Skip to content
//THE ACADEMY IS GROWING DAILY. CHECK OUT THE FIELD NOTES FROM TECHS HERE AT THE ACADEMY
>_DAEMONCORE // ACADEMY
The Curator
DAEMONCORE ACADEMY v10 // PRODUCTION // WINDOWS & LINUX
TODAY'S 60S SOC DRILL: ACTIVE→

STOP STUDYING CYBERSECURITY.START OPERATING.

Version 10 is out now for Windows. All versions are free and include FieldOps on Windows and Linux.

DaemonCore Academy v10 in production for Windows.
Complete Academy package including FieldOps. No recurring subscription.
FOUNDING FATHERS // SPECIAL LAUNCH OFFER

GET THE COMPLETE DAEMONCORE ACADEMY PACKAGE—INCLUDING FIELDOPS.

100% FREE ON WINDOWS & LINUX. VERSION 10 OUT NOW.

To celebrate our community, the entire DaemonCore Academy ecosystem—including all 127 guided lessons, Docker-isolated ranges, and the complete professional FieldOps War Room—is available together in one unified package. There is no separate FieldOps purchase, no license gate, and no recurring subscription.

COMPLETE ACADEMY

127 practical lessons, 505 guided sections, 8 pathways, and 151 sealed missions.

FIELDOPS INCLUDED

Full FieldOps War Room, authorization deck, campaign engine, and resilience testing. No separate unlock.

NO SUBSCRIPTIONS

Free on Windows and Linux. Version 10 out now with all ongoing content updates included.

DaemonCore Academy v10 in production • All versions free with FieldOps included

MAJOR MILESTONE

THE ACADEMY JUST GOT EASIER TO INSTALL.

DaemonCore Academy was built to make serious cybersecurity training accessible without putting the useful material behind a paywall. Now getting started is even easier. Version 10 is officially available through the Microsoft Store. All versions are now free and include FieldOps with no recurring subscriptions.

100% FREEFieldOps Included
127 PRACTICAL LESSONSComplete Academy + FieldOps
MICROSOFT STORE+ Direct Linux Download
GET IT FROM MICROSOFT
DaemonCore Academy v10 in production • All versions free with FieldOps included
STABLE DESKTOP UPDATE // v10

DaemonCore Academy v10

DaemonCore Academy v10 is out now for Windows. All versions are free and include FieldOps.

v10 in production • Windows package identity remains unchanged

WHAT'S NEW IN v10

Performance & Recovery
  • ▹Faster first launch through parallel local-store initialization.
  • ▹Clear renderer recovery state instead of an unexplained black screen.
  • ▹Improved interactive workbench completion and evidence handling.
  • ▹Preserved local progress, settings, records, and licensing during upgrades.
  • ▹Windows package identity remains unchanged for Microsoft Store updates.
Living Range & Docker
  • ▹More reliable Living Range startup with automatic Docker subnet conflict detection.
  • ▹Automatic selection of an available isolated Docker network.
  • ▹Cleanup of stale Docker Compose resources before launching a range.
  • ▹Reduced “pool overlaps with other one” network failures.
  • ▹Preserved sealed internal-network containment.
Desktop Layout & UX
  • ▹Improved Lab Range and Living Range layouts for laptops, desktops, and smaller windows.
  • ▹Refined dark scrollbars, spacing, typography, borders, and responsive presentation.
  • ▹Streamlined objective panels and responsive command viewports.
  • ▹Optimized full-screen terminal docking across multi-monitor setups.

