The definitive, zero-to-elite offensive security engineering curriculum, low-level systems syllabus, and operational security compendium built from the metal up.
Curriculum Index • Visual Learning Path • Weaponized Payloads • Bleeding-Edge Modules • Journey Tracker • Citation • Legal Notice
44,900+ Lines · 8 Phases · 300+ Tools · 200+ ATT&CK Techniques · 1,080+ Code Blocks · 150+ Diagrams · 325+ Lines (Payloads)
If this curriculum has value for your offensive security journey, consider starring the repository to help other researchers and operators discover it.
- Built from the metal up. Every phase teaches the underlying system internals before attack techniques. No "just run this tool" shortcuts.
- Compilable offensive code. Not just theory. Includes working C and Rust payloads with PEB traversal, DJB2 hashing, and in-memory loaders.
- OPSEC before hacking. Phase -1 comes before Phase 0. Operational security, threat modeling, and anonymous infrastructure are prerequisites.
- Full MITRE ATT&CK alignment. 200+ techniques mapped across Enterprise v15, ICS, and ATLAS. Every section ties back to the framework.
- Covers what others skip. Physical red teaming, drone reconnaissance, social engineering pretexts, quantum SNDL, and post-quantum cryptography.
| Your Background | Recommended Entry Point | Modules | Estimated Time | Parallel Learning |
|---|---|---|---|---|
| Everyone starts here | Phase -1: OPSEC & Infrastructure | 24 | 4-6 weeks | Survival Tactics · Mindset · FAQ |
| Complete beginner | Phase 0: Foundation | 23 | 12-16 weeks | Lab Setup Guide |
| Web developer / bug bounty | Phase 1: Web Security | 39 | 8-12 weeks | - |
| Sysadmin / network engineer | Phase 2: Network & Infrastructure | 23 | 10-14 weeks | - |
| Reverse engineer / CTF player | Phase 3: Binary Exploitation & RE | 21 | 12-16 weeks | MITRE Reference · Tools (300+) · Resources |
| Experienced pentester | Phase 4: Specialized Tracks (4A-4I) | 16 | Choose your track | Pick 1 primary + 1 secondary |
| Researcher / exploit dev | Phase 5: GREATEST | 22 | Ongoing | Final Word |
| Special operator | Phase 6: Special Operations | 39 | Ongoing | Parallel with Phase 5 · Final Word |
Fork the Journey Tracker to monitor your progress across phases.
Reading Guide
- It is recommended to use a mobile device because there are over 150 high-quality diagrams, which you can easily zoom in and out on mobile.
- Avoid using the GitHub app on mobile; instead, access GitHub through your browser in desktop view.
- All diagrams have been tested in light mode, so using dark mode is not advised.
- Are you facing any problems? Is there anything difficult to understand? Do you have any suggestions? Join the conversation and drop a comment in GitHub Discussions. Community feedback and contributions are always welcome.
- For broken links, typos, payload errors, or bug reports, please open an issue.
Explore Phase -1 Syllabus (24 Modules)
- Why This Comes Before Everything Else
- Real Operators. Real Failures. Real Lessons.
