01 / Curriculum
Course Outlines
Nine courses. Full step-by-step outlines. Tap any course to open its complete module list — expand each one to see every topic covered.
01
Cyber Security & Ethical Hacking Overview
- What is cybersecurity and why it matters
- Ethical hacking vs black hat / grey hat hacking
- Roles: pentester, red teamer, security researcher
02
Methodologies - NIST, PTES, OWASP
- NIST SP 800-115 assessment framework
- PTES: Pre-Engagement to Reporting
- When to use OWASP Testing Guide (web) vs OSSTMM (general)
03
MITRE ATT&CK Framework
- Tactics, techniques and procedures (TTPs)
- Navigating ATT&CK Navigator
- Mapping real attacks to ATT&CK techniques
04
Pre-Engagement
- Scoping, rules of engagement (RoE)
- Legal considerations and authorization
- Kick-off meeting and deliverables agreement
05
Reconnaissance / Information Gathering
- Passive vs active recon
- Footprinting a target
- Documenting findings for the next phase
06
Vulnerability Assessment & Threat Modeling
- Identifying weaknesses in scope
- Asset classification and attack-surface review
- Prioritising findings by risk
07
Exploitation
- Exploiting identified vulnerabilities safely
- Getting initial access
- Proving impact without causing damage
08
Post-Exploitation (Introduction)
- Lateral movement basics
- Privilege escalation intro
- Maintaining access (covered in depth later)
09
Reporting
- Writing a professional pentest report
- Executive summary vs technical detail
- Remediation advice and retesting
01
Introduction To Ethical Hacking & Overview
- Offensive And Defensive Security
02
Hacking Environment Setup: Kali Linux & Linux Mastery
- How To Install Kali Linux On Your Computer
- Master Linux From Basic To Advanced
03
Web Application Testing Fundamentals
- Burpsuite For Web Application Pentesting
- Master BurpSuite Professional In One Lecture
04
File Path Traversal Vulnerabilities
- File path traversal, simple case
- File path traversal, traversal sequences blocked with absolute path bypass
- File path traversal, traversal sequences stripped non-recursively
- Automation of File path traversal vulnerabilities
05
Information Disclosure Vulnerabilities
- Information Leakage Vulnerabilities
- Information Leakage In Error Messages
- Information Leakage On Debug Page
- Source Code Disclosure Via Backup Files
- Automating Information Disclosure Discovery: Feroxbuster, FFUF, Dirbuster & Dirb Step by Step
06
Automated Information Disclosure Techniques
- Automate The Process Of Finding Information Disclosure Vulnerabilities
07
OS Command Injection
- Introduction To OS Command Injection
- OS Command Injection Simple Case
- Blind OS Command Injection With Time Delays
- Blind OS Command Injection With Output Redirection
08
SSRF Vulnerabilities
- Introduction To SSRF Vulnerability
- Basic SSRF Against The Local Server
- SSRF Against Blacklist-Based Input Filter
- Basic SSRF Against Another Back-End System
09
File Upload Vulnerabilities & Remote Code Execution
- Introduction To File Upload Vulnerabilities
- Remote Code Execution Via Web Shell Upload
- Web Shell Upload Via Content-Type Restriction Bypass
- Web Shell Upload Via Path Traversal
- Remote Code Execution Via Polyglot Web Shell Upload
- Web Shell Upload Via Obfuscated File Extension
10
Access Control Vulnerabilities
- Introduction To Access Control Vulnerabilities
- Unprotected Admin Functionality
- Unprotected Admin Functionality With Unpredictable URL
- User Role Controlled By Request Parameter
- User Role Can Be Modified In User Profile
- Insecure Direct Object References
- User ID Controlled By Request Parameter With Password Disclosure
11
Business Logic Vulnerabilities
- Introduction To Business Logic Vulnerabilities
- Excessive Trust In Client-Side Controls
- High-Level Logic Vulnerability
- Inconsistent Security Controls
- Flawed Enforcement Of Business Rules
- Weak Isolation On Dual-Use Endpoint
- Insufficient Workflow Validation
12
Cross-Site Scripting (XSS)
- Introduction To XSS-Cross Site Scripting
- Reflected XSS
- Stored XSS
- DOM XSS
- DOM XSS- Part 2
13
SQL Injection Fundamentals
- SQL Programming
- Introduction To SQL Injection Vulnerability
