Research // Offensive Reference Platform

Research domains for offensive work, specialist target classes and operator tradecraft.

Move by surface, not by syllabus. The academy view groups the site into practical domains so you can jump straight into web, internal, cloud, API, mobile, identity, supply-chain, AI or industrial work without losing operational context.

independent structurecurated referencespublic research surface

Research domains

Each domain opens into standalone reference notes, command-heavy pages and linked public material.

domain

Foundations

Reference pages for planning, authorisation, scoping, documentation and delivery logic.

domain hubpublic links
domain

Internal Operations

Infrastructure-led offensive work from enumeration and credential pressure to pivoting and C2.

domain hubpublic links
domain

Escalation Paths

Host-level privilege paths across Linux, Windows and macOS with emphasis on verification and realism.

domain hubpublic links
domain

Application Security

Application-security coverage spanning workflow, browser behaviour and exploitation logic.

domain hubpublic links
domain

API Security

Dedicated endpoint, token, object and schema abuse coverage beyond classic browser-led testing.

domain hubpublic links
domain

Cloud Offensive Security

Provider identities, control planes, IaC drift, Kubernetes and cloud automation abuse.

domain hubpublic links
domain

Mobile App Pentesting

Android and iOS testing, instrumentation, pinning bypass, storage and mobile reversing.

domain hubpublic links
domain

Identity / SSO Abuse

Entra, Okta, federation, token theft, consent abuse and tenant trust failures.

domain hubpublic links
domain

Wireless Operations

Signal capture, protocol analysis, rogue infrastructure and client-side wireless attack paths.

domain hubpublic links
domain

DevSecOps / Supply Chain

Git, CI/CD, runner abuse, package trust, signing, SBOM and build-system compromise.

domain hubpublic links
domain

OT / ICS Security

Modbus, DNP3, PLC and HMI trust, segmentation drift and process manipulation risk.

domain hubpublic links
domain

AI Security

Prompt injection, agent compromise, retrieval abuse, model APIs and offensive AI ops.

domain hubpublic links
domain

Exploit Development

Payload engineering, shellcoding, analysis and exploit-oriented custom tooling.

domain hubpublic links
domain

Reverse Engineering

Static and dynamic binary analysis across desktop and specialist targets.

domain hubpublic links