JavaScript
-
JavaScript Essentials
- JavaScript Fundamentals
- Variables and Data Types
- Operators and Expressions
- Conditions and Loops
- Functions and Arrow Functions
- Scope, Hoisting and Closures
- Strings and Numbers
- Type Conversion and Coercion
- Date and Time
- Built-in Objects and Methods
-
DOM and Browser
- JavaScript in HTML
- DOM Tree and Element Selection
- Creating, Modifying and Removing Elements
- DOM Traversal
- Events and Event Listeners
- Event Bubbling and Delegation
- Browser APIs
- Timers: setTimeout and setInterval
- Browser DevTools and Debugging
-
Arrays and Objects
- Arrays and Array Methods
- Objects and Object Methods
- Destructuring and Spread Syntax
- Rest Parameters
- Iteration: for, for...of, for...in
- Map, Set and Other Collections
- References and Mutability
-
Strings and Numbers
- String Properties and Methods
- Template Literals
- Searching and Extracting Substrings
- Replacing and Splitting Strings
- Trimming and Changing Case
- String Interpolation and Formatting
- Number Types and Precision
- Type Conversion and Parsing
- Math Operators and Remainder
- Number Formatting
- Working with BigInt
-
Loops
- for Loop
- while and do...while Loops
- for...of and for...in Loops
- break and continue
- Nested Loops
- Looping Through Arrays and Objects
- Array Iteration Methods: forEach, map, filter, reduce
- Loop Control and Common Pitfalls
- Performance and Loop Optimization
-
Date and Time
- Date Object Fundamentals
- Creating Dates and Timestamps
- Getting and Setting Date Components
- Date Formatting and Localization
- Date Arithmetic and Comparisons
- Working with Timezones and UTC
- Parsing Date Strings
- Measuring Time Intervals
- Timers: setTimeout and setInterval
- Intl.DateTimeFormat
-
Built-in Methods
- Math Object: round, floor, ceil, abs, min, max, pow, sqrt
- Random Numbers: Math.random
- Generating Random Integers
- Number Methods: toFixed, toPrecision, Number.isNaN
- String Methods: includes, startsWith, endsWith, slice, substring, split, replace
- Array Methods: push, pop, shift, unshift, splice, slice
- Array Methods: includes, indexOf, find, findIndex
- Array Methods: map, filter, reduce, forEach, sort
- Array Methods: some, every, flat, flatMap
- Object Methods: keys, values, entries, assign
- Object Methods: fromEntries, hasOwn
- JSON: stringify and parse
- Set and Map
- Optional Chaining and Nullish Coalescing
- Spread Syntax and Rest Parameters
-
Functions in JavaScript
- Pure Functions
- Higher-order Functions
- Callbacks and Function Composition
- Immutability
- Closures and Currying
- Functional Array Methods
- Separation of Concerns
-
Browser Events
- Event Fundamentals and addEventListener
- Mouse Events: click, dblclick, mousedown, mouseup, mousemove
- Pointer Events: pointerdown, pointerup, pointermove
- Keyboard Events: keydown, keyup
- Keyboard Shortcuts and Key Detection
- Input Events: input, change, focus, blur
- Form Events: submit, reset
- Scroll Events and Scroll Position
- Wheel Events
- Touch Events and Mobile Interaction
- Drag and Drop Events
- Clipboard Events
- Window Events: load, resize, beforeunload
- Event Object and Event Properties
- Event Bubbling and Capturing
- Event Delegation
- preventDefault and stopPropagation
- Debouncing and Throttling Event Handlers
- Passive Event Listeners
-
Fetch and API
- HTTP Fundamentals
- JSON and Serialization
- Fetch API
- HTTP Methods and Status Codes
- Request Headers and Body
- Handling API Responses and Errors
- Loading and Error States
- Working with Public APIs
-
HTML Forms
- Form Elements and Input Types
- Reading and Handling Form Data
- Client-side Validation
- Custom Validation Messages
- Form Submission and Reset
- Working with FormData
-
Regular Expressions
- Regex Syntax and Patterns
- Character Classes and Quantifiers
- Matching and Searching
- Replacing Text
- Form Validation with Regex
-
Common website components: modals, tabs, burger menus
- Modal Windows
- Tabs and Accordions
- Dropdowns and Burger Menus
- Image Sliders and Carousels
- Search and Filtering
- Sorting and Pagination
- Dynamic Lists
- Reusable UI Components
-
Popular JavaScript Libraries
- jQuery: DOM Manipulation, Events and AJAX
- Bootstrap: Components, Modals, Tooltips and Layout
- Swiper: Sliders, Carousels and Touch Navigation
- GSAP: Advanced Animations and Timelines
- Anime.js: Lightweight Animations
- AOS: Scroll-triggered Animations
- Chart.js: Charts and Data Visualization
- D3.js: Advanced Data Visualization
- Lodash: Utility Functions and Data Manipulation
- Day.js: Date and Time Manipulation
- date-fns: Date Utilities
- Axios: HTTP Requests
- Zod: Data Validation
- SortableJS: Drag and Drop Sorting
- Three.js: 3D Graphics
- Fabric.js: Interactive Canvas and Drawing
- SweetAlert2: Dialogs and Notifications
- Select2: Enhanced Select Elements
- FullCalendar: Calendar Interfaces
- Howler.js: Audio Playback
- Library Installation with npm and pnpm
- CDN vs Package Installation
- Library Documentation and Version Compatibility
- Choosing Between Native JavaScript and Libraries
-
ES6 syntax and features
- let, const and Arrow Functions
- Template Literals
- Optional Chaining and Nullish Coalescing
- Default Parameters
- Modules: import and export
- Classes and Inheritance
- Prototypes and the Prototype Chain
- this, call, apply and bind
-
LocalStorage and browser storage
- LocalStorage and SessionStorage
- Cookies Fundamentals
- Saving and Loading JSON Data
- Persisting Application State
- Browser Storage Limitations
-
JavaScript Debugger
- Browser DevTools Overview
- Console: log, warn, error, table and dir
- Using debugger and Breakpoints
- Step Into, Step Over and Step Out
- Inspecting Variables and Scope
- Call Stack and Execution Context
- Conditional Breakpoints
- Watch Expressions
- DOM Breakpoints
- Debugging Event Handlers
- Network Tab and API Debugging
- Source Maps
- Debugging Asynchronous Code
- Handling Exceptions and Stack Traces
- Common JavaScript Errors
