cron, git forensics, /proc. Where every operator starts.
Post-exploitation — the full chain. SUID, sudo, capabilities, kernel CVEs, credential harvesting, persistence, defense evasion, lateral movement, container escape, Kubernetes takeover, cloud pivot.
Recon & initial access — how you get in. A four-part series: OSINT, network & wireless, defence evasion & disruption, and social engineering. Specter I (OSINT, 14 levels) and Specter II (network & wireless, eight levels) are live; III–IV are planned.
Web application exploitation, in two parts. Mirage I — the full ladder from recon to AI, 41 browser targets: client trust, broken access control, BaaS/RLS, auth & tokens, the injection family, XSS, SSRF, deserialization, GraphQL, and AI/LLM attacks. Mirage II — the advanced sequel, 12 targets: cache deception, request smuggling, parser desync, HTTP/2 downgrade, single-packet races, and deserialization RCE.
Cryptography and password attacks. Hash cracking, TLS exploitation, padding oracle, RSA vulnerabilities, JWT forgery, credential stuffing.
CI/CD and supply chain. Git secrets, pipeline poisoning, dependency confusion, container registry attacks, IaC exploitation.
AI/LLM security. Prompt injection, jailbreaking, data exfiltration through LLMs, agent exploitation, RAG poisoning, model attacks.
Windows and Active Directory. PowerShell, token impersonation, Kerberoasting, pass-the-hash, DCSync, Golden Ticket, AMSI bypass, GPO abuse.
Anonymity, OPSEC, and darknet. Tor, VPN chains, anonymous communications, cryptocurrency privacy, counter-forensics, attribution resistance.
Blue team — the full SOC-to-DFIR arc. Log analysis & SIEM hunting, alert triage, incident response, endpoint & Windows forensics, memory & disk DFIR, malware analysis, network detection, threat hunting, CTI & attribution, detection engineering (Sigma/YARA/Suricata), cloud & identity detection, and detection-driven hardening. A purple-team through-line has you detect the exact TTPs you attacked in Ghost, Phantom, Mirage and Specter.
Apple security. macOS SIP/TCC/Gatekeeper bypass, Keychain extraction, iOS jailbreak fundamentals, app analysis, AirDrop exploitation.
Red team operations. C2 frameworks, implant development, payload delivery, infrastructure setup, EDR bypass, campaign planning, purple teaming.
Binary exploitation and reverse engineering. Stack overflow, ROP, heap, shellcoding, mitigation bypass, malware RE, firmware analysis, exploit development.