Six modules. One clear order.
Follow it top to bottom if you're new. Already know the basics? Skip straight to what you need.
- 01FundamentalsCIA triad, threat modeling, reading a CVE.
- 02Web SecurityTrust boundaries and a real testing methodology.
- 03OWASP Top 10The standard risk categories, with real scenarios.
- 04Network SecurityLayers, segmentation, and core recon tools.
- 05Bug BountyScope, recon workflow, reports that get triaged.
Written from real engagements, not textbooks

How I Found a Chain of Critical Vulnerabilities in a Public Platform’s GraphQL API
A chain of GraphQL vulnerabilities discovered while testing a public application, walked through end to end.
Read on Medium →
Who Needs Admin Rights When You’ve Got Bugs?
A business-logic vulnerability that let low-privilege actions produce admin-level outcomes.
Read on Medium →
Exploit the Game Blindly: With Blind XSS
How a blind XSS payload was used to exfiltrate sensitive information from an internal admin panel.
Read on Medium →Built in the open, on purpose
Every doc, every write-up, every line of this site is a public commit. Found a gap, a bug, or have a write-up worth sharing? Fork it and open a PR — no application, no gatekeeping.