📚 Learning Paths

Pick a series. Start at chapter one.

Each series is a set of posts meant to be read in order: setup first, then the techniques, then the harder stuff. From building a lab to breaking smart contracts.

Every chapter builds on the previous one
Labs you can reproduce at home
Tools named, commands shown, nothing hand-waved
Browse All Series
Grimoire - Series Icon
10
Series
77
Posts
21
Chapters in the longest series

All Series Available

Choose your path and start your learning journey in offensive security

Building the Offensive Security Playground: A Step-by-Step Guide
3 Posts

Building the Offensive Security Playground: A Step-by-Step Guide

Set up a personal hacking lab on Proxmox: virtual machines, networks and the targets you will use in the other series.

Explore Series
Exploring API Security: A Practical Guide to Uncovering Vulnerabilities
7 Posts

Exploring API Security: A Practical Guide to Uncovering Vulnerabilities

REST and GraphQL from the attacker's side: enumeration, broken auth, mass assignment and BOLA, with Burp Suite and Postman.

Explore Series
Forging Valeris: Building a Rust CLI to Secure Docker & Kubernetes
2 Posts

Forging Valeris: Building a Rust CLI to Secure Docker & Kubernetes

Build log of Valeris, a Rust CLI that scans Docker (and soon Kubernetes) for misconfigurations: design, code, plugin architecture and the checks themselves.

Explore Series
Initiating Linux Binary Exploitation: A Beginner's Expedition into Code Manipulation
11 Posts

Initiating Linux Binary Exploitation: A Beginner's Expedition into Code Manipulation

Linux binary exploitation from the start: assembly, stack overflows, format strings, shellcode and the mitigations that get in the way.

Explore Series
Navigating the Active Directory Maze: Unveiling Hacking Strategies
15 Posts

Navigating the Active Directory Maze: Unveiling Hacking Strategies

Active Directory from enumeration to domain admin: Kerberos, NTLM, credential theft and lateral movement with PowerShell, Mimikatz and BloodHound.

Explore Series
No More Enemies: The Battle for Inner Freedom
1 Post

No More Enemies: The Battle for Inner Freedom

Notes on focus, discipline and purpose. The only series here that is not about breaking computers.

Explore Series
Open Source Web Hacking Mastery: A Junior's Guide to Methodical Penetration Testing
6 Posts

Open Source Web Hacking Mastery: A Junior's Guide to Methodical Penetration Testing

Web application testing with open-source tools like Nuclei and mitmproxy, practised on OWASP Juice Shop.

Explore Series
Python Prowess: Ethical Hacking Explorations for Security Enthusiasts
1 Post

Python Prowess: Ethical Hacking Explorations for Security Enthusiasts

Python for offensive work: web exploitation, cryptography and pentest tooling, one script at a time.

Explore Series
Securing Android: An In-Depth Exploration
10 Posts

Securing Android: An In-Depth Exploration

Android app security through the Damn Vulnerable Bank app: finding, exploiting and fixing common and less common mobile flaws.

Explore Series
Web3 Exploitation Fundamentals: Navigating Security in Decentralized Systems
21 Posts

Web3 Exploitation Fundamentals: Navigating Security in Decentralized Systems

Smart contract exploitation with Foundry and Hardhat: reentrancy, front-running, signatures, proxies and the defenses that actually hold.

Explore Series