01 / Curriculum
Course Outlines
Nine courses. Full step-by-step outlines. Tap any course to open its complete module list — expand each one to see every topic covered.
01
Cyber Security & Ethical Hacking Overview
- 1What is cybersecurity and why it matters
- 2Ethical hacking vs black hat / grey hat hacking
- 3Roles: pentester, red teamer, security researcher
02
Methodologies - NIST, PTES, OWASP
- 1NIST SP 800-115 assessment framework
- 2PTES: Pre-Engagement to Reporting
- 3When to use OWASP Testing Guide (web) vs OSSTMM (general)
03
MITRE ATT&CK Framework
- 1Tactics, techniques and procedures (TTPs)
- 2Navigating ATT&CK Navigator
- 3Mapping real attacks to ATT&CK techniques
04
Pre-Engagement
- 1Scoping, rules of engagement (RoE)
- 2Legal considerations and authorization
- 3Kick-off meeting and deliverables agreement
05
Reconnaissance / Information Gathering
- 1Passive vs active recon
- 2Footprinting a target
- 3Documenting findings for the next phase
06
Vulnerability Assessment & Threat Modeling
- 1Identifying weaknesses in scope
- 2Asset classification and attack-surface review
- 3Prioritising findings by risk
07
Exploitation
- 1Exploiting identified vulnerabilities safely
- 2Getting initial access
- 3Proving impact without causing damage
08
Post-Exploitation (Introduction)
- 1Lateral movement basics
- 2Privilege escalation intro
- 3Maintaining access (covered in depth later)
09
Reporting
- 1Writing a professional pentest report
- 2Executive summary vs technical detail
- 3Remediation advice and retesting
01
Introduction To Ethical Hacking & Overview
- 1Offensive And Defensive Security
02
Hacking Environment Setup: Kali Linux & Linux Mastery
- 1How To Install Kali Linux On Your Computer
- 2Master Linux From Basic To Advanced
03
Web Application Testing Fundamentals
- 1Burpsuite For Web Application Pentesting
- 2Master BurpSuite Professional In One Lecture
04
File Path Traversal Vulnerabilities
- 1File path traversal, simple case
- 2File path traversal, traversal sequences blocked with absolute path bypass
- 3File path traversal, traversal sequences stripped non-recursively
- 4Automation of File path traversal vulnerabilities
05
Information Disclosure Vulnerabilities
- 1Information Leakage Vulnerabilities
- 2Information Leakage In Error Messages
- 3Information Leakage On Debug Page
- 4Source Code Disclosure Via Backup Files
- 5Automating Information Disclosure Discovery: Feroxbuster, FFUF, Dirbuster & Dirb Step by Step
06
Automated Information Disclosure Techniques
- 1Automate The Process Of Finding Information Disclosure Vulnerabilities
07
OS Command Injection
- 1Introduction To OS Command Injection
- 2OS Command Injection Simple Case
- 3Blind OS Command Injection With Time Delays
- 4Blind OS Command Injection With Output Redirection
08
SSRF Vulnerabilities
- 1Introduction To SSRF Vulnerability
- 2Basic SSRF Against The Local Server
- 3SSRF Against Blacklist-Based Input Filter
- 4Basic SSRF Against Another Back-End System
09
File Upload Vulnerabilities & Remote Code Execution
- 1Introduction To File Upload Vulnerabilities
- 2Remote Code Execution Via Web Shell Upload
- 3Web Shell Upload Via Content-Type Restriction Bypass
- 4Web Shell Upload Via Path Traversal
- 5Remote Code Execution Via Polyglot Web Shell Upload
- 6Web Shell Upload Via Obfuscated File Extension
10
Access Control Vulnerabilities
- 1Introduction To Access Control Vulnerabilities
- 2Unprotected Admin Functionality
- 3Unprotected Admin Functionality With Unpredictable URL
- 4User Role Controlled By Request Parameter
