Advanced
Advanced Exploit Development
This is the most technical course in the catalogue, and it assumes you can already write exploits. You take on kernel exploitation, browser exploitation, patch diffing, and the modern mitigation bypasses that stand between a crash and reliable code execution.
Everything happens in the academy lab under written authorization, against targets and builds we provide. You leave able to analyse a patch, find the changed code, and develop a working exploit past current defences.
- Duration
- 12 weeks
- Format
- Live online, instructor-led
- Prerequisites
- Advanced Penetration Testing and Exploit Writing
- Class size
- Capped at 12 learners

What you will be able to do
- Explain how modern exploit mitigations work and where they fail
- Exploit heap corruption, use-after-free and type confusion bugs
- Diff a patch, locate the fix and reconstruct the vulnerability
- Build read and write primitives toward browser code execution
- Develop a kernel privilege escalation exploit in the lab
- Improve the reliability of an advanced exploit
- Document and disclose a serious vulnerability responsibly
Course outline
6 modules
- How current exploit mitigations work
- Data execution prevention and address randomisation
- Stack and control-flow protections
- Reasoning about what a bug can still do
What you need before you start
- Completion of Advanced Penetration Testing and Exploit Writing
- Fluency with a debugger and comfort reading assembly
- Solid programming, including C and a scripting language
- Experience writing at least basic memory corruption exploits
Who this course is for
- Experienced exploit developers pushing into kernel and browser work
- Vulnerability researchers building advanced capability
- Red team tool developers who need deeper exploitation skill
- Engineers specialising in offensive research
Questions about this course
More in offensive security
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



