Structured Training

Learning Paths

Guided curricula mapped to real certification exams. Work through sequential modules, each building on the last, with hands-on labs at every step.

🥷

OSEP · PEN-300 · Advanced Red Team NEW

OSEP Track

Where OSCP ends and the red team begins. Restricted-shell breakouts, filter & defense evasion, lateral movement & pivoting, advanced Active Directory, and insecure deserialization — getting a shell isn't enough here, you have to get it past the defences.

5Modules
12Machines
FreeAccess
Evasion Lateral Movement Active Directory Deserialization
Start OSEP Track →
🎓

Certified Modern Web App Pentester

CMWAP Practice

Practice for the CMWAP exam: methodology-first, no-flag web-app engagements. Warm up on the core bug classes, then run full 24-hour engagements — plan, report, and a debrief video, exactly like the exam.

2 Modules
8 Machines
Free Access
Web App Pentest Methodology No Flags Plan · Report · Debrief
Start CMWAP Path →
🎯

OffSec PEN-200

OSCP Preparation

Nine modules covering every technique that appears on the OSCP exam — from DNS recon and cleartext protocols through to Active Directory and buffer overflows. Work in order for the best results.

10 Modules
26 Machines
10 Free Modules
Network Services Web Exploitation Active Directory Buffer Overflow
Start OSCP Path →
🏆

HTB Certified Penetration Testing Specialist

CPTS Preparation

Seven modules aligned to the HTB CPTS curriculum — network footprinting, common service attacks, web exploitation, databases, LDAP enumeration, and a full Active Directory engagement. Deeper coverage of modern enterprise attack paths than OSCP.

9 Modules
18 Machines
1 Free Modules
Footprinting Common Services Web Attacks Active Directory
Start CPTS Path →
🔌

Tool Mastery · ⭐ Premium

Port Scanning Mastery

Eight modules of professional-grade scanning technique — host discovery, TCP scan types, UDP scanning, service & version detection, OS fingerprinting, NSE scripting, masscan/RustScan pipelines, and firewall evasion. Every module includes structured per-lab assignments practised against live machines, not screenshots.

8 Modules
8 Machines
Premium
nmap masscan UDP Scanning NSE Scripts Evasion RustScan
📂

Protocol Exploitation · ⭐ Premium

FTP Exploitation Mastery

Six modules covering every FTP attack technique — anonymous access, banner grabbing, credential brute-force, TFTP unauthenticated file retrieval, writable FTP shell delivery, and full protocol chaining across FTP, SMB, and rsync. Practised against live machines with structured per-lab assignments.

6 Modules
3 Machines
Premium
Anonymous FTP TFTP Brute-Force Shell Delivery Protocol Chaining
🖥️

SMB Exploitation · ⭐ Premium

SMB Mastery

Null sessions, share enumeration, SYSVOL credential harvesting, and GPP decrypt. Progress from anonymous access to domain credential extraction across live Windows-like machines.

2Modules
1Machines
Premium
Null Session SYSVOL GPP Decrypt CrackMapExec
📡

SNMP Exploitation · ⭐ Premium

SNMP Mastery

UDP discovery, community string brute-force, full MIB tree walking, and credential extraction from NET-SNMP extend OIDs. One machine, two modules, root shell.

2Modules
1Machines
Premium
MIB Walk Community String OID Enum Credential Extraction
🔐

SSH Exploitation · ⭐ Premium

SSH Mastery

Service fingerprinting, auth method probing, credential attacks, and full SSH tunneling. Local port forwards, dynamic SOCKS proxies, ProxyJump, and sshuttle VPN pivoting.

2Modules
2Machines
Premium
Fingerprinting Brute-Force Port Forwarding Tunneling
🌳

LDAP Exploitation · ⭐ Premium

LDAP Mastery

Anonymous bind, root DSE queries, full object enumeration, and credential extraction from description fields. Module 2 scales to Active Directory with windapsearch and ldapdomaindump.

2Modules
2Machines
Premium
Anonymous Bind ldapsearch AD Enum BloodHound
📋

Professional Skills

Pentest Reporting

Learn to write PTES-aligned pentest plans and reports. From pre-engagement scope to executive summary — with hands-on practice on real labs.

4 modules · PTES standard · Free
Planning Documentation Reporting

How the free unlock works

1
Pick a locked module

Modules beyond the free tier show an unlock button on their card.

2
Start the 24h timer

Click "Unlock Free (24h)". A countdown begins. You can only unlock one module at a time — choose wisely.

3
Access unlocks automatically

When the timer hits zero the module opens. No action required — just come back and train.

4
Or skip the wait

Premium gives instant access to all modules on all paths, unlimited daily labs, and walkthroughs.

⭐ Get Premium