The full curriculum
Every lesson below is original, written-from-scratch content, built around the OWASP Top 10, real-world attack patterns, and what actually pays on HackerOne and Bugcrowd. This is the structure; the full lessons, labs, and exams live inside the platform.
How the web really works: HTTP, DNS, browsers, Linux, the request lifecycle.
Mapping the full attack surface before touching a single endpoint.
The core vulnerability classes every hunter has to own cold.
Scope, safe testing, triage, CVSS scoring, and report writing.
Finding the secrets applications leak without realising it.
The #1 vulnerability class on HackerOne, where most hunters earn their first bounty.
Reflected, stored, and DOM XSS, then chaining it into account takeover.
Error-based, blind, and union-based SQLi, plus automation with sqlmap.
From a single input field to remote code execution.
Blind and full-read SSRF, cloud metadata, and internal pivoting.
REST and GraphQL attacks, broken auth, and mass assignment.
Password reset flaws, JWT, OAuth, SAML, and 2FA bypass.
XXE, SSTI, request smuggling, deserialization, race conditions, chaining.
Building a fast, repeatable hunting workflow and toolchain.
Putting it all together on live programs for real payouts.
Inside Codéjà Vu, each lesson comes with hands-on labs, timed exams, daily hunting logs, and live instructor review. Curious how we're scaling it, or want to partner on the mission?