Enrolling

Crimson Academy

Forge your future. Enhance your expertise. Twenty-four online, self-paced courses in cybersecurity, IT and programming, taught by working operators. Level One assumes no prior experience; the catalog runs through to threat hunting, penetration testing and hypervisor security.

Catalog24 courses, 5 tracks, 3 levels.
FormatOnline and self-paced. Start and stop on your own schedule.
LabsBrowser-based lab environments. Nothing to install, and each lab resets when you leave it.
Entry requirementNone at Level One. No prior coursework, no prior IT role, no hardware of your own.
CertificationFoundations and Defensive track courses are built against the published objectives for CompTIA A+, Network+ and Security+.Crimson Academy is not an accredited body and does not administer exams. The coursework prepares you to sit them elsewhere.
AssessmentEach track ends in a graded capstone engagement against a live lab environment.
AudienceYouth, young adults, and career changers.

Background

Most security courses assume the student already knows what a process is, what a subnet mask does, and why anyone would open a terminal. That assumption filters out a large share of the people who want into the field, in week one, over prerequisites nobody listed.

Level One assumes none of it. The catalog then continues through programming and automation, defensive operations, offensive tradecraft, and the cloud and hypervisor layers where a growing share of intrusions now occur.

The academy also supplies PenCrimson's own bench. The curriculum is drawn from what the consulting and product teams need people to know, which is why Track 05 covers the same hypervisor and control-plane material TensorOne was built to defend.

Course catalog

Start at whichever level fits. Foundations requires nothing; every track above it states what it expects you to have already.

Level One · no experience Level Two · fundamentals complete Level Three · operator track

Track 01 · Foundations

5 courses · no prior experience needed

Everything the rest of the catalog assumes. If you have never used a terminal, never configured a network interface and are not sure what a kernel does, this is the entry point.

Linux Fundamentals

Level One

Get hands-on with Linux. Your essential first step to mastering the open-source power behind cybersecurity. Covers the filesystem, permissions, processes, package management and the shell.

Windows Fundamentals

Level One

Master core Windows skills. An essential first step into the world of IT and cybersecurity. Covers the registry, services, event logs, users and groups, and introductory PowerShell.

Networking Fundamentals

Level One

Master the language of the internet. Understand how the world connects, starting with network essentials: the OSI model, TCP/IP, DNS, DHCP, routing, and reading a packet capture.

Prepares for CompTIA Network+

Computing & Hardware Essentials

Level One

What the machine does underneath the operating system. CPU, memory, storage, the boot process, and an introduction to virtualization.

Prepares for CompTIA A+

Command Line & Shell Basics

Level One

Working fluently at the prompt on both platforms. Navigation, pipes and redirection, text processing, remote sessions over SSH, and introductory scripting.

Track 02 · Programming & Automation

4 courses · Foundations recommended

Tooling and automation for security work. An analyst who can write a short script handles volumes of work that are otherwise manual.

Git & Version Control

Level One

Branches, merges, history and collaboration. A prerequisite for the rest of this track.

Python for Security

Level Two

Python from syntax through the libraries security work relies on: parsing logs, calling APIs, handling structured data, and packaging small tools for reuse.

Bash & PowerShell Automation

Level Two

Automating administration and investigation on both platforms. Scheduled execution, remote execution, log triage, and writing scripts safe to run against production.

Web Technologies, HTTP & APIs

Level Two

Requests and responses, sessions and tokens, REST and JSON, TLS, and the browser security model. Prerequisite for Web Application Security in Track 04.

Track 03 · Defensive Operations

6 courses · blue team

Detecting an intrusion, judging whether it matters, and ending it. This track maps most directly to a first role in a security operations centre.

Security Essentials

Level Two

Threats and threat actors, the CIA triad, applied cryptography, identity and access management, risk, and the control families that address each.

Prepares for CompTIA Security+

Log Analysis & SIEM Fundamentals

Level Two

Log sources across Windows, Linux, network and cloud; normalization and parsing; and writing queries and detections that produce a workable alert volume.

Endpoint Detection & Response

Level Two

What EDR observes and what it misses. Process trees, persistence mechanisms, living-off-the-land binaries, and containment procedure.

Incident Response Fundamentals

Level Two

The full lifecycle: preparation, identification, containment, eradication, recovery, and the post-incident write-up. Includes running a tabletop exercise.

Digital Forensics Essentials

Level Three

Acquiring and examining evidence without altering it. Disk and memory imaging, filesystem and registry artifacts, timeline reconstruction, and chain of custody.

Threat Hunting

Level Three

Hypothesis-driven hunting in the absence of an alert. Constructing and testing a hypothesis, pivoting through telemetry, and converting a confirmed hunt into a standing detection.

Track 04 · Offensive Operations

5 courses · red team

Taught for defenders as well as testers. Every course runs inside lab environments the student is authorized to attack; scope, authorization and the applicable law are covered before any tooling.

Ethical Hacking Fundamentals

Level Two

Methodology, scope, rules of engagement and the legal framework, then reconnaissance, enumeration, exploitation and post-exploitation as a repeatable process.

OSINT & Social Engineering

Level Two

Open-source reconnaissance, pretexting and phishing mechanics, and the organizational controls that reduce exposure to both.

Network Penetration Testing

Level Three

An internal network end to end: scanning, service exploitation, credential capture and relay, pivoting, privilege escalation, and client-ready reporting.

Web Application Security

Level Three

Injection, broken authentication, access control failures, SSRF and deserialization, identified manually and then remediated in code.

Active Directory Attack & Defense

Level Three

Domain enumeration, Kerberos abuse, delegation, ACL-based privilege paths and forest-level compromise, each paired with its hardening measure.

Track 05 · Cloud & Infrastructure

4 courses · the layer under the endpoint

The infrastructure layer PenCrimson's own product was built to defend. Most curricula stop at the endpoint.

Cloud Security Fundamentals

Level Two

The shared responsibility model across the major providers: identity and permissions, network boundaries, storage exposure, logging, and the misconfigurations behind most cloud incidents.

Virtualization & Hypervisor Security

Level Three

VMware, Proxmox, Nutanix and KVM from the defender's position. Control-plane access, management network exposure, guest isolation, and detecting an intruder who has reached the hypervisor.

Containers & Kubernetes Security

Level Three

Image supply chain, runtime isolation, RBAC, secrets handling, network policy, and the escape paths between a container, its node and the cluster.

Infrastructure as Code & Secure Deployment

Level Three

Declarative infrastructure, policy as code, secrets management, and placing security checks inside a deployment pipeline.

Where to start

The most common admissions question. The answer depends on what you already do.

No IT background at allYou have never opened a terminal
TRACK 01
Working in IT, moving into securityYou know the systems and need the threat model
TRACK 03
Aiming at testing or red team workRequires Track 02 or equivalent scripting ability
TRACK 04
Running infrastructure you need to defendCloud, hypervisor and container layers
TRACK 05
Building tooling and automationSecurity engineering rather than analysis
TRACK 02

Capstone and placement

Every track ends in a scoped, graded engagement against a live lab environment.

The capstone produces the artifact the job produces: an incident report, a penetration test report, a detection package, or a hardened build with its justification. The student keeps it and can show it to an interviewer, which a completion badge does little to substitute for.

Students who finish an operator-level track are routed to the rest of PenCrimson where there is a fit. The consulting desk, the Cerebro operator pool and the TensorOne engineering team all recruit from people whose work we have already assessed.

Enrollment

Tell us where you are starting from and what you want to be doing in a year. We will tell you which track to open first, and if the honest answer is that you do not need us, we will tell you that instead.