Skip to content
normSight — Cyber Security

Offensive Trainings

Exploit Development

The Exploit Development (XDS) course builds, from the ground up, the ability to turn a memory corruption vulnerability into a working exploit and to bypass modern memory protections.

XDSv1 is entirely self-paced, with interactive slides and videos students can access online without restriction.

Students have lifetime access both to the training materials and to Hera Lab, the world’s best exploit development virtual labs, and can take the course from home, from the office or anywhere with an internet connection.

Highly Practical

Thanks to extensive use of Hera Lab and broad coverage of the exploit development field, the XDS course is the most practical training course on the subject. Exploit development techniques are taught against real-world software.

Designed for Beginners

XDS starts from the very basics and covers all the exploit development fundamentals every penetration tester or information security enthusiast should know — but it does not stop there. It also covers advanced Windows and Linux exploit development techniques as well as exploit mitigation bypasses.

The Course at a Glance

  • Based on the techniques used by professional exploit developers
  • Covers basic and advanced exploitation techniques in full
  • Software debugging
  • Shellcoding
  • Covers both Windows and Linux exploit development
  • Identifying and fully weaponising 0-day vulnerabilities
  • Bypassing modern exploit mitigation mechanisms
  • Learn how to use tools such as Immunity Debugger, x32dbg, Mona, Pwntools, GDB and Ropper
  • Highly practical, with 19 labs and exercises
  • Earning the eCXD certification qualifies you for 40 CPE credits
  • For penetration testers looking to advance their careers

Course Material

  • 2 hours of high-quality video training material
  • Over 1000 slides
  • 19 comprehensive Hera labs

Course Delivery

  • Self-paced / HTML5, PDF, MP4
  • Offline access available
  • Access from PC, tablet and smartphone

Curriculum

  • Section 1: Linux Exploit Development

  • Linux Stack Smashing

  • Linux Exploit Mitigations and Bypasses

  • Linux Return Oriented Programming

  • Linux Shellcoding

  • Linux Advanced Exploitation

Section 2: Windows Exploit Development

  • Windows Stack Smashing
  • Windows SEH-Based Overflows
  • Windows Egghunting
  • Unicode Buffer Overflows
  • Windows Shellcoding
  • Windows Return Oriented Programming

Prerequisites

  • A good understanding of Windows and Linux internals
  • Basic reverse engineering skills
  • Basic knowledge of penetration testing
  • Basic Python scripting skills
  • A basic understanding of x86/x64 assembly and C/C++
  • Knowledge of basic programming concepts such as variables, loops and functions

Who Can Attend

  • Penetration testers
  • Vulnerability researchers
  • IT staff and students
  • IT security enthusiasts
  • CTF enthusiasts

Frequently Asked Questions

What do I need to know before learning exploit development?

Experience in a programming language, familiarity with operating system memory management, and the ability to read basic assembly are expected. The course reinforces this grounding from first principles.

Are modern protections covered?

Yes. How protections such as data execution prevention and address space layout randomisation work, and the techniques for bypassing them, are addressed in the later parts of the course.

Where is this knowledge used in practice?

In developing bespoke exploits during penetration tests where no ready-made exploit exists, in vulnerability research, and in proving whether a vulnerability is genuinely exploitable.

See the real risks in your systems.

Talk to our team about a penetration test or training plan that fits your scope.