Enter
HUNTER, NOT JUST HACKER

Exploit it. Forge the counter. Master both.

A browser RPG where offense and defense are one skill tree, not two courses. Hunt real vulnerabilities in live sandboxes, drag the wreckage back to the Forge, and craft the detection that would have stopped you.

1. Hunt

Exploit a real, live vulnerable target through a genuine terminal — no scripted button-mashing.

2. Loot

A clean hunt drops real material: the actual logs, tokens, or traces the attack generated.

3. Forge

Write a real detection rule in your own discipline and watch it scored against real traffic — precision and recall, no shortcuts.

Everyone breaks in the same way. Nobody defends the same way.

Your archetype does not gate content — every hunter runs the same exploits, because the attack is the attack. What it decides is which evidence you are allowed to catch it with.

Watch four people investigate one Kerberoast: the network defender sees RC4 tickets on the wire, the endpoint analyst sees the tooling, the PKI owner sees a service account whose password predates the hardware. Three rules, one attack, nobody wrong. That is the part the courses never make you feel.

Vanguard
NETWORK & TRAFFIC

You read the wire. Who talked to whom, how often, over what, and to where.

Network intrusion
Network defense
Phantom
IDENTITY & BEHAVIOUR

You read people. Which account did this, and is that a thing this account does?

Social engineering
Identity & behaviour defense
Cryptomancer
CRYPTOGRAPHY & SECRETS

You read the maths. What algorithm, what key, whose signature, and how long is it good for.

Crypto attacks
PKI & key management
Warden
PAYLOADS & ARTEFACTS

You read what was actually sent. The literal shape of the malicious thing.

Exploit dev & malware
Reverse engineering & EDR

Four regions. The whole world, free, in full.

Web App Wilds is where the internet leaks — injection, broken access control, SSRF, and a Log4Shell boss that uses the real interpolation syntax.

AD Kingdom is stranger. Nothing there is broken. Every hunt abuses a feature working exactly as designed — roasting, delegation, a forged ticket the domain has no way to disbelieve — which is precisely why it is so hard to defend.

Cloud Highlands floats above the ground truth — one misconfigured permission cascading into a mass exfiltration nobody had to breach a single firewall to pull off.

IoT Marches is the endgame — a device you can telnet into, a firmware image you can pull apart, a radio you can just listen to, ending in a botnet DDoS built the way the real 2016 one actually worked.

No paywall, no subscription.