Section
Track
Difficulty

Showing all 214 pages. Start typing to search their full text.

🧪 Labs 135

Access Control Lists (ACLs)LabMedium🌐 Networking⏱ 65 minutesStandard, extended, and named ACLs for network traffic filtering.Active Directory BasicsLabHard🏰 Infrastructure & AD⏱ 75 minutesAD enumeration with net commands, PowerShell, and LDAP queries.Active Directory LDAP EnumerationLabIntermediate🏰 Infrastructure & AD⏱ 1.5 hoursldapsearch, windapsearch, and manual LDAP queries to map AD structure.Active Directory Trust AttacksLabAdvanced🏰 Infrastructure & AD⏱ 3 hoursSID history injection, foreign principal abuse, and cross-forest attacks.AD Certificate Services (ADCS) AttacksLabAdvanced🏰 Infrastructure & AD⏱ 3 hoursESC1–ESC8 ADCS misconfigurations for certificate-based domain compromise.AD Enumeration with BloodHoundLabIntermediate🏰 Infrastructure & AD⏱ 1.5 hoursSharpHound collection, BloodHound graph analysis, and finding attack paths.AD Enumeration with CrackMapExecLabIntermediate🏰 Infrastructure & AD⏱ 1.5 hoursCME for SMB enumeration, credential testing, and lateral movement.AD Enumeration with PowerViewLabIntermediate🏰 Infrastructure & AD⏱ 1.5 hoursPowerView functions for enumerating users, groups, ACLs, and SPNs.Advanced SQL InjectionLabAdvanced🕸️ Web Security⏱ 3 hoursSecond-order SQLi, stored procedures, and WAF bypass techniques.Advanced XSS & CSRFLabIntermediate🕸️ Web Security⏱ 1.5 hoursXSS chaining, CSP bypass, CSRF token theft, and SameSite attribute bypass.Adversarial AI Evasion Under a Query BudgetLabIntermediate🤖 AI Security⏱ 2.5 hoursEvade a phishing classifier you can train in seconds, but only through the API and only within a query budget — the way a real attacker has to.AI Data & Model Attacks: The Backdoor That Passes Every TestLabIntermediate🤖 AI Security⏱ 2.5 hoursPlant a backdoor in training data, keep clean accuracy at 95%, flip every triggered input, and prove the model passes its tests anyway.AI Lab: EU AI Act Article 50 Transparency in CodeLabAdvanced🤖 AI Security⏱ 2 hours🔒 Free accountSign an asset with c2patool, verify it, tamper with it and watch verification fail — then implement the Article 50(1) chatbot disclosure. Graded on the verification exit code.AI Lab: LLM-Assisted Log and Alert TriageLabIntermediate🤖 AI Security⏱ 3 hours🔒 Free accountRun an LLM over a labelled alert corpus and find out where it helps, where it lies, and what it costs.AI Lab: Model Supply Chain — When torch.load Is Remote Code ExecutionLabIntermediate🤖 AI Security⏱ 3 hours🔒 Free accountA downloaded model file can own your machine on load. Prove it safely, then build the scan-and-refuse controls that stop it — and load only what you trust.AI Lab: Satisfy a NIST RMF MEASURE Subcategory with garakLabAdvanced🤖 AI Security⏱ 2 hours🔒 Free accountScan llama3.2:1b with garak under Docker Compose, then turn the report into a NIST AI RMF MEASURE 2.7 evidence record. Graded on the artefact and the metric being in range.AI Lab: Securing a RAG PipelineLabIntermediate🤖 AI Security⏱ 4 hours🔒 Free accountBuild a RAG stack on CPU, break it four ways, then drive the hidden attack tests from fail to pass.AI Lab: Unbounded ConsumptionLabIntermediate🤖 AI Security⏱ 3 hours🔒 Free accountTurn a summarisation pipeline into a cost bomb, then defuse it with four controls and re-plot the curve.AI-Augmented Penetration TestingLabAdvanced🤖 AI Security⏱ 2 hoursAI as the tester's tool: four genuine accelerants, the boundaries you never cross, and a graded checker that catches fabricated findings.Android Dynamic AnalysisLabIntermediate📱 Mobile⏱ 1.5 hoursFrida hooking, SSL unpinning, and runtime method tracing on Android.Android Malware AnalysisLabAdvanced📱 Mobile⏱ 3 hoursAnalyse an Android malware sample: C2 extraction, permissions, and indicators.Android Static AnalysisLabIntermediate📱 Mobile⏱ 1.5 hoursAPK decompilation, manifest review, jadx, and secret extraction.API & Web Service