
Full syllabus · nothing withheld
The route, session by session
All 66 recorded sessions across 10 modules — 82+ hours and 36 tools. Every title is the real session title. Read the whole thing before you decide.
12 sessions · 16 h 10 m · Sessions 1–12
IPv4, subnetting and CIDR, the OSI model layer by layer, routing and switching configured live in Cisco Packet Tracer, then DNS and the transport layer. Every attack later in the programme is an abuse of something in this module.
4 sections · 12 sessions · 16 h 10 m
Addressing and subnetting7 h 4 m
Where every security career starts. Nothing here assumes you have seen a network diagram before.
- 01Orientation · How the programme runs and what you will build3:13:13
- 02IPv4 · The classes of IPv41:28:06
- 03Subnetting1:32:16
- 04Class A and Class B subnetting · CIDR50:10
Layers, ports and protocols2 h 19 m
- 01The OSI model · Physical and Data Link layers58:06
- 02OSI layers · Ports and protocols1:20:42
Routing and switching, built in Cisco Packet Tracer4 h 8 m
Configured device by device on screen, not described on a slide.
- 01Network facts · Routers · Introduction to Cisco Packet Tracer1:06:24
- 02Routing protocols · Switches and LANs in Packet Tracer1:07:21
- 03HTTP request methods · HTTP response codes · Serial cable in Packet Tracer57:39
- 04Cisco Packet Tracer · Router, switch and end-device configuration56:20
DNS and the transport layer2 h 40 m
- 01DNS · Types of DNS · DNS queries · How the internet actually works1:29:27
- 02DNS records · Mail spoofing and its mitigation · TCP and UDP1:10:16
6 sessions · 7 h 33 m · Sessions 15–17, 20–22
Linux installed in a VM and then driven entirely from the command line — users and permissions, the file system, package management, SSH, and Bash scripts that take arguments and do real work.
2 sections · 6 sessions · 7 h 33 m
Linux from zero3 h 56 m
Installed in a VM on screen, then driven entirely from the command line.
- 01Linux and virtual machines · Why Linux · Types of Linux users · Basic commands1:26:01
- 02Linux user management · Shodan · exploit-db · Zero-day attacks1:08:41
- 03Linux commands · The Linux file system1:21:27
Scripting, packages and remote access3 h 37 m
- 01Bash scripting · Shell, variables, system and user-defined variables · Input and arguments1:06:12
- 02Linux package management · apt and dpkg · Installing packages · TELNET and SSH1:21:34
- 03Ask-me-anything and open discussion1:09:25
Reconnaissance, OSINT & Scanning
Intermediate6 sessions · 7 h 50 m · Sessions 13–14, 18–19, 59–60
Everything a target publishes without meaning to: subdomains, dorks, leaked keys in public repositories, staff email addresses — then Nmap to turn a map into a list of open doors.
2 sections · 6 sessions · 7 h 50 m
Mapping the attack surface5 h 1 m
Everything a target publishes without meaning to.
- 01Subdomains and subdomain enumeration · Sublist3r · SubBrute · VirusTotal · httpstatus.io · whois1:28:41
- 02Google dorking · The Google Hacking Database1:35:48
- 03GitHub recon · Gitrob · GitHound1:46:47
- 04Hunter.io and theHarvester9:36
Port scanning with Nmap2 h 49 m
- 01Logical ports · Nmap · Scanning and scan types · Hibernation vs shutdown1:07:16
- 02Hunting for security jobs and internships · Advanced Nmap scans1:41:25
Core Web Attacks
Intermediate5 sessions · 6 h 18 m · Sessions 23–27
The four that appear in almost every report: SQL injection by hand and with SQLMap, IDOR against a real API, JWT flaws, and cross-site request forgery — each one exploited in a lab before it is defended.
2 sections · 5 sessions · 6 h 18 m
Injection and broken access control4 h 6 m
- 01SQL injection · Types of SQL · POST-based SQLi1:36:20
- 02SQL injection · GET-based SQLi · SQLMap1:06:27
- 03IDOR · API fundamentals · Hacker101 · Postbook challenges1:22:45
Tokens and forged requests2 h 13 m
- 01JWT · JWT authentication · JWT vulnerabilities · CTF challenges1:02:50
- 02Cross-Site Request Forgery (CSRF) · PortSwigger labs1:09:40
OWASP Top 10 & The Classic Vulnerabilities
Intermediate6 sessions · 7 h 51 m · Sessions 43–48
Both editions of the OWASP Top 10 and the API Top 10 — because interviewers still ask about 2017 — then CSRF protection bypass, every type of XSS, and SSRF with its filters defeated.
2 sections · 6 sessions · 7 h 51 m
The OWASP lists4 h 6 m
Both editions, because interviewers still ask about 2017.
- 01OWASP Top 10, 2017 and 2021 · Interview questions · Salting and iteration in hashing1:26:08
- 02The OWASP API Top 101:22:29
- 03Authentication methods · HTTP headers1:17:19
CSRF, XSS and SSRF3 h 45 m
- 01CSRF mitigation · Bypassing CSRF protection · PortSwigger labs1:11:17
- 02XSS · Types of XSS · PortSwigger labs · Prevention1:20:48
- 03Server-Side Request Forgery (SSRF) · PortSwigger labs · Bypassing SSRF protection1:13:16
Advanced Web Exploitation
Advanced11 sessions · 15 h 40 m · Sessions 49–52, 55–58, 61–63
The eleven sessions that separate a scanner operator from a tester: authentication bypass and 2FA defeat, information disclosure, both HTTP request smuggling desyncs, business logic flaws, host header attacks and directory traversal.