- 5User Role Can Be Modified In User Profile
- 6Insecure Direct Object References
- 7User ID Controlled By Request Parameter With Password Disclosure
11
Business Logic Vulnerabilities
- 1Introduction To Business Logic Vulnerabilities
- 2Excessive Trust In Client-Side Controls
- 3High-Level Logic Vulnerability
- 4Inconsistent Security Controls
- 5Flawed Enforcement Of Business Rules
- 6Weak Isolation On Dual-Use Endpoint
- 7Insufficient Workflow Validation
12
Cross-Site Scripting (XSS)
- 1Introduction To XSS-Cross Site Scripting
- 2Reflected XSS
- 3Stored XSS
- 4DOM XSS
- 5DOM XSS- Part 2
13
SQL Injection Fundamentals
- 1SQL Programming
- 2Introduction To SQL Injection Vulnerability
- 3SQL Injection Vulnerability Allowing Login Bypass
14
Advanced SQL Injection Techniques
- 1SQL Injection UNION Attack, Determining Number Of Columns
- 2SQL Injection UNION Attack, Finding A Column Containing Text
- 3SQL Injection UNION Attack, Retrieving Data From Other Tables
- 4SQL Injection UNION Attack, Retrieving Multiple Values
- 5SQL Injection Attack, Listing Database Contents On Non-Oracle Databases
- 6Blind SQL Injection With Time Delays
- 7Mastering SQLmap Step by Step
15
Automation In Cybersecurity
- 1Introduction To Automation (The Core Of Cybersecurity)
16
Subdomain Enumeration & Reconnaissance Tools
- 1Installation Of Subfinder - Subdomain Enumeration
- 2Installation Of Assetfinder - Subdomain Enumeration
- 3Configure And Install Findomain - Subdomain Enumeration
17
URL & HTTP Reconnaissance Tools
- 1How To Install Waymore URLs
- 2Configure And Install HTTPX Tool
18
Exploitation Tools - Part 1
- 1Install Katana Tool
- 2How To Install Nuclei Framework - Exploitation
- 3How To Install And Configure Nuclei Templates
19
Exploitation Tools - Part 2
- 1Install Parallel, Qsreplace Tools
20
Web Security Automation - Integration
- 1Putting It All Together - Web Security Automation Part: 1
- 2Web Security Automation Part: 2
21
Web Security Automation - Exploitation Phase
- 1Exploitation Phase - Web Security Automation Part: 3
22
Advanced Automation & Final Chapter
- 1The Final Chapter; Automate Everything
23
XML Injection & XXE Attacks
- 1Introduction To XML Injection Attacks
- 2Exploiting XXE Using External Entities To Retrieve Files
- 3Exploiting XXE To Perform SSRF Attacks
- 4Blind XXE With Out-Of-Band Interaction
24
Authentication Vulnerabilities & User Enumeration
- 1Introduction To Authentication Vulnerabilities
- 2Username Enumeration Via Subtly Different Responses
- 32FA Simple Bypass
- 4Password Reset Broken Logic
25
Reconnaissance & Vulnerability Assessment
- 1The Art Of Hacking- Reconnaissance
- 2NetSec Challange- Reconnaissance Part 2
- 3Practical Vulnerabilities Exploitation
- 4Penetration Testing Vulnerabilities 101
26
Metasploit & Exploitation Frameworks
- 1Mastering Metasploit Framwork Part 1
- 2Hack Windows Machine Using Metasploit
27
Linux Privilege Escalation
- 1Sensitive Credentials Hunting
- 2Weak File Permissions
- 3Cron Jobs
- 4SUID Wildcard
- 5SUDO - Shell Escape Sequences
- 6SUDO Exploitation ld_preload
- 7SUDO LD_LIBRARY_PATH
- 8SUID Exploitation - Known Vulnerabilities (CVEs)
- 9SUID Shared Object Injection
- 10Linux Capabilities
- 11Service Exploitation: MySQL (Boot to Root)
- 12Network File System (NFS)
- 13Revision of LinuxPrivEsc
28
Practical Hacking into Linux Machines (Projects)
- 1Mr.Robot CTF Linux
- 2TryHackMe CTF: Vulnversity - Walkthrough Linux
- 3Skynet Walkthrough Linux
- 4DailyBugle TryHackMe Walkthrough Linux
- 5Game Zone Linux
- 6Kenobi Linux
29