AttacksLabIntermediate🕸️ Web Security⏱ 1.5 hoursREST API enumeration, BOLA, mass assignment, and API-specific fuzzing.Application Whitelisting BypassLabAdvanced🏰 Infrastructure & AD⏱ 3 hoursAppLocker rule bypass via trusted paths, DLL side-loading, and COM objects.Attacking Authentication MechanismsLabIntermediate🕸️ Web Security⏱ 1.5 hours2FA bypass, brute force protection bypass, and credential stuffing.Attacking Enterprise NetworksLabIntermediate🏰 Infrastructure & AD⏱ 1.5 hoursFull attack chain from external foothold to domain admin in a lab network.Attacking GraphQLLabIntermediate🕸️ Web Security⏱ 1.5 hoursIntrospection abuse, batching attacks, and GraphQL injection.Attacking WPA3 NetworksLabIntermediate📡 Wireless⏱ 1.5 hoursDragonblood side-channel attacks and WPA3 transition mode weaknesses.Blind SQL InjectionLabAdvanced🕸️ Web Security⏱ 3 hoursBoolean-based and time-based blind SQLi with sqlmap and manual methods.Broken Authentication & SessionsLabIntermediate🕸️ Web Security⏱ 1.5 hoursSession fixation, prediction, and authentication logic flaws.Buffer Overflow BasicsLabHard💣 Exploit Dev⏱ 90 minutesClassic stack overflow: control EIP/RIP, find bad chars, and deliver shellcode.Burp Suite BasicsLabEasy🕸️ Web Security⏱ 45 minutesIntercept, modify, and replay HTTP requests using Burp Suite Community Edition.Bypassing Wi-Fi Captive PortalsLabIntermediate📡 Wireless⏱ 1.5 hoursMAC spoofing, DNS tunnelling, and other captive portal evasion techniques.Cloud AWS EnumerationLabIntermediate☁️ Cloud⏱ 2 hoursEnumerate AWS with compromised keys: IAM, S3, EC2, Lambda, and Secrets Manager.Command & Control with SliverLabAdvanced🏰 Infrastructure & AD⏱ 3 hoursDeploy and operate the Sliver C2 framework for red team engagements.Command InjectionLabMedium🕸️ Web Security⏱ 45 minutesOS command injection via semicolons, pipes, and backticks with filter bypass.Cracking WPA/WPA2 NetworksLabIntermediate📡 Wireless⏱ 1.5 hoursCapture 4-way handshake and crack with hashcat GPU-accelerated wordlists.Cross-Site Scripting (XSS)LabMedium🕸️ Web Security⏱ 70 minutesReflected, stored, and DOM-based XSS with cookie theft and keylogger payloads.DACL Attacks in Active DirectoryLabAdvanced🏰 Infrastructure & AD⏱ 3 hoursGenericAll, WriteDACL, GenericWrite, and AddMember for privesc.DHCP Configuration LabLabEasy🌐 Networking⏱ 40 minutesCisco IOS DHCP server and relay agent configuration.DNS Enumeration with PythonLabIntermediate🚀 Zero to Hacker⏱ 1.5 hoursBuild a DNS reconnaissance tool from scratch in Python.Docker Container EscapeLabAdvanced☁️ Cloud⏱ 2.5 hoursSocket abuse, privileged mode, CAP_SYS_ADMIN cgroup escape, and runc CVE.Dynamic Malware Analysis with WinDbgLabAdvanced💣 Exploit Dev⏱ 3 hoursDynamic binary analysis with WinDBG, setting breakpoints, and inspecting memory.Egghunters & Custom ShellcodingLabAdvanced💣 Exploit Dev⏱ 3 hoursEgghunter technique for small buffer spaces and custom shellcode writing.EIGRP Routing LabLabMedium🌐 Networking⏱ 60 minutesConfigure and verify EIGRP routing including neighbour adjacency and metrics.Excessive AgencyLabIntermediate🤖 AI Security⏱ 2 hours🔒 Free accountExploit an agent with an unrestricted shell tool, then add an allowlist and approval gate and prove the same attack now fails. Before/after transcript grading.File TransfersLabBeginner🚀 Zero to Hacker⏱ 45 minutesMove files between machines using HTTP, FTP, SCP, SMB, and base64 encoding.File Upload VulnerabilitiesLabMedium🕸️ Web Security⏱ 55 minutesBypass extension filters, MIME type checks, and upload webshells.Format String VulnerabilitiesLabAdvanced💣 Exploit Dev⏱ 2.5 hoursRead stack memory, leak canaries, and perform arbitrary writes with %n.Game Hacking FundamentalsLabEasy🎮 Game Hacking⏱ 1.5 hoursMemory scanning, value freezing, pointers, and basic code patching against a running game.Game Reversing & ModdingLabIntermediate🎮 Game Hacking⏱ 1.5 hoursByte-array signatures, script persistence, logic reversing, and packaging a simple mod.Hardware & Bluetooth AttacksLabIntermediate📡 Wireless⏱ 1.5 hoursBLE scanning, GATT attribute enumeration, and Bluetooth relay attacks.Hidden Context ExposureLabIntermediate🤖 AI Security⏱ 2 hours🔒 Free accountExtract a decoy API key from a system prompt, then re-architect so the secret is never in context. Flag capture plus a hidden pytest on every context payload.HTML & CSS LabLabBeginner⏱ 3 hoursBuild real webpages from scratch. 