learning path

From beginner to your first findings.

Everything here is open. Lessons are ordered, but nothing is locked, read in order if you're starting out, or jump straight to what you need.

your progress
0 / 60lessons complete
Start: Programming Languages for Ethical Hackers
Your learning journey

Part 1: Foundations

Master the fundamentals of security and how the web works.

4
Milestone 4

TLS, Certificates & Trust

What the padlock really means: the TLS handshake and the chain of trust behind it.

0/2
  1. 01TLS, SSL & the HandshakeConceptual lesson, no terminal needed.
  2. 02Certificates & the Chain of TrustConceptual lesson, no terminal needed.

Part 2: Linux & Recon

Learn Linux, networking, and how to find your target.

8
Milestone 8

Enumeration & Scanning

Information gathering end to end: the big-picture flow, dorking, search engines and crawlers, then subdomains, port scanning, service and web fingerprinting, wordlists, content discovery, and deeper web recon.

0/11
  1. 01The Big Picture: Recon, Scanning & EnumerationThe map of this whole week: the three phases of information gathering, in plain English.
  2. 02Reconnaissance & The Enumeration WorkflowHands-on: try whois, nslookup, traceroute, telnet and netcat in the sandbox terminal.
  3. 03Search Engines, Crawlers & robots.txtHands-on: curl robots.txt, sitemap.xml and llms.txt in the sandbox terminal, and see how they feed the Google dorking you just learned.
  4. 04Search Engine Dorking: Google, GitHub & BeyondHands-on. Turn search operators into precise recon queries, all passive, touching only the search engine.
  5. 05OSINT: Open Source Intelligence, Finding the Puzzle PiecesA long one. The art of gathering intelligence from public sources, all passive, plus the ethics that must come with it.
  6. 06Subdomain Enumeration: Passive & Active ReconHands-on: run subfinder, amass intel, gobuster, httpx, dig axfr in the sandbox terminal.
  7. 07Enumeration & Port Scanning with nmapHands-on lesson: run nmap scans in the terminal and interpret the results.
  8. 08Service Enumeration: Fingerprinting the PortsHands-on: after nmap finds ports, dig into each service with curl, nikto, nuclei, enum4linux, smbclient, dig.
  9. 09Wordlists: Fuzzing & Password CrackingHands-on: locate rockyou.txt with find/locate, build a name-based list with cewl/cupp, crack a hash with john.
  10. 10Directory & Content DiscoveryHands-on: brute-force hidden web paths with gobuster and ffuf using a SecLists wordlist.
  11. 11Deeper Web Recon: Crawling, Params & ScreenshotsHands-on: crawl with katana, pull archives with gau, find params with arjun, screenshot with gowitness.
9
Milestone 9

Remote Access & File Transfer

Administer a server the real way: SSH login and hardening, scp/sftp transfers, tunnels, and FTP.

0/1
  1. 01Configuring SSH & FTP: Login, Transfer, TunnelsHands-on: two sandbox terminals (client + server). Connect, transfer files, tunnel.

Part 3: Exploitation

Exploit vulnerabilities and escalate privileges.

10
Milestone 10

The Hacker Methodology

Zoom out on the whole engagement, see what Phase 2 already covered, and what's still ahead.

0/1
  1. 01The Hacker Methodology: From Recon to ReportingThe map of the whole engagement: where Phase 2 fits, and what this phase covers next.
More phases on the way.
Recon, host attacks, web app testing, Active Directory, reporting, they all connect back to the foundations you're learning right now.
Practice in a lawful, authorized lab only.