Skip to content

Curriculum

27 modules in 5 tracks, roughly 47 hours of contact time, ordered so each one depends only on the ones before it. Every module is the same five things: a lesson that explains the technique, the tools that perform it, real challenges to practise on, a checkpoint you can actually grade, and the chapters to read if you want the subject rather than the answer - each one linked to our notes on that book.

Teaching this? The instructor page has the module outlines, the checkpoints, and the paragraph your IT department will ask for. Mid-challenge rather than mid-course? The decision guide skips the ordering and starts from the symptom.

Foundations

Triage, encodings, statistics and the habits every other track assumes.

  1. Foundation60 min10 tools59 challenges

    1. Recognising encodings

    Tell Base64 from hex from Base32 from binary on sight, peel layered encodings, and learn why an encoding is not encryption.

    Open module
  2. Foundation90 min13 tools24 challenges

    2. Classical ciphers and frequency analysis

    Break Caesar, Vigenere, and arbitrary substitution using letter statistics - and learn why statistics beat guessing.

    Open module
  3. Foundation60 min5 tools17 challenges

    3. Hashes, identification and cracking

    Identify a digest by shape, understand why hashing is one-way, and learn where wordlist cracking works and where it is a trap.

    Open module
  4. Foundation90 min6 tools37 challenges

    4. Reconnaissance and OSINT

    Treat open-source intelligence as a pivot loop rather than a search, and know what metadata survives which route.

    Open module
  5. Foundation90 min7 tools33 challenges

    5. Misc, esolangs and prompt injection

    The category you cannot prepare for by learning a technique - so prepare the triage instead, and learn to identify a dozen shapes on sight.

    Open module

Cryptography

Not the primitives - the ways they are wired up wrong: reused keys, weak parameters, leaking oracles.

  1. Core90 min5 tools27 challenges

    6. XOR and the cost of reusing a key

    Break single-byte and repeating-key XOR, then recover both plaintexts from a reused one-time pad by crib dragging.

    Open module
  2. Core120 min6 tools19 challenges

    7. Block ciphers, modes and oracles

    AES is not the target. ECB's repeated blocks, CBC's malleability, a padding oracle, a reused GCM nonce, and a predictable PRNG all are.

    Open module
  3. Core120 min7 tools32 challenges

    8. RSA and the parameters that break it

    Work the RSA decision tree - small modulus, close primes, tiny exponent, shared modulus - and learn to read a key for its weakness.

    Open module
  4. Advanced120 min6 tools9 challenges

    9. Discrete logs, Diffie-Hellman and elliptic curves

    The other half of public-key crypto: weak groups, small subgroups, invalid curves, and the nonce that leaks a signing key.

    Open module

Web and applications

From finding the endpoint nobody linked to, through injection and the browser's trust model, to code running on the server.

  1. Core90 min6 tools46 challenges

    10. Web recon and attack surface

    Find the endpoint the challenge is really about: unlinked paths, JavaScript-only routes, exposed .git, and the parameters nobody documented.

    Open module
  2. Core120 min5 tools23 challenges

    11. Injection: SQL and everything after it

    One bug class, five parsers. Break out of a SQL string, a shell argument, an XML document, a NoSQL query and an LDAP filter, and read the response for confirmation.

    Open module
  3. Core90 min5 tools35 challenges

    12. Client-side: XSS and the browser's trust model

    Get your JavaScript to run in someone else's page, past a CSP and an admin bot - and see why polluting a prototype changes every object in the process.

    Open module
  4. Core120 min6 tools19 challenges

    13. Sessions, tokens and access control

    Read and forge JWTs and Flask sessions, break the assumptions behind a session cookie, and win the races that a request boundary creates.

    Open module
  5. Advanced120 min6 tools14 challenges

    14. Server-side takeover: from input to execution

    SSRF, template injection, path traversal, file upload and deserialization - five routes from a parameter you control to code running on the server.

    Open module
  6. Core90 min6 tools19 challenges

    15. APIs, GraphQL and application logic

    The bugs that live between endpoints rather than inside one: object references, mass assignment, over-broad queries, and workflows that can be run out of order.

    Open module

Forensics and defence

Files, captures, memory images and malware - reading what happened out of what was left behind.

  1. Core90 min10 tools45 challenges

    16. File forensics and carving

    Identify files by their bytes, find data appended past a format's end marker, and pull evidence out of images, archives and documents.

    Open module
  2. Core90 min8 tools32 challenges

    17. Steganography

    Sweep an image, audio file, or paragraph for hidden data across the whole technique space rather than guessing one method.

    Open module
  3. Advanced90 min12 tools20 challenges

    18. Network forensics

    Triage a packet capture: find the one conversation that matters, extract transferred files, and spot exfiltration over DNS.

    Open module
  4. Advanced120 min5 tools26 challenges

    19. Memory and disk forensics

    Answer the three questions a memory image is asked - what was running, what was typed, what was on disk - and know why a scan beats a list.

    Open module
  5. Advanced120 min6 tools9 challenges

    20. Malware triage and defensive telemetry

    Sort a pile of samples by similarity, defeat the tricks that stop them being analysed, and read the logs and telemetry that catch them.

    Open module

Reversing and exploitation

Binaries, mobile apps, firmware and contracts: what the code really does, and what it does when you break it.

  1. Core120 min8 tools101 challenges

    21. Reverse engineering

    Get from an unknown executable to the one function that decides whether your input is right, and recognise which of four shapes the check takes.

    Open module
  2. Core120 min5 tools23 challenges

    22. Mobile applications

    Take an APK apart: the manifest rules that define the attack surface, navigating DEX without decompiling it, and when to stop reading and hook.

    Open module
  3. Advanced120 min7 tools16 challenges

    23. Firmware, hardware and signals

    Find the filesystem inside a firmware blob, read a debug interface off a board, and decode a captured signal back into bytes.

    Open module
  4. Advanced150 min11 tools66 challenges

    24. Binary exploitation

    Read a binary's protections, find an overflow offset in one crash, and build a ROP chain when the stack is not executable.

    Open module
  5. Advanced120 min5 tools21 challenges

    25. Fuzzing and crash triage

    Stop reading for the bug and make the crash come to you - then work out which crashes are the same bug and which one is exploitable.

    Open module
  6. Advanced90 min5 tools32 challenges

    26. After the shell: privilege escalation

    A shell is the middle of the challenge. Enumerate systematically, recognise the misconfiguration classes, and know what a Windows token actually grants.

    Open module
  7. Advanced90 min4 tools5 challenges

    27. Smart contracts and the EVM

    Public code, public state, and an execution model where a callback in the middle of your function is a normal event.

    Open module