~/curriculum

The 8 Pillars.

A complete, hands-on path through offensive and defensive security. It maps to the entire CEH body of knowledge — but where CEH tests you with multiple choice, every pillar here is earned in a real shell.

PILLAR 01

Reconnaissance & Footprinting

Map the target before you touch it: passive and active information gathering, OSINT, and building an attack-surface picture.

Covers CEH: Footprinting & Reconnaissance · Track: Networking & Recon
PILLAR 02

Scanning & Enumeration

Discover live hosts, open ports, running services and versions — then enumerate users, shares, and misconfigurations.

Covers CEH: Scanning Networks · Enumeration · Track: Networking & Recon
PILLAR 03

Vulnerability Analysis

Turn findings into a plan: identify weaknesses, understand root cause, and prioritise what is actually exploitable.

Covers CEH: Vulnerability Analysis · Track: Vulnerability Analysis
PILLAR 04

Web Application Exploitation

Break real web apps: injection, auth bypass, access-control flaws, and the OWASP classics — including hands-on SQL injection.

Covers CEH: Web Servers · Web Apps · SQL Injection · Track: Web Hacking · Databases & SQLi
PILLAR 05

System Hacking & Privilege Escalation

Gain a foothold, escalate to root, establish persistence, and understand how attackers cover their tracks.

Covers CEH: System Hacking · Malware Threats · Track: Privilege Escalation
PILLAR 06

Network Attacks & Pivoting

Sniff traffic, run man-in-the-middle, hijack sessions, and pivot across machines on isolated internal lab networks.

Covers CEH: Sniffing · Session Hijacking · Evading IDS/FW · Track: Sniffing · Evasion · Live Network Labs
PILLAR 07

Cryptography & Password Attacks

Recognise weak crypto, decode and reverse encodings, and crack password hashes the way real attackers do.

Covers CEH: Cryptography · Track: Cryptography · Bash Scripting
PILLAR 08

Defense, Detection & Forensics

Flip to the other side: hunt intruders in logs, run incident response, do forensics, and learn how defenders catch you.

Covers CEH: IDS/Firewall/Honeypot (defensive) · Track: Blue Team · Forensics & IR
diff shellquest ceh

Built for skill, not for a test-prep binder.

 ShellQuestTraditional theory cert
How you're testedHands-on in live Linux boxesLargely multiple-choice exam
Practice environmentReal per-player sandboxes + networked labsMostly theory; limited or paid labs
CoachingGuided hints as you workSelf-study or classroom courses
Feedback loopInstant — flag accepted, XP, rank upOne high-stakes exam at the end
Staying sharpSeasons, CTF arena, daily challengesRenew every 3 years via credits
Cost to startFree — Pro from ~$12/moOften $1,000+ for exam & training

// comparison reflects the format of typical multiple-choice ethical-hacking certifications, including CEH.