Academy Core Capabilities

Full-Spectrum Practical Security Training

  • ▹8 curriculum pathways across 127 practical lessons and 505 guided sections
  • ▹125+ hours of instruction with 16 Intel references and 16 repeatable drill sets
  • ▹151 sealed missions across 18 tracks and 3 principal capstones
  • ▹Local progress tracking, lesson scoring, XP, streaks, achievements, and adaptive remediation
  • ▹Docker-isolated Lab Range scenarios and Living Range synthetic incident environments
  • ▹Web/API workbench with OpenAPI/Swagger importing, request replay, response analysis, and redaction controls
  • ▹Training spans Linux, networking, web/API security, Windows and Active Directory, cloud, detection engineering, incident response, forensics, containers, Kubernetes, and software supply-chain security
ALL VERSIONS FREE // DaemonCore Academy complete package includes FieldOps on Windows & Linux. No recurring subscription.

Commercial Boundaries & FieldOps

Included in Founding Fathers Offer

  • ▹Included in Offer: FieldOps is included in the Founding Fathers complete package. There is no separate FieldOps purchase or license unlock.
  • ▹Third-Party Tool Orchestration: Coordinates Nmap, Nuclei, OWASP ZAP, testssl.sh, and k6 with exact-target execution boundaries.
  • ▹Evidence Integrity: Append-only ledgers, DNS target pinning, redirect escape prevention, and tamper-evident findings.
  • ▹Assessment Notice: Operator dossiers and records represent verifiable practical skills assessment and do not claim external certification or institutional accreditation.
FIELDOPS NOTICE // Requires explicit written authorization before conducting live target operations.
DAEMONCORE COLLECTIVE // GLOBAL OPERATIVE NETWORK

UNITED IN SECURITY MASTERY

The DaemonCore Anonymous Collective unites independent security operators, red teamers, and defensive engineers across the globe.

Daemoncore Anonymous Hacker Group Collective
ANONYMOUS_COLLECTIVE_SEC_OPS // v10
OPERATOR SOLIDARITY

NO GATES. NO FLUFF. PURE EXECUTION.

DaemonCore is built for operators who demand rigorous technical depth, real sandbox ranges, and verifiable evidence ledgers. Stand with a global community dedicated to mastery.

TRAINING MODULES127 LESSONS
HANDS-ON RANGES70 LAB CONDITIONS

LIVE PRODUCT PREVIEW // NO INSTALL REQUIRED

Enter DaemonCore
before you download it.

Initialize a temporary operator profile and explore the actual DaemonCore workflow directly in your browser. Walk through Command, Academy, Mission OS, workbenches, labs, progression, and the FieldOps interface. Docker execution and native system integrations require the installed Windows or Linux application.

V10 WEB PREVIEW // NO INSTALL // LOCAL BROWSER SESSION
FULL APP REQUIRED FOR DOCKER +
NATIVE EXECUTION
1

INITIALIZE

Create a temporary operator handle.

2

EXPLORE

Walk through the real interface and guided workflow.

3

INSTALL

Download the complete application for Docker ranges and native execution.

THE LOOP

NOT ANOTHER
CYBER COURSE.

Most platforms teach security like a spectator sport.

  • Watch a video.
  • Copy three commands.
  • Get XP.
  • Move on.

DaemonCore Academy was built around a different loop.

  1. 01

    LEARN

    MENTAL MODEL

  2. 02

    VALIDATE

    KNOWLEDGE CHECK

  3. 03

    OPERATE

    DISPOSABLE RANGE

  4. 04

    EVIDENCE

    ARTIFACT CAPTURE

  5. 05

    MASTER

    GATE SATISFIED

If you can't explain the signal, reproduce it, document it, and prove what happened—you haven't finished the lesson.

FULL-SPECTRUM TRAINING

127 LESSONS. EIGHT
ACADEMY PATHWAYS.

127 COMPLETE LESSONS // 125+ HOURS GUIDED PRACTICAL WORK

DaemonCore Academy v10 contains 125+ hours of instruction and 505 guided sections across 8 complete pathways. Every node depends on the one before it: you don't skip ahead by clicking, you advance by producing the required artifact and satisfying the mastery gate.

