How it works

Small reads. Real work. Earned access.

student.mlab.sh teaches cyber by giving you short, focused courses you actually finish. You pay with gems you earn by doing the free ones. There's a loop, and it works because the loop is short.

The loop

From signup to first badge, in five steps.

  • Sign in & get 50 gems

    SSO with mlab, no new password. You land on your dashboard with a welcome wallet of 50 gems.

  • Pick a free course (Tier 0)

    Cybersecurity 101, Linux for cyber, Networking primer, Python for hackers. No gems required.

  • Read the lessons

    Each course is a sequence of self-contained markdown lessons. Read one, hit "Next lesson", it marks done and moves on.

  • Finish, earn gems, unlock the next tier

    Completing a course rewards more gems. Spend them on a Tier 1 course, repeat.

  • Chain courses into a path

    Once you finish every course in a path, the path completes automatically. A badge gets attached to your profile.

The five tiers

A ladder, not a paywall.

Each tier is a separate floor. You climb when you're ready, on your own pace.

T0 · Foundations

Free. The bedrock. Take these even if you think you know them.

T1 · Practitioner

5 gems each. Core skills: web, recon, crypto, SOC.

T2 · Operator

15 gems each. Applied technique, one specific skill per module.

T3 · Specialist

30 gems each. Long deep dives on a single area.

T4 · Master

60 gems each. Elite, by-design hard, write your own C2.

Our pedagogy

Four principles, no fluff.

Short reads, often

A 6-lesson course beats a 40h video. You stay engaged because you keep finishing things.

Reward the doing

Every completion pays gems. Motivation is engineered into the platform, not asked of you.

Paths over playlists

A learning path ships with a badge at the end. That tells recruiters the whole story, not random clips.

Red + blue, side by side

For every offensive topic there's a defensive companion. Knowing both makes you twice as employable.

Privacy

No tracker on logged-in pages.

We don't run a third-party analytics script once you sign in. We track what we strictly need (lesson progress, course unlocks, gem balance) and nothing else. No social pixel, no remarketing.

Security posture
student@mlab:~$ session --check
HMAC-SHA512 signed session cookieauthok
mlab SSO with PKCEauthok
No third-party JS post-loginprivacyok
Gem balance is per-account, localdataok
student.mlab.sh data posture

Now do it with your hands.

Sign in, claim your 50 gems, start the first lesson. The platform is the explanation.

 Start the first course