Skip to content

Recorded live programme · Beginner to advanced

Learn security in the order it actually builds.

One ordered route from IPv4 subnetting to HTTP request smuggling66 recorded live sessions, every lab solved on screen, every dead end left in. No prerequisites, no subscription, no module sold separately.

One payment, lifetime access. ₹14,800 estimated value across the 10 modules.

recorded sessions
66

recorded sessions

hours
82+

hours

modules
10

modules

tools driven
36

tools driven

rootpath — the route

$ rootpath --list-modules

  1. 01Networking12 sessions16 h 10 m
  2. 02Linux6 sessions7 h 33 m
  3. 03Recon6 sessions7 h 50 m
  4. 04Web core5 sessions6 h 18 m
  5. 05OWASP6 sessions7 h 51 m
  6. 06Advanced web11 sessions15 h 40 m
  7. 07Browser3 sessions2 h 49 m
  8. 08Python7 sessions7 h 29 m
  9. 09Cloud6 sessions6 h 22 m
  10. 10CTF4 sessions4 h 28 m

10 modules · 66 sessions · 82+ hours

$

  • Driven on screen
  • Cisco Packet Tracer
  • whois
  • dig
  • Linux
  • Bash
  • apt
  • dpkg
  • SSH
  • Shodan
  • exploit-db
  • Sublist3r
  • SubBrute
  • VirusTotal
  • Gitrob
  • GitHound
  • Hunter.io
  • theHarvester
  • Nmap
  • SQLMap
  • Burp Suite
  • Hacker101
  • PortSwigger Labs
  • jwt.io
  • OWASP
  • smuggler
  • Browser DevTools
  • Python
  • requests
  • pip
  • AWS
  • EC2
  • S3
  • IAM
  • AWS CLI
  • picoCTF
  • CyberChef

The route

10 modules, walked in order

Each stage assumes the one before it and nothing else. Start at 01 if you are new, or join where your gap actually is — but the order is the product, not a suggestion.

Foundation

The ground nothing else stands on. Start here even if you think you know it.

  1. 01

    12 sessions · 16 h 10 m · Sessions 1–12

    IPv4, subnetting and CIDR, the OSI model layer by layer, routing and switching configured live in Cisco Packet Tracer, then DNS and the transport layer. Every attack later in the programme is an abuse of something in this module.

    • Cisco Packet Tracer
    • whois
    • dig
  2. 02

    6 sessions · 7 h 33 m · Sessions 15–17, 20–22

    Linux installed in a VM and then driven entirely from the command line — users and permissions, the file system, package management, SSH, and Bash scripts that take arguments and do real work.

    • Linux
    • Bash
    • apt
    • dpkg
    • SSH
    • Shodan
    • exploit-db

Offensive

Finding the flaw, proving it, and writing it up. The bulk of the programme.

  1. 03

    6 sessions · 7 h 50 m · Sessions 13–14, 18–19, 59–60

    Everything a target publishes without meaning to: subdomains, dorks, leaked keys in public repositories, staff email addresses — then Nmap to turn a map into a list of open doors.

    • Sublist3r
    • SubBrute
    • VirusTotal
    • Gitrob
    • GitHound
    • Hunter.io
    • theHarvester
    • Nmap
  2. 04
    Core Web AttacksIntermediate

    5 sessions · 6 h 18 m · Sessions 23–27

    The four that appear in almost every report: SQL injection by hand and with SQLMap, IDOR against a real API, JWT flaws, and cross-site request forgery — each one exploited in a lab before it is defended.

    • SQLMap
    • Burp Suite
    • Hacker101
    • PortSwigger Labs
    • jwt.io
  3. 05

    6 sessions · 7 h 51 m · Sessions 43–48

    Both editions of the OWASP Top 10 and the API Top 10 — because interviewers still ask about 2017 — then CSRF protection bypass, every type of XSS, and SSRF with its filters defeated.

    • PortSwigger Labs
    • Burp Suite
    • OWASP
  4. 06

    11 sessions · 15 h 40 m · Sessions 49–52, 55–58, 61–63

    The eleven sessions that separate a scanner operator from a tester: authentication bypass and 2FA defeat, information disclosure, both HTTP request smuggling desyncs, business logic flaws, host header attacks and directory traversal.

    • Burp Suite
    • smuggler
    • PortSwigger Labs
    • Hacker101
  5. 07

    3 sessions · 2 h 49 m · Sessions 64–66

    How the browser itself decides what is allowed: session management and fixation, the SSL handshake, cookie attributes, the Same-Origin Policy and CORS — plus the closing project discussion.

    • Burp Suite
    • Browser DevTools

Toolkit

What turns a one-off finding into work you can repeat and get paid for.

  1. 08

    7 sessions · 7 h 29 m · Sessions 28–34

    Python taught for scripting a scanner, not for passing a CS exam — types and collections, control flow, functions, the standard library modules that matter, requests, and enough OOP to structure a tool.

