The 8 Pillars.
A complete, hands-on path through offensive and defensive security. It maps to the entire CEH body of knowledge — but where CEH tests you with multiple choice, every pillar here is earned in a real shell.
Reconnaissance & Footprinting
Map the target before you touch it: passive and active information gathering, OSINT, and building an attack-surface picture.
Scanning & Enumeration
Discover live hosts, open ports, running services and versions — then enumerate users, shares, and misconfigurations.
Vulnerability Analysis
Turn findings into a plan: identify weaknesses, understand root cause, and prioritise what is actually exploitable.
Web Application Exploitation
Break real web apps: injection, auth bypass, access-control flaws, and the OWASP classics — including hands-on SQL injection.
System Hacking & Privilege Escalation
Gain a foothold, escalate to root, establish persistence, and understand how attackers cover their tracks.
Network Attacks & Pivoting
Sniff traffic, run man-in-the-middle, hijack sessions, and pivot across machines on isolated internal lab networks.
Cryptography & Password Attacks
Recognise weak crypto, decode and reverse encodings, and crack password hashes the way real attackers do.
Defense, Detection & Forensics
Flip to the other side: hunt intruders in logs, run incident response, do forensics, and learn how defenders catch you.
Built for skill, not for a test-prep binder.
| ShellQuest | Traditional theory cert | |
|---|---|---|
| How you're tested | Hands-on in live Linux boxes | Largely multiple-choice exam |
| Practice environment | Real per-player sandboxes + networked labs | Mostly theory; limited or paid labs |
| Coaching | Guided hints as you work | Self-study or classroom courses |
| Feedback loop | Instant — flag accepted, XP, rank up | One high-stakes exam at the end |
| Staying sharp | Seasons, CTF arena, daily challenges | Renew every 3 years via credits |
| Cost to start | Free — Pro from ~$12/mo | Often $1,000+ for exam & training |
// comparison reflects the format of typical multiple-choice ethical-hacking certifications, including CEH.