- The Legal Framework: Read This First
- Counter-OSINT: Know Your Exposure Before You Start
- Threat Modeling: Think Before You Act
- Communication Security: The Number One Arrest Vector
- Phone and Mobile OPSEC
- Anonymous Infrastructure Setup
- Anonymization Stack: VPN, Tor, and Chaining
- Browser Fingerprinting: You Are Being Identified
- Cryptocurrency: Why Monero and How It Actually Works
- Identity Compartmentalization and Stylometry
- Secure Research OS
- Physical OPSEC: The Layer Most Guides Ignore
- Timing and Pattern OPSEC: The Invisible Fingerprint
- Metadata: The Silent Killer
- Secure Deletion: Leaving Nothing Behind
- What Logs Exist on Every System You Touch
- Forensic Artifacts on Your Own Machine (New in v5.5)
- Cold Boot and Evil Maid: Concrete Mitigations (Expanded in v5.5)
- When Things Go Wrong: The Burn Protocol (New in v5.5)
- Crew OPSEC and Cell Structure (New in v5.5)
- Phase -1 Milestones Checklist
- Resources
Explore Phase 0 Syllabus (23 Modules)
- Goal and Philosophy
- How to Use This Phase
- Prerequisites
- Checkpoint: What You Must Know by the End
- Timeline and Parallel Track Architecture
- Section 1: Operating Systems Fundamentals
- Section 1B: Bash Scripting Essentials
- Section 2: C Programming
- Section 3: Python Scripting
- Section 4: Networking Fundamentals
- Section 5: x86-64 Assembly
- Section 6: Reverse Engineering Basics
- Section 7: Cryptography Primer
- Section 8: ARM64 Architecture Awareness
- Section 9: glibc Internals Primer
- Milestone Projects: Full Spec Cards
- Lab Setup
- GDB Setup and Command Reference
- CTF Platform Guide
- Common Failure Points and Fixes
- Phase 0 Master Checklist
- What Comes Next
- Resources Aggregated
Parallel Learning Alongside Phase 0: Operational OPSEC, Mindset & FAQ (3 Master Guides)
- For the Beginner: Start Here
- Threat Modeling Framework
- Section 1: Digital Identity and Persona Architecture
- Section 2: Device Security - OS and Hardware
- Section 3: Network-Level OPSEC
- Section 4: Communications Security
- Section 5: Cryptocurrency and Financial Security
- Section 6: Physical Location Security
- Section 7: Physical Appearance and Counter-Surveillance
- Section 8: Social Engineering Defense (Self-Protection)
- Section 9: AI-Powered Surveillance Evasion (2027)
- Section 10: Blockchain Forensics Threat Model (2027)
- Section 11: Darknet Operational Security
- Section 12: Legal Counter-Intelligence
- Section 13: Long-Term Survival Planning
- Section 14: Emergency Exfil Protocol
- Section 15: Counter-LE Awareness
- Section 16: International Jurisdictions 2027
- Section 17: OPSEC Golden Rules
- Section 18: Case Studies
- Section 19: Advanced Hardware Attack Resistance
- Section 20: In-Memory Forensics and Cold Boot Defense
- Section 21: Server-Side Detection and eBPF Awareness
- Quick Reference Operational Checklist
- What This Is Not
- What a BlackHat Actually Is
- The Cognitive Progression
- The Separation That Matters: Student, Operator, Researcher
- GREATEST vs Good - The 2027 Edition
- The Seven Pillars of the BlackHat Mindset
- The 2027 Landscape Reality
- The Psychological Framework
- Reality Check - Updated 2027
- The Closing Truth
- Getting Started
- Hardware, OS, and Environment
- Learning Path and Methodology
- Certifications and Courses
- Technical Questions
- AI, Tools, and the 2027 Landscape
- Bug Bounty and Real-World Practice
- Mindset, Burn-Out, and Staying Operational
- Authorization, OPSEC, and Legal Reality