15 exercises that take you from basic tags to a complete styled portfolio page — all you need is a text editor and a browser.HTTP Misconfiguration AbuseLabAdvanced🕸️ Web Security⏱ 3 hoursCORS, caching, host header injection, and HTTP/2 downgrade attacks.HTTP Request SmugglingLabAdvanced🕸️ Web Security⏱ 3 hoursCL.TE and TE.CL desync attacks to bypass front-end security controls.Hydra Brute ForceLabEasy🚀 Zero to Hacker⏱ 40 minutesOnline password attacks against SSH, FTP, HTTP forms, and RDP with Hydra.IDS/IPS Detection EngineeringLabIntermediate🛡️ Defensive⏱ 1.5 hoursSnort/Suricata rule writing, tuning, and evasion-aware detection.Injection Attacks: XPath, LDAP & HTML-to-PDFLabIntermediate🕸️ Web Security⏱ 1.5 hoursExploit XML XPath and LDAP directory injection vulnerabilities.Insecure DeserializationLabAdvanced🕸️ Web Security⏱ 3 hoursJava, PHP, and Python deserialization gadget chains for RCE.Insecure Direct Object References (IDOR)LabEasy🕸️ Web Security⏱ 45 minutesIDOR via predictable IDs, GUIDs, and horizontal vs vertical privilege escalation.Introduction to Binary FuzzingLabAdvanced💣 Exploit Dev⏱ 3 hoursAFL++, libFuzzer, and coverage-guided fuzzing to discover binary vulnerabilities.IP Subnetting MasteryLabMedium🌐 Networking⏱ 90 minutesIP addressing, CIDR notation, and subnet calculation practice.IPv6 Configuration LabLabMedium🌐 Networking⏱ 55 minutesIPv6 addressing, EUI-64, SLAAC, and dual-stack configuration.JavaScript DeobfuscationLabBeginner🕸️ Web Security⏱ 45 minutesUnpack obfuscated JS, extract hidden endpoints, and reverse client-side logic.JavaScript LabLabBeginner⏱ 4 hoursInteractive JavaScript exercises — variables, DOM manipulation, events, arrays, APIs, and 5 browser mini-projects you build from scratch.Kali Linux Environment SetupLabEasy🚀 Zero to Hacker⏱ 30 minutesSet up your Kali VM, configure tools, and prepare your hacking lab environment.Kerberos AttacksLabAdvanced🏰 Infrastructure & AD⏱ 3 hoursKerberoasting, ASREPRoasting, Pass-the-Ticket, and Golden/Silver tickets.Linux ForensicsLabIntermediate🛡️ Defensive⏱ 1.5 hoursDisk acquisition, filesystem timeline, log analysis, and bash history forensics.Linux Privilege EscalationLabHard🚀 Zero to Hacker⏱ 90 minutesLinux and Windows privesc fundamentals using linpeas, winpeas, and manual methods.Linux Process Injection & DetectionLabAdvanced💣 Exploit Dev⏱ 3 hoursptrace-based injection, LD_PRELOAD abuse, and /proc/mem manipulation.LLM Output & Application AttacksLabIntermediate🤖 AI Security⏱ 1.5 hoursInsecure output handling: turn model output into XSS and command injection, then prove the fix blocks it. A two-stage grader script you run locally.Local & Remote File InclusionLabMedium🕸️ Web Security⏱ 60 minutesPath traversal, null byte injection, PHP wrappers, and remote file inclusion.Malicious Document AnalysisLabIntermediate🛡️ Defensive⏱ 1.5 hoursAnalyse malicious Office documents, PDFs, and macros with olevba and remnux.Mapping an Incident to MITRE ATLASLabAdvanced🤖 AI Security⏱ 2 hours🔒 Free accountMap a public AI incident to ATLAS techniques, emit a Navigator layer, render a heat map, and grade it against MITRE's own data.Memory Forensics with VolatilityLabIntermediate🛡️ Defensive⏱ 2 hoursAnalyse infected memory dumps: find malware, C2 IPs, injected code, and creds.Metasploit Framework BasicsLabMedium🚀 Zero to Hacker⏱ 75 minutesmsfconsole, searching modules, setting options, running exploits, and Meterpreter.Modern Web ExploitationLabAdvanced🕸️ Web Security⏱ 