- SQL Injection Vulnerability Allowing Login Bypass
14
Advanced SQL Injection Techniques
- SQL Injection UNION Attack, Determining Number Of Columns
- SQL Injection UNION Attack, Finding A Column Containing Text
- SQL Injection UNION Attack, Retrieving Data From Other Tables
- SQL Injection UNION Attack, Retrieving Multiple Values
- SQL Injection Attack, Listing Database Contents On Non-Oracle Databases
- Blind SQL Injection With Time Delays
- Mastering SQLmap Step by Step
15
Automation In Cybersecurity
- Introduction To Automation (The Core Of Cybersecurity)
16
Subdomain Enumeration & Reconnaissance Tools
- Installation Of Subfinder - Subdomain Enumeration
- Installation Of Assetfinder - Subdomain Enumeration
- Configure And Install Findomain - Subdomain Enumeration
17
URL & HTTP Reconnaissance Tools
- How To Install Waymore URLs
- Configure And Install HTTPX Tool
18
Exploitation Tools - Part 1
- Install Katana Tool
- How To Install Nuclei Framework - Exploitation
- How To Install And Configure Nuclei Templates
19
Exploitation Tools - Part 2
- Install Parallel, Qsreplace Tools
20
Web Security Automation - Integration
- Putting It All Together - Web Security Automation Part: 1
- Web Security Automation Part: 2
21
Web Security Automation - Exploitation Phase
- Exploitation Phase - Web Security Automation Part: 3
22
Advanced Automation & Final Chapter
- The Final Chapter; Automate Everything
23
XML Injection & XXE Attacks
- Introduction To XML Injection Attacks
- Exploiting XXE Using External Entities To Retrieve Files
- Exploiting XXE To Perform SSRF Attacks
- Blind XXE With Out-Of-Band Interaction
24
Authentication Vulnerabilities & User Enumeration
- Introduction To Authentication Vulnerabilities
- Username Enumeration Via Subtly Different Responses
- 2FA Simple Bypass
- Password Reset Broken Logic
25
Reconnaissance & Vulnerability Assessment
- The Art Of Hacking- Reconnaissance
- NetSec Challange- Reconnaissance Part 2
- Practical Vulnerabilities Exploitation
- Penetration Testing Vulnerabilities 101
26
Metasploit & Exploitation Frameworks
- Mastering Metasploit Framwork Part 1
- Hack Windows Machine Using Metasploit
27
Linux Privilege Escalation
- Sensitive Credentials Hunting
- Weak File Permissions
- Cron Jobs
- SUID Wildcard
- SUDO - Shell Escape Sequences
- SUDO Exploitation ld_preload
- SUDO LD_LIBRARY_PATH
- SUID Exploitation - Known Vulnerabilities (CVEs)
- SUID Shared Object Injection
- Linux Capabilities
- Service Exploitation: MySQL (Boot to Root)
- Network File System (NFS)
- Revision of LinuxPrivEsc
28
Practical Hacking into Linux Machines (Projects)
- Mr.Robot CTF Linux
- TryHackMe CTF: Vulnversity - Walkthrough Linux
- Skynet Walkthrough Linux
- DailyBugle TryHackMe Walkthrough Linux
- Game Zone Linux
- Kenobi Linux
29
Windows Privilege Architecture & Escalation
- User Account Control (UAC)
- Login to RDP and Dropping Files + Receiving
- Windows PrivEsc (Overview)
- Windows Services
- Service Abuse: Weak Service Executable
- Service Abuse: Weak Service Permission
- Service Abuse: Unquoted Service Paths
- Service Abuse: DLL Hijacking Intro
- Service Abuse: DLL Hijacking Practical
- Sensitive Credentials Hunting Theory
- Sensitive Credentials Hunting
- Part 1: SAM (Security Account Manager)
- Part 2: SAM (Security Account Manager)
- Introduction to Windows Registry
- Lab: Registry Autorun Exploitation
- Lab: Weak Registry Permissions
- AlwaysInstallElevated
- Theory - Impersonation Attacks
- [LAB] SeImpersonate Exploit: JuicyPotato
- Lab: PrintSpoofer (The King of Token Impersonation)
- [LAB] RoguePotato (Token Impersonation)
- Universal Methodology: SeTakeOwnership Exploit
- Startup Apps Exploitation
- Insecure GUI Apps
- seBackupExploit
- Kernel Exploit Windows 7
- Windows 10 Kernel Exploitation
- Attack Vector: Scheduled Task Resource Abuse
- UAC (User Account Control) Bypass
30
Practical Hacking into Windows Machines (Projects)
- Steel Mountain | WIN
- Alfred Walkthrough WIN
- HackPark TryHackMe WIN
- Relevant (TryHackMe) WIN
- Internal (TryHackMe) WIN
- Retro TryHackMe Walkthrough WIN
31
Advanced / Miscellaneous Topics
- Master Metasploit Overview