- Questions Nobody Asks But Should
- 2027 Special Operations and Horizons FAQ
Explore Phase 1 Syllabus (39 Modules)
- How To Use This Phase
- Difficulty Map
- The Developer Mindset
- Week-by-Week Spine
- When You Are Stuck
- Section 0: Lab Environment Setup
- Section 1: HTTP Fundamentals
- Section 2: Reconnaissance and Target Mapping
- Section 3: SQL Injection
- Section 3.5: Command Injection
- Section 4: Cross-Site Scripting (XSS)
- Section 5: CSRF and CORS Misconfiguration
- Section 6: Server-Side Request Forgery (SSRF)
- Section 7: XML External Entity Injection (XXE)
- Section 8: Authentication Attacks
- Section 8.5: NoSQL Injection
- Section 9: Access Control and IDOR
- Section 10: Business Logic Flaws
- Section 11: Path Traversal / LFI / RFI
- Section 12: File Upload Vulnerabilities
- Section 13: Server-Side Template Injection (SSTI)
- Section 14: HTTP Request Smuggling and H2C Attacks
- Section 15: Race Conditions
- Section 16: WebSocket Attacks
- Section 17: GraphQL Attacks
- Section 18: API Security (OWASP API Top 10: 2023)
- Section 19: Prototype Pollution
- Section 20: Web Cache Poisoning and Deception
- Section 21: OAuth2 and OIDC Attacks
- Section 22: Deserialization Attacks
- Section 23: Clickjacking
- Section 24: Modern SPA and Framework Attacks
- Section 25: LLM Integration Attack Surface
- Section 26: Chaining Vulnerabilities
- Milestone Projects
- Tools Reference and Decision Tree
- Web Testing Methodology Framework
- Phase 1 Final Milestones Checklist
- Resources Aggregated
Parallel Learning Alongside Phase 1: Enterprise Attack Labs (1 Master Guide)
- Overview and Philosophy
- Hardware Requirements
- Hypervisor Selection
- Lab Network Architecture
- Core VM Library
- Attacker VM: Kali Linux 2024+
- Development VM: Ubuntu 22.04 LTS
- Windows Target and Implant Dev VM
- Active Directory Lab: GOAD
- Malware Analysis Environment
- Kernel Debugging Environment
- Container Attack Lab
- Cloud Lab Alternative
- OPSEC Layer: Whonix + Qubes
- Detection Visibility Layer: DetectionLab
- ICS/SCADA Lab
- Hardware Hacking Lab
- Vulnerability Research & Fuzzing Lab (Phase 5: GREATEST)
- Special Operations Lab: Physical, SE & Quantum (Phase 6)
- Snapshot Discipline
- Phase-by-Phase Lab Evolution
- Environment Verification Checklist
- Maintenance Schedule
Explore Phase 2 Syllabus (23 Modules)
- What This Phase Builds
- Prerequisites Check
- Phase 2 Kill Chain
- Lab Topology
- Timeline Overview
- How to Use This Phase
- Section 1: Reconnaissance and OSINT
- Section 2: Service Exploitation
- Section 3: Privilege Escalation - Linux
- Section 4: Privilege Escalation - Windows
- Section 5: Credential Poisoning and Relay Attacks
- Section 6: Post-Exploitation and Lateral Movement
- Section 6.6: Active Directory - Enumeration and Attacks
- Section 7: Network Pivoting and Tunneling
- Section 8: Wireless Attacks
- Section 9: Password Attacks Methodology
- Section 10: AV/EDR Evasion and Payload Delivery
- Section 11: C2 Framework Operations
- Section 12: OPSEC Within Phase 2
- Milestone Projects
- Phase 2 Completion Checklist
- CTF Labs and Practice Targets
- Phase 2 to Phase 3 Bridge
Explore Phase 3 Syllabus (21 Modules)
- Who This Phase Is For
- Phase 3 Architecture Map
- Timeline
- Goal and Checkpoints
- Milestone Projects
- Block 0: Environment Setup
- Block 1: Binary Exploitation Fundamentals
- Block 2: Shellcode Writing
- Block 3: Exploit Mitigations and Bypass
- Block 4: Format String Vulnerabilities