3 hoursPrototype pollution, web cache poisoning, and client-side path traversal.MSSQL, Exchange & SCCM AttacksLabAdvanced🏰 Infrastructure & AD⏱ 3 hoursLinked server abuse, MSSQL xp_cmdshell, Exchange privilege escalation.NAT & PAT LabLabMedium🌐 Networking⏱ 55 minutesConfigure static NAT, dynamic NAT, and PAT overload.Netcat FundamentalsLabEasy🚀 Zero to Hacker⏱ 35 minutesNetcat as a network Swiss army knife — listeners, file transfer, reverse shells.Network Scanning with NmapLabEasy🚀 Zero to Hacker⏱ 45 minutesHost discovery, port scanning, service detection, OS fingerprinting, and NSE scripts.NoSQL InjectionLabIntermediate🕸️ Web Security⏱ 1.5 hoursMongoDB operator injection, authentication bypass, and data extraction.NTLM Relay AttacksLabAdvanced🏰 Infrastructure & AD⏱ 3 hoursResponder, NTLMrelayx, and relay chains for credential capture and relay.OAuth & JWT AttacksLabIntermediate🕸️ Web Security⏱ 2 hoursalg:none bypass, RS256→HS256 confusion, JWT cracking, and OAuth code theft.OSINT & Passive ReconnaissanceLabEasy🚀 Zero to Hacker⏱ 50 minutesEnd-to-end passive recon on a target: DNS, WHOIS, Shodan, theHarvester.OSPF Routing LabLabMedium🌐 Networking⏱ 75 minutesOSPF areas, DR/BDR election, and route summarisation.Password Attacks & Credential HuntingLabIntermediate🚀 Zero to Hacker⏱ 1.5 hoursPass-the-Hash, credential dumping with Mimikatz, and password spray techniques.Password Cracking LabLabMedium🚀 Zero to Hacker⏱ 60 minutesCrack NTLM, SHA1, and bcrypt hashes offline using hashcat and John the Ripper.Pivoting, Tunneling & Port ForwardingLabIntermediate🏰 Infrastructure & AD⏱ 1.5 hoursProxychains, SSH tunneling, Chisel, and Ligolo for network pivoting.Port Security LabLabEasy🌐 Networking⏱ 40 minutesConfigure port security, sticky MAC addresses, and violation modes.Process Injection & DetectionLabAdvanced🛡️ Defensive⏱ 3 hoursDetect DLL injection, process hollowing, and reflective injection in EDR logs.Prompt Injection AttacksLabIntermediate🤖 AI Security⏱ 1.5 hoursDirect and indirect prompt injection against a RAG chatbot you build yourself, graded on a canary flag string.Python Coding LabLabBeginner🚀 Zero to Hacker⏱ 3 hoursSocket programming, subprocess, file I/O, and building basic automation tools.Return Oriented Programming (ROP)LabAdvanced💣 Exploit Dev⏱ 3 hoursBypass NX/DEP with ROP gadget chains, ret2libc, and ASLR defeat via info leaks.Reverse ShellsLabMedium🚀 Zero to Hacker⏱ 50 minutesBash, Python, PHP, PowerShell, and Meterpreter reverse shells with netcat handlers.SEH-Based Buffer OverflowsLabAdvanced💣 Exploit Dev⏱ 3 hoursStructured Exception Handler overflow exploitation with POP/POP/RET chains.Server-Side Request Forgery & AttacksLabIntermediate🕸️ Web Security⏱ 1.5 hoursAdvanced SSRF chains, XXE, and server-side prototype pollution.Server-Side Template Injection (SSTI)LabIntermediate🕸️ Web Security⏱ 2 hoursDetect and exploit Jinja2, Twig, and Freemarker SSTI for RCE.Service FootprintingLabIntermediate🚀 Zero to Hacker⏱ 1.5 hoursBanner grabbing and service enumeration across FTP, SSH, SMTP, SMB, and HTTP.SMB EnumerationLabMedium🏰 Infrastructure & AD⏱ 50 minutesEnumerate SMB shares, null sessions, and users with enum4linux and smbclient.SOC Alert Triage with a SIEMLabIntermediate🛡️ Defensive⏱ 1.5 hoursWork a realistic alert queue: classify, investigate, and escalate findings.Spanning Tree Protocol (STP)LabMedium🌐 Networking⏱ 50 minutesSTP operation, root bridge election, and port states.SQL Coding LabLabBeginner⏱ 3 hoursHands-on SQL exercises from basic queries to complex JOINs and aggregations. Work through 20 challenges on a real database schema — no install required.SQL Injection Deep DiveLabMedium🕸️ Web Security⏱ 80 minutesError-based, union-based, and basic SQLi with manual exploitation.SSRF AttacksLabIntermediate🕸️ Web Security⏱ 1.5 hoursInternal service access, cloud metadata exploitation, and SSRF filter bypasses.Static Routing LabLabEasy🌐 Networking⏱ 