- Port Forwarding, Tunneling and Pivoting
- Port Forwarding, Tunneling and Pivoting in WINDOWS
32
Bash Scripting - Advanced Module
- Introduction to Bash Scripting
- Variables, Loops and Conditions
- Functions and Automation Scripting
- Writing Custom Recon Tools in Bash
33
Python for Hackers
- Introduction to Python Programming
- Network Programming (Sockets & Requests)
- Building Custom Exploits in Python
- Automating Tools with Python
34
AI in Red Teaming & Bug Bounty
- How to use AI to Hack Machines
- Using AI for Red Teaming and Pentesting
- Automating Bug Bounty Workflows with AI
- Creating Custom Exploits and Analysis using LLMs
01
OSINT Introduction & Framework
- What OSINT is and its legal boundaries
- The OSINT cycle: collection, analysis, reporting
- Setting up a safe and private OSINT workspace
02
Google Dorking & Search Techniques
- Google operators: site:, inurl:, filetype:
- Advanced search combinations
- Building your own dork cheatsheet
03
People, User & Email Investigation
- Username search across platforms
- Email breach lookups and format analysis
- Building a persona profile
04
Domain & IP Investigation (Shodan, Censys, WHOIS)
- WHOIS records and history
- Shodan / Censys host discovery
- DNS records and reverse lookups
05
SOCMINT (Social Media OSINT)
- Social media footprint analysis
- Metadata and EXIF extraction
- Geolocation from photos and posts
06
Corporate / Business Investigation
- Company structure and subsidiaries
- Employee disclosure analysis
- Suppliers, partners and tech stack
07
Social Engineering & Pretexting Techniques
- Phishing psychology and pretexts
- Open-source intel that powers pretexting
- Defensive awareness for each technique
08
Phishing Campaign Design
- Planning an engagement campaign
- Cloning / lures (in a lab only)
- Measuring and reporting results
09
OSINT Tooling & Automation
- theHarvester, Maltego, recon-ng
- Automating collection with scripts
- Organising data for analysis
10
Investigation / Recon Reporting
- Timeline building
- Attribution and confidence levels
- Writing a professional OSINT report
01
Websites & Web Application Structure
- HTTP/HTTPS request and response anatomy
- Client-side vs server-side processing
- Databases, sessions and cookies
02
Web Pentesting Setup
- Installing Burp Suite Community / Pro
- Configuring the browser proxy
- TLS/SSL interception and certificates
03
Bug Hunting Platforms Setup
- HackerOne / Bugcrowd / Intigriti profiles
- Reading scope and rules of engagement
- Using lab platforms: PortSwigger Web Security Academy, HackTheBox, TryHackMe
04
Burp Suite For Web Application Pentesting
- Proxy, Repeater, Intruder, Sequencer, Decoder
- Intercepting and modifying requests
- Common gotchas and workspace setup
05
Mastering Burp Suite Professional
- Project options, scope and sitemap
- Extensions: Active Scan++, Turbo Intruder, Logger++
- Automating workflow with BApp extensions
06
OWASP Top 10 Web Vulnerabilities
- A01 Broken Access Control, A02 Cryptographic Failures
- A03 Injection, A04 Insecure Design
- A05-A10: misconfig, vulnerable components, auth and logging failures
07
File Path Traversal Vulnerabilities
- Simple file path traversal case
- Traversal sequences blocked with absolute-path bypass
- Stripped non-recursively bypass
- Automating file path traversal discovery
08
Information Disclosure Vulnerabilities
- Information leakage basics
- Information leakage in error messages
- Information leakage on debug page
- Source code disclosure via backup files
- Automation with Feroxbuster, FFUF, Dirbuster & Dirb
09
Automated Information Disclosure Techniques
- Automating the process of finding info-disclosure bugs
- Building a repeatable discovery script
- Fuzzing for hidden endpoints and files
10
OS Command Injection
- Introduction to OS command injection
- Simple command injection case
- Blind command injection with time delays
- Blind command injection with output redirection
11
SSRF Vulnerabilities
- Introduction to SSRF
- Basic SSRF against the local server
- SSRF against blacklist-based input filters
- Basic SSRF against another back-end system
12
File Upload Vulnerabilities & RCE
- Introduction to file upload vulnerabilities