- Block 5: Heap Exploitation -- Linux glibc Modern
- Block 6: Windows Heap Exploitation
- Block 7: Linux Kernel Exploitation
- Block 8: Linux Kernel SLUB/Slab Exploitation
- Block 9: Windows Kernel Exploitation
- Block 10: ARM64 Exploitation + PAC Bypass
- Block 11: Control Flow Guard Bypass
- Block 12: Linux eBPF Rootkits + Anti-Detection
- Block 13: HVCI, VBS and Kernel Security 2026-2027
- Block 14: Mobile Security -- Android and iOS
- CTF Progression and Lab Resources
Explore Phase 4 Operator Tracks & Curriculums (16 Sections)
| Section | Topic | Difficulty | Time Estimate |
|---|---|---|---|
| Phase 4 Intro | How to read, pairings, bridge checklist, architecture map | - | 2 hrs |
| 4A | Implant and Malware Development | Expert | 8-12 weeks |
| 4B | C2 Framework Development | Expert | 6-10 weeks |
| 4C | EDR Evasion and Defense Bypass | Expert | 6-8 weeks |
| 4D | Vulnerability Research and 0-Day Development | Expert+ | 12-20 weeks |
| 4E | APT Persistence, Rootkits, Anti-Forensics | Expert | 8-12 weeks |
| 4F | Cloud, AiTM Phishing, and Advanced Web | Expert | 6-10 weeks |
| 4G | Hardware, Firmware, and Silicon | Expert | 8-16 weeks |
| 4H | Supply Chain and Ecosystem Attacks | Expert | 4-8 weeks |
| 4I | Active Directory and Identity Tradecraft | Expert | 8-12 weeks |
| 4J | macOS and Linux Offensive Tradecraft | Advanced | 4-8 weeks |
| 4X | Physical Red Team (Field Tradecraft) | Advanced | 4-8 weeks |
| MITRE Reference | ATT&CK technique mapping for all Phase 4 sections | - | Reference |
| Tools Master List | All tools organized by specialization | - | Reference |
| Completion Gates | 12 binary gates to verify Phase 4 depth | - | Checkpoints |
| What Comes After | Path from Phase 4 to top 0.0001% | - | Reference |
Parallel Learning Alongside Phase 4: Tactical Matrices, Tooling & Literature (3 Master Guides)
- Enterprise Tactic Overview
- TA0043: Reconnaissance
- TA0042: Resource Development
- TA0001: Initial Access
- TA0002: Execution
- TA0003: Persistence
- TA0004: Privilege Escalation
- TA0005: Defense Evasion
- TA0006: Credential Access
- TA0007: Discovery
- TA0008: Lateral Movement
- TA0009: Collection
- TA0011: Command and Control
- TA0010: Exfiltration
- TA0040: Impact
- Roadmap Phase to Technique Mapping
- Critical Attack Chain Diagrams
- Tool to Technique Mapping
- MITRE ATLAS: AI/ML Attack Techniques
- ICS ATT&CK Quick Reference
- Detection Signal Index
- How to Read This Inventory
- Phase -1: OPSEC & Anonymization
- Phase 0: Foundation Environment
- Phase 1: Web Application Security
- Phase 2: Recon, Network & Infrastructure
- Phase 3: Binary & System Exploitation
- Phase 4A/B: Implant, C2 & Loader Development
- Phase 4C: EDR / AV Evasion
- Phase 4D: Vulnerability Research & 0-Day
- Phase 4E: APT Persistence, Rootkits & Anti-Forensics
- Phase 4F: Cloud, AiTM & Advanced Web
- Phase 4G: Hardware, SDR & Embedded
- Phase 4H: Supply Chain
- Phase 4I: Active Directory & Identity
- AI / LLM Attack Surface
- Phase 5: GREATEST - Vulnerability Research & 0-Day Discovery
- Phase 6: Special Operations - Physical, Social & Quantum
- Practice Platforms
- Essential Resources
- ❌ Deprecated Stack - Do Not Use
- How to Use This Section
- Phase-to-Resource Navigator
- Reference Databases
- YouTube Channels - Active 2027
- Essential Books - Phase Ordered
- Courses - 2027 Pricing and Timing
- Practice Platforms
- Blogs and Research Sources
- Malware Sample Repositories and Sandboxes