45 minutesStatic route configuration, floating routes, and troubleshooting.Subdomain TakeoverLabIntermediate🕸️ Web Security⏱ 1.5 hoursEnumerate dangling DNS, claim GitHub Pages and S3 buckets, exploit cookie scope.Supply Chain AttacksLabAdvanced🏰 Infrastructure & AD⏱ 3 hoursBuild process compromise, dependency confusion, and package hijacking.Threat Detection with SplunkLabIntermediate🛡️ Defensive⏱ 1.5 hoursWrite SPL queries, build dashboards, and create detection rules in Splunk.Threat Hunting with ElasticLabIntermediate🛡️ Defensive⏱ 1.5 hoursHypothesis-driven hunting in Elastic/Kibana using KQL and EQL.User Behavior ForensicsLabIntermediate🛡️ Defensive⏱ 1.5 hoursUEBA concepts, detecting insider threats, and anomalous account activity.VLANs & Trunking LabLabEasy🌐 Networking⏱ 60 minutesConfigure VLANs, trunk ports, and inter-VLAN routing on Cisco switches.Web Application ReconLabEasy🕸️ Web Security⏱ 60 minutesDirectory busting, technology fingerprinting, and web attack surface mapping.Web Attacks: IDOR, XXE & Verb TamperingLabIntermediate🕸️ Web Security⏱ 1.5 hoursXXE external entity injection, blind XXE via OOB, and mass IDOR testing.Web Fuzzing & Directory Brute ForcingLabBeginner🕸️ Web Security⏱ 45 minutesFast directory, parameter, and vhost fuzzing with ffuf and SecLists.WEP Wireless AttacksLabIntermediate📡 Wireless⏱ 1.5 hoursIV collection and statistical WEP key recovery with aircrack-ng.White-Box Web Exploitation: Auth Bypass to RCELabAdvanced🕸️ Web Security⏱ 3 hoursCode review-driven RCE finding in PHP, Python, and Java web applications.Wi-Fi Evil Twin AttacksLabIntermediate📡 Wireless⏱ 1.5 hourshostapd-wpe captive portal, SSL strip, and credential capture via rogue AP.WiFi Hacking with Aircrack-ngLabMedium📡 Wireless⏱ 60 minutesMonitor mode, packet capture, deauth attacks, and WPA2 handshake cracking.WiFi Recon → SSH TakeoverLabBeginner-Friendly📡 Wireless⏱ 15 minute readRecon a same-network target with Wireshark and Nmap, crack SSH with Hydra, then flip to the defender's view. 7 steps, every command explained.Windows Attacks & DefenseLabIntermediate🛡️ Defensive⏱ 1.5 hoursAttack and detect common Windows attack patterns in a paired lab environment.Windows Evasion TechniquesLabAdvanced🏰 Infrastructure & AD⏱ 3 hoursAMSI bypass, PowerShell logging bypass, and process injection methods.Windows Event Log AnalysisLabIntermediate🛡️ Defensive⏱ 1.5 hoursKey event IDs for logon, process creation, lateral movement, and privilege use.Windows Heap ExploitationLabAdvanced💣 Exploit Dev⏱ 3 hoursHeap spray, use-after-free, and Windows heap internals for exploitation.Windows Lateral MovementLabIntermediate🏰 Infrastructure & AD⏱ 1.5 hoursPSExec, WMI, WinRM, DCOM, and token impersonation for lateral movement.Windows Privilege EscalationLabIntermediate🏰 Infrastructure & AD⏱ 1.5 hoursServices, tokens, registry, DLL hijacking, and AlwaysInstallElevated.Windows Stack Buffer Overflows (x86)LabAdvanced💣 Exploit Dev⏱ 3 hoursFull 32-bit Windows stack overflow with mona.py and custom shellcode.Wireshark Packet AnalysisLabEasy🚀 Zero to Hacker⏱ 50 minutesCapture, filter, and dissect network traffic to understand protocols.WMI Tradecraft & AnalysisLabIntermediate🏰 Infrastructure & AD⏱ 1.5 hoursWMI for persistence, lateral movement, and stealthy code execution.WordPress ExploitationLabBeginner🕸️ Web Security⏱ 45 minutesWPScan, plugin CVEs, theme RCE, XML-RPC abuse, and brute force.WPS AttacksLabIntermediate📡 Wireless⏱ 1.5 hoursReaver and Bully WPS PIN brute force against vulnerable routers.YARA & Sigma for DefendersLabBeginner🛡️ Defensive⏱ 45 minutesWrite YARA malware signatures and Sigma detection rules for SIEM platforms.إعداد بيئة كالي لينكسLabسهل🚀 Zero to Hacker⏱ ٣٠ دقيقةSet up your Kali VM, configure tools, and prepare your hacking lab environment.فحص الشبكات باستخدام NmapLabسهل🚀 Zero to Hacker⏱ ٤٥ دقيقةHost discovery, port scanning, service detection, OS fingerprinting, and NSE scripts.

