██▀███ ▓█████ ▄████▄ ▒█████ ███▄ █ ▓██ ▒ ██▒▓█ ▀ ▒██▀ ▀█ ▒██▒ ██▒ ██ ▀█ █ ▓██ ░▄█ ▒▒███ ▒▓█ ▄ ▒██░ ██▒▓██ ▀█ ██▒ ▒██▀▀█▄ ▒▓█ ▄ ▒▓▓▄ ▄██▒▒██ ██░▓██▒ ▐▌██▒ ░██▓ ▒██▒░▒████▒▒ ▓███▀ ░░ ████▓▒░▒██░ ▓██░
welcome operator
Six modules. Six tools. Each one teaches you a real-world reconnaissance, vulnerability research, or hardening tool — explanation, simulated terminal output, and hands-on challenges with hints. All progress saves locally in your browser.
Each module: Brief → Command anatomy → Simulated runs → Hands-on challenges
- Type commands into the practice terminals and press Enter
- Use ↑ to recall previous commands
- Use hint buttons (staged — only get as much help as you need)
- Progress saves automatically in your browser
searchsploit
A command-line search tool for Exploit-DB — the public archive of exploits maintained by Offensive Security. Bundled with Kali. When you find an old service version on a target, this is usually the first place you look.
Searchsploit searches a local copy of the Exploit-DB archive — fast, offline, and scriptable. Give it terms (software name, CVE, version) and it prints matching entries with paths to exploit code on disk.
The local mirror lives at /usr/share/exploitdb/. Update it with searchsploit -u.
Basic form: searchsploit [options] [term1] [term2] ...
| flag | purpose |
|---|---|
| -c | case-sensitive search |
| -e | exact match on the title |
| -t | search title only |
| -w | show Exploit-DB URLs instead of local paths |
| -m EDB-ID | mirror (copy) the exploit to current directory |
| -x EDB-ID | examine an exploit in pager |
| -u | update the local exploit database |
| --cve CVE-ID | search by CVE identifier |
| --nmap FILE.xml | auto-search using nmap XML scan results |
| --exclude="term" | filter results out (e.g. exclude "/dos/") |
Watch valid and invalid syntax before trying it yourself.
Your turn. Type the command and press Enter.
OBJECTIVE — Find exploits for vsftpd 2.3.4
An nmap scan revealed vsftpd 2.3.4 on port 21. Search the local Exploit-DB.
OBJECTIVE — Find exploits by CVE
Search by CVE identifier CVE-2021-41773 (Apache path traversal).
OBJECTIVE — Search wordpress, exclude DoS
Find WordPress exploits but filter out denial-of-service entries.
OBJECTIVE — Mirror an exploit to your working directory
You found EDB-ID 49757. Copy it into the current directory.
searchscan
Searchsploit's --nmap integration — feed it XML output from a service-version scan and it cross-references every detected service against Exploit-DB automatically.
Run nmap with version detection and dump XML, then pass that file to searchsploit. The tool parses each banner and runs a search per service.
Step 1: nmap -sV -oX scan.xml 10.10.10.5
Step 2: searchsploit --nmap scan.xml
Watch the full workflow.
OBJECTIVE — Generate the XML for a target
Run a service-version scan against 10.10.10.40 and save XML as recon.xml.
OBJECTIVE — Correlate the XML against Exploit-DB
You have recon.xml. Run the auto-correlation.
OBJECTIVE — Verbose correlation, suppress DoS
Same XML but verbose mode and exclude DoS entries.
cve-bin-tool
Open-source scanner from Intel that inspects binaries to detect known-vulnerable components. Points at a directory, archive, or binary — identifies what's inside and reports CVEs.
OBJECTIVE — Basic scan of a directory
Scan ./firmware_extract for known CVEs.
OBJECTIVE — High/critical only, HTML report
Same target, only high severity, output HTML to report.html.
OBJECTIVE — Scan an SBOM offline
Air-gapped network. Scan CycloneDX SBOM at ./sbom.json using only cached database.
nmap NSE
The Nmap Scripting Engine turns nmap from a port scanner into a programmable recon and vuln-detection platform. ~600 scripts, organized into categories.
OBJECTIVE — Default scripts + version detection
Scan 10.10.10.5 with version detection and default NSE scripts.
OBJECTIVE — All vuln scripts on a target
Run all vuln category scripts against 10.10.10.5 with version detection.
OBJECTIVE — Targeted SMB vuln check
Run all smb-vuln-* scripts on port 445 against 10.10.10.5.
OBJECTIVE — Read the docs first
Show help for http-shellshock without running it.
linux-exploit-suggester
Bash script that suggests local privilege-escalation exploits based on kernel version and distribution. Drop-and-run the moment you get a low-priv shell.
OBJECTIVE — Make it executable and run it
You downloaded linux-exploit-suggester.sh to /tmp. Make it executable and run it.
OBJECTIVE — Triage from a captured kernel string
A pcap recovered kernel string 4.4.0-116-generic. Ask the tool what exploits apply.
OBJECTIVE — Check binary mitigations
Use LES checksec mode against /usr/local/bin/myapp.
sslscan
Focused tool for inspecting SSL/TLS configuration. Enumerates protocol versions, cipher suites, certificate details, and known weaknesses.
OBJECTIVE — Basic scan
Default sslscan against example.com port 443.
OBJECTIVE — Cert-only check on non-standard port
Get cert details from internal.lab:8443 without enumerating every cipher.
OBJECTIVE — STARTTLS on SMTP submission
Inspect TLS on mail.corp.local port 587 using STARTTLS.
OBJECTIVE — Verify only TLS 1.2 is offered
Test only TLS 1.2 on secure.lab and save XML report to tls12.xml.