- Vulnerability Databases and Exploit Sources
- AI and LLM Security Resources
- Nation-State and APT Research
- Community and Networking
- Deprecated Stack - Do Not Use
- MITRE ATT&CK Reference - 2027
- Lab Setup Guide
- Phase 5: GREATEST - Vulnerability Research & 0-Day Resources
- Phase 6: Special Operations Resources
- Resource-by-Phase Matrix
Explore Phase 5 Syllabus (22 Modules)
- What GREATEST Actually Is
- The Decision to Go Further
- What GREATEST Is NOT
- The Real Markers of GREATEST
- What You Must Bring From Phase 4
- Your Research Environment: Setup From Scratch
- Your First 30 Days in Phase 5
- The Research Loop: How GREATEST Actually Finds 0-Days
- Patch Diffing: The Most Teachable Path Into Research
- Fuzzing for Research: Not Just Crashing, But Finding
- Triage: From Crash to Confirmed Vulnerability
- Exploit Development Standards: What a Real PoC Looks Like
- Research Domain Deep-Dives (2026 to 2027 Frontiers)
- The Exploit Market: The BlackHAT Path
- The Publication Path: If You Choose Disclosure
- The Community: Getting Into the Right Rooms
- The Complete Reading List: Surface and Underground
- The Mindset Gap: From Phase 4 Operator to GREATEST Researcher
- Measuring Your Progress
- Extended Failure: When Nothing Is Happening
- Legal Risk: The GREATEST Operator's Landscape
- The Algorithm
Phase 6: Special Operations & Adversary Simulation (Parallel learning alongside Phase 5)
Explore Phase 6 Syllabus (39 Modules & Sub-disciplines)
- Why Phase 6 Exists
- Section 1: Physical Red Team
- 1.1 Lockpicking: The Foundational Skill
- 1.2 Bump Keys and Impressioning
- 1.3 Bypass Tools: Faster Than Picking
- 1.4 Electronic Access Control Bypass (Wiegand + OSDP)
- 1.5 Camera Bypass and Visual Surveillance Defeat
- 1.6 RFID / HID Cloning (Legacy + Modern Readers)
- 1.7 Badge Visual Cloning
- 1.8 Hardware Implants: LAN Turtle + EDR-Evasive Callbacks
- 1.9 Tailgating and Pretext Entry
- 1.10 Drone Recon: Full Curriculum (Optical + Thermal)
- Section 2: Social Engineering
- 2.1 The Psychology Framework: Six Principles of Influence
- 2.2 Elicitation Techniques
- 2.3 Vishing: Voice Phishing (Full Scripts + Objection Handling)
- 2.4 Email Phishing Construction
- 2.5 USB Drop Attacks
- 2.6 In-Person SE: Non-Verbal and Body Language
- 2.7 Pretext Abort Signals and Recovery
- 2.8 Persona Development and Identity Legends
- 2.9 SE Campaign Planning and Metrics
- Section 3: Quantum Computing 2027
- Section 4: Red Team Operations
- Section 5: Post-Engagement Cleanup
- Section 6: TSCM: Finding Bugs to Plant Them
- Section 7: ADCS Attack Paths
- Section 8: Full Operational Scenario: Operation Silent Ledger v2
- Phase 6 Resource Reference
- Phase 6 Competency Checklist
Explore Final Word Sections (Capstone & Verification)
The cybersecurity industry is saturated with surface-level certification guides, multiple-choice cheat sheets, and automated tool tutorials that fail the moment modern defensive telemetry is encountered.
The BlackHAT Roadmap v1.2.0 · GREATEST Edition is engineered on a fundamentally different principle: understanding systems completely from the metal up.
This repository contains over 44,900 lines of battle-tested technical documentation, weaponized code architectures, evasion mechanics, and operational security doctrines across 15 master modules. It bridges the gap between running automated point-and-click tools and operating as a tier-one security researcher, red team engineer, or exploit developer.