Windows Privilege Architecture & Escalation
- 1User Account Control (UAC)
- 2Login to RDP and Dropping Files + Receiving
- 3Windows PrivEsc (Overview)
- 4Windows Services
- 5Service Abuse: Weak Service Executable
- 6Service Abuse: Weak Service Permission
- 7Service Abuse: Unquoted Service Paths
- 8Service Abuse: DLL Hijacking Intro
- 9Service Abuse: DLL Hijacking Practical
- 10Sensitive Credentials Hunting Theory
- 11Sensitive Credentials Hunting
- 12Part 1: SAM (Security Account Manager)
- 13Part 2: SAM (Security Account Manager)
- 14Introduction to Windows Registry
- 15Lab: Registry Autorun Exploitation
- 16Lab: Weak Registry Permissions
- 17AlwaysInstallElevated
- 18Theory - Impersonation Attacks
- 19[LAB] SeImpersonate Exploit: JuicyPotato
- 20Lab: PrintSpoofer (The King of Token Impersonation)
- 21[LAB] RoguePotato (Token Impersonation)
- 22Universal Methodology: SeTakeOwnership Exploit
- 23Startup Apps Exploitation
- 24Insecure GUI Apps
- 25seBackupExploit
- 26Kernel Exploit Windows 7
- 27Windows 10 Kernel Exploitation
- 28Attack Vector: Scheduled Task Resource Abuse
- 29UAC (User Account Control) Bypass
30
Practical Hacking into Windows Machines (Projects)
- 1Steel Mountain | WIN
- 2Alfred Walkthrough WIN
- 3HackPark TryHackMe WIN
- 4Relevant (TryHackMe) WIN
- 5Internal (TryHackMe) WIN
- 6Retro TryHackMe Walkthrough WIN
31
Advanced / Miscellaneous Topics
- 1Master Metasploit Overview
- 2Port Forwarding, Tunneling and Pivoting
- 3Port Forwarding, Tunneling and Pivoting in WINDOWS
32
Bash Scripting - Advanced Module
- 1Introduction to Bash Scripting
- 2Variables, Loops and Conditions
- 3Functions and Automation Scripting
- 4Writing Custom Recon Tools in Bash
33
Python for Hackers
- 1Introduction to Python Programming
- 2Network Programming (Sockets & Requests)
- 3Building Custom Exploits in Python
- 4Automating Tools with Python
34
AI in Red Teaming & Bug Bounty
- 1How to use AI to Hack Machines
- 2Using AI for Red Teaming and Pentesting
- 3Automating Bug Bounty Workflows with AI
- 4Creating Custom Exploits and Analysis using LLMs
01
OSINT Introduction & Framework
- 1What OSINT is and its legal boundaries
- 2The OSINT cycle: collection, analysis, reporting
- 3Setting up a safe and private OSINT workspace
02
Google Dorking & Search Techniques
- 1Google operators: site:, inurl:, filetype:
- 2Advanced search combinations
- 3Building your own dork cheatsheet
03
People, User & Email Investigation
- 1Username search across platforms
- 2Email breach lookups and format analysis
- 3Building a persona profile
04
Domain & IP Investigation (Shodan, Censys, WHOIS)
- 1WHOIS records and history
- 2Shodan / Censys host discovery
- 3DNS records and reverse lookups
05
SOCMINT (Social Media OSINT)
- 1Social media footprint analysis
- 2Metadata and EXIF extraction
- 3Geolocation from photos and posts
06
Corporate / Business Investigation
- 1Company structure and subsidiaries
- 2Employee disclosure analysis
- 3Suppliers, partners and tech stack
07
Social Engineering & Pretexting Techniques
- 1Phishing psychology and pretexts
- 2Open-source intel that powers pretexting
- 3Defensive awareness for each technique
08
Phishing Campaign Design
- 1Planning an engagement campaign
- 2Cloning / lures (in a lab only)
- 3Measuring and reporting results
09
OSINT Tooling & Automation
- 1theHarvester, Maltego, recon-ng
- 2Automating collection with scripts
- 3Organising data for analysis
10
Investigation / Recon Reporting
- 1Timeline building
- 2Attribution and confidence levels
- 3Writing a professional OSINT report
01
