security-offensive
Offensive Security
How attacks actually work, lab-framed and ethics-first: recon, web and infrastructure exploitation, and pentest methodology — so you can defend and read a findings report.
Start track → 00
Start here
The attacker mindset for defenders — and the ethics, scope, and authorization that make it legal. 01
Recon and enumeration
Map the attack surface before touching it: OSINT, footprinting, scanning, and service enumeration — ethics first. 02
Web exploitation
The attacker's view of OWASP: how injection, XSS, SSRF, IDOR, and auth bypass are found and proven — lab-framed. 03
Network and infrastructure attacks
How attackers move below the app: MITM, privilege escalation, password attacks, and lateral movement — conceptually. 04
Exploitation and post-exploitation
From a vulnerability to control, and what attackers do after — so defenders can detect each step. 05
Tooling and methodology
The pentester's toolkit and process: Burp, nmap, a repeatable methodology, and a finding/report that lands.Build with this track
Guided projects that exercise what you learn here.
Defensive Security
Detect, respond, and harden: logging and detection engineering, incident response, defense-in-depth, and the security operations an engineer runs in production.