+-----------------------------------------------------------------------------+
| REPOSITORY AT A GLANCE (v1.2.0 · 2027 EDITION) |
+-----------------------------------------------------------------------------+
| Total Content Volume : 44,900+ lines of dense offensive engineering |
| Total Documentation : ~1.80 MB source markdown across 15 master modules |
| Progression Depth : 8 Core Phases (Phase -1 through Phase 6) |
| Section Count : 440+ Major Sections (H2), 1,120+ Subsections (H3) |
| Code Implementation : 1,080+ Verified Code Blocks across 13+ Languages |
| Offensive Tooling : 300+ Unique offensive tools cataloged |
| MITRE Alignment : 200+ ATT&CK Techniques (Enterprise, ICS, ATLAS) |
| Compilable Labs : Native C API Resolver & Offensive Rust In-Memory Dev |
| Special Operations : Physical Red Team, SE, Drone Recon, Quantum / SNDL |
+-----------------------------------------------------------------------------+
Most educational resources teach how software is supposed to work. Real offensive security requires understanding how software actually works when subjected to edge cases, flawed assumptions, and memory corruption.
| Category | Standard InfoSec Curriculums | The BlackHAT Roadmap v1.2.0 |
|---|---|---|
| Core Objective | Passing multiple-choice exams (CEH, PenTest+) | Engineering original capabilities from scratch |
| Tooling Approach | Running public scanners (Nmap, Metasploit, Nikto) | Writing custom implants, loaders, and C2 agents |
| Defense Evasion | Basic payload encoding and obfuscation | Ekko/Foliage sleep obfuscation, indirect syscalls, stack spoofing |
| Active Directory | Basic password spraying and simple bloodhound | ADCS ESC1-15, Auth Coercion, Shadow Credentials, Entra ID PRT theft |
| Binary Exploitation | Classical stack overflows in outdated Linux VMs | Modern Windows heap exploitation, ROP chains, V8 browser exploitation |
| Special Operations | Not covered or treated as separate domains | Physical covert entry, drone recon, SE pretexts, quantum SNDL |
| Persistence & Kernel | Scheduled tasks and standard registry run keys | eBPF rootkits, COM hijacking, HVCI bypasses, hypervisor ring -1 |
| Operational Security | "Turn on a commercial VPN service" | Hardware stripping, Tails/Whonix chains, Monero loops, RAM sanitization |
The-BlackHAT-roadmap/
├── .github/ <- Project metadata, issue templates, PR template & tracker
├── assets/
│ ├── banner.svg <- Cybernetic HUD SVG banner (v1.2.0)
│ └── diagrams/ <- Modularized Mermaid diagrams & high-res renders
├── black-bag/ <- Covert operational tradecraft & survival payload
│ └── BlackHat_Long-Term_Survival_Tactics.md <- 3,000+ line master OPSEC & counter-surveillance manual
├── field-guides/ <- Operational manuals, tactical matrices & infrastructure
│ ├── FAQ.md <- Career realities & operational transitions FAQ
│ ├── Final_Word.md <- Verification statistics, attributions & 2027-2028 roadmap
│ ├── Lab_Setup_Guide.md <- Multi-tier enterprise AD & hypervisor blueprints
│ ├── MITRE_ATT&CK_Quick_Reference.md <- Enterprise v15, ICS & ATLAS tactical matrix
│ ├── Philosophy_The_BlackHat_Mindset.md <- Cognitive doctrine & primitive mental models
│ ├── Resources_Aggregated.md <- Canonical literature, whitepapers & archives
│ └── Tools_Inventory.md <- 300+ phase-aligned offensive tool directory
├── payloads/ <- Compilable weaponized source implementations
│ ├── README.md <- Master payload index, toolchains & lab prerequisites
│ ├── 01_dynamic_api_resolver/ <- In-memory PEB traversal & DJB2 export hashing in C
│ └── 02_offensive_rust_loader/ <- RW -> RX memory state flipping & binary hardening in Rust
├── phases/ <- STRICTLY the 8 chronological curriculum phases
