Web, system, device — defend and authorized-test like a senior.
Threat modeling, attack mechanics for defenders, and authorized testing across web, systems, devices, and infrastructure. Every module bridges the attacker's and defender's view: the same mechanism that lets you write a hardened cookie also lets you spot a forgery. Anchored in OWASP, MITRE ATT&CK, CIS Benchmarks, and NIST — with hands-on labs in DVWA, Juice Shop, HackTheBox, and TryHackMe.
Close the holes attackers actually reach for — a forged cookie, a leaked table, a comment box that runs code — before a stranger does.
Ten layers of defence — from a locked-down Linux baseline to a live detection pipeline — so a breach gets caught in minutes, not months.
Phones, sensors, and embedded boards end up in strangers’ hands — learn to keep secrets, firmware, and fleet updates safe anyway.
Work a real engagement end to end — signed scope, recon, exploitation in the lab, and a report the client can actually act on.
Reproduce the exploit in Foundry, patch it, then prove the patch holds with an invariant — the loop behind every real audit report.
Build the fraud rules, KYC checks, and breach playbooks that stop a fintech from losing customer money and its banking licence.
Build the bench and fuzzing rigs that turn a $30 gadget into a filed vulnerability report — and a competition writeup that gets you noticed.
Your prompt is not a wall and your agent's tools are the attacker's tools; find the holes yourself, then keep them closed with tests.