- Performance Profiling and Memory Inspection
-
TypeScript
- TypeScript Fundamentals
- Primitive and Complex Types
- Type Inference and Type Annotations
- Interfaces and Type Aliases
- Union and Intersection Types
- Narrowing and Type Guards
- Generics
- Typing Functions and Objects
- Typing DOM Elements
- Working with API Response Types
- TypeScript Configuration
-
OOP in JavaScript
- Objects and Methods
- Constructor Functions
- Classes and Constructors
- Inheritance and Encapsulation
- Static Methods and Properties
- Prototypes and the Prototype Chain
- this, call, apply and bind
-
Charts and Data Visualization
- Working with Chart Libraries
- Line, Bar and Pie Charts
- Chart Configuration and Customization
- Dynamic Data Updates
- Interactive Charts
- Visualizing API Data
-
JavaScript animations: from pure to Three.js
- CSS Transitions and Animations
- Animating with JavaScript
- requestAnimationFrame
- Scroll-based Animations
- Canvas API Fundamentals
- Three.js and 3D Web Development
-
Moving on to frameworks: React
- Components and JSX
- Props and Component Composition
- State and Event Handling
- Conditional Rendering
- Lists and Keys
- Forms in React
- useEffect and Side Effects
- Custom Hooks
- Routing and Navigation
- API Integration
- TypeScript with React
- Project Structure and Reusable Components
-
Making Games with JavaScript
- Game Loops and Timing
- Keyboard and Mouse Input
- Collision Detection
- Canvas-based Games
- Sprites and Animation
- Physics Fundamentals
- Game State Management
-
OOP in Python
- Objects and Methods
- Constructor Functions
- Classes and Constructors
- Inheritance and Encapsulation
- Static Methods and Properties
- Prototypes and the Prototype Chain
- this, call, apply and bind
-
NPM, packages, pnpm
- Node.js Fundamentals
- NPM and Package Management
- package.json and npm Scripts
- Installing and Managing Dependencies
- pnpm
- Vite and Development Server
- Environment Variables
- JavaScript Modules and Project Structure
- Git and GitHub
-
Asynchronous JavaScript
- Synchronous vs Asynchronous Execution
- Callbacks
- Promises
- async and await
- Error Handling: try...catch
- Promise Chaining and Promise Combinators
- Event Loop and Task Queues
-
Web Workers and Multithreading
- JavaScript Concurrency Fundamentals
- Main Thread and Event Loop
- What Web Workers Are and When to Use Them
- Creating a Worker with the Worker API
- Sending and Receiving Messages
- postMessage and Message Events
- Structured Clone Algorithm
- Transferring ArrayBuffers
- SharedArrayBuffer and Atomics Fundamentals
- Worker Lifecycle and Error Handling
- Dedicated Workers vs Shared Workers
- Worker Limitations: DOM Access and Browser APIs
- Web Workers with Modules
- Practical Use Cases: Data Processing, Calculations and File Parsing
- Communicating Between the Main Thread and Workers
- When to Use Web Workers vs Async JavaScript
-
Git and Github
- What Git Is and Why Version Control Matters
- Installing Git and Initial Configuration
- Creating a Repository with git init
- Cloning Repositories with git clone
- Checking Status with git status
- Staging Changes with git add
- Committing Changes with git commit
- Viewing History with git log
- Working with .gitignore
- Branches and Branch Management
- Switching Branches with git switch
- Merging Branches with git merge
- Handling Merge Conflicts
- Connecting Local Repositories to GitHub
- Pushing and Pulling Changes
- Fetching Remote Changes
- Working with Remote Repositories
- Creating and Reviewing Pull Requests
- Forking and Cloning Repositories
- Issues and Discussions
- README.md and Project Documentation
- GitHub Collaboration Workflow
- Resolving Common Git Problems
- Reverting Changes with git revert
- Undoing Local Changes Safely
- Git Tags and Releases
- GitHub Pages Fundamentals
- GitHub Actions Introduction
-
Testing and Code Quality
- JavaScript Unit Testing
- Assertions and Test Structure
- Mocking and Test Doubles
- Testing Asynchronous Code
- ESLint and Code Formatting
- Refactoring and Clean Code
- Debugging and Error Analysis
React
-
React Fundamentals
- JSX
- Components
- Props
- Children
- Rendering
- Conditional rendering
- Lists and keys
- Event handling
- Component composition
- Fragments
- Basic project structure
- Vite
- React DevTools
-
State and Interactivity
- useState
- State updates
- Functional state updates
- State and component re-rendering
- Controlled components
- Forms
- Form validation
- Lifting state up
- Derived state
- State vs props
- Component communication
-
React Hooks
- useEffect
- Effect dependencies
- Cleanup functions
- useRef
- useMemo
- useCallback
- useReducer
- Custom hooks
- Rules of Hooks
- Common hook mistakes
- Avoiding unnecessary effects
-
Working with APIs
- HTTP fundamentals
- fetch
- REST APIs
- GET / POST / PUT / PATCH / DELETE
- Loading states
- Error handling
- Async operations
- Request cancellation
- Environment variables
- API service layer
- CRUD applications
-
Routing
- React Router
- Routes
- Nested routes
- Dynamic routes
- Route parameters
- Query parameters
- Navigation
- Link and NavLink
- Programmatic navigation
- 404 pages
- Protected routes
- Route layouts
- Authentication flows
-
Forms and User Input
- Controlled inputs
- Uncontrolled inputs
- Form state
- Validation
- Reusable form components
- File uploads
- Multi-step forms
- Form libraries
- Schema validation
-
Global State Management
- Context API
- useContext
- When to use Context
- Global UI state
- Authentication state
- State management patterns
- Redux
- Redux Toolkit
- Async Redux logic
- Zustand
- Choosing a state management solution
-
Server State and Data Fetching
- Server state vs client state
- TanStack Query
- Queries
- Mutations
- Caching
- Query invalidation
- Optimistic updates
- Pagination
- Infinite queries
- Prefetching
- Request retries
- Error handling
- Loading and stale states
-
Authentication
- Authentication concepts
- Sessions
- JWT
- Access tokens