│ ├── PHASE_-1.md <- Hardened OPSEC & Anonymous Infrastructure
│ ├── PHASE_0.md <- Low-Level Foundations & Systems Internals
│ ├── PHASE_1.md <- Modern Web & API Attack Surface
│ ├── PHASE_2.md <- Network Pivoting & Active Directory Mastery
│ ├── PHASE_3.md <- System & Kernel Exploitation
│ ├── PHASE_4.md <- Specialized Operator Tracks (4A-4I)
│ ├── PHASE_5.md <- GREATEST (Apex Vulnerability Research & 0-Day)
│ └── PHASE_6.md <- Special Operations & Adversary Simulation
├── CHANGELOG.md <- Version history and public release notes
├── CITATION.cff <- Native GitHub Citation metadata
├── LICENSE <- MIT License
└── README.md <- Master curriculum hub & navigation launchpad
To bridge the gap between theoretical comprehension and binary execution, the repository includes ready-to-compile, weaponized codebases in payloads/:
payloads/
|-- README.md # Master payload index, toolchains & lab prerequisites
|-- 01_dynamic_api_resolver/ # Windows PEB traversal, In-Memory API export hashing in C (DJB2)
`-- 02_offensive_rust_loader/ # Memory protection flips (RW -> RX), Native API wrapping in Rust
- Payload 01: Dynamic API Resolver in C: Demonstrates resolving Windows API functions purely in memory by traversing the Process Environment Block (PEB) and hashing export table strings, defeating static Import Address Table (IAT) analysis.
- Payload 02: Offensive Rust In-Memory Loader: Demonstrates staging encrypted shellcode in memory, avoiding direct RWX allocation flags, and flipping memory permissions to executable (
PAGE_EXECUTE_READ) immediately prior to thread dispatch.
The curriculum integrates the newest offensive paradigms required to defeat modern security stacks:
Defeating memory scanners (Moneta, Hunt-Sleeping-Beacons, Pe-sieve) through asynchronous timer-based memory protection flips.
- Ekko, Foliage, and Cronos implementations: ROP chain encryption via
NtContinue,CreateTimerQueueTimer, and stack frame wiping. - Call Stack Spoofing: Synthetic stack frame generation (SilentMoonwalk, Unwinder) to pass return address validation.
- Indirect Syscalls: Resolving SSNs dynamically and executing syscall instructions from within legitimate
ntdll.dllmemory space to bypass user-mode hooks.
- ADCS Exploitation: Abuse of Enterprise Certificate Authority misconfigurations across ESC1 through ESC15.
- Authentication Coercion: Forcing NTLM authentication via PetitPotam (MS-EFSR), DFSCoerce (MS-DFSNM), and Shadow Credentials.
- Entra ID (Azure AD): Primary Refresh Token (PRT) extraction, Conditional Access bypasses, Device Code phishing, and Azure Arc lateral movement.
Replacing legacy C/C++ loaders with high-performance, statically compiled Rust:
- Dynamic API resolution via hashed PE exports.
- Direct invocation of Windows Native APIs using safe wrappers.
- In-memory shellcode execution without RWX allocation artifacts.
- Exploitation of LLM-integrated enterprise applications: Indirect prompt injections, Retrieval-Augmented Generation (RAG) poisoning, and agent jailbreaking.
- Local offensive LLM pipelines: Fine-tuned local models for automated vulnerability triaging, decompilation analysis, and exploit script generation.
- Store Now, Decrypt Later (SNDL): Harvesting encrypted enterprise traffic ahead of Cryptanalytically Relevant Quantum Computers (CRQCs).
- Post-Quantum Cryptography (PQC) Downgrades: Forcing hybrid key exchange negotiation fallbacks to classical ciphers during migration windows.
- Non-destructive entry: pin tumbler lockpicking, bypass tools, latch slips, and under-door tools.
- Electronic access control: Wiegand protocol interception, OSDP auditing, and RFID/NFC badge cloning.
- Drone reconnaissance: optical patrol mapping and thermal HVAC/server room heat profile analysis.