📘 Workbooks 79

Active Directory Enumeration & AttacksWorkbookAdvanced🏰 Infrastructure & AD⏱ ~5 hours🔒 Free accountBloodHound, PowerView, Kerberoasting, ASREPRoasting, and DACL abuse.Active Directory FundamentalsWorkbookIntermediate🏰 Infrastructure & ADAD architecture, objects, Kerberos, NTLM, GPOs, and trusts before attacking AD.Advanced AI Red TeamingWorkbookAdvanced📈 Guided Tracks⏱ ~8 hours🔒 Free accountAdvanced adversarial attacks on AI systems, data poisoning, and model extraction.Advanced Web Attacks & ExploitationWorkbookAdvanced📈 Guided Tracks⏱ ~8 hours🔒 Free accountAdvanced techniques: request smuggling, deserialization, prototype pollution, and more.Advanced Windows ExploitationWorkbookAdvanced📈 Guided Tracks⏱ ~8 hours🔒 Free accountHeap exploitation, kernel basics, ROP chains, and 64-bit exploits.AI Governance with the NIST AI Risk Management FrameworkWorkbookAdvanced🤖 AI Security⏱ ~4 hours🔒 Free accountThe four AI RMF functions, the Generative AI Profile (AI 600-1), and the governance artefacts that turn framework prose into exit codes.AI Literacy: Embeddings and RetrievalWorkbookBeginner🤖 AI Security⏱ ~90 minutesHow text becomes numbers, how similarity is computed, and what a RAG pipeline really does to a prompt. Worked by hand in three dimensions, then run for real on a CPU.AI Literacy: LLM MechanicsWorkbookBeginner🤖 AI Security⏱ ~90 minutesWhat happens between your prompt and the model's reply: tokenisation, the context window, the decoding loop, and the mechanism behind hallucination and non-determinism.AI Literacy: The Confusion Matrix and Base RatesWorkbookBeginner🤖 AI Security⏱ ~75 minutesTP/FP/TN/FN, precision and recall, and the base-rate arithmetic that decides whether a detector is useful or useless. Worked on the page, with a napkin method you can use in a meeting.AI Literacy: Thresholds and ConfidenceWorkbookBeginner🤖 AI Security⏱ ~75 minutesThreshold sweeps worked by hand, ROC and AUC explained without calculus, and the misconception that causes more misplaced trust in AI output than any other: confidence is not correctness.AI Red Teaming: A MethodologyWorkbookAdvanced🤖 AI Security⏱ ~5 hoursScope, threat-model, attack, evidence and report an AI system — the discipline, not a list of jailbreak prompts.AI Security Essentials: Detection, Segmentation and Model OperationsWorkbookBeginner🤖 AI Security⏱ ~4 hours🔒 Free accountML detection and the base-rate problem, AI dev-environment segmentation, SIEM correlation, safe LLM use at work, model backups and drift — for beginners, with three CPU-only labs.AI Security Essentials: Non-Human Identity and Behavioural AuthenticationWorkbookBeginner🤖 AI Security⏱ ~3 hours🔒 Free accountNon-human identities, the owner/expiry/review rule, agent authority and behavioural authentication, for beginners — with a CPU-only lab that builds a broker refusing to issue a bad credential.AI Security Essentials: Poisoning, Bias and GovernanceWorkbookBeginner🤖 AI Security⏱ ~3 hours🔒 Free accountPoisoning, bias and AI under GRC, taught from first principles for beginners — with a CPU-only lab in which you backdoor a spam classifier you trained yourself.AI Security Essentials: Start HereWorkbookBeginner🤖 AI Security⏱ ~2 hours🔒 Free accountOrientation for a four-page AI security series for beginners: the four framings that make every later topic recognisable, and a CPU-only Docker lab box you build once and reuse.Android FundamentalsWorkbookBeginner📚 Other⏱ ~3 hours🔒 Free accountAndroid architecture, ADB, APK analysis, and mobile application security.Applications of AI in InfoSecWorkbookAdvanced🤖 AI Security⏱ ~4 hoursSix real uses of AI in security work, the specific way each one fails, and the control that bounds it.Bash ScriptingWorkbookBeginner🚀 Zero to Hacker⏱ ~3 hours🔒 Free accountShell scripting, conditionals, loops, and automation on Linux.Binary Exploitation FoundationsWorkbookAdvanced💣 Exploit Dev⏱ ~5 hours🔒 Free accountMemory layout, protections (ASLR, NX, canaries), and exploitation primitives.Bug Bounty HuntingWorkbookBeginner🕸️ Web Security⏱ ~3 hours🔒 Free accountHackerOne/Bugcrowd methodology, triaging, report writing, and maximising payouts.C++ FundamentalsWorkbookIntermediate💻 Programming⏱ 7 hours🔒 Free accountMemory management, pointers, and C++ for understanding binary vulnerabilities.CCNA Foundation GuideWorkbookIntermediate🌐 Networking⏱ ~6 hours🔒 Free accountCCNA syllabus: switching, routing, VLANs, ACLs, and network fundamentals.Cloud