H2-CPAE · Core certification path
Offensive Security
H2 Certified Platform Attack Engineer
Break what the other paths build, on live ranges. Recon, web and API attacks, network exploitation, Active Directory, and the cloud, container and mesh attacks that the platform paths are the defense against.
6 courses · 21 lessons · ~38 h of guided work
Assumes Foundation
What you leave with
A record of full attack chains you executed on live ranges, from recon to a written report, including a container escape and a mesh abuse against a platform like the one you built.
- Ranges
- Live lab targets
- Web/API
- Burp-class tooling
- Cloud/K8s
- Real cluster targets
- Reporting
- Rubric-graded
Syllabus
6 courses · every lesson graded · minutes are guided work
Course 01
Recon and OSINT
Map the target before touching it: attack surface, exposed services, and the open-source footprint that hands an attacker the first move.
4 lessons · ~6 h
- 01Scoping and rules of engagementWhat you may and may not touch, in writing, before anything else.90 min
- 02Passive reconThe open-source footprint; what leaks from DNS, certs and public repos.90 min
- 03Active reconService discovery and fingerprinting; the difference between noisy and quiet.90 min
- 04Mapping the surfaceEverything reachable, ranked by likely reward, each item confirmable.90 min
Course checkProduce a complete, sourced attack-surface map of a scoped target, with every finding a probe can confirm.
You leave withAn attack-surface map of a scoped target with services, exposures and an OSINT footprint, each finding evidenced.
Course 02
Web and API attacks
The OWASP families as things you exploit and then fix: injection, broken auth, IDOR and the API-specific top ten against a real target.
4 lessons · ~8 h
- 01The web attack surfaceWhere trust boundaries break; how a request becomes a compromise.90 min
- 02InjectionSQL, command and template injection against a real target; the fix that actually closes it.120 min
- 03Broken access controlIDOR and privilege escalation; object-level authorization from the attacker's side.120 min
- 04API attacksThe API top ten; mass assignment, broken object-level auth, and rate-limit abuse.120 min
Course checkCompromise a target web app and its API through chained findings, then write the fix for each.
You leave withDocumented exploits of injection, broken access control and IDOR against a live app and API, each with a remediation.
Course 03
Network exploitation
From a foothold to more: service exploitation, privilege escalation on Linux, and pivoting through a segmented network.
3 lessons · ~6 h
- 01Getting a footholdService exploitation into a first shell; stabilizing it.120 min
- 02Linux privilege escalationSUID abuse, capability misconfiguration, cron path injection; and when a kernel exploit is the wrong move.120 min
- 03Pivoting and tunnellingThrough segmentation to a target you could not reach directly.120 min
Course checkFrom a single foothold, escalate and pivot to a target on another segment, documenting every step.
You leave withA full chain from a foothold through Linux privilege escalation to a pivot into a segmented network.
Course 04
Active Directory attack paths
The enterprise's soft center: enumeration, credential attacks, and the delegation and trust abuses that turn one account into domain control.
3 lessons · ~6 h
- 01AD enumerationThe graph of who can do what to whom; the query that finds the path.120 min
- 02Credential attacksKerberoasting, AS-REP, and the hygiene failures that enable them.120 min
- 03Delegation and trust abuseThe misconfigurations that collapse a domain; the fix for each.120 min
Course checkFrom a low-privilege account, reach a documented domain-admin-equivalent position on a lab forest.
You leave withA documented attack path from a standard user to domain compromise on a live AD forest.
Course 05
Cloud, container and mesh attacks
Attack the exact stack the platform paths build: cloud IAM, a Kubernetes cluster, a container escape, and abuse of a service mesh.
4 lessons · ~8 h
- 01Cloud IAM attacksOver-permissive roles, the metadata endpoint, and privilege escalation in the cloud control plane.120 min
- 02Attacking KubernetesExposed workloads, RBAC gaps, and secrets reachable from a pod.120 min
- 03Container escapesThe misconfigurations and capabilities that let a process leave its container.120 min
- 04Mesh and gateway abuseTurning a mesh's trust against it; what the platform path's mTLS and policy actually prevent.90 min
Course checkCompromise a cloud-hosted Kubernetes target: from an exposed workload to cluster control, including one container escape.
You leave withDocumented attacks against cloud IAM, a Kubernetes cluster, a container boundary and a service mesh, mapped to the defenses that stop them.
Course 06
Reporting that gets fixed
A finding nobody acts on is wasted. Write reports engineers fix from: reproduction, impact, and a remediation they can ship.
3 lessons · ~5 h
- 01The report is the productWhy the write-up, not the shell, is what the client paid for.90 min
- 02Reproduction and impactSteps anyone can follow, and impact stated without inflation.90 min
- 03Remediation that shipsFixes an engineer can act on; mapping each to the control that prevents recurrence.90 min
Course checkGiven a set of raw findings, produce a report graded on reproduction, accurate impact and actionable remediation.
You leave withA penetration-test report to a rubric: clear reproduction, honest impact, and remediation an engineer can act on this sprint.
Certification course
H2 Certified Platform Attack Engineer
$499 · one price · courses + 90-day labs + exam
A four-hour practical against a live range and one written report: from external recon to a documented compromise of a platform, graded on both the exploitation and the report.
Opens when Foundation is complete and the 6 course checks are passed. One proctored attempt, plus a free retake if you fail by a margin. The credential is an Open Badges 3.0 credential, signed and verifiable.
Counts toward H2-CTSE. Certified T-Shaped Security Expert is the credential of the whole T: hold all seven core credentials and it is awarded automatically, free, with no extra exam.
Create an account to enrol