Learn
Free, self-paced security courses, and a small certification that proves you did the work.
- 4 paths
- 17 lessons
- 83 min read
- free, no signup
Courses
Structured, skimmable guides on ethical hacking, OSINT, penetration testing and responsible disclosure. Track your progress as you go.
- 01
Ethical Hacking Fundamentals
Foundations of authorized security testing: what, why, and the rules you must follow.
Beginner4 lessons19 min - 02
OSINT Techniques
Find, correlate and analyze publicly available information, ethically and efficiently.
Intermediate4 lessons21 min - 03
Penetration Testing Methodology
The end-to-end structured approach professionals follow on real engagements.
Advanced5 lessons25 min - 04
Responsible Disclosure
How to report vulnerabilities ethically, and what bug bounty programs actually expect.
All levels4 lessons18 min
Path 01
Ethical Hacking Fundamentals
Beginner · 4 lessons · 19 min
Key takeaways
- Ethical hacking = authorized testing; malicious hacking = unauthorized intrusion.
- Written authorization precedes every assessment.
- Scope limits, responsible reporting and confidentiality are non-negotiable.
Ethical hacking, also called penetration testing or white-hat hacking, is the practice of testing systems, networks and applications for vulnerabilities with explicit permission from the owner. Unlike criminals, ethical hackers are hired to find and help fix weaknesses before someone else exploits them. Strong technical skills matter, but what separates a professional from a nuisance is discipline: written authorization, respect for scope, protection of sensitive findings and responsible disclosure.
Legal
Never test systems you don't own or don't have written permission to test, no matter how “obviously vulnerable” they appear.
Key takeaways
- The CFAA (US) and equivalents worldwide criminalize unauthorized access.
- Valid authorization sources: employment contracts, signed engagements, bug bounty rules, owner consent.
- Rules of engagement exist to protect both parties: read them carefully.
Before any testing, understand the legal framework. The Computer Fraud and Abuse Act in the US, and similar laws globally, criminalize unauthorized access to computer systems. Authorization is everything. Valid sources: employment contracts authorizing internal testing, signed engagement letters for penetration tests, bug bounty program rules granting permission on specific assets, or written consent from device owners for hardware research. Even with authorization, respect scope: which systems are in, which are out, and which actions (e.g. data destruction, DoS) are prohibited. Professional testers use detailed contracts and rules-of-engagement documents to make expectations explicit.
Key takeaways
- Attack surface = every entry and exit point an attacker might use.
- Network, application, human and physical surfaces all count.
- Attackers exploit the weakest link, so holistic assessments matter.
The attack surface is the sum of all points where an unauthorized user could try to enter or extract data from a system. Network surfaces include exposed ports, wireless, VPN and infrastructure devices. Application surfaces cover web apps, APIs, mobile apps and authentication. Human surfaces include social engineering targets and insider threats. Physical surfaces include building access, hardware tampering opportunities and unlocked workstations. Comprehensive assessments examine all of these: attackers exploit the weakest link regardless of what else is defended.
Key takeaways
- OWASP-style categories: injection, authentication, authorization, XSS, crypto, misconfiguration.
- Each category maps to a testing approach and a set of tools.
- Knowing the taxonomy helps you build test checklists.
Security vulnerabilities fall into common categories. Injection (SQLi, command injection) occurs when untrusted data flows into interpreters. Authentication flaws include weak passwords, missing MFA, session hijacking and credential stuffing. Authorization flaws let users perform actions they shouldn't. Cross-site scripting (XSS) lets attackers run scripts in other users' browsers. Cryptographic failures: weak algorithms, insecure storage, bad certificate validation. Security misconfigurations, such as insecure defaults and verbose errors, are some of the most common and most fixable bugs in production systems.
Classic SQLi payloadsql ' OR '1'='1' --
Path 02
OSINT Techniques
Intermediate · 4 lessons · 21 min
Key takeaways
- OSINT uses only public information: no classified or proprietary sources.
- The value is speed of correlation, not access to secrets.
- Legal is not always ethical: privacy judgement matters.
Open Source Intelligence (OSINT) is intelligence collected from publicly available sources: public records, social media, news, academic publications, government datasets, website metadata, DNS records and archived pages. OSINT is valuable for assessments, threat intelligence and investigations. The skill is in finding, correlating and analyzing efficiently, not in accessing secret information. It is legal when used on public data, though ethical questions about privacy still apply.
Key takeaways
- Operators (site:, filetype:, intitle:, -) turn Google into a precision tool.
- Combine operators to scope searches to single domains or document types.
- Time filters, cached versions and Boolean logic extend your reach.
