SPECTER
Recon & Initial Access. Four sub-tracks, ~40 levels, ephemeral per-session containers from day one. Specter I is live; II, III, and IV ship in order.
Where operatives stop reading about attacks and start performing them — reconnaissance and initial access, from the open web to the wire, the airwaves, and the human in front of the screen.
Each sub-track is independent — take them in order or specialise. Specter I is live; II–IV follow.
Sub-tracks
Passive intelligence gathering at professional grade. Multi-engine pivots, source independence, OPSEC discipline, adversarial targets. The only OSINT track that grades operational tradecraft alongside collection.
Enter →Infrastructure warfare — initial access through the wire and the air. Switched-LAN recon, LLMNR/NBT-NS poisoning and MITM, NAC bypass, AD CS ESC8 coercion, WPA2 keyspace economics, enterprise evil-twin PEAP, WPA3 client isolation, and a relay-plus-Bluetooth capstone.
Enter →Both sides of the line. DDoS attack and defence, firewall bypass, IDS signature evasion, DNS/HTTPS/ICMP tunneling.
The human attack surface. Pretexting, vishing, baiting, USB drops (Rubber Ducky), targeted elicitation, persona ops. Every target is a scripted mark with its own personality, jargon, security awareness level, and detection cues — you craft pretext, run conversation, exfiltrate intel without tripping the alarm. The only wargame track that actually grades social tradecraft.
New here? Start with Ghost or advance through Phantom.