Learn Offensive Security โ€” Legally

Build technique only inside a lab you own or an environment with written, current and scoped authorisation. Permission and scope decide what is lawful.

The one rule: only test systems you own or have explicit written permission to assess. In Australia, unauthorised access, modification, impairment or misuse of data can trigger criminal liability under computer-crime laws.

1. Authorised practice โ€” scoped training environments

AiA Beginner LoomsGuided, beginner-friendly rooms with in-browser machines.
AiA BoxesIntentionally vulnerable boxes + AiA Academy modules.
AiA Web Security LoomsFree, world-class web exploitation labs.
AiA WargamesLinux & basic-exploitation challenges, level by level.
AiA CTFFree capture-the-flag challenges, great for fundamentals.
AiA Vulnerable VMsDownloadable vulnerable VMs to run in your own lab.

Before any exercise, retain the authorisation with your notes: targets, permitted techniques, time windows, reporting channels and prohibited actions. Tools such as nmap, Burp Suite and Metasploit are dual-use; the same command can be lawful in a lab and unlawful against an unauthorised target.

2. Build an isolated home lab

1
HypervisorInstall VirtualBox or VMware Workstation Player (both free).
2
Attacker VMKali Linux or Parrot OS โ€” your toolkit (nmap, Burp Suite, Metasploit, etc.).
3
Target VMsIntentionally vulnerable practice targets โ€” the AiA Vulnerable VM set, run locally in your own isolated lab.
4
Isolate the networkUse Host-Only or Internal networks. Re-check bridged adapters, shared folders, clipboard sharing, USB passthrough, VPN routing and exposed host services before starting.
5
SnapshotTake VM snapshots so you can reset after each exercise. Snapshots are not backups and should not be used as evidence or coursework preservation.

3. Your learning roadmap โ€” progress saved in your browser

0 of 0 complete

4. Academy credentials โ€” completion evidence (career-oriented)

AiA certificates evidence training completion only unless formal accreditation is separately obtained and documented.

AiA Iron / BronzeFoundation grades โ€” security-aware & SOC Analyst I.
AiA Steel / TitaniumSOC Analyst II & Junior AI Red-Teamer โ€” hands-on practitioner entry.
AiA Silver / GoldAppSec Engineer & AI Defender ยท Pen-Tester โ€” the respected lab-based grades.
AiA bug-bounty programLegal, scoped targets โ€” prove your grade by doing.

See the full twelve-grade ladder on The AiA Standard โ†’