Editorial & responsible-use policy

Every article on this site is written by me, Ismail Ghaedi. Not machine-translated, not a rewrite of somebody else's post. This page explains how the material is written, what it is checked against, when it gets updated, and where the legal line is.

1. Who writes it

I write every article in the Learn section and every module in the course syllabus. I hold a BSc in Cybersecurity from Manchester Metropolitan University with First Class Honours, and my work sits on both sides of the table: I write payloads and run penetration tests, and I harden and defend systems.

Nothing here is published under an "editorial team" byline or an invented name. My name is on every piece, and it links to the same About page.

2. How it is written

Before writing about a technique or a tool, I run it in my own lab — a virtual machine, an isolated network, and a target that belongs to me. I do not teach something I have not run myself.

Command output, error messages and tool behaviour come from that run, not from memory and not from an English tutorial. Where I am quoting documentation rather than reporting experience, I say so and name the source.

3. Sources

Where a topic touches a standard or a specific tool, I cite the primary source: OWASP for web security, NIST and MITRE ATT&CK for frameworks and attack taxonomies, and the tool's own official documentation (Kali, Nmap, Wireshark, Metasploit and the rest) for technical detail.

I do not cite second-hand blogs or copied posts. If there is a number or a claim in the text, it has to be checkable.

4. Updates and review

Security ages fast. Every article shows its publication date and the date it was last reviewed at the top of the page, and that date only moves when the text has actually changed — not on every deploy.

When a tool version changes, a command stops working, or something I wrote turns out to be wrong, I fix the text and update the review date. If you spot a mistake, tell me through the support page — I follow it up properly.

5. Lawful and ethical use

This site teaches ethical hacking: finding weaknesses in order to close them, with permission. Run the techniques explained here only against your own systems, your own lab, or a target whose owner has given you specific written permission.

Unauthorised access to someone else's system is a crime — in the UK under the Computer Misuse Act 1990, and under equivalent law almost everywhere else. Nothing on this site is authorisation to do it, and the responsibility for what you do with the knowledge is entirely yours.

That is also why I never publish real targets, leaked data, or ready-made exploits aimed at a live service. Practise on lawful environments such as TryHackMe and Hack The Box, or in your own lab.

6. Advertising and transparency

Gadget and tool write-ups are based on my own use of them. If a piece is ever sponsored or carries an affiliate link, that is stated plainly at the top of it.

The Cyber News section is an automated summary of other outlets' reporting, not original journalism. Every story links its original source and is labelled as an automated summary on the page.