Domain // 02
Pentest
Use the pentest portal when you want the broadest operational hub across the platform.
Open Pentest
HackTheCoreHackTheCore organizes web, API, cloud, identity, mobile, OT, AI and tradecraft content into domain hubs, field notes and assessment references that stay useful while work is in motion.
Use Areas when you need the full surface map, Pentest when an engagement spans multiple disciplines, and Knowledge when you need fast terminology, exploit classes or protocol context.
Move by surface, not by course order. Each route is built to get you from the target class to validation logic, references and supporting notes with minimal overhead.
The structure supports scoping, reconnaissance, exploitation, escalation and reporting without forcing an academic reading path.
Pages are written as concise hubs and deeper notes so the material stays useful during active testing, review and documentation.
Primary domains
These entry points cover the domains most likely to drive day-to-day offensive work. Open Areas for the complete map when the target spans several technologies or trust zones.
Domain // 02
Use the pentest portal when you want the broadest operational hub across the platform.
Open PentestDomain // 04
Application trust boundaries, browser-side pressure and classic web exploitation routes.
Open WebDomain // 05
REST, GraphQL, JWT, OAuth/OIDC, object abuse and API fuzzing as a dedicated surface.
Open APIDomain // 06
AWS, Azure, GCP, Kubernetes, identities, CI/CD trust and cloud control-plane abuse.
Open CloudDomain // 07
Android and iOS testing, instrumentation, pinning bypass, storage and mobile reversing.
Open MobileDomain // 08
Entra, Okta, SSO, tenant drift, token abuse, federation and conditional-access pressure.
Open IdentityDomain // 12
Industrial protocols, PLC/HMI trust, segmentation failures and process-level risk.
Open OT / ICSDomain // 13
Prompt injection, jailbreaks, retrieval abuse, tool misuse and offensive AI operations.
Open AIDirectory
Open the full domain map to browse all 16 platform areas, including tradecraft, supply chain, knowledge and exam.
Browse all areasPlatform structure
HackTheCore is structured around attack surfaces, operator decisions and reference value. The goal is to reduce time spent hunting for context and increase time spent validating what matters.
Recommended routes