Security & AWSWorkbookIntermediate☁️ CloudAWS IAM, S3 misconfigs, IMDS exploitation, IAM privesc, and cloud hardening.Computer Architecture & AssemblyWorkbookIntermediate💣 Exploit Dev⏱ ~4 hours🔒 Free accountx86/x64 assembly, registers, calling conventions, and reading disassembly.Containers for AI Labs: Docker and Compose from ZeroWorkbookBeginner🤖 AI Security⏱ ~3 hoursDocker and Compose from zero — images vs containers, volumes, ports, logs, cleanup, and a worked compose.yaml that runs a local model.Cryptography FundamentalsWorkbookBeginner📚 OtherSymmetric, asymmetric, hashing, PKI, TLS, and common crypto weaknesses.CTF Beginner's GuideWorkbookBeginner🚀 Zero to Hacker⏱ 2.5 hoursHow CTFs work, common categories, tools, and tips for first-timers.Cybersecurity EssentialsWorkbookFoundational🚀 Zero to Hacker⏱ ~3 hoursThe CIA triad, threat actors, vulnerability lifecycle, and security frameworks.Detection EngineeringWorkbookAdvanced🛡️ Defensive⏱ ~5 hours🔒 Free accountWriting detection rules, YARA, Sigma, and tuning for low false positive rates.Digital Forensics & Incident ResponseWorkbookIntermediate🛡️ Defensive⏱ ~4 hours🔒 Free accountEvidence acquisition, chain of custody, disk and memory forensics fundamentals.Docker & Container SecurityWorkbookIntermediate☁️ CloudContainer escapes, Docker socket abuse, image scanning, and Kubernetes security.Documentation & ReportingWorkbookBeginner🚀 Zero to Hacker⏱ ~3 hours🔒 Free accountExecutive summaries, technical findings, remediation tables, and templates.Evasion Techniques & Breaching DefensesWorkbookAdvanced📈 Guided Tracks⏱ ~8 hours🔒 Free accountAV evasion, EDR bypass, AppLocker, AMSI bypass, and living-off-the-land.Foundational Incident ResponseWorkbookIntermediate📈 Guided Tracks⏱ ~5 hours🔒 Free accountComplete incident response from detection to lessons learned.Foundational Threat HuntingWorkbookIntermediate📈 Guided Tracks⏱ ~5 hours🔒 Free accountHypothesis-driven hunting, data sources, TTP mapping, and Elastic/Splunk.Fundamentals of AIWorkbookBeginner🤖 AI Security⏱ ~90 minutesAI vs ML vs DL vs GenAI, supervised vs unsupervised, what a model is as a file on disk, training vs inference, and an honest statement of what this track will not teach you.HTML & CSS BasicsWorkbookBeginner🕸️ Web Security⏱ 4 hours🔒 Free accountHTML structure, CSS, forms, and JavaScript basics for web security context.HTTP & Web RequestsWorkbookBeginner🚀 Zero to Hacker⏱ ~3 hoursHow HTTP works: methods, headers, cookies, proxies, and Burp basics.Incident HandlingWorkbookIntermediate🛡️ Defensive⏱ ~4 hours🔒 Free accountIncident lifecycle, communication, containment, eradication, and post-mortems.Introduction to C#WorkbookBeginner💻 Programming⏱ ~3 hours🔒 Free account.NET, C# basics, and Windows development context for security work.Introduction to Penetration TestingWorkbookBeginner🚀 Zero to Hacker⏱ ~3 hoursWhat pentesting is, legal context, scope, phases, and methodology.Introduction to Web ApplicationsWorkbookBeginner🕸️ Web Security⏱ ~3 hoursClient-server model, web technologies, cookies, sessions, and same-origin policy.ISO/IEC 42001: The AI Management System, and How It Meets ISO 27001WorkbookAdvanced🤖 AI Security⏱ ~3 hours🔒 Free accountAIMS clauses 4–10, the Annex A control themes, the Statement of Applicability as a checked file, and where ISO 27001 stops and 42001 starts.Java FundamentalsWorkbookBeginner💻 Programming⏱ 6 hours🔒 Free accountJava OOP, JVM, serialisation, and security-relevant Java concepts.JavaScript BasicsWorkbookBeginner💻 Programming⏱ 5 hours🔒 Free accountES6+, DOM, async/await, and security implications of JavaScript.Kali Linux FundamentalsWorkbookBeginner Friendly🚀 Zero to Hacker⏱ ~4 hoursKali toolset, configuration, and staying organised during engagements.Linux for BeginnersWorkbookBeginner🚀 Zero to Hacker⏱ 3 hours totalStart from zero — navigation, files, permissions, processes, bash basics.macOS FundamentalsWorkbookBeginner🚀 Zero to Hacker⏱ ~3 hours🔒 Free accountmacOS architecture, filesystem, security model (SIP, Gatekeeper), and the command line.Malware AnalysisWorkbookAdvanced🛡️ Defensive⏱ ~5 hours🔒 Free accountStatic and dynamic analysis, sandboxes, deobfuscation, and IOC extraction.Memory ForensicsWorkbookAdvanced🛡️ DefensiveVolatility 3, process analysis, code injection detection, and rootkit hunting.Network Traffic AnalysisWorkbookIntermediate🛡️ Defensive⏱ ~4 hours🔒 Free accountWireshark, tcpdump, protocol analysis, and detecting anomalies in