Search engines index billions of pages, but most people only use the basics. Advanced operators turn Google into a reconnaissance tool, and combining them creates powerful queries. Time filters, cached pages and Boolean logic extend your reach further.
Find exposed PDFs on a university domaintext site:edu filetype:pdf "internal use only"Admin login pagestext intitle:"admin login" -inurl:example.comKey takeaways
- WHOIS, DNS and Certificate Transparency logs expose extensive infrastructure data.
- Shodan and Censys index internet-exposed devices: search before you scan.
- All passive: no packets are sent to the target.
Before touching a target network, gather public infrastructure data. WHOIS reveals registration details. DNS enumeration finds subdomains via Certificate Transparency logs (crt.sh), brute forcing and passive DNS archives (SecurityTrails). Shodan and Censys are search engines for internet-exposed devices, revealing services and vulnerable versions worldwide. Reverse IP lookup finds co-hosted domains. ARIN and RIPE show IP allocations. All of this is legal and invisible to the target: you only query public databases.
Discover subdomains via crt.shbash curl -s "https://crt.sh/?q=%25.example.com&output=json" | jq -r '.[].name_value' | sort -u
Path 03
Penetration Testing Methodology
Advanced · 5 lessons · 25 min
Key takeaways
- Scope defines in-scope systems, excluded systems, test types and time windows.
- Rules-of-engagement documents formalize expectations and legal protections.
- Poor scoping = legal risk + a worthless assessment.
Professional tests begin with planning long before any technical work. Scoping defines in-scope systems (IP ranges, domains, apps), excluded systems, testing types (black, gray or white box), permitted methods, time windows, success criteria, communication protocols and legal protections. A rules-of-engagement document formalizes all of this into a signed contract. Poor scoping leads to misunderstandings, legal issues and inadequate assessments.
Key takeaways
- Passive recon uses only public data; active recon touches the target.
- Time spent on recon is rarely wasted.
- Tools: Nmap, Burp spider, dirb/gobuster, banner grabbers.
Passive reconnaissance uses publicly available information without touching targets: OSINT, search engines, job postings revealing tech stacks, DNS records, archived versions. Active reconnaissance interacts directly: Nmap port scans, service enumeration, web app spidering, network mapping, banner grabbing, vulnerability scanning. The goal: understand the target's attack surface, technologies, potential vulnerabilities and security controls before exploitation.
Nmap service + version detectionbash nmap -sV -sC -oA recon/target 10.0.0.0/24Key takeaways
- Automated scanners find known CVEs fast; manual testing finds logic flaws.
- CVSS gives technical severity; business context gives real risk.
- Verify every finding before you report it.
After recon, vulnerability assessment identifies specific weaknesses. Automated tools (Nessus, OpenVAS, Qualys) check thousands of known CVEs quickly, but they produce false positives and miss business-logic flaws. Manual testing covers configuration review, authentication, authorization and privilege escalation, input handling, error message leaks and cryptographic implementation. CVSS standardizes severity. Risk-based prioritization weighs business context: a medium finding on a payment processor outranks a critical one on an isolated dev box.
Key takeaways
- Exploitation proves impact: don't overreach.
- Post-exploitation: lateral movement, privilege escalation, data exfiltration (all simulated).
- Professional restraint: document, don't destroy.
Exploitation proves vulnerabilities are real. It may mean SQL injection to extract data, RCE to gain a shell, privilege escalation, authentication bypass, or XSS to show account compromise. Post-exploitation demonstrates the full impact: lateral movement, admin privilege escalation, (simulated) data exfiltration, persistence mechanisms, pivoting. Professional testers stop once impact is proven, minimize access to real data, document everything and notify the client immediately about critical findings.
Warning
The goal is to demonstrate risk so it gets fixed, not to cause harm or access more data than you need to prove the point.
Key takeaways
- The report is the deliverable, not the shells.
- Executive summary + technical findings + prioritized remediation.
- Retest after fixes to confirm they really work.
The report translates technical findings into business intelligence. It should include an executive summary without jargon, technical findings with reproduction steps and evidence, CVSS or risk ratings, remediation recommendations and strategic suggestions for the overall security posture. Prioritize by business risk, not just technical severity. Remediation verification means retesting after the fixes are in, to confirm they work and nothing regressed. The value of a test is in the improvements it drives, not in the shells.
Path 04
Responsible Disclosure
All levels · 4 lessons · 18 min
Key takeaways
- Coordinated disclosure protects users while patches ship.
- Full disclosure, no disclosure and selling vulnerabilities all fail the public.
- The community consensus is about 90 days to patch.
Responsible (coordinated) disclosure means reporting issues privately to the vendor and giving them reasonable time to patch before details go public. It protects users, gives vendors room to fix, and maintains trust. The alternatives fail: full disclosure helps attackers first, indefinite non-disclosure leaves users silently exposed, and selling to criminal or nation-state buyers enables harm. Most researchers and major vendors treat coordinated disclosure as the ethical standard.