Websites & Web Application Structure
- 1HTTP/HTTPS request and response anatomy
- 2Client-side vs server-side processing
- 3Databases, sessions and cookies
02
Web Pentesting Setup
- 1Installing Burp Suite Community / Pro
- 2Configuring the browser proxy
- 3TLS/SSL interception and certificates
03
Bug Hunting Platforms Setup
- 1HackerOne / Bugcrowd / Intigriti profiles
- 2Reading scope and rules of engagement
- 3Using lab platforms: PortSwigger Web Security Academy, HackTheBox, TryHackMe
04
Burp Suite For Web Application Pentesting
- 1Proxy, Repeater, Intruder, Sequencer, Decoder
- 2Intercepting and modifying requests
- 3Common gotchas and workspace setup
05
Mastering Burp Suite Professional
- 1Project options, scope and sitemap
- 2Extensions: Active Scan++, Turbo Intruder, Logger++
- 3Automating workflow with BApp extensions
06
OWASP Top 10 Web Vulnerabilities
- 1A01 Broken Access Control, A02 Cryptographic Failures
- 2A03 Injection, A04 Insecure Design
- 3A05-A10: misconfig, vulnerable components, auth and logging failures
07
File Path Traversal Vulnerabilities
- 1Simple file path traversal case
- 2Traversal sequences blocked with absolute-path bypass
- 3Stripped non-recursively bypass
- 4Automating file path traversal discovery
08
Information Disclosure Vulnerabilities
- 1Information leakage basics
- 2Information leakage in error messages
- 3Information leakage on debug page
- 4Source code disclosure via backup files
- 5Automation with Feroxbuster, FFUF, Dirbuster & Dirb
09
Automated Information Disclosure Techniques
- 1Automating the process of finding info-disclosure bugs
- 2Building a repeatable discovery script
- 3Fuzzing for hidden endpoints and files
10
OS Command Injection
- 1Introduction to OS command injection
- 2Simple command injection case
- 3Blind command injection with time delays
- 4Blind command injection with output redirection
11
SSRF Vulnerabilities
- 1Introduction to SSRF
- 2Basic SSRF against the local server
- 3SSRF against blacklist-based input filters
- 4Basic SSRF against another back-end system
12
File Upload Vulnerabilities & RCE
- 1Introduction to file upload vulnerabilities
- 2RCE via web shell upload
- 3Web shell upload via content-type restriction bypass
- 4Web shell upload via path traversal
- 5RCE via polyglot web shell upload
- 6Web shell upload via obfuscated file extension
13
Access Control Vulnerabilities
- 1Introduction to access control vulnerabilities
- 2Unprotected admin functionality
- 3Unprotected admin functionality with unpredictable URL
- 4User role controlled by request parameter
- 5User role modified in user profile
- 6Insecure Direct Object References (IDOR)
- 7User ID controlled by request parameter with password disclosure
14
Business Logic Vulnerabilities
- 1Introduction to business logic vulnerabilities
- 2Excessive trust in client-side controls
- 3High-level logic vulnerability
- 4Inconsistent security controls
- 5Flawed enforcement of business rules
- 6Weak isolation on dual-use endpoint
- 7Insufficient workflow validation
15
Cross-Site Scripting (XSS)
- 1Introduction to XSS
- 2Reflected XSS
- 3Stored XSS
- 4DOM XSS (Part 1 & Part 2)
- 5Escalating XSS to account takeover
16
SQL Injection Fundamentals
- 1SQL programming basics
- 2Introduction to SQL injection vulnerability
- 3SQL injection allowing login bypass
17
Advanced SQL Injection Techniques
- 1UNION attack - determining number of columns
- 2UNION attack - finding a column containing text
- 3UNION attack - retrieving data from other tables
- 4UNION attack - retrieving multiple values
