// new to the field or a decade deep

Learn to hack
by hacking.

The home base for everyone in security. ShellQuest is a hands-on training platform that drops you into a real, hardened Linux box in your browser and hands you missions to break, defend, and escalate — with step-by-step guidance when you're stuck. Skill built from your first shell, and kept sharp for your thousandth.

24 tracks
138 hands-on missions
8 curriculum pillars
100% practical certification
live CTF arena
# the problem

A cert that tests what you memorized isn't proof you can hack.

The industry is full of credentials you earn by passing a multiple-choice exam. Hiring managers know the difference between someone who read about privilege escalation and someone who has actually done it. ShellQuest makes you the second kind — everything here is the real thing, in a real shell.

whoami

One gate. Everyone in security.

Whether you're taking your first step or you've been breaking things for years, ShellQuest meets you where you are — and keeps pushing.

» Career switchers breaking in» Students who want proof, not notes» Aspiring pentesters & red teamers» Blue teamers & SOC analysts» Developers hardening their code» Seasoned pros keeping their edge» CTF players & whole teams
~/how-it-works

Four steps, then you're in a shell.

01

Drop into a real box

A per-player, network-isolated, hardened Linux sandbox spins up in your browser. Nothing to install.

02

Get a mission

Recon a target, break a web app, escalate to root, hunt an intruder, or capture a flag — real objectives on real artifacts.

03

Type real commands

Work the box like an operator. Stuck? Step-by-step, in-context hints nudge you toward the next move — without ever handing you the answer.

04

Submit the flag

Land the objective, earn XP, climb the rank ladder, unlock the next track. Zero to operator, one command at a time.

~/curriculum --pillars 8 --tracks 24

Everything the big certs teach — and a lot they don't.

Eight hands-on pillars cover the full ethical-hacking body of knowledge — the CEH and OSCP core — from first recon to full compromise to defending the box you just broke. Then 24 tracks take you further: cloud, Active Directory & red team, malware analysis, mobile & IoT, wireless, OSINT, and more.

P1

Recon & Footprinting

P2

Scanning & Enumeration

P3

Vulnerability Analysis

P4

Web Exploitation

P5

System Hacking & Privesc

P6

Network Attacks & Pivoting

P7

Crypto & Password Attacks

P8

Defense & Forensics

~/what-you-get

A whole lab, guided practice, and a community — in one tab.

./sandbox --hardened

Real sandboxes

Isolated, throwaway Linux containers — no network, no root, read-only rootfs. Practice offense safely on artifacts we stage.

hint --in-context

Guided hints

Stuck on a box? In-context hints read where you are and nudge you toward the next step — they never just hand you the flag, so you actually learn.

forum --scope mission

Community & write-ups

Discuss a mission once you've solved it, share write-ups, and learn how others broke the same box.

sudo ./certify

Certification you earn in a live box.

Not a questionnaire — a practical exam you pass by doing the work, with a publicly verifiable credential.

./compete

Hack Me If You Can.

CTF, 1v1 duels, and seasonal ladders with a live leaderboard. Prove it against other operators — live.

./start

Ready to prove it?

Free while we're in early access. Create your account and get your first shell in under a minute.

Start free