To execute the practical exercises in this curriculum, the recommended self-hosted lab setup includes:
- Virtualization Hypervisor: Proxmox VE, VMware ESXi, or VMware Workstation Pro.
- Active Directory Range: Dual Windows Server Domain Controllers (2019/2022) with Active Directory Certificate Services (ADCS) installed, and 2-3 joined Windows 10/11 enterprise workstations.
- Malware Analysis Sandbox: Isolated FlareVM (Windows) and REMnux (Linux) nodes configured with non-routed virtual host-only adapters.
- Tooling Environment: Dedicated Kali Linux or Debian instance equipped with Docker, Rust toolchain, MinGW-w64, Clang/LLVM, and Ghidra.
- Hardware Security Kit (Phase 4G & Phase 6): RTL-SDR blog V4, HackRF One, SouthOrd/Sparrows lockpick set, Proxmark3 RDV4 / Flipper Zero, Hak5 LAN Turtle, and CAN bus transceiver module.
roadmap · blackhat-roadmap · greatest-roadmap · penetration-testing-roadmap · cybersecurity-roadmap · AI-ML-Jailbreak · security · cybersecurity · reverse-engineering · security-tools · hacking · pentesting · osint · penetration-testing · network-security · ctf · infosec · malware · ethical-hacking · red-team · kali-linux · malware-analysis · active-directory · web-security · mitre-attack · bug-bounty
If this curriculum provides value to your research or career, consider starring the repository to help other researchers find it:
Contributions that raise the technical bar are welcome. Whether it is a new payload, a deeper module, or a dead link fix, real contributions from the community make this curriculum stronger.
- Getting Started: Check out the Contributing Guidelines and look for issues tagged
good first issuefor approachable entry points. - Quality Threshold: PRs adding generic tool lists or introductory material will not be merged. We prioritize depth over breadth.
- Code Standards: Code samples must be functional, accompanied by technical rationale, and compiled against modern toolchains. Check out the Weaponized Payloads directory.
- Formatting Rule: Adhere strictly to clean markdown standards. Do not include em-dashes anywhere in text or documentation.
If you utilize this curriculum, offensive engineering architectures, or lab implementations in your academic research, technical whitepapers, or institutional courses, please cite this work as follows:
@misc{biswas2026blackhat,
author = {Sagar Biswas},
title = {The BlackHAT Roadmap: From 0 to GREATEST (v1.2.0)},
year = {2026},
publisher = {GitHub},
journal = {GitHub repository},
howpublished = {\url{https://github.com/SagarBiswas-MultiHAT/The-BlackHAT-roadmap}}
}Or reference the native CITATION.cff file via GitHub's "Cite this repository" interface.
Caution
Strictly For Authorized Educational, Research, and Defensive Purposes Only.
The materials, methodologies, code snippets, and operational guidance provided in this repository are designed solely for authorized cybersecurity professionals, penetration testers, red team engineers, and academic researchers operating under explicit, formal written authorization.
Unauthorized testing, access, or exploitation against networks, servers, or endpoints without explicit permission is illegal under local, national, and international laws (including the US Computer Fraud and Abuse Act, UK Computer Misuse Act, and equivalent statutes).
The author assumes no liability and is not responsible for any misuse, damage, or legal consequences resulting from the application of the information contained herein. Learn responsibly. Refer to SECURITY.md for scope and reporting.
Sagar Biswas
- GitHub: @SagarBiswas-MultiHAT
- Agency: MultiHAT Dev
- Projects: Portfolio & Engineering Projects
- Notebooks: Technical Research Notebooks
- Articles & Blog: Security Analysis & Writeups
- Penetration Testing Roadmap: Practical workflows, methodologies, and toolchains for real-world offensive assessments.
- Awesome Cybersecurity Paths: Structured learning paths across defensive, offensive, and research specializations.
- Awesome Cybersecurity Books: Essential foundational and advanced literature for security researchers and practitioners.
Built for those who demand mastery from the silicon up.
Maintained with discipline. No filler. No shortcuts. No apologies.