    • Python
    • requests
    • pip
  2. 09

    6 sessions · 6 h 22 m · Sessions 35–38, 53–54

    EC2, S3 and the identity model hands-on, then the same account attacked: S3 bucket misconfiguration through the AWS CLI, and IAM users, groups and policies written to shut it down.

    • AWS
    • EC2
    • S3
    • IAM
    • AWS CLI
  3. 10

    4 sessions · 4 h 28 m · Sessions 39–42

    Real picoCTF challenges solved end to end — including the wrong turns — across web, general skills and cryptography, with the hashing and encryption theory that the crypto challenges need.

    • picoCTF
    • CyberChef
    • Hacker101

Compare

You could assemble this yourself

--- a/self-taught

+++ b/rootpath (₹699)

  • Twelve browser tabs, none of which agree on what to learn next
  • Tutorials that stop at the definition and never exploit anything
  • No idea whether you have a gap until an interview finds it for you
  • Labs shown already solved, with the failed attempts edited out
  • Tool videos recorded against a version that changed two years ago
  • Nobody to ask when the payload does not land
  • One ordered route, numbered, with each module naming what it assumes
  • Every technique exploited in a lab before it is defended
  • Full session list published up front — you can see the gaps before you pay
  • Real live recordings, dead ends and debugging left in
  • Networking, Linux, Python, AWS and web all in one library, taught to fit together
  • A support address that a person answers

Everything on the left is genuinely free and genuinely good — PortSwigger’s Academy, picoCTF and the OWASP documentation are all used inside this programme. What you are paying for is the order, the completeness and somebody having already worked out which twelve tabs were the right ones.

The offer

Everything, for one payment

No subscription, no renewal, no per-module upsell, no cheaper tier that quietly leaves things out. The price you see is the only price there is.

Estimated standalone value of each module, and the single price for all of them
IncludedEstimated value
01

Networking & Protocol Foundations

12 sessions · 16 h 10 m

₹2,000
02

Linux, the Shell & Bash Scripting

6 sessions · 7 h 33 m

₹1,200
03

Reconnaissance, OSINT & Scanning

6 sessions · 7 h 50 m

₹1,300
04

Core Web Attacks

5 sessions · 6 h 18 m

₹1,500
05

OWASP Top 10 & The Classic Vulnerabilities

6 sessions · 7 h 51 m

₹1,600
06

Advanced Web Exploitation

11 sessions · 15 h 40 m

₹2,500
07

Sessions, TLS & Browser Security

3 sessions · 2 h 49 m

₹700
08

Python for Security Automation

7 sessions · 7 h 29 m

₹1,300
09

AWS & Cloud Security

6 sessions · 6 h 22 m

₹1,800
10

CTF Practice & Cryptography

4 sessions · 4 h 28 m

₹900
Estimated value, all in₹14,800
You pay, onceLifetime access · no subscription · no renewal₹69995%

“Estimated value” is our own estimate of what each module would be worth on its own. No module has ever been sold separately at any price, and none is available separately now.

Get full access · ₹699

Before you buy

The questions that actually matter

How do I get access after paying?

Immediately. The moment your payment succeeds you land on a page showing your access link, and the same link is emailed to you. There is no account to create and no password to remember — open the link any time, on any device.

Why do you ask for a Gmail address?

Because the library is shared with your Google account. Access is granted directly on the Drive folder holding the recordings, and Google can only grant that to a Google account. Use the Gmail address you actually watch on.

Do I need any background in IT or programming?

No. The route opens with networking from IPv4 and subnetting, then Linux from a fresh virtual machine, then Python from zero. Nothing before those is assumed. If you already have the foundations, start at Recon — the 10 modules are ordered, but each one stands on its own.

What exactly do I get?

10 modules built from 66 recorded live sessions, totalling over 82 hours, covering 36 named tools and platforms. One Google Drive library, shared with your account permanently.

Are the session running times exact?

Not yet — they are close estimates while the library is re-indexed, and the page says so wherever a total appears. They are derived from each recording's file size rather than typed by hand, so they are proportionally right, but treat the headline hours figure as approximate until this note disappears.

Are these live recordings or polished studio videos?

Recordings of real live sessions, with the questions, the debugging and the dead ends left in. That is the point: you watch a lab actually get solved, including the attempts that fail, rather than a rehearsed demo where the payload lands first time.

Is any of this legal to practise?

Every technique is demonstrated against targets that exist to be attacked — PortSwigger Web Security Academy, Hacker101, picoCTF, deliberately vulnerable applications and the instructor's own AWS account. Practising on those is entirely legal. Running the same techniques against a system you do not own or have written permission to test is a criminal offence under the Information Technology Act, 2000, and that is on you, not on us.

More questions? Read the full FAQ or write to us.

Ready

Stop collecting tabs. Walk the route.

66 sessions, 82+ hours, in the order they should be watched — shared straight to your Google account the moment you pay.

Get full access · ₹699

Lifetime access. Your link arrives by email the moment payment succeeds, and the library appears in Drive under “Shared with me” even if the email does not.

Running times shown across this site are close estimates while the library is re-indexed — see the FAQ.

₹699

All 10 modules · lifetime access

Get access