traffic.Networking Deep DiveWorkbookIntermediate🚀 Zero to Hacker⏱ 4 hours🔒 Free accountTCP/IP, subnetting, DNS, routing, OSI model, and packet analysis.OSINT & ReconnaissanceWorkbookBeginner🚀 Zero to HackerGoogle dorking, Shodan, WHOIS, theHarvester, Maltego, and recon reports.Penetration Testing with KaliWorkbookAdvanced📈 Guided Tracks⏱ ~8 hours🔒 Free accountFull enterprise pentest from external recon to domain dominance.Pre-Engagement & Setting UpWorkbookBeginner🚀 Zero to Hacker⏱ ~3 hours🔒 Free accountScope documents, rules of engagement, and lab environment configuration.Privilege Escalation — Linux & WindowsWorkbookIntermediate🏰 Infrastructure & ADSUID, sudo, services, tokens, DLL hijacking — complete privesc reference.Python for AI Work: Environments, Data, and TestsWorkbookBeginner🤖 AI Security⏱ ~4 hoursvenv/uv and committed lockfiles, HTTP and JSON, CSV and pandas, scikit-learn as an API only, the chat-completions message shape, and pytest as the grading mechanism.Python for HackersWorkbookBeginner💻 Programming⏱ 4 hours🔒 Free accountSockets, subprocess, ctypes, pwntools, and offensive Python scripting.Python FundamentalsWorkbookBeginner🚀 Zero to Hacker⏱ 6 hoursVariables, functions, loops, file I/O, and scripting for automation.Reading AI-Written Code: Review from Week OneWorkbookBeginner🤖 AI Security⏱ ~3 hoursA repeatable six-question review pass, then six flawed AI-generated snippets with the flaw, the cause, the fix, and a failing test.Red Team OperationsWorkbookAdvanced🏰 Infrastructure & AD⏱ ~5 hours🔒 Free accountC2 frameworks, tradecraft, OPSEC, persistence, and advanced lateral movement.Secure CodingWorkbookAdvanced💻 Programming⏱ ~5 hours🔒 Free accountInput validation, output encoding, and secure SDLC practices.Secure Java DevelopmentWorkbookAdvanced📈 Guided Tracks⏱ ~8 hours🔒 Free accountSecure Java coding patterns, OWASP Java guidance, and code review.Security Operations & Defensive AnalysisWorkbookIntermediate📈 Guided Tracks⏱ ~5 hours🔒 Free accountComplete SOC analyst track: detection, response, and documentation.Shell and Data Wrangling for AI WorkWorkbookBeginner🤖 AI Security⏱ ~3 hoursTerminal, filesystem, permissions, processes and ssh, plus the text-processing verbs used to inspect model output and datasets.SOC Operations & SIEMWorkbookIntermediate🛡️ Defensive⏱ ~4 hours🔒 Free accountSOC workflow, alert triage, SIEM platforms, and escalation procedures.Social EngineeringWorkbookIntermediate📚 OtherPhishing, vishing, pretexting, physical intrusion, and building awareness defences.SQL FundamentalsWorkbookBeginner💻 Programming⏱ 4 hours🔒 Free accountSELECT, INSERT, JOIN, subqueries, and understanding SQL for injection attacks.SQL Injection FundamentalsWorkbookIntermediate🕸️ Web Security⏱ ~4 hours🔒 Free accountIn-band, blind, and out-of-band SQLi with manual and automated exploitation.The EU AI Act After the Omnibus: Who Owes What, and WhenWorkbookAdvanced🤖 AI Security⏱ ~3 hours🔒 Free accountRisk tiers, the provider/deployer split, GPAI duties, and the Article 50 transparency rules that are live right now.The Penetration Testing ProcessWorkbookBeginner🚀 Zero to Hacker⏱ ~3 hours🔒 Free accountFull pentest lifecycle: recon → scan → exploit → post-exploit → report.Vulnerability AssessmentWorkbookBeginner🚀 Zero to Hacker⏱ ~3 hours🔒 Free accountNessus, OpenVAS, prioritisation frameworks, and CVSS scoring.Web Application PentestingWorkbookIntermediate🕸️ Web Security⏱ 4 hours🔒 Free accountOWASP Top 10, Burp Suite advanced usage, and web pentest methodology.Web Attacks with KaliWorkbookIntermediate📈 Guided Tracks⏱ ~5 hours🔒 Free accountComplete web attack track: injection, authentication, client-side, and serialisation.Windows Active Directory for PentestersWorkbookAdvanced🏰 Infrastructure & AD⏱ 5 hours🔒 Free accountDeep dive into AD administration, enumeration, and attack paths.Windows Command Line & PowerShellWorkbookBeginner🏰 Infrastructure & AD⏱ ~3 hours🔒 Free accountCMD and PowerShell commands, scripts, and automation for enterprise environments.Windows FundamentalsWorkbookBeginner🚀 Zero to Hacker⏱ ~3 hours🔒 Free accountWindows OS, registry, services, file system, and PowerShell basics.Windows User-Mode Exploit DevelopmentWorkbookAdvanced📈 Guided Tracks⏱ ~8 hours🔒 Free accountStack overflows, SEH, egghunters, shellcoding on 32-bit Windows.Wireless Penetration TestingWorkbookIntermediate📡 Wireless⏱ ~4 hours🔒 Free accountWPA2/WPA3, evil twin, deauth attacks, captive portal bypass, and WPS attacks.