RECON
- Record the source of every fact.
- Resolve before you scan.
- Version hints are hypotheses, not findings.
- Note what you deliberately did not touch.

Version 10 is out now for Windows. All versions are free and include FieldOps on Windows and Linux.
100% FREE ON WINDOWS & LINUX. VERSION 10 OUT NOW.
To celebrate our community, the entire DaemonCore Academy ecosystem—including all 127 guided lessons, Docker-isolated ranges, and the complete professional FieldOps War Room—is available together in one unified package. There is no separate FieldOps purchase, no license gate, and no recurring subscription.
127 practical lessons, 505 guided sections, 8 pathways, and 151 sealed missions.
Full FieldOps War Room, authorization deck, campaign engine, and resilience testing. No separate unlock.
Free on Windows and Linux. Version 10 out now with all ongoing content updates included.
DaemonCore Academy v10 in production • All versions free with FieldOps included
DaemonCore Academy was built to make serious cybersecurity training accessible without putting the useful material behind a paywall. Now getting started is even easier. Version 10 is officially available through the Microsoft Store. All versions are now free and include FieldOps with no recurring subscriptions.
DaemonCore Academy v10 is out now for Windows. All versions are free and include FieldOps.
v10 in production • Windows package identity remains unchanged
Full-Spectrum Practical Security Training
Included in Founding Fathers Offer
The DaemonCore Anonymous Collective unites independent security operators, red teamers, and defensive engineers across the globe.

DaemonCore is built for operators who demand rigorous technical depth, real sandbox ranges, and verifiable evidence ledgers. Stand with a global community dedicated to mastery.
LIVE PRODUCT PREVIEW // NO INSTALL REQUIRED
Initialize a temporary operator profile and explore the actual DaemonCore workflow directly in your browser. Walk through Command, Academy, Mission OS, workbenches, labs, progression, and the FieldOps interface. Docker execution and native system integrations require the installed Windows or Linux application.
Create a temporary operator handle.
Walk through the real interface and guided workflow.
Download the complete application for Docker ranges and native execution.
THE LOOP
Most platforms teach security like a spectator sport.
DaemonCore Academy was built around a different loop.
MENTAL MODEL
KNOWLEDGE CHECK
DISPOSABLE RANGE
ARTIFACT CAPTURE
GATE SATISFIED
If you can't explain the signal, reproduce it, document it, and prove what happened—you haven't finished the lesson.
FULL-SPECTRUM TRAINING
127 COMPLETE LESSONS // 125+ HOURS GUIDED PRACTICAL WORK
DaemonCore Academy v10 contains 125+ hours of instruction and 505 guided sections across 8 complete pathways. Every node depends on the one before it: you don't skip ahead by clicking, you advance by producing the required artifact and satisfying the mastery gate.
RANGE FABRIC 5.0
DaemonCore ships with 9 bundled range packs, including 7 sealed field missions through a content-addressed pack registry. Every launch fails closed when pack integrity does not match SHA-256 signatures. Runtime containment verification is performed before you ever get a shell.
Identity Citadel is the first protocol-native enterprise identity range. Unlike simulated web wrappers, it runs a full Samba Active Directory environment using live DNS, Kerberos, LDAP, and SMB.
TRUST CHAIN 5.1
Trust Chain 5.1 ensures that the environment you are testing is exactly what it claims to be. Full-tree fingerprints cover Dockerfiles, scripts, fixtures, cases, scenario contracts, and Compose definitions.
{
"receipt_id": "rcpt_7f3b9...",
"timestamp": "2026-08-26T20:01:00Z",
"version": "5.1",
"pack_digest": "sha256:8a1f...",
"containment_state": "verified",
"tree_fingerprint": {
"dockerfiles": "match",
"scripts": "match",
"fixtures": "match"
},
"network": "isolated",
"signature": "sig_4d9a..."
}CAMPAIGN ENGINE
MULTI-TARGET ORCHESTRATION // RESTART RECOVERY // EVIDENCE TRACEABILITY
Campaign Engine coordinates FieldOps across as many as 100 explicitly authorized targets and 128 declared TCP ports. It does not widen scope or accept arbitrary commands. It executes fixed professional assessment profiles through the same address pinning, network-boundary checks, testing window, and tamper-evident audit chain as every manual FieldOps action.
DNS control-plane evidence, deep service inventory, and a bounded surface baseline for every selected asset.
Service/version discovery across the declared TCP allowlist through local Nmap, Docker Desktop, or the native fallback engine.
Repeat DNS and surface baselines to expose new services, removed services, response changes, TLS identity drift, and security-control changes.
See queued, running, completed, failed, and pending work for every target and module.
Pause between modules, retry unfinished work, or cancel after the active evidence capture settles.
An interrupted desktop session becomes a resumable campaign; each successful task links to a digest-sealed capture included in reports.
MASTERY SYSTEM
The Mastery System evaluates your capability across six measured domains through fifteen evidence-driven professional decisions. We use practical scores, decision history, and adaptive remediation based on actual performance—no fake rankings, invented readiness scores, or imaginary community statistics.
