Learn · learn.redsec.cc

Start learning at RedSec.

A free, open learning library for offensive security. Work through structured tutorials, labs, references, and reporting guides in the order that matches your goal.

698+
lessons
22
sections
0
accounts required
22 lessons

Getting started

New here? Start with the platform, safe practice, and study habits.

25 lessons

Security foundations

Core concepts: risk, trust boundaries, threat modeling, and HTTP basics.

26 lessons

Tools and workflows

Practical workflows for notes, terminals, proxies, wordlists, and repeatable testing.

26 lessons

Linux

Shell skills, permissions, services, logs, and safe privilege escalation practice.

28 lessons

Networking

TCP/IP, DNS, TLS, routing, service discovery, and packet analysis.

38 lessons

Web security

How modern web apps work and where common security assumptions fail.

28 lessons

API security

REST, GraphQL, authorization, schema review, and safe API testing.

28 lessons

Authentication

Login flows, sessions, reset logic, MFA, OAuth, and identity mistakes.

28 lessons

Access control

Ownership checks, role boundaries, multi-tenant data, and authorization review.

32 lessons

Injection

SQL, command, template, LDAP, and deserialization injection fundamentals.

28 lessons

Client-side security

Browser trust, JavaScript review, XSS, CORS, CSP, and frontend storage.

28 lessons

Cloud security

Identity, storage, serverless, metadata, logging, and cloud review patterns.

26 lessons

Containers

Docker, Kubernetes, image hygiene, runtime boundaries, and cluster basics.

28 lessons

Active Directory

Windows domains, Kerberos concepts, delegation, and defensive lab practice.

34 lessons

Cryptography

Practical crypto failures: encoding, randomness, modes, tokens, and protocols.

32 lessons

Forensics

Files, memory, logs, packet captures, timelines, and evidence handling.

35 lessons

Reverse engineering

Static and dynamic analysis, file formats, strings, control flow, and patching basics.

52 lessons

Binary exploitation

Memory layout, mitigations, crashes, and lab-only exploitation concepts.

72 lessons

CTFs

Capture the flag: formats, tooling, and worked challenges.

29 lessons

Bug bounties

Hunt real targets: recon, scoping, and reports that pay.

33 lessons

Finding vulnerabilities

The core bug classes and how to actually find them.

20 lessons

Reporting and career

Clear writeups, responsible disclosure, portfolios, interviews, and growth.