Learn to hack. For free. Prove it.
Structured paths in web exploitation, bug bounty, network defense, malware and cloud, you read a beat, then immediately do it in a real terminal. No card. No setup.
Become a Bug Bounty Hunter
A territory, not a to-do list. Each node is a real task you have to solve, see exactly where you are and what’s next.
- ✓Recon4 tasks
- ✓Web Exploitation9 tasks
- Access Control6 tasks
- Chaining Bugs5 tasks
- Out-of-band4 tasks
- The Report3 tasks
One finding, start to finish
scroll to advanceThis is the shape of every path here: look, get in, go deeper, connect two things, then write it up so someone can act on it.
api.target.lab staging.target.lab legacy.target.lab
Map the surface before touching it. Most findings start here.
200 OK {"id":1042,"email":"a***@target.lab"}One object reference, one identifier you were never meant to change.
200 OK {"id":1,"role":"admin"}Access control fails quietly. That is what makes it worth reporting.
iam/security-credentials/app-role
Two medium bugs become one critical when they touch each other.
evidence bundle ready · 3 screenshots · 1 request/response pair
Anyone can find it. You get paid for proving it, cleanly.
“Most security training sells you noise. We teach you to find the signal, and to prove it’s real.”
Learning paths
6 paths · more weeklyGet ThreatFound before everyone else.
We’re opening continuous exposure monitoring — the same proof-first engine, now watching the domains you own for leaked keys, exposed .env/.git files and subdomain takeover. Join the waitlist for first access, plus new courses as they drop.
No spam · we only monitor domains you own · unsubscribe anytime
- ✓operator_4fSSRF → cloud metadata2m ago
- ✓null_byteStored XSS in profile6m ago
- ✓m4lware_kUnpacking a packed sample11m ago
- ✓recon_dogSubdomain takeover18m ago
Join free, keep a daily streak, climb the board. Earn evidence, never pay for it.
Everything here is for defenders and authorized testing. Practise on the included labs and intentionally-vulnerable targets, only ever test systems you own or are explicitly authorized to assess.