SecMissions
Practice security the way you will be tested: a real proxy workbench, a real vulnerability to find, no setup.
Three minutes. Keyboard friendly. Press P for presenter mode.
The playable mission
Find the leaked invoice
This is the exact workflow used inside every SecMissions proxy mission: capture a request, tamper with it in Repeater, and defend the finding.
Open the billing portal on the left, then click Download invoice.
Acme Corp Billing Portal
Invoice#1042
CustomerAcme Corp
Amount$4,280.00
Target maps every captured host and path. This demo captures a single host: billing.acmecorp.example.
Intercept is off. Captured traffic flows straight to HTTP History.
| # | Method | Path | Status | Length |
|---|---|---|---|---|
| No requests captured yet. Click Download invoice. | ||||
No request sent to Repeater yet. Select the captured request in HTTP History first.
Request
Response
Press Send to view the response.
Attempts
| # | invoice_id | Status | Result |
|---|
Intruder automates a payload across a request and flags the outlier response. It appears once a mission declares payload data.
Decoder transforms a value between common encodings.
Comparer diffs two requests or responses side by side.
Which vulnerability class is this?
Finding confirmed
+0 XP
Streak day 1 protected
What a real interviewer would ask next
Topic: how authorization checks should scope access to a single record.
Ten security domains
One structured practice system across the role.
Hover or focus a tile to see three example skills practiced inside that domain.
Who it is for
Built for three kinds of buyers.
Enterprise and consulting teams
- A coupon cohort with a membership term sized to a short engagement
- An admin roster showing who redeemed, their plan, and their expiry, with per-person revoke
- The Introduction to Pentesting track as a shared pre-engagement warm-up
Career switchers and new graduates
- The Junior Launchpad interview round, free in full, every day
- An interview lab to rehearse explaining a finding out loud
- A proxy workbench that mirrors the tool used on the job, with no install
Universities and bootcamps
- A private cohort code sized to a class roster
- An admin view of who has worked which missions and when
- Terminal missions with tab completion, so a first session feels like a real shell
How a workshop runs
Four steps from code to reviewed progress.
Mint a code
Pick a plan, a membership term, and a seat count sized to the workshop headcount.
Team signs up with it
Each member redeems the code and their plan updates immediately for the membership term.
Team works the pentest track
A twelve mission Introduction to Pentesting path: proxy fundamentals, authorization bypass, injection, then reporting.
Progress reviewed
The roster shows who redeemed, when, and their current plan, with access revocable per person once the engagement ends.
Trust and safety
Honest, synthetic, and revocable.
Pricing, in public
Start free. One yearly plan for everything else.
Pro, per year
$149
$12.40 per month, billed yearly
Founding member rate: $99 per year
Interview Sprint
$79
one time, 30 days of full access
Teams & EDU cohort
$995
per cohort, up to 40 seats