← All 186 courses
SEC-404 Security

Offensive Security Foundations (Authorized Testing)

Understand attacks well enough to prevent them — inside strict rules of engagement: assessment methodology, reconnaissance and enumeration concepts, common exploitation classes demonstrated in an isolated lab, and the reporting craft that turns findings into fixes. Scoping, authorization and ethics are graded components, not footnotes.

B4Professional
5modules
33skill atoms
3role journeys
Curriculum

What this course covers.

5 modules, 33 named skill atoms. Expand any module to see them.

1Rules of Engagement7 skill atoms
authorizationscopelegal/ethical boundariessigned rules-of-engagement documentsin-scope asset & address range definitiontesting windows and emergency stop procedurehandling of incidentally discovered sensitive data
2Assessment Methodology7 skill atoms
reconenumerationprioritisationPTES-style phase structurepassive vs active information gatheringattack surface inventoryingevidence capture discipline
3Exploitation Classes (Lab)6 skill atoms
web/app/infrastructure classes in a sealed rangeCWE vulnerability class taxonomyvalidating findings rather than assumingexploitability vs theoretical risknon-destructive testing constraintsisolated range safety controls
4Post-Exploitation Concepts6 skill atoms
impact demonstrationevidence limitsminimum proof required to show impactno-exfiltration data handling rulesartefact cleanup after testingnotifying the client on a live compromise finding
5Reporting that Fixes7 skill atoms
severity honestyremediation-first writeupsCVSS scoring with environmental contextreproduction detail for the fixing teamroot cause vs symptom framingexecutive summary vs technical annexretest & closure workflow
Where it fits

SEC-404 in the role journeys.

This course appears in 3 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

Security Engineer

Professional stage
SEC-403SEC-404SEC-306

DevSecOps Engineer

Capstone stage
SEC-307SEC-404SEC-205

AppSec Engineer

Professional stage
SEC-301SEC-404SEC-306

Roles this course serves

The capability ladder

This course is authored to band B4.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-404 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free