MENTOR TRACK // M21
What This Plan Is Still Missing
Prioritized additions to the base 8-week curriculum.
Biggest weaknesses first
- Web application + API security depth (auth, IDOR, SSRF, deserialization patterns).
- Active Directory Certificate Services: ESC1-ESC14 style misconfigurations.
- Enterprise identity: federation, tokens, conditional access, hybrid trust.
- Cloud identity + workload security (IAM misconfig, metadata service, storage).
- Containers and orchestration basics: namespaces, RBAC, mounted secrets.
- Linux privilege escalation depth beyond SUID checklists.
- Network security: segmentation testing, egress control, DNS-based detection.
- Scripting maturity: reusable tooling, not one-liners.
- Exploit development fundamentals (memory model, mitigations) as literacy, not craft.
- Detection engineering: writing and tuning rules, not just triggering them.
- OPSEC concepts: opsec vs stealth vs authorization.
- Reporting and engagement management as skills of their own.