CORESPECIALISTENTERPRISEDEFENSEPLATFORM
PATHWAY 07 DOSSIERPLATFORM

CONTAINERS AND KUBERNETES

OBJECTIVE
Assess isolation, capabilities, and runtime boundaries in clusters.
EXPECTED SIGNAL
Capability or mount that dissolves the container boundary.
REQUIRED ARTIFACT
Runtime configuration evidence and cluster mapping.
MASTERY GATE
Demonstrate lateral movement across disposable Docker-based pods.
PREREQUISITEPATHWAY 06
GATEENFORCED

RANGE FABRIC 5.0

SEALED
TRAINING RANGES.

DaemonCore ships with 9 bundled range packs, including 7 sealed field missions through a content-addressed pack registry. Every launch fails closed when pack integrity does not match SHA-256 signatures. Runtime containment verification is performed before you ever get a shell.

IDENTITY CITADEL

Identity Citadel is the first protocol-native enterprise identity range. Unlike simulated web wrappers, it runs a full Samba Active Directory environment using live DNS, Kerberos, LDAP, and SMB.

SEALED BOUNDARIES

  • 9 BUNDLED RANGE PACKS, INCLUDING 7 SEALED FIELD MISSIONS
  • CONTENT-ADDRESSED REGISTRY
  • SHA-256 INTEGRITY CHECKING
  • FAILS CLOSED ON MISMATCH
  • RUNTIME CONTAINMENT VERIFICATION

TRUST CHAIN 5.1

EVIDENCE YOU CAN
ACTUALLY VERIFY.

Trust Chain 5.1 ensures that the environment you are testing is exactly what it claims to be. Full-tree fingerprints cover Dockerfiles, scripts, fixtures, cases, scenario contracts, and Compose definitions.

  • DOCKER ENGINE & COMPOSE PREFLIGHT DIAGNOSTICS
  • DETECTION OF MODIFIED, REMOVED, OR INJECTED FILES
  • DIGEST-SEALED LAUNCH RECEIPTS
  • EXPORTABLE JSON INTEGRITY RECEIPTS
  • RUNTIME VERSION & CONTAINMENT STATE BOUND INTO RECEIPT
  • RECEIPT REFERENCES RETAINED WITH MISSION ATTEMPTS
INTEGRITY RECEIPTSEALED
{
  "receipt_id": "rcpt_7f3b9...",
  "timestamp": "2026-08-26T20:01:00Z",
  "version": "5.1",
  "pack_digest": "sha256:8a1f...",
  "containment_state": "verified",
  "tree_fingerprint": {
    "dockerfiles": "match",
    "scripts": "match",
    "fixtures": "match"
  },
  "network": "isolated",
  "signature": "sig_4d9a..."
}

CAMPAIGN ENGINE

THE ENGAGEMENT IS
THE UNIT OF WORK.

MULTI-TARGET ORCHESTRATION // RESTART RECOVERY // EVIDENCE TRACEABILITY

Campaign Engine coordinates FieldOps across as many as 100 explicitly authorized targets and 128 declared TCP ports. It does not widen scope or accept arbitrary commands. It executes fixed professional assessment profiles through the same address pinning, network-boundary checks, testing window, and tamper-evident audit chain as every manual FieldOps action.

// MODULE 01

Complete Assessment

DNS control-plane evidence, deep service inventory, and a bounded surface baseline for every selected asset.

// MODULE 02

Service Inventory

Service/version discovery across the declared TCP allowlist through local Nmap, Docker Desktop, or the native fallback engine.

// MODULE 03

Change Verification

Repeat DNS and surface baselines to expose new services, removed services, response changes, TLS identity drift, and security-control changes.

// MODULE 04

Live Operations Ledger

See queued, running, completed, failed, and pending work for every target and module.

// MODULE 05

Pause, Resume & Safe Cancellation

Pause between modules, retry unfinished work, or cancel after the active evidence capture settles.

// MODULE 06

Restart Recovery & Traceability

An interrupted desktop session becomes a resumable campaign; each successful task links to a digest-sealed capture included in reports.