- Refresh tokens
- Cookies
- Login
- Registration
- Logout
- Protected routes
- Role-based access
- Permissions
- OAuth
- Google authentication
- Frontend security basics
-
Styling and UI
- CSS fundamentals
- CSS Modules
- Tailwind CSS
- Responsive design
- Component styling
- Design systems
- Reusable UI components
- Accessibility
- Dark mode
- Animations
- Headless UI libraries
-
TypeScript with React
- TypeScript fundamentals
- Typing props
- Typing state
- Typing events
- Typing refs
- Typing children
- Interfaces and types
- Generics
- Utility types
- API response types
- Reusable generic components
- Type-safe custom hooks
- Type-safe forms
-
Advanced Component Patterns
- Component composition
- Compound components
- Render props
- Higher-order components
- Custom hooks
- Controlled vs uncontrolled components
- State machines
- Headless components
- Reusable component APIs
- Polymorphic components
-
Performance
- React rendering model
- Reconciliation
- Component re-rendering
- React.memo
- useMemo
- useCallback
- Code splitting
- Lazy loading
- Suspense
- Virtualized lists
- Bundle optimization
- Network optimization
- Performance profiling
- React DevTools Profiler
- Core Web Vitals
-
Advanced React
- Concurrent rendering
- Suspense
- Error boundaries
- Server Components
- Server-side rendering
- Static rendering
- Streaming
- Hydration
- React Compiler
- Advanced rendering patterns
-
React Frameworks
- Next.js
- App Router
- Server Components
- Server Actions
- Layouts
- Loading UI
- Error handling
- Metadata
- Image optimization
- Caching
- SSR
- SSG
- ISR
- Middleware
- API routes
- Full-stack React applications
-
Testing
- Unit testing
- Component testing
- Vitest
- React Testing Library
- Mocking APIs
- Integration testing
- End-to-end testing
- Playwright
- Testing forms
- Testing authentication
- Testing user flows
-
Architecture
- Feature-based architecture
- Component architecture
- Container vs presentational components
- Shared components
- Design systems
- Service layers
- API clients
- State architecture
- Custom hooks architecture
- Domain-driven frontend structure
- Dependency management
- Reusable modules
- Scalable folder structures
-
Production React
- Environment configuration
- Build process
- Deployment
- Vercel
- Docker
- CI/CD
- GitHub Actions
- Environment variables
- Logging
- Error monitoring
- Performance monitoring
- Analytics
- Security
- Production debugging
-
Advanced Frontend Engineering
- Frontend architecture
- Micro-frontends
- Monorepos
- Module boundaries
- Design systems
- Advanced caching
- Offline applications
- PWA
- WebSockets
- Real-time applications
- Web workers
- Web performance
- Accessibility engineering
- Internationalization
- Localization
-
Professional React Development
- Code reviews
- Git workflows
- Clean code
- Refactoring
- Technical debt
- Documentation
- Component documentation
- Storybook
- Design-to-code workflows
- API contracts
- Frontend/backend collaboration
- Security practices
- Performance budgets
- Production incident debugging
-
Real-World Projects
- Todo application
- Weather application
- Movie browser
- E-commerce frontend
- Dashboard
- Authentication system
- Admin panel
- Real-time chat
- Social media application
- Full-stack SaaS
- Production-grade React application
Python
-
Tkinter for building simple GUI's
-
Python modules: OS, JSON, datetime
-
Web Scrapping
-
Server for a backend: FastAPI
-
Practicing functions
-
Encoding and Encryption algorithms in Python
-
Databases
-
Telegram bots
-
Websockets
-
Keyboard, mouse, events
-
Pushing libraries to PyPi
-
Server configuration: error handling, middleware, security
Django for web development
-
Django Fundamentals
- Python fundamentals for Django
- Virtual environments
- pip
- Django installation
- Django project structure
- Django applications
- settings.py
- urls.py
- manage.py
- Django development server
- Django configuration
- Environment variables
- Development vs production settings
-
Django CLI
- django-admin
- manage.py
- startproject
- startapp
- runserver
- check
- shell
- dbshell
- makemigrations
- migrate
- showmigrations
- sqlmigrate
- createsuperuser
- changepassword
- collectstatic
- test
- dumpdata
- loaddata
- inspectdb
- makemessages
- compilemessages
-
URLs & Routing
- URL patterns
- path()
- re_path()
- URL parameters
- Path converters
- Named URLs
- URL namespaces
- include()
- URL reversing
- reverse()
- redirect()
- resolve()
- URL organization
-
HTTP & Django Requests
- HTTP methods
- GET
- POST
- PUT
- PATCH
- DELETE
- HTTP status codes
- Request objects
- Response objects
- Headers
- Cookies
- Sessions
- Query parameters
- Form data
- JSON requests
- File uploads
-
Django Views
- Function-based views
- Class-based views
- Generic views
- TemplateView
- ListView
- DetailView
- CreateView
- UpdateView
- DeleteView
- View inheritance
- Mixins
- Decorators
- Custom responses
- JSON responses
-
Templates
- Django Template Language
- Template variables
- Template tags
- Template filters
- Template inheritance
- Base templates
- Template includes
- Custom template tags
- Custom template filters
- Static files
- Template context
-
Models
- Django models
- Model fields
- Field options
- Model metadata
- Model methods
- Model managers
- Model inheritance
- Abstract models
- Proxy models
- Model relationships
- One-to-one relationships
- Foreign keys
- Many-to-many relationships
- Choices
- Constraints
- Indexes
-
Django ORM
- QuerySets
- Query expressions
- Filtering
- Excluding
- Ordering
- Slicing
- get()
- create()
- update()
- delete()
- get_or_create()
- update_or_create()
- exists()
- count()
- first()
- last()
- values()
- values_list()
- annotate()
- aggregate()
- F expressions
- Q objects
- Subqueries
- Conditional expressions
-
Database Design
- Relational databases
- PostgreSQL
- Database normalization
- Primary keys
- Foreign keys
- Constraints
- Unique constraints
- Indexes
- Database transactions
