EXPLORE THE CURRICULUM
Your learning map
See how it fits together. Find the lesson you want to learn next.
14 lessons · Security research
Reset filtersL4Vulnerability research & contributionStep 314–32310 lessons
- 314 Starting Bug Bounty — Understanding the System and Picking Your First TargetExplain the structure of the bug bounty system (platforms, programs, triage)
- 315 Real-Service Recon — Attack Surface MappingExecute the 4 stages of the recon chain — collect → liveness check → classify → map — in order
- 316 Vulnerability Discovery — A Systematic Feature-by-Feature ApproachExplain why "scanner dependence" is a beginner's trap
- 317 Verifying Candidates and Confirming ImpactApply the "is it a bug or not" judgment criteria (reproducibility + security impact)
- 318 Writing a Report That Gets AcceptedExplain the standard report structure (summary · reproduction steps · impact · fix suggestion · evidence)
- 319 Submitting Your First Report & Handling Triage — The Real Work Starts After the ButtonExplain the triage flow a submitted report goes through (intake → review → verdict)
- 320 1-day Vulnerability Analysis — Reverse-Engineering the Flaw from a Patch diffExplain what a 1-day vulnerability and patch-diff analysis are, and why they're powerful
- 321 CVE Reproduction and Publishing the Analysis Report — The Proof of an Analysis Is ReproductionExplain the structure of reproduction proof: "success on the vulnerable version + blocked on the patched versi…
- 322 Second CVE: Independent Analysis — Standing Alone Through the Analysis CyclePerform the full 1-day analysis cycle alone, guided only by a checklist
- 323 Publishing an Open-Source Tool and Contributing to the Community — Code as a WorkChoose a tool to publish and clean its code into "a state others can use"
L4New fields & integrated practiceStep 341–3444 lessons
- 341 Exploring the Next Growth Axis — Cloud/Mobile/IoT Security: A New Layer to Lay on the Fundamentals You've BuiltExplain the attack surfaces and representative resources of the four areas: cloud, mobile, IoT, and AI securit…
- 342 Launching into a New Field — With the Posture of Level 0 and a Proven MethodologyFind the selected area's standard entry path (official docs, beginner labs, community curricula) and fix its t…
- 343 The Integrated Intrusion Scenario — Operating Your Full Capability: From a List of Techniques to an OperationDefine an intrusion scenario with the three elements of goal, starting point, and rules
- 344 Penetration Playbook v2.0 — The Cycle Where Experience Becomes a ManualExhaustively collect the assets accumulated since v1.0 (checklists, timelines, lessons) and build a revision-c…