DAEMONCORE TRUST AUTHORITY

EVERY OPERATION HAS A NAME,
PERMIT, SCOPE, AND RECEIPT.

DEVICE-PROTECTED ED25519 IDENTITY // SIGNED PERMITS // HASH-CHAINED LEDGER

FieldOps no longer relies on an anonymous authorization checkbox. Operators bind a protected Ed25519 identity to their installation before opening a new engagement. DaemonCore then signs the engagement permit and every operation receipt with the operator’s name, organization, role, device-key fingerprint, and timestamp.

Device-protected operator identity

The private signing key is protected by the operating system and never appears in evidence exports.

Named approving authority

The permit records the approving person and professional email alongside the client and ROE reference.

Cryptographically bound scope

Targets, ports, network mode, policy, and testing window are covered by the permit signature. A changed field fails verification and blocks execution.

Observe, Validate & Stress policies

Enforces distinct authorization tiers from posture and protocol-identity collection up to multi-target campaigns and bounded Chaos Engine resilience profiles.

Signed operation receipts & attribution

Completed, blocked, paused, and failed actions retain the named signer inside a hash-chained ledger for attribution-ready case files and printable reports.

TRUST STATEMENT
“DaemonCore Trust Authority provides device-key attribution and tamper-evident records. It does not independently verify that a typed identity or authorization claim is truthful, and it never replaces written permission from the system owner.”
SIGNED PERMIT & RECEIPTED25519 VERIFIED
{
  "permit_id": "prmt_8a2f...",
  "operator": "Alex Vance (Lead Operator)",
  "approving_authority": "Director of Security <sec@acme.com>",
  "scope": {
    "targets": ["198.51.100.0/24"],
    "ports": [80, 443, 8443],
    "policy": "VALIDATE"
  },
  "device_fingerprint": "sha256:e3b0c44...",
  "signature": "sig_ed25519_9c12..."
}

MASTERY SYSTEM

YOU DON'T PASS
BY WATCHING.

The Mastery System evaluates your capability across six measured domains through fifteen evidence-driven professional decisions. We use practical scores, decision history, and adaptive remediation based on actual performance—no fake rankings, invented readiness scores, or imaginary community statistics.

0

PROFESSIONAL DECISIONS

0

PRINCIPAL CAPSTONES

0

MASTERY DOMAINS

0

LAB CONDITIONS

INCIDENT // AUTHORIZATION FAILURE WORKBENCH ACTIVE

OBSERVED

GET /api/accounts/8841
200 OK

OPERATOR HYPOTHESIS

EVIDENCE REQUIRED

CONFIDENCE46%

AWAITING INTERPRETATION — NO COMMAND WILL PASS THIS GATE FOR YOU

LIVE CAPABILITY DIAGNOSTIC

TRIAL BY
EVIDENCE.

NO TRIVIA. NO FAKE TERMINAL. MAKE THE DECISION.

Face twelve evidence-driven cybersecurity decisions across scope, network analysis, web and API security, identity, cloud, containers, detection and evidence handling. Identify the signal, choose the next defensible action and prove where your judgment holds — or breaks.

COMMUNITY SESSION // OFFLINE|INDIVIDUAL DIAGNOSTIC ACTIVE

  • 12 PROFESSIONAL DECISIONS
  • 6 MEASURED DOMAINS
  • APPROXIMATELY 10 MINUTES
  • PERSONALIZED ACADEMY PATH
  • NO ACCOUNT REQUIRED
  • FREE TO COMPLETE
START THE DIAGNOSTIC

Your result is calculated from the decisions you make. No seeded score. No imaginary rank.

MEASURED DOMAINS
  • 01SCOPE
  • 02NETWORK
  • 03WEB/API
  • 04IDENTITY
  • 05CLOUD
  • 06DETECTION
DECISION STRUCTURE
  • > REVIEW SUPPLIED EVIDENCE
  • > SELECT STRONGEST HYPOTHESIS
  • > CHOOSE NEXT EVIDENCE TO COLLECT
  • > JUDGE EVIDENCE SUFFICIENCY
  • > COMMIT REMEDIATION OR CONTAINMENT
  • > SET CONFIDENCE LEVEL

DISPOSABLE RANGE

THE GHOST PORT

A REAL RANGE. A REAL SHELL. A HARD BOUNDARY.