- Isolation concepts
- Query optimization
- N+1 queries
-
Migrations
- Migration fundamentals
- makemigrations
- migrate
- Migration files
- Migration dependencies
- Data migrations
- RunPython
- Migration conflicts
- Squashing migrations
- Migration rollback
- Safe schema changes
-
Django Admin
- Django Admin
- Model registration
- ModelAdmin
- List display
- Search
- Filtering
- Ordering
- Admin actions
- Inline models
- Custom forms
- Permissions
- Admin customization
- Custom admin pages
-
Forms
- Django Forms
- ModelForms
- Form fields
- Form validation
- Custom validation
- clean()
- clean_field()
- Validation errors
- Widgets
- Form rendering
- File uploads
- Multiple forms
-
Authentication
- Django authentication
- Users
- Groups
- Permissions
- Password hashing
- Login
- Logout
- Authentication middleware
- LoginRequiredMixin
- PermissionRequiredMixin
- Custom user model
- User profile
- Password reset
- Email verification
- Social authentication
-
Authorization
- Permissions
- Groups
- Object-level permissions
- Custom permissions
- Permission decorators
- Permission mixins
- Role-based access control
- Access control patterns
-
Sessions & Cookies
- Django sessions
- Session backends
- Cookies
- Session security
- Session expiration
- Session-based authentication
- Session storage
-
Security
- CSRF
- XSS protection
- SQL injection protection
- Clickjacking protection
- Host validation
- Secure cookies
- HTTPS
- Security headers
- Content Security Policy
- Secret management
- Security middleware
- Security checklist
-
Static & Media Files
- Static files
- MEDIA_ROOT
- MEDIA_URL
- STATIC_ROOT
- STATIC_URL
- collectstatic
- FileField
- ImageField
- Storage backends
- User uploads
- Cloud storage
-
Django REST APIs
- Django REST Framework
- Serializers
- ModelSerializer
- APIView
- Generic API views
- ViewSets
- Routers
- Request parsing
- Response rendering
- Status codes
- Validation
- Pagination
- Filtering
- Ordering
-
API Authentication
- Session authentication
- Token authentication
- JWT
- OAuth 2.0
- API keys
- Authentication classes
- Permission classes
- CORS
- CSRF in APIs
- Rate limiting
-
API Design
- REST principles
- Resources
- Endpoints
- HTTP methods
- Status codes
- Request validation
- Response structure
- Error responses
- Pagination
- Filtering
- Sorting
- Versioning
- API documentation
-
Django Testing
- Django TestCase
- pytest
- pytest-django
- Unit tests
- Integration tests
- Model tests
- View tests
- API tests
- Form tests
- Authentication tests
- Test fixtures
- Factories
- Mocking
- Test database
- Test coverage
-
Django Signals
- Signals
- pre_save
- post_save
- pre_delete
- post_delete
- m2m_changed
- Custom signals
- Signal receivers
- Signal design problems
-
Middleware
- Middleware architecture
- Request middleware
- Response middleware
- Authentication middleware
- Custom middleware
- Middleware ordering
- Exception handling middleware
-
Caching
- Django caching
- Cache framework
- Per-view caching
- Template fragment caching
- Low-level cache API
- Redis
- Cache invalidation
- Cache keys
- Cache strategies
-
Background Tasks
- Background jobs
- Celery
- Redis
- Task queues
- Periodic tasks
- Retries
- Task monitoring
- Idempotent tasks
- Async tasks
-
Asynchronous Django
- ASGI
- WSGI
- Async views
- async def
- sync_to_async
- Django async ORM
- Async requests
- Async consumers
- Async limitations
-
Django Channels
- WebSockets
- Channels
- Consumers
- Routing
- Channel layers
- Redis channel layer
- Real-time notifications
- Real-time applications
-
Performance
- Query optimization
- select_related()
- prefetch_related()
- Database indexes
- Query profiling
- N+1 detection
- Caching
- Lazy QuerySets
- Pagination
- Connection management
- Django Debug Toolbar
- Application profiling
-
Django Management
- Custom management commands
- Command arguments
- Command options
- Command output
- Command errors
- Scheduled commands
- Data import
- Data export
- Automation scripts
-
Email
- Django email
- Email backends
- SMTP
- HTML email
- Email templates
- Transactional email
- Email verification
- Password reset emails
- Background email tasks
-
Internationalization
- Translations
- gettext
- gettext_lazy
- Locale middleware
- Language switching
- Translation files
- Timezone handling
- Localization
-
Advanced Django Architecture
- Fat models
- Service layer
- Repository pattern
- Selectors
- Managers
- Mixins
- Domain logic
- Application boundaries
- Dependency management
- Reusable applications
- Modular Django
-
Production Configuration
- Production settings
- Environment variables
- Secrets
- DEBUG
- ALLOWED_HOSTS
- Database configuration
- Static files
- Media files
- Logging
- Error reporting
- Security settings
-
Deployment
- Linux server
- Gunicorn
- Uvicorn
- Nginx
- ASGI deployment
- WSGI deployment
- PostgreSQL
- Redis
- Docker
- Docker Compose
- HTTPS
- SSL certificates
- Domain configuration
- DNS
- CI/CD
-
Django with Docker
- Dockerfile
- Docker Compose
- Django container
- PostgreSQL container
- Redis container
- Environment variables
- Volumes
- Networks
- Static files
- Database migrations
- Production containers
-
CI/CD
- Git
- GitHub
- GitHub Actions
- Automated testing
- Linting
- Formatting
- Build pipelines
- Deployment pipelines
- Database migrations
- Static files deployment
- Environment management
-
Observability
- Django logging
- Structured logging
- Error tracking
- Sentry
- Application metrics
- Health checks
- Database monitoring
- Performance monitoring
- Request tracing
-
Advanced ORM
- Advanced QuerySets
- Custom managers
- Custom QuerySet methods
- Expressions
- Subqueries
- OuterRef
- Exists
- Window functions
- Database functions
- Raw SQL
- Database-specific features
-
Advanced Django REST Framework
- Custom serializers
- Nested serializers
- Serializer validation
- Custom fields
- Custom permissions
- Custom authentication
- Custom pagination
- Custom filters
- Custom throttling
- API versioning
