kavklaw@llm $ ./start_training.sh
Offensive, defensive, and full-spectrum security in 9 phases. Hands-on exercises, quizzes, interview prep, and a full box walkthrough. Pick a track and go.
Pick the track that matches your goals, or follow all three.
Learn to think like an attacker. Penetration testing, exploitation, privilege escalation, and Active Directory attacks.
Learn to detect, respond, and defend. Incident response, log analysis, threat detection, SIEM, and network monitoring.
Both sides. How attackers operate AND how defenders detect them. The full picture.
💡 Recommendation: Start with Phase 0 (Lab Setup) and Phase 1 (Foundations) regardless of track — they're prerequisites for everything else. After that, follow your color. Not sure? Go Purple. Knowing both sides makes you better at either one.
✅ = Core for this track 📖 = Recommended reading
Click any phase to jump in. Following them in order works best.
Install VMs, configure networking, build your hacking environment.
Start →Networking, Linux, web tech, and cryptography — the essentials everything else builds on.
Continue →Passive & active recon, OSINT, Nmap, DNS enumeration, and directory fuzzing.
Continue →SQL injection, XSS, SSRF, command injection, auth bypass, and Burp Suite.
Continue →Reverse shells, privilege escalation on Linux & Windows, SUID, and post-exploitation.
Continue →Kerberoasting, BloodHound, NTLM relay, DCSync, Golden Tickets, and domain takeover.
Continue →Put it all together — complete walkthrough from recon to root.
Take the Challenge →Incident response, SIEM, log analysis, threat detection, and network monitoring.
Continue →Certifications (OSCP, CEH, BTL1), interview prep, resume building, and specializations.
Continue →