Key takeaways
- Check /.well-known/security.txt or bug bounty platforms first.
- security@<domain> is the industry fallback.
- A report has: description, reproduction steps, impact, PoC, contact, PGP if sensitive.
Start by checking for a published disclosure policy or /.well-known/security.txt. Many companies run bounty programs on HackerOne, Bugcrowd or Intigriti. If neither exists, contact security@<domain>. Your report should include a clear description, reproduction steps, an impact assessment, a proof of concept, your contact details and a request for acknowledgment. Use PGP for exploit code. Be patient, and follow up politely after one to two weeks of silence. Keep detailed records of all communication.
Minimal security.txt filetext Contact: mailto:security@example.com Expires: 2027-01-01T00:00:00.000Z Preferred-Languages: en Canonical: https://example.com/.well-known/security.txtKey takeaways
- 90 days from report to public disclosure is the community-standard window.
- Critical, actively exploited bugs warrant faster disclosure.
- Public disclosure should warn and advise, not hand attackers a recipe.
90 days from report to public disclosure is the common baseline, adjusted to the circumstances: faster if the bug is critical and actively exploited, longer for architectural issues when the vendor is cooperating. Public disclosure should warn users, provide mitigations if no patch is available, credit everyone fairly, and avoid more exploit detail than defenders need. The goal is protecting users, not punishing vendors or chasing headlines.
Key takeaways
- Platforms: HackerOne, Bugcrowd, Intigriti.
- Read the scope carefully: out of scope means no reward, and sometimes legal risk.
- High-quality reports win; spam reports get researchers banned.
Bug bounty programs offer structured disclosure with rewards. The major platforms host programs for thousands of companies. Each program defines its scope, excluded issues (e.g. self-XSS, DoS), reward ranges and rules of engagement. For researchers they mean money, legal clarity, real-world targets and reputation. For companies: continuous coverage, diverse perspectives and good community relations. Taking part successfully means reading the rules carefully, respecting scope, writing high-quality reports, and accepting that not every finding qualifies.
Keep learning
Curated platforms, tools, certifications and communities.
Learning platforms
Essential tools
Certifications
Certification
Small, useful, real: a scenario-based credential proving you can run authorized engagements end to end.
Live · take it now
ZeroTrace HID Course Completion
A scenario-based exam proving you can run an authorized HID engagement end to end: scope, deployment, reporting, cleanup. Anchored to a course you actually complete.
- Free
- 10 questions
- 20 minutes
- Pass at 70%
- 24 h retake cooldown
How it works
1Learn
Work through the course material, then open the dashboard with your ZeroTrace account.
- No subscription, no extra signup
- Covered by your ZeroTrace account
2Exam
10 scenario questions from a pool of 30+, on a 20-minute timer.
- Multiple choice, multi-select, numeric, short text
- The server shuffles the options on every attempt
- Proctored: fullscreen and focus tracked
3Badge
Pass with 70% or more. Grading is instant and shows every question with the correct answer and rationale.
- A public /verify URL, signed and revocable
- Download the badge as SVG
- Share it on a CV, a portfolio, a hiring portal
Integrity without invasion
What keeps the exam honest, and what we won't do.
No webcam, no fingerprinting
Proctoring is session-scoped: focus loss and leaving fullscreen are tracked during the attempt only. No persistent device ID, no IP logging beyond the existing session.
Time-limited and shuffled
The server picks your questions from a pool and shuffles the answer order per attempt. The correct answer never reaches your browser until you submit.
Public badge, private exam
Pass and you get a /verify URL anyone can check. Your answers and the integrity event log stay on your account.
Honest cooldown
Fail and the same cert locks for 24 hours. It stops spam attempts and gives you a beat to revisit the material instead of guessing.
What we hold to
Start small, ship something real
A small cert that proves you ran the HID workflow is more useful than a big one nobody finishes.
Tied to courses people complete
Every cert maps to a real course. If you've done the work on a real device, you should be able to pass.
Authorized-testing-first language
No “elite operator” branding. The cert says you can run authorized engagements responsibly, which is what employers and labs want to see.
Coming later
ZeroTrace OSINT Training
A heavier credential earned by completing the OSINT training and solving a real investigation scenario. Still small-team, still authorized-testing-first.
- Scenario-based: solve a real OSINT case
- Recognizes investigation discipline, not trivia
- Probably proctored, probably with a recertification rhythm
- Your feedback shapes the scope
Not committed yet
Earn one, or verify one
Holders get a public URL on this site. Anyone can verify it, no account needed.