When Docker Desktop is available, The Ghost Port provisions a disposable operator container and purpose-built target.

Nmap and curl return live results. Arbitrary shell commands work inside the operator container. When the run ends, the target disappears.

THE SHELL IS UNRESTRICTED.
THE BOUNDARY IS NOT.

DAEMONCORE HOST
CONTAINMENT GATE

INTERNAL RANGE

OPERATOR

UNRESTRICTED SHELL

TARGET

DISPOSABLE // EPHEMERAL

✕INTERNET
CONTAINMENT VERIFICATION 0/7
  • NO HOST MOUNTSCHECKING
  • NO PUBLISHED TARGET PORTSQUEUED
  • NO PRIVILEGED CONTAINERSQUEUED
  • CAPABILITIES DROPPEDQUEUED
  • NO-NEW-PRIVILEGESQUEUED
  • EGRESS BLOCKEDQUEUED
  • RESOURCE CEILINGSQUEUED
AWAITING VERIFICATION

MANAGED RESILIENCE TESTING

MANAGED k6 &
CHAOS ENGINE.

PROFESSIONAL INFRASTRUCTURE RESILIENCE TESTING UNDER VERIFIED AUTHORIZATION.

FieldOps executes managed Grafana k6 resilience tests after validating both the signed operator permit and a target-hosted capacity grant. Every workload remains restricted to the authorized hostname, resolved endpoint, port, TLS mode, request rate, concurrency, duration, and validity window.

DaemonCore does not provide anonymous traffic generation or indiscriminate denial-of-service functionality. Managed workloads require a signed permit and a capacity grant issued by the tested infrastructure. Two-sided emergency stops allow immediate local termination or target-side kill signals.

P1

RAMP

Increase pressure gradually while watching latency and SLO boundaries.

P2

SPIKE

Measure system behavior and elasticity under a sudden controlled load increase.

P3

SOAK

Observe memory, connection pooling, and stability under sustained pressure.

P4

BREAKPOINT

Incrementally discover the precise saturation threshold where degradation begins.

P5

RECOVERY

Validate MTTR and latency normalization after shedding peak workload volume.

LIVE OPERATIONAL TELEMETRY // MANAGED k6 STREAMING
ACHIEVED RPS24 RPS
TOTAL REQUESTS1240
LATENCY (p50 / p90 / p95 / p99)22 / 48 / 68 / 112 ms
ERROR RATE0.12 %
DROPPED ITERATIONS0
MAX VIRTUAL USERS35 VUs
SLO THRESHOLD RESULTSPASS // ALL THRESHOLDS SATISFIED
RECOVERY TIME1.2 s
PROCESS OUTPUTk6 worker :: sealed run intact

SLO LIMIT

P95 < 250ms

ERROR RATE

< 1.0%

TWO-SIDED STOP

ARMED (LOCAL & TARGET)

LOCAL OPERATOR KILL SWITCH + TARGET-SIDE RUN TERMINATION
  1. STEP 01

    SLO BREACH DETECTED

  2. STEP 02

    LOAD PHASE TERMINATED

  3. STEP 03

    RECOVERY VALIDATION

  4. STEP 04

    RESULT SEALED

CONTAINED LABORATORY POWER

SEALED
POWER DOMAIN.

Inside the sealed Academy range, operators can study saturation, breakpoint discovery, guardrail design, and recovery engineering against a disposable black-box target. None of this capability is pointed at a public network.

