Built for pentesters, bug bounty hunters & cloud defenders

Security testing checklists, deep enough to actually rely on.

Interactive, offline-friendly roadmaps for web, mobile, and cloud security. Check items off as you go — every bit of progress stays in your browser, never on a server.

3/10 roadmaps live745 checklist items publishedSuggest a roadmap →

Live checklists

Coming soon

Coming Soon

Bug Bounty Recon

Asset discovery and reconnaissance workflows built for bounty hunting at scale.

Coming Soon

Red Team Operations

Adversary emulation, initial access, and post-exploitation tradecraft.

Coming Soon

Blue Team / SOC

Detection engineering, triage playbooks, and incident response workflows.

Coming Soon

IoT / OT-SCADA

Embedded device, firmware, and industrial control system security testing.

Coming Soon

API Security

Deep-dive REST, GraphQL, and gRPC testing beyond the basics.

Coming Soon

Web3 / Smart Contracts

Solidity auditing patterns and on-chain exploitation classes.

Coming Soon

iOS Pentest

IPA analysis, keychain review, and runtime instrumentation for iOS apps.