4 sections · 11 sessions · 15 h 40 m
Authentication and information disclosure6 h 33 m
- 01Authentication vulnerabilities · PortSwigger labs1:44:12
- 02Authentication bypass · 2FA and 2FA bypass · Brute-forcing credentials1:36:04
- 03Information disclosure vulnerabilities1:46:20
- 04Information disclosure labs1:26:01
HTTP request smuggling3 h 7 m
Both desync variants, with the smuggler tool driven on screen.
- 01HTTP request smuggling · CL.TE · The smuggler tool1:32:46
- 02HTTP request smuggling · TE.CL · PortSwigger labs1:34:29
Business logic and host header attacks3 h 29 m
- 01Business logic flaws · Password reset vulnerabilities · PortSwigger labs1:29:53
- 02PortSwigger labs · Logical vulnerabilities39:18
- 03Host header attacks · PortSwigger labs1:19:55
Traversal, DoS and Hacker101 CTFs2 h 31 m
- 01Long-password DoS attack · Hacker101 CTF · Micro CMS v11:09:57
- 02Directory traversal attacks · Hacker101 · Petshop Pro1:20:50
Sessions, TLS & Browser Security
Intermediate3 sessions · 2 h 49 m · Sessions 64–66
How the browser itself decides what is allowed: session management and fixation, the SSL handshake, cookie attributes, the Same-Origin Policy and CORS — plus the closing project discussion.
1 section · 3 sessions · 2 h 49 m
Sessions, TLS and the browser security model2 h 49 m
The programme closes on the rules the browser itself enforces — and the project discussion.
- 01Sessions · Session management · Session fixation · httpOnly1:02:22
- 02SSL and the SSL handshake · Cookies · Introduction to cookie security51:22
- 03Cookie security · Cookie attributes · Same-Origin Policy · CORS · Project discussion55:17
Python for Security Automation
Beginner7 sessions · 7 h 29 m · Sessions 28–34
Python taught for scripting a scanner, not for passing a CS exam — types and collections, control flow, functions, the standard library modules that matter, requests, and enough OOP to structure a tool.
2 sections · 7 sessions · 7 h 29 m
The language4 h 25 m
Taught for scripting a scanner, not for passing a CS exam.
- 01Python introduction · Variables, strings, integers, floats and lists1:03:15
- 02Python · Lists, tuples and sets1:10:01
- 03Dictionaries · if / elif / else · for and while loops · Booleans · break and continue1:09:24
- 04Python functions · Types of function · Defining a function · Important built-ins1:02:04
Modules, HTTP and objects3 h 5 m
- 01Modules · os, requests, calendar, time and random51:24
- 02The Python requests library · Introduction to cloud · Server vs cloud · AWS1:03:02
- 03Python OOP · Classes, inheritance, class and instance variables · Cloud models1:10:04
AWS & Cloud Security
Intermediate6 sessions · 6 h 22 m · Sessions 35–38, 53–54
EC2, S3 and the identity model hands-on, then the same account attacked: S3 bucket misconfiguration through the AWS CLI, and IAM users, groups and policies written to shut it down.
2 sections · 6 sessions · 6 h 22 m
AWS fundamentals3 h 11 m
- 01Introduction to AWS · Services, regions and availability zones · Cloud certification1:17:34
- 02AWS · EC2 · Security and identity47:19
- 03EC2 hands-on · Storage in AWS · S3 · SSH clients1:05:53
Attacking and then locking down an account3 h 11 m
The same S3 bucket, misconfigured and then fixed.
- 01Introduction to AWS pentesting · S3 bucket misconfiguration · The AWS CLI1:14:25
- 02Identity and Access Management (IAM) · Users, groups and permissions · Hands-on1:02:33
- 03IAM policies · Hands-on54:23
CTF Practice & Cryptography
Intermediate4 sessions · 4 h 28 m · Sessions 39–42
Real picoCTF challenges solved end to end — including the wrong turns — across web, general skills and cryptography, with the hashing and encryption theory that the crypto challenges need.
2 sections · 4 sessions · 4 h 28 m
Capture the flag1 h 58 m
Real picoCTF challenges solved end to end, including the wrong turns.
- 01CTFs and how to solve them · Web challenges · picoCTF1:05:09
- 02picoCTF · General skills challenges52:32
Cryptography and hashing2 h 30 m
- 01picoCTF cryptography challenges · ROT13 · Caesar cipher1:27:03
- 02Cryptography · Hashing and encryption · Hashing vs encryption · Rainbow table attacks1:02:59
That is the entire programme.
Everything above is included. Nothing is sold separately, and there is no tier that leaves some of it out. One payment, lifetime access, shared to your Google account the moment payment succeeds.
Get full access · ₹699Running times are close estimates while the library is re-indexed — see the FAQ.
₹699
All 10 modules · lifetime access