Resources

Learn the craft. Meet the people doing it.

The Academy is free to browse and free to join. Below it, the community where findings get discussed and the board where security work gets hired. Everything here is open — you do not need a program to start.

Learn

The Academy.

Over a hundred hands-on labs across every vulnerability class, plus the reading and the walkthroughs that go around them. Browsing is open to everyone; joining is free and one click, and it is what unlocks flag submission and progress.

How it fits together

Concept to capture to a real finding.

  1. 01

    Read the concept

    What a class of bug actually is, before you go looking for one.

  2. 02

    Watch the walkthrough

    A short video of someone finding it, so you know what the process looks like.

  3. 03

    Capture the flag

    A hands-on lab at one of four difficulty tiers. Hints cost points; the walkthrough forfeits them.

    → Points and a level

  4. 04

    Finish the course

    A guided path that strings readings and labs into one sequence, tracked to completion.

    → Course progress

  5. 05

    Hunt for real

    Take it to a live program and file your first report. That is a different scoreboard, and it is the one that counts.

    → Reputation

Write-ups

What researchers are publishing.

All write-ups →

Community

Threads on technique, disclosure and the platform itself, organised by vulnerability class and specialty. Researchers and companies both post here.

Open the community →

Talent

Companies listing security roles, and researchers open to work. Both sides are reviewed before anything is published.

3 hiring · 4 open to work

Open the board →