- 5Listing database contents on non-Oracle databases
- 6Blind SQL injection with time delays
- 7Mastering SQLmap step by step
18
Automation In Cybersecurity
- 1Introduction to automation (the core of bug bounty)
- 2When to automate vs test manually
19
Subdomain Enumeration & Reconnaissance Tools
- 1Installing Subfinder for subdomain enumeration
- 2Installing Assetfinder for subdomain enumeration
- 3Configure and install Findomain
20
URL & HTTP Reconnaissance Tools
- 1How to install Waymore URLs
- 2Configure and install HTTPX tool
21
Exploitation Tools - Part 1
- 1Install Katana tool
- 2How to install Nuclei framework
- 3How to install and configure Nuclei templates
22
Exploitation Tools - Part 2
- 1Install Parallel and Qsreplace tools
23
Web Security Automation - Integration
- 1Putting it all together - web security automation Part 1
- 2Web security automation Part 2
- 3Exploitation phase - web security automation Part 3
24
Advanced Automation & Final Chapter
- 1The final chapter: automate everything
- 2Building your personal recon and scan pipeline
25
XML Injection & XXE Attacks
- 1Introduction to XML injection attacks
- 2Exploiting XXE using external entities to retrieve files
- 3Exploiting XXE to perform SSRF attacks
- 4Blind XXE with out-of-band interaction
26
Authentication Vulnerabilities & User Enumeration
- 1Introduction to authentication vulnerabilities
- 2Username enumeration via subtly different responses
- 32FA simple bypass
- 4Password reset broken logic
27
Bug Hunting Methodology & Reporting
- 1Recon-first methodology for bug bounty
- 2Validating impact before writing a report
- 3Writing clear, triage-friendly reports
- 4How to escalate and work with programs
01
Networking Basics
- 1What is a network
- 2LAN, WAN and the internet
- 3IP addressing and subnetting
02
TCP/IP and OSI Model
- 1The OSI 7-layer model
- 2TCP/IP protocol suite
- 3Handshake and packet flow
03
Ports & Services
- 1Common ports and their services
- 2How services listen for connections
- 3Port vs service correlation
04
Servers & Client Systems
- 1How clients and servers interact
- 2Role of DNS and DHCP
- 3Common server roles
05
Pivoting & Lateral Movements in Networking
- 1Why pivoting matters
- 2Routing through a compromised host
- 3Lateral movement concepts
06
Manual Network Scanning
- 1Nmap basics and scan types
- 2Reading scan output
- 3OS and service fingerprinting
07
Advanced Network Enumeration
- 1Service version probing
- 2SMB, RDP, SSH enumeration
- 3Vulnerability mapping against services
08
Automated Tools for Network Scanning
- 1Masscan and fast sweeping
- 2Automating scans with scripts
- 3Integrating results into a workflow
09
Reporting the Infrastructure Engagement
- 1Documenting the attack path
- 2Severity and business impact
- 3Remediation for each finding
01
Pentesting vs Red Team Operations
- 1Differences in goals and mindset
- 2Adversary simulation vs compliance testing
- 3When organisations need a red team
02
MITRE ATT&CK-Based Threat Emulation
- 1Choosing an adversary profile
- 2Emulating techniques from ATT&CK
- 3Planning the operation plan (OP)
03
Info Gathering Under the Hood
- 1Deep-dive active recon
- 2Identifying valuable targets and crown jewels
- 3Attack surface analysis
04
C2 Frameworks Overview
- 1What a C2 is and how it works
- 2Command & control topologies
- 3Overview: Cobalt Strike, Sliver, Mythic, Metasploit
05
Beacons & Payloads
- 1Beacon generation and staging
- 2Payload types: staged vs stageless
- 3Delivering payloads
06
Malware and Its Types
