Type to search across the blog, guides, tools, and services.
A 4–8 hour session on a single technique, tool, or attack chain, once a month. Hands-on from the first minute, with live Q&A throughout the day.
Each workshop goes deep on one technique or tool, with the goal that you can do the work independently by the end of the day.
Topics rotate monthly based on what the community asks for and what's currently being exploited in the wild.
Web Application Hacking
OWASP Top 10, IDOR, SSRF, and modern app testing.
API Security Testing
REST/GraphQL endpoint discovery and exploitation.
OSINT & Reconnaissance
Open-source intelligence and target profiling.
Authentication Attacks
JWT flaws, OAuth misconfigurations, and brute-force.
Bug Bounty Methodology
A structured workflow for finding high-severity bugs.
Pentest Reporting
Writing reports that clients actually understand.
Same topic, different depth. Pick the track that matches your current level.
No prior experience with the topic needed. Concepts are explained from first principles before any hands-on work begins, and the guided labs go step by step.
Concepts from scratch · Guided labs · Q&A on fundamentals
Assumes familiarity with the basics. Covers edge cases, real engagement scenarios, and advanced exploitation chains, with a focus on methodology.
Real-world scenarios · Advanced tooling · Chaining techniques
Each workshop has limited seats. Once you're registered we email the session link and prep materials before the date.
Workshops are built for focused skill upgrades. If you're after a full curriculum with mentorship and career guidance, look at the training programme instead.