0RPS

SUSTAINED CEILING

0WORKERS

CONCURRENCY CAP

0REQUESTS

TOTAL BUDGET

SEALED CONTAINMENT BOX

ISOLATED LOOPBACK // ZERO WAN EGRESS
CONTAINMENT: LOCKED•0.34ms

CHAOS WORKER

DISPOSABLE TARGET

BLACK BOX

  • 500 RPS MAX
  • 100 WORKERS MAX
  • 30K REQUEST CAP
  • NO PRIVILEGES
  • NO INTERNET EGRESS
  • NO HOST MOUNTS
  • NO PUBLISHED PORTS
  • AUTO TEARDOWN
✕INTERNET // DISCONNECTED

POWER WITHOUT CONTAINMENT
IS A LIABILITY.

The same pressure profiles that teach breakpoint discovery inside the range are deliberately unavailable against public infrastructure. FieldOps handles public targets under authorization and fixed rates; the sealed domain handles force.

OPERATOR RECORD

YOUR RECORD
IS EARNED.

XP, streaks, weekly minutes, lessons completed, workbench scores, validation checks, drill performance, field missions, achievements and activity history — all of it derived from work you actually finished.

  • NO SEEDED XP.
  • NO FAKE PROGRESS.
  • EVERY NUMBER COMES FROM COMPLETED WORK.

Records are local-first with atomic writes, backup recovery, JSON export and reset controls.

OPERATOR // THORIllustrative operator record
RECORD VERIFIED
LESSONS COMPLETED0/127
PRACTICAL SCORE0
VALIDATIONS0/70
FIELD MISSIONS0/7
CURRENT STREAK12 DAYS
EVIDENCE ARTIFACTS47
WEEKLY MINUTES412
ASSESSMENT PROGRESS66%
DRILL AVERAGE89
ACHIEVEMENTS09

ACTIVITY HISTORY

  • D-01WORKBENCH 12 // AUTHORIZATIONPASSED
  • D-01EVIDENCE ARTIFACT SEALED+3
  • D-02DRILL SET 06 // API SURFACE94
  • D-03RANGE RUN // GHOST PORTCONTAINED
  • D-04VALIDATION 16 // SECRETSVERIFIED

FIELD NOTES

TECHNICAL REFERENCE CARDS.

COMPACT OPERATOR CARDS // NOT BLOG POSTS

  • FN-01

    RECON

    • Record the source of every fact.
    • Resolve before you scan.
    • Version hints are hypotheses, not findings.
    • Note what you deliberately did not touch.
  • FN-02

    HTTP EVIDENCE

    • Capture the full request and response pair.
    • One variable changes per comparison.
    • Timestamps in UTC, always.
    • Redact credential material at capture time.
  • FN-03

    FINDING WRITING

    • Impact first, mechanism second.
    • State the affected identity and object.
    • Include a reproducer a peer can run.
    • Separate observation from inference.
  • FN-04

    RANGE RULES

    • Authorization precedes the first packet.
    • Stay inside the declared boundary.
    • Log refusals as well as results.
    • Tear down what you provisioned.

LOCAL FIRST

YOUR TRAINING RECORD
BELONGS TO YOU.

The Academy keeps your operator record on your machine. Nothing about your training work, evidence, or engagement data is shipped off to DaemonCore.

  • No account dependency.
  • Operator data remains local.
  • Atomic persistence.
  • Backup recovery.
  • JSON export.
  • Reset controls.
  • Secure license-key storage.

PERSISTENCE PATH

ACADEMY
LOCAL OPERATOR RECORD
BACKUP / EXPORT

NO UPLOAD PATH // NO REMOTE TRAINING STORE

SYSTEM REQUIREMENTS

WHAT THE RANGE
NEEDS.

Docker Desktop (Windows) or Docker Engine with Compose v2 (Linux) is required for the live Ghost Port range. Without it, the Academy still runs the lessons, workbenches, validations and record — the range simply reports simulation mode instead of pretending to be live.

Professional infrastructure resilience testing under verified authorization. DaemonCore does not provide anonymous traffic generation or indiscriminate denial-of-service functionality. Managed workloads require a signed permit and a capacity grant issued by the tested infrastructure.

