Pick your path.
From first lab to full adversary simulation.
Build the lab. Break things safely.
Stand up an isolated home lab, then walk a guided path from your first nmap scan to your first authorized web finding.
Start the lab path Saved pathRun a real pentest.
Pre-engagement wizard, RoE template, MITRE-tagged playbooks, exploitation references, and report builders — kickoff to deliverable.
Open the pentest path Saved pathAdversary simulation.
Objectives, infrastructure, initial access, C2, evasion, AD attack paths, and post-ex tradecraft — for mature programs simulating real threat actors.
Open red team opsDefender? Jump to secure architecture, DFIR, or threat intel.
Tools that do the work.
End-to-end engagement guides.
Web Penetration Test
Pre-engagement, recon, scanning, enumeration, vuln analysis, exploitation, labs, and reporting. The default starting point for most engagements.
Open guideInternal Penetration Test
Network discovery, AD enumeration, Kerberos attacks, lateral movement, persistence, and domain dominance — with BloodHound paths and OPSEC notes throughout.
Open guideRed Team Operations
Adversary simulation: objectives, infrastructure, initial access, C2, evasion, and reporting. For mature programs simulating real threat actors.
Open guideBrowse by domain.
Application & API
Web, API, source code, and crypto attacks aligned to OWASP WSTG v4.2.Infrastructure & Cloud
Network, AD, containers, CI/CD, AWS, Azure, GCP.Hardware & Wireless
IoT, OT, automotive, drone, WiFi, physical, counter-surveillance.Offensive Research
Low-level offense and emerging-AI tradecraft.Defense, Intel & Architecture
For blue, purple, and architecture-side readers.Process & Standards
The operational half of professional security testing.Tool cheatsheets for fast reference.
“This is our world now… the world of the electron and the switch, the beauty of the baud.”
— The Mentor, The Hacker Manifesto, 1986