- 1Trojan, ransomware, worm, rootkit
- 2How malware evades detection
- 3Malware analysis intro (static/dynamic)
07
AV / EDR Evasion Techniques
- 1Signature-based detection vs behavioral
- 2Obfuscation, packing and encryption
- 3Living off the land (LOLBins)
08
Persistence Techniques
- 1Registry and startup persistence
- 2Scheduled tasks and services
- 3Account-based persistence
09
Red Team Operation Reporting
- 1Purple teaming and debrief
- 2Technical IOC list for defenders
- 3Executive report with business impact
01
Operating System Basics
- 1What an operating system is
- 2Kernel, user space and processes
- 3File systems and permissions
02
Operating System Types and Usage
- 1Linux distributions for hacking
- 2Windows editions and versions
- 3Choosing the right OS for a task
03
Linux Attack Surface
- 1Services and daemons
- 2Open ports and exposed functions
- 3Common misconfigurations
04
Linux System Enumeration
- 1Basic enumeration commands
- 2User, group and file enumeration
- 3Gathering version and kernel info
05
Linux Exploits (LPE)
- 1Sensitive credentials hunting
- 2Weak file permissions
- 3Cron jobs
- 4SUID wildcard
- 5SUDO - shell escape sequences
- 6SUDO exploitation: LD_PRELOAD and LD_LIBRARY_PATH
- 7SUID exploitation - known vulnerabilities (CVEs)
- 8SUID shared object injection
- 9Linux capabilities
- 10Service exploitation: MySQL (boot to root)
- 11Network File System (NFS)
- 12Revision of Linux PrivEsc
06
Privilege Escalation in Linux
- 1Combining enumeration findings
- 2Automating with LinPEAS
- 3Building a full priv-esc chain
07
Practical Linux Machines (Projects)
- 1Mr.Robot CTF (Linux)
- 2TryHackMe: Vulnversity walkthrough
- 3Skynet walkthrough
- 4DailyBugle TryHackMe walkthrough
- 5Game Zone
- 6Kenobi
08
Windows Attack Surface
- 1Windows services and architecture
- 2Attack surface of SMB, RDP, WinRM
- 3Common Windows misconfigurations
09
Windows System Enumeration
- 1System and user enumeration commands
- 2Service and privilege enumeration
- 3Using WinPEAS for automation
10
Windows Exploits
- 1User Account Control (UAC)
- 2Login to RDP and dropping / receiving files
- 3Windows PrivEsc overview
- 4Windows services abuse (weak executable, weak permission, unquoted paths)
- 5DLL hijacking (intro + practical)
- 6Sensitive credentials hunting (theory + practical)
- 7SAM registry extraction (Part 1 & 2)
- 8Registry autorun exploitation
- 9Weak registry permissions
- 10AlwaysInstallElevated
- 11Impersonation attacks (theory)
- 12SeImpersonate: JuicyPotato, PrintSpoofer, RoguePotato
- 13SeTakeOwnership exploit
- 14Startup apps exploitation
- 15Insecure GUI apps
- 16SeBackupExploit
- 17Kernel exploits: Windows 7 / Windows 10
- 18Scheduled task resource abuse
- 19UAC bypass
11
Privilege Escalation in Windows (WinPeas, Mimikatz)
- 1Using WinPEAS for enumeration
- 2Mimikatz: dumping credentials
- 3Combining techniques into a full escalation path
12
Practical Windows Machines (Projects)
- 1Steel Mountain (WIN)
- 2Alfred walkthrough (WIN)
- 3HackPark TryHackMe (WIN)
- 4Relevant TryHackMe (WIN)
- 5Internal TryHackMe (WIN)
- 6Retro TryHackMe walkthrough (WIN)
13
Reporting the Whole Attack Vector
- 1Documenting the complete kill chain
- 2Screenshots and evidence
- 3Clear remediation for each step
Active Directory Modules — Coming Soon
- 1Modules and topics are being finalised — update coming soon.
Tap any course to expand the full module outline.
1-on-1 Mentorship
Masaud teaches these modules live
Get hands-on guidance through the full curriculum with weekly sessions, labs, and career support.