Watch
Learn the concept through an embedded video lesson.
A structured, video-first academy combining core knowledge, guided practice, official tools, downloadable how-to guides, and ethical laboratory work.
Every module follows the same professional learning sequence so students know exactly what to do and how to document their work.
Learn the concept through an embedded video lesson.
Download the step-by-step guide and reference notes.
Apply the lesson inside an isolated, authorized lab.
Document sources, commands, observations, and results.
Confirm meaningful findings through independent sources.
Select any lesson or tool card below. The video will load here while your learning checklist remains visible.
Build the foundations first, then choose a specialization. Each step loads a related lesson into the academy workspace.
Each classroom is designed to grow into a complete course with videos, guides, exercises, prerequisites, and progress tracking.
Authorized reconnaissance, scanning, enumeration, web testing, privilege escalation, reporting, and remediation.
SIEM, IDS/IPS, endpoint defense, network monitoring, detection engineering, and threat hunting.
Preparation, detection, containment, eradication, recovery, evidence handling, and lessons learned.
AWS, Azure, Google Cloud, IAM, logging, containers, Kubernetes, secrets, and Zero Trust.
Static and dynamic analysis, sandboxing, indicators of compromise, behavioral analysis, and reporting.
Disk imaging, memory analysis, Windows artifacts, logs, registry analysis, timelines, and chain of custody.
Assembly, Ghidra, IDA Free, x64dbg, binary formats, debugging, decompilation, and memory inspection.
Hashing, AES, RSA, ECC, signatures, TLS, certificates, PKI, and key management.
Prompt injection, model privacy, adversarial ML, agent security, red teaming, and secure deployment.
Watch the lesson inside Polymath Studies, open the official tool when needed, download the how-to, and complete a safe exercise.
A curated collection of essential Kali tools. Every card follows the same four-step visual learning pattern: watch the lesson, use the official reference, download the guide, and practice safely in CyberLab.
Identify hosts, services, domains, and public-facing information.
Visual concept: tester → packets → target ports → service map.
Emphasizes passive collection, source attribution, and false-positive review.
Inspect requests, test training applications, and understand common web weaknesses.
Visual concept: browser request pauses inside an intercepting proxy.
The lab begins with manual understanding before automated testing.
Observe packets and connect command-line activity to defensive evidence.
Visual concept: live packets → protocol layers → conversation timeline.
Understand 802.11 frames and assess only isolated laboratory wireless networks.
Initial exercises use prerecorded training captures before live lab hardware.
Learn how storage choices, password length, and defensive controls affect resistance to guessing.
Labs use fabricated hashes—never obtained credentials or third-party data.
Understand vulnerability validation and remediation using intentionally vulnerable targets.
Every offensive action is paired with a defensive observation and fix.
Practice in isolated environments and never test systems, accounts, networks, or people without explicit permission.
Use VirtualBox, VMware, or Proxmox to isolate laboratory systems from production devices.
Use Kali Linux or another controlled environment for authorized exercises.
Use intentionally vulnerable systems such as OWASP Juice Shop and Metasploitable.
Use Wireshark, Zeek, Suricata, Security Onion, and endpoint logs to observe lab activity.