- RCE via web shell upload
- Web shell upload via content-type restriction bypass
- Web shell upload via path traversal
- RCE via polyglot web shell upload
- Web shell upload via obfuscated file extension
13
Access Control Vulnerabilities
- Introduction to access control vulnerabilities
- Unprotected admin functionality
- Unprotected admin functionality with unpredictable URL
- User role controlled by request parameter
- User role modified in user profile
- Insecure Direct Object References (IDOR)
- User ID controlled by request parameter with password disclosure
14
Business Logic Vulnerabilities
- Introduction to business logic vulnerabilities
- Excessive trust in client-side controls
- High-level logic vulnerability
- Inconsistent security controls
- Flawed enforcement of business rules
- Weak isolation on dual-use endpoint
- Insufficient workflow validation
15
Cross-Site Scripting (XSS)
- Introduction to XSS
- Reflected XSS
- Stored XSS
- DOM XSS (Part 1 & Part 2)
- Escalating XSS to account takeover
16
SQL Injection Fundamentals
- SQL programming basics
- Introduction to SQL injection vulnerability
- SQL injection allowing login bypass
17
Advanced SQL Injection Techniques
- UNION attack - determining number of columns
- UNION attack - finding a column containing text
- UNION attack - retrieving data from other tables
- UNION attack - retrieving multiple values
- Listing database contents on non-Oracle databases
- Blind SQL injection with time delays
- Mastering SQLmap step by step
18
Automation In Cybersecurity
- Introduction to automation (the core of bug bounty)
- When to automate vs test manually
19
Subdomain Enumeration & Reconnaissance Tools
- Installing Subfinder for subdomain enumeration
- Installing Assetfinder for subdomain enumeration
- Configure and install Findomain
20
URL & HTTP Reconnaissance Tools
- How to install Waymore URLs
- Configure and install HTTPX tool
21
Exploitation Tools - Part 1
- Install Katana tool
- How to install Nuclei framework
- How to install and configure Nuclei templates
22
Exploitation Tools - Part 2
- Install Parallel and Qsreplace tools
23
Web Security Automation - Integration
- Putting it all together - web security automation Part 1
- Web security automation Part 2
- Exploitation phase - web security automation Part 3
24
Advanced Automation & Final Chapter
- The final chapter: automate everything
- Building your personal recon and scan pipeline
25
XML Injection & XXE Attacks
- Introduction to XML injection attacks
- Exploiting XXE using external entities to retrieve files
- Exploiting XXE to perform SSRF attacks
- Blind XXE with out-of-band interaction
26
Authentication Vulnerabilities & User Enumeration
- Introduction to authentication vulnerabilities
- Username enumeration via subtly different responses
- 2FA simple bypass
- Password reset broken logic
27
Bug Hunting Methodology & Reporting
- Recon-first methodology for bug bounty
- Validating impact before writing a report
- Writing clear, triage-friendly reports
- How to escalate and work with programs
01
Networking Basics
- What is a network
- LAN, WAN and the internet
- IP addressing and subnetting
02
TCP/IP and OSI Model
- The OSI 7-layer model
- TCP/IP protocol suite
- Handshake and packet flow
03
Ports & Services
- Common ports and their services
- How services listen for connections
- Port vs service correlation
04
Servers & Client Systems
- How clients and servers interact
- Role of DNS and DHCP
- Common server roles
05
Pivoting & Lateral Movements in Networking
- Why pivoting matters
- Routing through a compromised host
- Lateral movement concepts
06
Manual Network Scanning
- Nmap basics and scan types
- Reading scan output
- OS and service fingerprinting
07
Advanced Network Enumeration
- Service version probing
- SMB, RDP, SSH enumeration
- Vulnerability mapping against services
08
Automated Tools for Network Scanning
- Masscan and fast sweeping
- Automating scans with scripts
- Integrating results into a workflow
09
Reporting the Infrastructure Engagement
- Documenting the attack path
- Severity and business impact
- Remediation for each finding
01
