██████╗  ██████╗  ██████╗ ████████╗██████╗  █████╗ ████████╗██╗  ██╗
██╔══██╗██╔═══██╗██╔═══██╗╚══██╔══╝██╔══██╗██╔══██╗╚══██╔══╝██║  ██║
██████╔╝██║   ██║██║   ██║   ██║   ██████╔╝███████║   ██║   ███████║
██╔══██╗██║   ██║██║   ██║   ██║   ██╔═══╝ ██╔══██║   ██║   ██╔══██║
██║  ██║╚██████╔╝╚██████╔╝   ██║   ██║     ██║  ██║   ██║   ██║  ██║
╚═╝  ╚═╝ ╚═════╝  ╚═════╝    ╚═╝   ╚═╝     ╚═╝  ╚═╝   ╚═╝   ╚═╝  ╚═╝

[ ok ] inicializando rootpath

[ ok ] carregando trilha OSCP

[ ok ] modo: ética · labs autorizados

Current focus · Learning

Studying offensive security, from the fundamentals to the method.

rootpath is my personal ethical cybersecurity academy: a structured track with method, notes and my own labs, on the path to the OSCP certification. The name comes from "path to root" — the journey to truly understand how privilege is escalated, always with permission.

root@rootpath: ~

root@rootpath:~$ whoami

dev estudando segurança ofensiva

root@rootpath:~$ cat foco.txt

trilha OSCP · ética · labs autorizados

root@rootpath:~$ ./proximo-passo

enumeração & rede

In progress · practice only in authorized environments · OSCP as a long-term horizon

8
phases in the track, from ethics to the OSCP method
100%
practice in authorized environments
DEV
study room I built myself
OSCP
the certification on the horizon
root@rootpath:~/01$./trilha

The path to root

Eight phases in order, from the ethical foundation to the exam method. Each one has a lesson, an exercise and a review before moving on.

In progress

00

Ethics, mindset and notes

The foundation: permission, method and the habit of documenting every step.

01

First lab (TryHackMe)

Platform tutorial and Linux fundamentals on the command line.

Next

  1. 02

    TCP/IP networking

    Without IP, port and service, there is no reconnaissance.

  2. 03

    Enumeration

    Most of the work is gathering information patiently.

  3. 04

    Offensive web basics

    The most common surface, studied after the fundamentals.

  4. 05

    Exploitation and escalation

    Getting in and escalating privilege with method, on lab targets.

  5. 06

    Active Directory

    Fundamentals of a topic that weighs heavily in the modern OSCP.

  6. 07

    OSCP method

    Time, reporting and repetition under pressure, the way the exam works.

root@rootpath:~/02$./sala-de-estudo

I built my own study room

To study my own way, I built a terminal-style room: lessons, exercises and an AI copilot that asks for method instead of handing over the answer. It is real, version-controlled software that also shows how I build.

Interactive in-browser terminal with xterm.js, wired to a real shell over WebSocket

Curriculum read straight from the repository Markdown files, a single source of truth

AI copilot that gives graded hints and asks for the reasoning, never the finished flag

Switchable hacker themes (rootpath green, Matrix with code rain, retro amber)

Notes and history saved locally, with an AI usage indicator

How it was built

ViteJavaScriptxterm.jsnode-ptyWebSocketOpenRouterMarkdown
root@rootpath:~/03$./etica

Ethics first, always

Offensive security only makes sense within the law and with authorization. That is the first rule of the track, not a footnote.

Only authorized environments

Practice limited to training platforms (TryHackMe, Hack The Box), my own virtual machines and bug bounty programs with a clear scope.

Method before tooling

The focus is understanding the why of each step and recording everything in a writeup, not memorizing commands.

Document like a report

Each lab becomes a structured note: goal, what I tried, what worked and what I learned.

root@rootpath:~/04$./status

Where I am now

Already in place

  • Fundamentals of ethics, mindset and documentation in place
  • Active TryHackMe account and first recon and enumeration labs
  • My own lab environment set up (WSL2 with Kali Linux)
  • First documented writeups and the study room built and version-controlled

On the way

  • Going deeper into TCP/IP networking and enumeration before moving to exploitation
  • A daily lab habit, 20 to 40 minutes a day
  • Active Directory fundamentals and, in the long run, the OSCP exam

Want to talk about security?

I am early on this track and I take the subject seriously. If your team values people who understand security, let us talk.

Get in touch

rootpath is a personal, ethical study project. All content concerns authorized environments and defense. The repository is private.