Security testing checklists, deep enough to actually rely on.
Interactive, offline-friendly roadmaps for web, mobile, and cloud security. Check items off as you go — every bit of progress stays in your browser, never on a server.
Live checklists
Web Application Pentest & Bug Bounty Checklist
A structured, end-to-end methodology for testing web applications and APIs, from passive reconnaissance through exploitation, business logic abuse, and professional reporting.
Android Application Pentest Checklist
A structured methodology for assessing Android applications, covering static and dynamic analysis, local storage, network communication, IPC, WebViews, reverse-engineering protections, cryptography, and professional reporting.
Cloud Security Roadmap
A zero-to-mastery learning path for cloud security — cloud fundamentals, core identity concepts, then deep, hands-on hardening across AWS, GCP, Azure, and beyond, finishing with containers, IaC, compliance, and career guidance.
Coming soon
Bug Bounty Recon
Asset discovery and reconnaissance workflows built for bounty hunting at scale.
Red Team Operations
Adversary emulation, initial access, and post-exploitation tradecraft.
Blue Team / SOC
Detection engineering, triage playbooks, and incident response workflows.
IoT / OT-SCADA
Embedded device, firmware, and industrial control system security testing.
API Security
Deep-dive REST, GraphQL, and gRPC testing beyond the basics.
Web3 / Smart Contracts
Solidity auditing patterns and on-chain exploitation classes.
iOS Pentest
IPA analysis, keychain review, and runtime instrumentation for iOS apps.