- OpenAPI
- Swagger
- DRF Spectacular
-
Django Security in Practice
- Authentication attacks
- Authorization vulnerabilities
- CSRF attacks
- XSS
- SQL injection
- IDOR
- Mass assignment
- File upload vulnerabilities
- Session attacks
- JWT security
- API security
- Rate limiting
- Security headers
-
Professional Django Development
- Project structure
- Code organization
- Reusable components
- Configuration management
- Database design
- API design
- Testing strategy
- Error handling
- Logging
- Documentation
- Code review
- Git workflow
- Dependency management
- Technical debt
- Refactoring
-
Real Django Projects
- CRUD application
- Authentication system
- REST API
- Admin dashboard
- Payment integration
- Background processing
- Real-time application
- File storage
- Email system
- Third-party API integration
- Dockerized application
- Production deployment
- CI/CD pipeline
- Monitoring
Backend & Deployment
-
Backend Fundamentals
- Backend Fundamentals
- Client-server architecture
- HTTP / HTTPS
- Request / response lifecycle
- URLs, routes and endpoints
- HTTP methods
- Status codes
- Headers
- Query parameters
- Path parameters
- Request body
- JSON
- Content types
- REST API principles
- API versioning
- Idempotency
- Stateless vs stateful systems
- WebSockets for real-time applications
-
Python Backend Fundamentals
- Python for backend development
- Virtual environments
- pip / package management
- Project structure
- Configuration and environment variables
- Logging
- Exceptions and error handling
- Type hints
- Pydantic
- Dependency management
- Application settings
-
FastAPI
- FastAPI project structure
- Routes and path operations
- Request validation
- Pydantic models
- Response models
- Dependency injection
- Routers
- Middleware
- Exception handlers
- Authentication
- Authorization
- OpenAPI / Swagger
- API documentation
- File uploads
- Background tasks
- Async endpoints
- Sync endpoints
- ASGI
- Uvicorn
-
Django
- Django project structure
- Apps
- URLs
- Views
- Request / response
- Templates
- Middleware
- Django settings
- Static and media files
- Management commands
- Django Admin
- Authentication
- Permissions
- Sessions
- Django REST Framework
- Serializers
- API views
- ViewSets
- Routers
- API authentication
- Permissions
- Pagination
- Filtering
- API documentation
-
Sync & Async Programming
- Synchronous execution
- Asynchronous execution
- Blocking operations
- Non-blocking operations
- Event loop
- async / await
- Coroutines
- Tasks
- Concurrency vs parallelism
- I/O-bound operations
- CPU-bound operations
- Threads
- Processes
- Async database access
- Async HTTP requests
- When async actually helps
- Common async mistakes
-
Databases Fundamentals
- Relational databases
- Tables
- Rows and columns
- Primary keys
- Foreign keys
- Relationships
- One-to-one
- One-to-many
- Many-to-many
- Constraints
- Indexes
- Transactions
- ACID
- Normalization
- SQL basics
- SELECT / INSERT / UPDATE / DELETE
- JOINs
- Aggregations
- Transactions and isolation
-
SQLite
- SQLite architecture
- Local development databases
- SQLite limitations
- Database files
- Migrations
- When SQLite is appropriate
- When to move to PostgreSQL
-
PostgreSQL
- PostgreSQL architecture
- Schemas
- Roles and permissions
- Data types
- Indexes
- Constraints
- Transactions
- PostgreSQL-specific features
- Query optimization
- Connection management
- Production databases
-
ORM
- Object-relational mapping
- Models
- Fields
- Relationships
- Queries
- Querysets
- Lazy evaluation
- Migrations
- Transactions
- N+1 query problem
- Eager loading
- Raw SQL
- ORM vs SQL
- Django ORM
- SQLAlchemy
- FastAPI + SQLAlchemy
- Database sessions
-
Users & Authentication
- User accounts
- Registration
- Login / logout
- Password hashing
- Password reset
- Sessions
- Cookies
- Secure cookies
- HTTP-only cookies
- SameSite
- CSRF
- JWT
- Access tokens
- Refresh tokens
- Authentication vs authorization
- Roles
- Permissions
- OAuth
- Google / GitHub login
- Account security
-
HTTP & Server Architecture
- Web server
- Application server
- Reverse proxy
- Middleware
- Request lifecycle
- Routing
- Authentication middleware
- CORS
- Rate limiting
- Compression
- Static files
- Error handling
- Global exception handling
- Logging
- Monitoring
- Health checks
- Graceful shutdown
-
API Development
- REST APIs
- Resource-oriented design
- CRUD
- Request validation
- Response serialization
- Error responses
- Pagination
- Filtering
- Sorting
- Search
- File uploads
- Webhooks
- API authentication
- API versioning
- OpenAPI
- Swagger
- Postman / Insomnia
- API testing
-
Background Tasks
- Why background processing exists
- Long-running operations
- Scheduled tasks
- Email sending
- File processing
- Notifications
- Data processing
- Task queues
- Workers
- Retries
- Failed jobs
- Job status
- Scheduling
-
Redis
- In-memory data storage
- Key-value model
- Caching
- TTL
- Sessions
- Rate limiting
- Pub/Sub
- Redis as a queue
- Redis data structures
- Cache invalidation
- Redis in production
-
Message Queues
- Message brokers
- Producer / consumer model
- Queues
- Messages
- Workers
- Acknowledgements
- Retries
- Dead-letter queues
- RabbitMQ
- Redis-based queues
- Celery
- Task queues vs message brokers
- When to use each approach
-
Workers
- Worker processes
- Celery
- Celery workers
- Celery Beat
- Redis / RabbitMQ as brokers
- Background jobs
- Scheduled jobs
- Retries
- Monitoring workers
- Worker scaling
-
Testing Backend Applications
- Unit tests
- Integration tests
- API tests
- Database tests
- Authentication tests
- Mocking
- Fixtures
- Test databases
- Pytest
- Django Test Framework
- FastAPI testing
- Test-driven development basics
-
Docker
- Containers
- Images
- Dockerfile
- Docker Compose
- Environment variables
- Volumes
- Networks
- Port mapping
- Multi-container applications
- Backend + PostgreSQL
- Backend + Redis
- Backend + worker
- Production containers
- Docker image optimization
-
