Ethics, mindset and notes
The foundation: permission, method and the habit of documenting every step.
██████╗ ██████╗ ██████╗ ████████╗██████╗ █████╗ ████████╗██╗ ██╗ ██╔══██╗██╔═══██╗██╔═══██╗╚══██╔══╝██╔══██╗██╔══██╗╚══██╔══╝██║ ██║ ██████╔╝██║ ██║██║ ██║ ██║ ██████╔╝███████║ ██║ ███████║ ██╔══██╗██║ ██║██║ ██║ ██║ ██╔═══╝ ██╔══██║ ██║ ██╔══██║ ██║ ██║╚██████╔╝╚██████╔╝ ██║ ██║ ██║ ██║ ██║ ██║ ██║ ╚═╝ ╚═╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═╝ ╚═╝ ╚═╝ ╚═╝ ╚═╝ ╚═╝
[ ok ] inicializando rootpath
[ ok ] carregando trilha OSCP
[ ok ] modo: ética · labs autorizados
rootpath is my personal ethical cybersecurity academy: a structured track with method, notes and my own labs, on the path to the OSCP certification. The name comes from "path to root" — the journey to truly understand how privilege is escalated, always with permission.
root@rootpath:~$ whoami
dev estudando segurança ofensiva
root@rootpath:~$ cat foco.txt
trilha OSCP · ética · labs autorizados
root@rootpath:~$ ./proximo-passo
enumeração & rede
In progress · practice only in authorized environments · OSCP as a long-term horizon
Eight phases in order, from the ethical foundation to the exam method. Each one has a lesson, an exercise and a review before moving on.
The foundation: permission, method and the habit of documenting every step.
Platform tutorial and Linux fundamentals on the command line.
Without IP, port and service, there is no reconnaissance.
Most of the work is gathering information patiently.
The most common surface, studied after the fundamentals.
Getting in and escalating privilege with method, on lab targets.
Fundamentals of a topic that weighs heavily in the modern OSCP.
Time, reporting and repetition under pressure, the way the exam works.
To study my own way, I built a terminal-style room: lessons, exercises and an AI copilot that asks for method instead of handing over the answer. It is real, version-controlled software that also shows how I build.
Interactive in-browser terminal with xterm.js, wired to a real shell over WebSocket
Curriculum read straight from the repository Markdown files, a single source of truth
AI copilot that gives graded hints and asks for the reasoning, never the finished flag
Switchable hacker themes (rootpath green, Matrix with code rain, retro amber)
Notes and history saved locally, with an AI usage indicator
Offensive security only makes sense within the law and with authorization. That is the first rule of the track, not a footnote.
Practice limited to training platforms (TryHackMe, Hack The Box), my own virtual machines and bug bounty programs with a clear scope.
The focus is understanding the why of each step and recording everything in a writeup, not memorizing commands.
Each lab becomes a structured note: goal, what I tried, what worked and what I learned.
I am early on this track and I take the subject seriously. If your team values people who understand security, let us talk.
rootpath is a personal, ethical study project. All content concerns authorized environments and defense. The repository is private.