Focus on security outcomes each month: CTF writeups, tooling, vuln research, and red-team style work. Same calendar as the developer track — enroll, build during the window, and submit on the site.
Juice Shop Starter Pack: Three Wins, One Clean Writeup
Run OWASP Juice Shop locally (npm or container, whichever you prefer) and solve three beginner-level challenges. Then write them up clearly. Core scope (~10 days part-time, relaxed pace): - Pick three 1–2 star challenge…
Auth Log Hunter: Spot Brute-Force Patterns with a Script
Write a small detection script that analyzes SSH or web login logs and flags suspicious behavior. Core scope (~10 days part-time, no crunch needed): - Use sample logs you generate yourself (a simple generator mixing nor…
Fuzz a Tiny Parser: Harness, Crashes, and Triage Notes
Pick a small, self-contained parser and fuzz it locally, then triage what you find. Core scope (~10 days part-time, relaxed): - Choose a target: a small open-source parsing library (INI, JSON, URL, CSV, image header, et…
Ready to take this on? Run /enroll in Discord to claim a tier before the window closes.
2026-09
Beginner
CTF writeup: crypto 101
Goal Solve a public beginner crypto challenge and document every step. Requirements - Flag or full walkthrough - Explain the mistake that made it solvable
Goal Build a small tool that flags risky dependency patterns in a repo. Requirements - CLI or script - Clear rules documented - Sample run on an OSS repo
Goal Pick an open-source component, audit a narrow surface, and write a professional memo. Requirements - Hypothesis, methodology, result - Responsible disclosure stance even if no bug
Ready to take this on? Run /enroll in Discord to claim a tier before the window closes.
2026-08
Beginner
CTF writeup: crypto 101
Goal Solve a public beginner crypto challenge and document every step. Requirements - Flag or full walkthrough - Explain the mistake that made it solvable
Goal Build a small tool that flags risky dependency patterns in a repo. Requirements - CLI or script - Clear rules documented - Sample run on an OSS repo
Goal Pick an open-source component, audit a narrow surface, and write a professional memo. Requirements - Hypothesis, methodology, result - Responsible disclosure stance even if no bug
Ready to take this on? Run /enroll in Discord to claim a tier before the window closes.
2026-07
Beginner
CTF writeup: crypto 101
Goal Solve a public beginner crypto challenge and document every step. Requirements - Flag or full walkthrough - Explain the mistake that made it solvable
Goal Build a small tool that flags risky dependency patterns in a repo. Requirements - CLI or script - Clear rules documented - Sample run on an OSS repo
Goal Pick an open-source component, audit a narrow surface, and write a professional memo. Requirements - Hypothesis, methodology, result - Responsible disclosure stance even if no bug
Ready to take this on? Run /enroll in Discord to claim a tier before the window closes.
2026-06
Beginner
CTF writeup: crypto 101
Goal Solve a public beginner crypto challenge and document every step. Requirements - Flag or full walkthrough - Explain the mistake that made it solvable
Goal Build a small tool that flags risky dependency patterns in a repo. Requirements - CLI or script - Clear rules documented - Sample run on an OSS repo
Goal Pick an open-source component, audit a narrow surface, and write a professional memo. Requirements - Hypothesis, methodology, result - Responsible disclosure stance even if no bug
Ready to take this on? Run /enroll in Discord to claim a tier before the window closes.
2026-05
Beginner
WiFi Security Assessment Tool
Create a Python script that scans for nearby WiFi networks and identifies common security misconfigurations — weak encryption, default passwords, or suspicious SSIDs. Document your methodology and findings in a short wri…
Build a custom web application fuzzer that automatically tests for common vulnerabilities like SQL injection, XSS, and directory traversal. Include payload generation and result analysis. Size this for about 10 days of f…
Research and implement a monitoring system that detects potential container escape attempts in real-time. Focus on syscall monitoring, capability abuse, and namespace violations. This advanced project suits about 10 days…