Linux & Server Fundamentals
- Linux filesystem
- Processes
- Users and permissions
- SSH
- Environment variables
- Ports
- Processes and services
- Logs
- System resources
- Networking basics
- DNS
- TCP/IP basics
- HTTP/HTTPS
- Firewall basics
- Reverse proxies
- Nginx
- Systemd
- Cron
-
Deployment Fundamentals
- Development vs production
- Environment configuration
- Secrets
- Production databases
- Build process
- Application startup
- Process management
- Logs
- Health checks
- Domain names
- DNS
- SSL/TLS
- HTTPS
- Reverse proxy
- Backups
- Database migrations
- Deployment strategies
- Zero-downtime deployment
-
Railway
- Railway projects
- Services
- PostgreSQL
- Environment variables
- Deployments
- GitHub integration
- Logs
- Domains
- Custom domains
- Service-to-service communication
- Redis
- Volumes
- Deployment configuration
- Production debugging
-
Cloud Deployment
- Cloud computing concepts
- Virtual machines
- Managed databases
- Object storage
- Networking
- Load balancing
- Containers
- Serverless concepts
- Environment variables
- Secrets
- Monitoring
-
AWS
- AWS fundamentals
- IAM
- EC2
- RDS
- S3
- CloudFront
- Route 53
- Load Balancer
- CloudWatch
- VPC basics
- Security groups
- ECS / containers
- Lambda overview
- Managed services
- Cost awareness
-
Alternative Cloud Platforms
- Railway
- Render
- Fly.io
- DigitalOcean
- Hetzner
- AWS
- Cloudflare
- Vercel
- Choosing the right platform
- Managed vs self-managed infrastructure
-
CI/CD
- Git
- GitHub
- GitHub Actions
- Automated testing
- Build pipelines
- Deployment pipelines
- Environment-specific deployments
- Secrets
- Rollbacks
- Database migrations during deployment
- Continuous integration
- Continuous deployment
-
Security
- OWASP fundamentals
- SQL injection
- XSS
- CSRF
- Authentication security
- Authorization
- Password security
- Secrets management
- CORS
- Rate limiting
- Input validation
- File upload security
- Dependency vulnerabilities
- HTTPS
- Security headers
- Least privilege
- Secure database access
-
Caching & Performance
- Why applications become slow
- Database bottlenecks
- Query optimization
- Indexes
- N+1 queries
- Application caching
- Redis caching
- HTTP caching
- CDN
- Connection pooling
- Async I/O
- Background jobs
- Load testing
- Profiling
-
Microservices
- Monolith architecture
- Modular monolith
- Microservice architecture
- Service boundaries
- Service-to-service communication
- REST between services
- Internal APIs
- Message queues
- Event-driven architecture
- Service discovery
- Independent deployment
- Independent databases
- Distributed transactions
- Eventual consistency
- Failure between services
- Observability
- When NOT to use microservices
-
Architecture & Design
- MVC
- Layered architecture
- Service layer
- Repository pattern
- Dependency injection
- Separation of concerns
- Domain logic
- Application logic
- Infrastructure layer
- SOLID principles
- Design patterns
- Clean Architecture overview
- Modular architecture
- Monolith vs microservices
-
Laravel
- PHP backend fundamentals
- Laravel project structure
- Routing
- Controllers
- Middleware
- Requests / responses
- Validation
- Blade
- Authentication
- Authorization
- Eloquent ORM
- Migrations
- Relationships
- Query Builder
- API development
- Laravel Sanctum
- Queues
- Jobs
- Events
- Listeners
- Scheduling
- Cache
- Redis
- Laravel Artisan
- Laravel deployment
- Laravel vs Django
- Laravel vs FastAPI
-
Production Project
- Design backend architecture
- PostgreSQL database
- Authentication
- REST API
- Django or FastAPI backend
- Redis
- Background worker
- Message queue
- Docker
- Automated tests
- GitHub Actions
- Production deployment
- Domain + HTTPS
- Logging
- Monitoring
- Backups
- Documentation
- Production debugging
- Performance optimization
Client-Server Architecture
-
Web Fundamentals: HTML, CSS, JS
-
Fetch and API
-
Request / Response structure: body, headers, CORS. Preflight request
-
AJAX
-
HTTP Methods and Status Codes
-
Browser console. Network and requests
-
RESTful API
-
SQL and NoSQL databases
-
Sqlite
-
PostgreSQL
-
MongoDB
-
Schema validation. Types
-
OpenAPI and Swagger
-
CRUD
-
Building middleware
-
Errors Handling
-
Authentication and Authorization. JWT Tokens
-
Pagination
-
States. Async storages
-
Sync and async code and requests
-
Retries. Timeouts. Request cancellation
-
Session, cookies, tokens. JWT
-
Login with Google
-
Security Fundamentals. OWASP TOP 10
-
Password Security
-
State. Server state. Persistent storage
-
Queries and caching. Network optimization
-
Real-time apps. WebSockets, polling, Server-Sent Events
-
Jobs. Workers. Notifications
-
Uploading. File types. Multipart form data. Uploading progress
Linux for server development
-
WSL2
-
20 most common Linux commands
-
Oracle Cloud
-
Github Actions: automating your deployment
-
Docker & Docker Containers
Kali Linux for security artisans
-
Kali Linux Fundamentals
- Kali Linux installation
- Virtual machines
- Kali Linux filesystem
- Terminal
- Shell
- APT package management
- Users and permissions
- sudo
- Processes
- Services
- Environment variables
- SSH
- Bash basics
- Kali Linux tool organization
- Man pages
- Kali documentation
- Updating Kali
- Installing security tools
-
Linux Skills for Pentesting
- Essential Linux commands
- File permissions
- Processes
- Services
- Networking commands
- ip
- ss
- ping
- traceroute
- curl
- wget
- grep
- find
- awk
- sed
- sort
- cut
- xargs
- Pipes and redirection
- Bash scripting
-
Networking for Pentesting
- TCP/IP
- IPv4
- IPv6
- MAC addresses
- ARP
- TCP
- UDP
- Ports
- Sockets
- DNS
- DHCP
- ICMP
- Routing
- NAT
- CIDR
- Subnets
- Firewalls
- Proxies
- VPNs
-
Network Reconnaissance
- Passive reconnaissance
- Active reconnaissance
- OSINT
- WHOIS
- DNS enumeration
- Subdomain enumeration
- Certificate Transparency
- Search engine reconnaissance
- theHarvester
- Amass
- Subfinder
-
Network Scanning
- Nmap
- Host discovery
- Port scanning
- TCP scanning
- UDP scanning