ENVIRONMENT CHECK3 / 3 DETECTED
OPERATING SYSTEM
Windows 10 / 11 x64 or Linux x64
RUNTIME
Self-contained
RANGE PROVIDER
Docker Desktop / Docker Engine (Compose v2)
  • WINDOWS & LINUX //

    PRODUCTION

  • DOCKER RANGE //

    AVAILABLE

  • BROWSER PREVIEW //

    SIMULATION MODE

COMPARISON

ACADEMY VERSUS
FIELDOPS PRO.

DaemonCore Academy compared with FieldOps Pro
DAEMONCORE ACADEMYFIELDOPS PRO
127 Practical LessonsAuthorization-bound diagnostics
Sealed Training RangesExact target allowlists
Identity CitadelTesting-window enforcement
Mastery Systemboundary-aware destination validation
No target authorization neededControlled resilience testing
Free on Windows & LinuxIncluded in Offer No separate FieldOps purchase or license unlockVIEW FIELDOPS

FAQ

FREQUENTLY ASKED
QUESTIONS.

Is DaemonCore Academy free?

Yes. All versions of DaemonCore Academy—including Windows (Microsoft Store) and Linux—are completely free and include FieldOps.

Is the Windows edition a subscription?

No. DaemonCore Academy is completely free on Windows and Linux, with no subscription or purchase required.

Are Academy curriculum updates included?

Yes. Ongoing Academy curriculum updates are included without separate course fees.

What is the Founding Fathers offer?

The Founding Fathers offer provides operators with DaemonCore Academy’s complete package—including FieldOps. All versions are free on Windows and Linux. There is no separate FieldOps purchase or license unlock.

Does the free package include FieldOps?

Yes. DaemonCore Academy’s complete package includes FieldOps on all platforms with no separate purchase or license unlock required.

Are Windows, Linux, and the browser preview identical?

They provide access to the Academy learning experience, but native desktop capabilities and system requirements vary by platform. Consult the current documentation for compatibility details.

Has the new Linux release shipped?

Check the official Linux download channel for the currently available release.

Can FieldOps test real systems?

Yes—public external systems or exact internal systems when they are explicitly included in an active, attested engagement. FieldOps enforces the declared targets, ports, network boundary, and testing window.

Does Campaign Engine run arbitrary commands?

No. It orchestrates fixed evidence-collection modules through FieldOps’ authorization boundary. Unrestricted command execution remains inside disposable, contained Academy ranges.

Will the download URL change?

No. The latest-download URL always resolves to the installer attached to the newest published GitHub release.

Is Cloud Classroom included?

Cloud Classroom is currently in beta and is planned as a premium educator feature beginning Q1 2027. Schools and instructors interested in early deployment should contact support@daemoncore.app for official access.

Does DaemonCore issue certifications?

DaemonCore certification is in development and planned for Q1 2027. Current completion records and candidate dossiers are not certifications and do not represent accreditation.

Is FieldOps intended for authorized work?

Yes. FieldOps is designed exclusively for systems and environments the operator owns or has explicit permission to test.

TRUST AUTHORITY STATEMENT

DaemonCore Trust Authority provides device-key attribution and tamper-evident records. It does not independently verify that a typed identity or authorization claim is truthful, and it never replaces written permission from the system owner.

STOP COLLECTING COURSES.START COLLECTING EVIDENCE.

  • Learn the model.
  • Enter the range.
  • Make the decision.
  • Capture the evidence.
  • Earn the record.

DAEMONCORE v10 // CHANGE INTELLIGENCE

//THE ACADEMY IS GROWING DAILY. CHECK OUT THE FIELD NOTES FROM TECHS HERE AT THE ACADEMY

TRAINING SOFTWARE IS NOT AUTHORIZATION.

USE ONLY ON SYSTEMS YOU OWN OR HAVE EXPLICIT PERMISSION TO TEST.