Skip to content

ProjectSecurity is live! Join today to lock in our one-time launch offer ending July 26.

ProjectSecurity > ProjectSecurity
CORE SECTIONS

Program

Begin your journey with a guided learning path. Each Core Section builds on the last. Provision homelabs, conduct attacks, and deploy real-world defenses using step-by-step guides and videos.

E101

Infrastructure & Enterprise 101

Free

Begin your homelab build with a simulated enterprise style network.

Build

A complete enterprise network from scratch. Provision VMs - Windows Server 2025, Windows 11, Ubuntu, Security Onion, Email Server, Active Directory, configure DNS/DHCP, user identities.

Break

Setup and configure your attacker environment using Kali Linux. Deploy an end-to-end cyber attack using the cyber kill chain.

Secure

Deploy Wazuh SIEM + EDR. Write detection rules to catch attacker activity and harden your environment to prevent repeat attacks.

Active DirectoryDNSDHCPGroup PolicyWindows ServerWazuh SIEMAttack SimulationKali Linux
Sign Up
Infrastructure & Enterprise 101 course thumbnail
NA101

Networks & Attacks 101

Homelab Builder Tier

Expand and advance to a fully functional corporate network with internal servers, architecture, and security tooling.

Build

Expand and deploy corporate enterprise infrastructure, including internal DNS resolver, internal FTP server, a HTTPS corporate web portal, a corporate router through pfSense, segment with secure network architecture, a DMZ, CORP-LAN.

Break

Conduct network style attacks ARP poisoning, DNS spoofing, IP Spoofing, a DoS attack, credential stuffing, and write and deploy a mini C2 server written in Python.

Secure

Defend with network Layer 2–7 monitoring through pfSense, Suricata, ARP Watch, Security Agents, AD GPO, and DNS security.

DockerWiresharkpfSenseSuricataARP SpoofingDNS AttacksDoSC2 ServersNetwork Monitoring
Sign Up
Networks & Attacks 101 course thumbnail
CA101

Cloud & Attacks 101

Homelab Builder Tier

Build and roll out a production network using AWS. Deploy an environment to serve a live threat intelligence application. Connect security tooling back into the corporate network.

Build

A fully functional production network using AWS free tier, deploy a VPC, with EC2 VMs, EBS storage, RDS, PostgreSQL, S3 Security Datalake, CloudTrail, VPC Flow Logs, Lambda serverless. This sets up a real-world web application.

Break

Conduct cloud-based attacks, including a leaky S3 bucket, Metadata SSRF attack, probe for and exploit an insecure API gateway, hunt for hardcoded secrets, insecure IAM, and opened VPCs.

Secure

Add VPC Flow Logs and CloudTrail to power customized detections, deploy AWS Config to catch misconfigurations and use secure infrastructure, AWS Secrets Manager, and SSM.

AWSIAMVPCEC2S3RDSLambdaCloudTrailSSRFCloud Security
Sign Up
Cloud & Attacks 101 course thumbnail
WA101

Web & Attacks 101

Homelab Builder Tier

Deploy a live threat intelligence web application tracking updated security information and attacks on nearly free tech stack.

Build

A live threat intelligence web application tracking updated security information and attacks. Deploy a live threat intelligence application on near free application stacks.

Break

Conduct SSRF, XSS, CSRF, Command Injection, IDOR, SQLi in a localized insecure threat intelligence web application. Use Burp Suite to probe for and test web vulnerabilities.

Secure

Add a ModSecurity WAF and understand secure coding practices.

OWASP Top 10SQL InjectionXSSAuthenticationAPI SecurityWeb Defense
Sign Up
Web & Attacks 101 course thumbnail
FAQ

Frequently Asked Questions

Who is this made for? And Are There Any Prerequisites?
Any level is welcomed. The content is best suited for beginners and intermediate-level practitioners who are looking to level-up. It is assumed you have a basic knowledge of computers.
Once I sign up, what happens?
You will receive an email to register for our backend learning platform, CourseStack, with the labs loaded in from the tier of your choice, from there you can log in and start labbing!
Is this platform free?
Yes, this platform is free. Free forever. We have a Lab Builder Career Bundle, Solo Builder, and Hybrid Bundles for additional features. This includes extra course modules, cloud-hosted labs, exclusive Discord community, and monthly community meetups.
How can I get more involved?
ProjectSecurity has an active community of professionals with monthly meetups. Join our Community on Discord. Come say Hello!
Do you offer technical support?
Help is offered if you do encounter issues. We do recommend starting with a search first. More detail is inside the program.
What are minimum computer specifications needed?
We recommend at least 8 GBs of RAM (Ideally 16GBs+) and 200 GBs of storage. Supported for all major OS platforms, Windows, macOS, and Linux.
Should I use VirtualBox or VMware Workstation Player?
Either hypervisor works. We use VirtualBox (VBox) during the core sections. VMware Worksation Player also works. It is also free and more mainstream.
Is the Homelab Builder Worth it?
The Homelab Builder Tier is best suited if you are a student looking to level-up your career prospects, a security enthusiast looking to level-up your technical skills, or an individual who likes anything homelabbing. Or all the above. Start with the Associate Tier to see what you think.
Is any coding knowledge required for the threat intelligence application?
No. We live in the AI era, we can create a majority of our front-end web application code with AI. Exercise files are provided for the web application, we encourage you to customize it with your AI agent of choice, such as Claude Code or Cursor.
If you had one cyber super power, what would it be?
Queue the ability to always... "We are In." the system.

Ready to start building?

Pick a core section and start building your homelab today. No experience required.