Pentesting vs Red Team Operations
- Differences in goals and mindset
- Adversary simulation vs compliance testing
- When organisations need a red team
02
MITRE ATT&CK-Based Threat Emulation
- Choosing an adversary profile
- Emulating techniques from ATT&CK
- Planning the operation plan (OP)
03
Info Gathering Under the Hood
- Deep-dive active recon
- Identifying valuable targets and crown jewels
- Attack surface analysis
04
C2 Frameworks Overview
- What a C2 is and how it works
- Command & control topologies
- Overview: Cobalt Strike, Sliver, Mythic, Metasploit
05
Beacons & Payloads
- Beacon generation and staging
- Payload types: staged vs stageless
- Delivering payloads
06
Malware and Its Types
- Trojan, ransomware, worm, rootkit
- How malware evades detection
- Malware analysis intro (static/dynamic)
07
AV / EDR Evasion Techniques
- Signature-based detection vs behavioral
- Obfuscation, packing and encryption
- Living off the land (LOLBins)
08
Persistence Techniques
- Registry and startup persistence
- Scheduled tasks and services
- Account-based persistence
09
Red Team Operation Reporting
- Purple teaming and debrief
- Technical IOC list for defenders
- Executive report with business impact
01
Operating System Basics
- What an operating system is
- Kernel, user space and processes
- File systems and permissions
02
Operating System Types and Usage
- Linux distributions for hacking
- Windows editions and versions
- Choosing the right OS for a task
03
Linux Attack Surface
- Services and daemons
- Open ports and exposed functions
- Common misconfigurations
04
Linux System Enumeration
- Basic enumeration commands
- User, group and file enumeration
- Gathering version and kernel info
05
Linux Exploits (LPE)
- Sensitive credentials hunting
- Weak file permissions
- Cron jobs
- SUID wildcard
- SUDO - shell escape sequences
- SUDO exploitation: LD_PRELOAD and LD_LIBRARY_PATH
- SUID exploitation - known vulnerabilities (CVEs)
- SUID shared object injection
- Linux capabilities
- Service exploitation: MySQL (boot to root)
- Network File System (NFS)
- Revision of Linux PrivEsc
06
Privilege Escalation in Linux
- Combining enumeration findings
- Automating with LinPEAS
- Building a full priv-esc chain
07
Practical Linux Machines (Projects)
- Mr.Robot CTF (Linux)
- TryHackMe: Vulnversity walkthrough
- Skynet walkthrough
- DailyBugle TryHackMe walkthrough
- Game Zone
- Kenobi
08
Windows Attack Surface
- Windows services and architecture
- Attack surface of SMB, RDP, WinRM
- Common Windows misconfigurations
09
Windows System Enumeration
- System and user enumeration commands
- Service and privilege enumeration
- Using WinPEAS for automation
10
Windows Exploits
- User Account Control (UAC)
- Login to RDP and dropping / receiving files
- Windows PrivEsc overview
- Windows services abuse (weak executable, weak permission, unquoted paths)
- DLL hijacking (intro + practical)
- Sensitive credentials hunting (theory + practical)
- SAM registry extraction (Part 1 & 2)
- Registry autorun exploitation
- Weak registry permissions
- AlwaysInstallElevated
- Impersonation attacks (theory)
- SeImpersonate: JuicyPotato, PrintSpoofer, RoguePotato
- SeTakeOwnership exploit
- Startup apps exploitation
- Insecure GUI apps
- SeBackupExploit
- Kernel exploits: Windows 7 / Windows 10
- Scheduled task resource abuse
- UAC bypass
11
Privilege Escalation in Windows (WinPeas, Mimikatz)
- Using WinPEAS for enumeration
- Mimikatz: dumping credentials
- Combining techniques into a full escalation path
12
Practical Windows Machines (Projects)
- Steel Mountain (WIN)
- Alfred walkthrough (WIN)
- HackPark TryHackMe (WIN)
- Relevant TryHackMe (WIN)
- Internal TryHackMe (WIN)
- Retro TryHackMe walkthrough (WIN)
13
Reporting the Whole Attack Vector
- Documenting the complete kill chain
- Screenshots and evidence
- Clear remediation for each step
Active Directory Modules — Coming Soon
- Modules and topics are being finalised — update coming soon.
Tap any course to expand the full module outline.
1-on-1 Mentorship
Masaud teaches these modules live
Get hands-on guidance through the full curriculum with weekly sessions, labs, and career support.