- SYN scanning
- Service detection
- Version detection
- OS detection
- Nmap NSE
- Nmap scripting
- Masscan
- RustScan
- Netcat
-
Network Traffic Analysis
- Wireshark
- tcpdump
- Packet capture
- TCP analysis
- UDP analysis
- DNS analysis
- HTTP analysis
- ARP analysis
- Network troubleshooting
-
Vulnerability Scanning
- CVE
- CVSS
- Vulnerability identification
- Vulnerability validation
- Nuclei
- Nikto
- Greenbone / OpenVAS
- Searchsploit
- Exploit-DB
-
Web Reconnaissance
- HTTP
- HTTPS
- HTTP methods
- HTTP headers
- Cookies
- Sessions
- Web technologies
- Directory enumeration
- File enumeration
- ffuf
- Gobuster
- Feroxbuster
- WhatWeb
- JavaScript reconnaissance
- API endpoint discovery
-
Web Pentesting with Burp Suite
- Burp Suite
- Proxy
- HTTP interception
- Repeater
- Intruder
- Decoder
- Request manipulation
- Response analysis
- Authentication testing
- Authorization testing
- Session testing
- Parameter testing
- Burp extensions
-
Basic Web Vulnerabilities
- SQL Injection
- XSS
- CSRF
- IDOR
- Path Traversal
- File Inclusion
- File Upload
- Command Injection
- SSRF
- SSTI
- XXE
- Authentication vulnerabilities
- Authorization vulnerabilities
- Security misconfiguration
-
Password Attacks
- Password hashes
- Hash identification
- Wordlists
- Hashcat
- John the Ripper
- Hydra
- Password spraying
- Brute-force concepts
- Credential stuffing concepts
-
Exploitation
- Exploit concepts
- Exploit-DB
- Searchsploit
- Metasploit
- Metasploit modules
- Payloads
- Auxiliary modules
- Exploit validation
- Manual exploitation
- Meterpreter
-
Linux Privilege Escalation
- Linux permissions
- SUID
- SGID
- sudo
- Capabilities
- Cron jobs
- PATH hijacking
- Writable files
- Writable services
- Environment variables
- Kernel vulnerabilities
- LinPEAS
- Manual enumeration
-
Windows Pentesting from Kali
- SMB
- RDP
- WinRM
- Windows enumeration
- Windows authentication
- Windows users
- Windows services
- PowerShell
- CrackMapExec / NetExec
- Impacket
- Evil-WinRM
- BloodHound
-
Active Directory Basics
- Domain enumeration
- LDAP
- Kerberos
- SMB
- Domain users
- Domain groups
- Domain controllers
- BloodHound
- Kerberoasting
- AS-REP Roasting
- Password spraying
- Lateral movement
-
Pivoting
- Network pivoting
- Port forwarding
- SSH tunneling
- SOCKS proxies
- Proxychains
- Chisel
- Ligolo-ng
- Internal network enumeration
-
Wireless Pentesting
- Wireless fundamentals
- 802.11
- Monitor mode
- Wireless interfaces
- Packet capture
- Aircrack-ng
- Wireshark
- WPA/WPA2/WPA3
- Wireless reconnaissance
-
Pentesting Automation
- Bash scripting
- Python for pentesting
- Requests
- Scapy
- Nmap automation
- API automation
- Custom enumeration scripts
- Parsing scan results
- Automated reconnaissance
-
Pentesting Methodology
- Scope
- Rules of engagement
- Reconnaissance
- Enumeration
- Scanning
- Vulnerability identification
- Exploitation
- Privilege escalation
- Lateral movement
- Pivoting
- Evidence collection
- Cleanup
- Reporting
-
Pentest Reporting
- Finding identification
- Evidence
- Proof of Concept
- Risk rating
- CVSS
- Business impact
- Remediation
- Technical report
- Executive summary
- Retesting
-
Practical Pentesting
- Vulnerable Linux machines
- Vulnerable Windows machines
- Web application labs
- Network penetration testing labs
- OWASP Juice Shop
- DVWA
- Metasploitable
- Hack The Box
- TryHackMe
- PortSwigger Web Security Academy
- Full penetration test simulation
Advanced Cybersecurity
-
Linux Fundamentals
- Kali Linux installation & VM setup
- Linux filesystem
- Terminal & shell
- Essential Linux commands
- Users & groups
- File permissions
- sudo
- Processes
- Services
- Environment variables
- Package management with apt
- Pipes & redirects
- grep
- awk
- sed
- sort
- cut
- xargs
- Bash scripting
- SSH
-
Networking Fundamentals
- OSI model
- TCP/IP model
- IPv4 / IPv6
- MAC addresses
- ARP
- TCP vs UDP
- Ports & sockets
- DNS
- DHCP
- ICMP
- Routing
- NAT
- Subnets & CIDR
- Firewalls
- Proxies
- VPNs
-
Network Analysis
Network interfaces ip ss route ping traceroute tcpdump Wireshark Packet capture TCP handshake analysis DNS traffic analysis HTTP/HTTPS traffic analysis Network troubleshooting
-
Reconnaissance
- Passive reconnaissance
- Active reconnaissance
- OSINT
- WHOIS
- DNS enumeration
- Subdomain discovery
- Certificate Transparency
- Search engine dorking
- Amass
- Subfinder
- theHarvester
- Maltego
- Attack surface discovery
-
Port & Service Enumeration
- Nmap
- TCP scanning
- UDP scanning
- SYN scanning
- Service detection
- Version detection
- OS detection
- NSE scripts
- Masscan
- RustScan
- Banner grabbing
- Netcat
- Service enumeration methodology
-
Vulnerability Assessment
- Vulnerability vs exploit
- CVE
- CVSS
- Vulnerability scanning
- False positives
- Vulnerability validation
- Nuclei
- Nikto
- OpenVAS / Greenbone
- Searchsploit
- Exploit-DB
- Manual vulnerability verification
-
Web Fundamentals
- HTTP
- HTTPS
- HTTP methods
- HTTP status codes
- HTTP headers
- Cookies
- Sessions
- Authentication
- Authorization
- REST APIs
- JSON
- CORS
- Same-Origin Policy
- TLS
- Browser DevTools
-
Web Reconnaissance
- Directory enumeration
- File enumeration
- ffuf
- Gobuster
- Feroxbuster
- robots.txt
- sitemap.xml
- Technology fingerprinting
- WhatWeb
- Wappalyzer
- JavaScript analysis
- API endpoint discovery
-
Burp Suite
- Proxy
- HTTP interception
- Repeater
- Intruder
- Decoder
- HTTP request manipulation
- HTTP response analysis
- Scope configuration
- Burp extensions
- Automating repetitive tasks
-
OWASP Top 10
- Broken Access Control
- Cryptographic Failures
- Injection
- Insecure Design
- Security Misconfiguration
- Vulnerable Components
- Authentication Failures
- Software and Data Integrity Failures
- Logging and Monitoring Failures
- SSRF
-
Web Application Pentesting
- Authentication testing
- Session management testing
- Authorization testing
- Access control testing
- Input validation
- Error handling
- Business logic testing
