Academy · Courses

Guided paths

Each course moves from the concept, through a walkthrough, to the labs that prove you have it — in order. Start one and it remembers where you left off.

ApprenticeWeb application

Web Security Foundations

The groundwork every other path stands on — HTTP, access control and injection.

5 lessons
PractitionerBroken access control / IDOR

Access Control in Depth

IDOR, mass assignment and privilege escalation, from the obvious to the chained.

5 lessons
ExpertSQL / command injection

Injection Mastery

SQL, blind extraction and command injection, up to remote code execution.

4 lessons
PractitionerCross-site scripting (XSS)

Client-Side Attacks

XSS and CSRF — everything that runs in somebody else's browser.

5 lessons
ExpertServer-side request forgery (SSRF)

Server-Side Request Forgery

Make the server fetch what it should not — up to the cloud metadata endpoint.

3 lessons
MasterCryptographic weakness

Breaking Crypto & Race Conditions

Predictable tokens, forgeable signatures, and the window between check and use.

4 lessons