Structured Training

Learning Paths

Guided curricula mapped to real certification exams. Work through sequential modules, each building on the last, with hands-on labs at every step.

🎯

OffSec PEN-200

OSCP Preparation

Nine modules covering every technique that appears on the OSCP exam — from DNS recon and cleartext protocols through to Active Directory and buffer overflows. Work in order for the best results.

8 Modules
14 Machines
4 Free Modules
Network Services Web Exploitation Active Directory Buffer Overflow
Start OSCP Path →
🏆

HTB Certified Penetration Testing Specialist

CPTS Preparation

Seven modules aligned to the HTB CPTS curriculum — network footprinting, common service attacks, web exploitation, databases, LDAP enumeration, and a full Active Directory engagement. Deeper coverage of modern enterprise attack paths than OSCP.

9 Modules
18 Machines
1 Free Modules
Footprinting Common Services Web Attacks Active Directory
Start CPTS Path →
🔌

Tool Mastery · ⭐ Premium

Port Scanning Mastery

Eight modules of professional-grade scanning technique — host discovery, TCP scan types, UDP scanning, service & version detection, OS fingerprinting, NSE scripting, masscan/RustScan pipelines, and firewall evasion. Every module includes structured per-lab assignments practised against live machines, not screenshots.

8 Modules
8 Machines
Premium
nmap masscan UDP Scanning NSE Scripts Evasion RustScan
📂

Protocol Exploitation · ⭐ Premium

FTP Exploitation Mastery

Six modules covering every FTP attack technique — anonymous access, banner grabbing, credential brute-force, TFTP unauthenticated file retrieval, writable FTP shell delivery, and full protocol chaining across FTP, SMB, and rsync. Practised against live machines with structured per-lab assignments.

6 Modules
3 Machines
Premium
Anonymous FTP TFTP Brute-Force Shell Delivery Protocol Chaining
🖥️

SMB Exploitation · ⭐ Premium

SMB Mastery

Null sessions, share enumeration, SYSVOL credential harvesting, and GPP decrypt. Progress from anonymous access to domain credential extraction across live Windows-like machines.

2Modules
1Machines
Premium
Null Session SYSVOL GPP Decrypt CrackMapExec
📡

SNMP Exploitation · ⭐ Premium

SNMP Mastery

UDP discovery, community string brute-force, full MIB tree walking, and credential extraction from NET-SNMP extend OIDs. One machine, two modules, root shell.

2Modules
1Machines
Premium
MIB Walk Community String OID Enum Credential Extraction
🔐

SSH Exploitation · ⭐ Premium

SSH Mastery

Service fingerprinting, auth method probing, credential attacks, and full SSH tunneling. Local port forwards, dynamic SOCKS proxies, ProxyJump, and sshuttle VPN pivoting.

2Modules
2Machines
Premium
Fingerprinting Brute-Force Port Forwarding Tunneling
🌳

LDAP Exploitation · ⭐ Premium

LDAP Mastery

Anonymous bind, root DSE queries, full object enumeration, and credential extraction from description fields. Module 2 scales to Active Directory with windapsearch and ldapdomaindump.

2Modules
2Machines
Premium
Anonymous Bind ldapsearch AD Enum BloodHound

How the free unlock works

1
Pick a locked module

Modules beyond the free tier show an unlock button on their card.

2
Start the 24h timer

Click "Unlock Free (24h)". A countdown begins. You can only unlock one module at a time — choose wisely.

3
Access unlocks automatically

When the timer hits zero the module opens. No action required — just come back and train.

4
Or skip the wait

Premium gives instant access to all modules on all paths, unlimited daily labs, and walkthroughs.

⭐ Get Premium