- Parameter manipulation
- Request manipulation
- Response manipulation
-
Web Exploitation
- SQL Injection
- NoSQL Injection
- Cross-Site Scripting
- CSRF
- SSTI
- XXE
- SSRF
- Path Traversal
- Local File Inclusion
- Remote File Inclusion
- File Upload vulnerabilities
- Command Injection
- Deserialization vulnerabilities
- Prototype Pollution
- HTTP Request Smuggling
-
Password & Authentication Security
- Password hashing
- Hash identification
- Hashcat
- John the Ripper
- Wordlists
- Password mutation
- Hash cracking concepts
- Password spraying
- Brute-force concepts
- Credential stuffing
- Hydra
- Authentication attack methodology
-
Exploitation Fundamentals
- Vulnerability vs exploit
- Public exploits
- Exploit-DB
- Searchsploit
- Metasploit Framework
- Modules
- Payloads
- Exploit modules
- Auxiliary modules
- Meterpreter
- Manual exploitation
- Exploit validation
-
Linux Privilege Escalation
- Linux permissions
- SUID
- SGID
- sudo misconfigurations
- Linux capabilities
- Cron jobs
- PATH hijacking
- Writable files
- Writable services
- Environment variables
- Kernel vulnerabilities
- LinPEAS
- Manual enumeration
- Privilege escalation methodology
-
Windows Fundamentals
- Windows architecture
- Windows users and groups
- Windows services
- Windows Registry
- PowerShell
- NTFS permissions
- Windows networking
- SMB
- RDP
- WinRM
- Windows authentication
-
Windows Privilege Escalation
- Service misconfigurations
- Unquoted service paths
- Weak file permissions
- Scheduled tasks
- Registry weaknesses
- Token privileges
- DLL hijacking
- Credential discovery
- WinPEAS
- Manual enumeration
- Privilege escalation methodology
-
Active Directory
- Active Directory architecture
- Domains
- Domain Controllers
- Forests
- LDAP
- Kerberos
- NTLM
- SMB
- Domain users
- Domain groups
- Group Policy
- BloodHound
- LDAP enumeration
- Kerberos enumeration
- Domain attack paths
-
Active Directory Attacks
- Kerberoasting
- AS-REP Roasting
- NTLM relay concepts
- Pass-the-Hash
- Pass-the-Ticket
- ACL abuse
- Delegation attacks
- Credential attacks
- Lateral movement
- Domain privilege escalation
-
Post-Exploitation
- Situational awareness
- Local enumeration
- Credential discovery
- Network discovery
- Internal service enumeration
- Process enumeration
- User enumeration
- Network configuration
- Persistence concepts
- Controlled access
- Evidence collection
- Cleanup
-
Network Pivoting
- Pivoting concepts
- Internal network mapping
- Routing through compromised hosts
- SOCKS proxies
- SSH tunneling
- Local port forwarding
- Remote port forwarding
- Proxychains
- Chisel
- Ligolo-ng
- Multi-hop pivoting
-
Wireless Security
- Wi-Fi architecture
- 802.11 fundamentals
- Wireless interfaces
- Monitor mode
- Packet capture
- Aircrack-ng
- Wireshark
- WPA/WPA2/WPA3
- Wireless authentication
- Rogue access point concepts
- Wireless security assessment
-
API Security
- REST APIs
- GraphQL
- JWT
- OAuth 2.0
- API authentication
- API authorization
- BOLA / IDOR
- Rate limiting
- Mass assignment
- API fuzzing
- API enumeration
- OWASP API Security Top 10
-
Cloud Security
- Cloud fundamentals
- IAM
- AWS fundamentals
- Azure fundamentals
- GCP fundamentals
- Object storage
- Security groups
- Cloud metadata services
- Access keys
- Cloud misconfigurations
- ScoutSuite
- Trivy
- Cloud enumeration
-
Container Security
- Docker architecture
- Docker images
- Dockerfiles
- Container networking
- Container privileges
- Docker socket
- Container secrets
- Image vulnerabilities
- Trivy
- Docker Bench
- Container escape concepts
-
Source Code Security
- Git fundamentals
- Git history analysis
- Secret discovery
- API key exposure
- Environment variables
- Dependency vulnerabilities
- SAST
- Semgrep
- Gitleaks
- TruffleHog
-
Security Automation
- Python for security
- Bash automation
- PowerShell automation
- Requests
- Scapy
- Nmap automation
- API automation
- Custom enumeration scripts
- Result parsing
- JSON
- CSV
- Reusable security tools
-
Exploit Development
- Python for exploit development
- C fundamentals
- Memory layout
- Stack
- Heap
- Registers
- Assembly basics
- GDB
- Buffer overflows
- Shellcode concepts
- ASLR
- DEP / NX
- Stack canaries
- Basic binary exploitation
-
Binary Analysis
- ELF
- PE
- Executable formats
- Static analysis
- Dynamic analysis
- Strings analysis
- Ghidra
- x64dbg
- Process analysis
- Debugging
- Reverse engineering fundamentals
-
Malware Analysis
- Malware fundamentals
- Static malware analysis
- Dynamic malware analysis
- PE analysis
- ELF analysis
- Indicators of Compromise
- Sandboxing
- Process monitoring
- Network behavior analysis
- Reverse engineering
-
Professional Pentesting Methodology
- Rules of engagement
- Scope definition
- Asset discovery
- Attack surface mapping
- Threat modeling
- Reconnaissance
- Enumeration
- Vulnerability analysis
- Exploitation
- Privilege escalation
- Lateral movement
- Pivoting
- Impact assessment
- Evidence collection
- Cleanup
- Documentation
-
Pentest Reporting
- Executive summary
- Technical findings
- Evidence
- Reproduction steps
- Risk rating
- CVSS
- Business impact
- Remediation
- Proof of Concept
- Retesting
- Final report
-
Real-World Pentesting Workflow
- Scope
- Reconnaissance
- Attack surface discovery
- Enumeration
- Service identification
- Vulnerability discovery
- Manual validation
- Initial access
- Privilege escalation
- Credential discovery
- Lateral movement
- Pivoting
- Impact validation
- Evidence collection
- Cleanup
- Reporting
- Remediation
- Retesting
-
Practice Labs
- OverTheWire
- PortSwigger Web Security Academy
- TryHackMe
- Hack The Box
- VulnHub
- OWASP Juice Shop
- DVWA
- Metasploitable
- Damn Vulnerable API
- Self-hosted vulnerable environments
-
Advanced Red Team Concepts
- Adversary simulation
- Initial access
- Command and Control
- C2 frameworks
- Evasion concepts
- OPSEC
- Identity attacks
- Active Directory attack paths
- Cloud attack paths
- Detection engineering
- Purple Team methodology