0
PROFESSIONAL DECISIONS
0
PRINCIPAL CAPSTONES
0
MASTERY DOMAINS
0
LAB CONDITIONS
OBSERVED
GET /api/accounts/8841
200 OKOPERATOR HYPOTHESIS
EVIDENCE REQUIRED
AWAITING INTERPRETATION — NO COMMAND WILL PASS THIS GATE FOR YOU
LIVE CAPABILITY DIAGNOSTIC
NO TRIVIA. NO FAKE TERMINAL. MAKE THE DECISION.
Face twelve evidence-driven cybersecurity decisions across scope, network analysis, web and API security, identity, cloud, containers, detection and evidence handling. Identify the signal, choose the next defensible action and prove where your judgment holds — or breaks.
COMMUNITY SESSION // OFFLINE|INDIVIDUAL DIAGNOSTIC ACTIVE
Your result is calculated from the decisions you make. No seeded score. No imaginary rank.
DISPOSABLE RANGE
A REAL RANGE. A REAL SHELL. A HARD BOUNDARY.
When Docker Desktop is available, The Ghost Port provisions a disposable operator container and purpose-built target.
Nmap and curl return live results. Arbitrary shell commands work inside the operator container. When the run ends, the target disappears.
THE SHELL IS UNRESTRICTED.
THE BOUNDARY IS NOT.
INTERNAL RANGE
OPERATOR
UNRESTRICTED SHELL
TARGET
DISPOSABLE // EPHEMERAL
MANAGED RESILIENCE TESTING
PROFESSIONAL INFRASTRUCTURE RESILIENCE TESTING UNDER VERIFIED AUTHORIZATION.
FieldOps executes managed Grafana k6 resilience tests after validating both the signed operator permit and a target-hosted capacity grant. Every workload remains restricted to the authorized hostname, resolved endpoint, port, TLS mode, request rate, concurrency, duration, and validity window.
DaemonCore does not provide anonymous traffic generation or indiscriminate denial-of-service functionality. Managed workloads require a signed permit and a capacity grant issued by the tested infrastructure. Two-sided emergency stops allow immediate local termination or target-side kill signals.
Increase pressure gradually while watching latency and SLO boundaries.
Measure system behavior and elasticity under a sudden controlled load increase.
Observe memory, connection pooling, and stability under sustained pressure.
Incrementally discover the precise saturation threshold where degradation begins.
Validate MTTR and latency normalization after shedding peak workload volume.
SLO LIMIT
P95 < 250ms
ERROR RATE
< 1.0%
TWO-SIDED STOP
ARMED (LOCAL & TARGET)
SLO BREACH DETECTED
LOAD PHASE TERMINATED
RECOVERY VALIDATION
RESULT SEALED
CONTAINED LABORATORY POWER
Inside the sealed Academy range, operators can study saturation, breakpoint discovery, guardrail design, and recovery engineering against a disposable black-box target. None of this capability is pointed at a public network.
0RPS
SUSTAINED CEILING
0WORKERS
CONCURRENCY CAP
0REQUESTS
TOTAL BUDGET
SEALED CONTAINMENT BOX
ISOLATED LOOPBACK // ZERO WAN EGRESSCHAOS WORKER
DISPOSABLE TARGET
BLACK BOX
POWER WITHOUT CONTAINMENT
IS A LIABILITY.
The same pressure profiles that teach breakpoint discovery inside the range are deliberately unavailable against public infrastructure. FieldOps handles public targets under authorization and fixed rates; the sealed domain handles force.
OPERATOR RECORD
XP, streaks, weekly minutes, lessons completed, workbench scores, validation checks, drill performance, field missions, achievements and activity history — all of it derived from work you actually finished.
Records are local-first with atomic writes, backup recovery, JSON export and reset controls.
ACTIVITY HISTORY
FIELD NOTES
COMPACT OPERATOR CARDS // NOT BLOG POSTS
LOCAL FIRST
The Academy keeps your operator record on your machine. Nothing about your training work, evidence, or engagement data is shipped off to DaemonCore.
PERSISTENCE PATH
NO UPLOAD PATH // NO REMOTE TRAINING STORE
SYSTEM REQUIREMENTS
Docker Desktop (Windows) or Docker Engine with Compose v2 (Linux) is required for the live Ghost Port range. Without it, the Academy still runs the lessons, workbenches, validations and record — the range simply reports simulation mode instead of pretending to be live.
Professional infrastructure resilience testing under verified authorization. DaemonCore does not provide anonymous traffic generation or indiscriminate denial-of-service functionality. Managed workloads require a signed permit and a capacity grant issued by the tested infrastructure.
WINDOWS & LINUX //
PRODUCTION
DOCKER RANGE //
AVAILABLE
BROWSER PREVIEW //
SIMULATION MODE
COMPARISON
| DAEMONCORE ACADEMY | FIELDOPS PRO |
|---|---|
| 127 Practical Lessons | Authorization-bound diagnostics |
| Sealed Training Ranges | Exact target allowlists |
| Identity Citadel | Testing-window enforcement |
| Mastery System | boundary-aware destination validation |
| No target authorization needed | Controlled resilience testing |
| Free on Windows & Linux | Included in Offer No separate FieldOps purchase or license unlockVIEW FIELDOPS |
FAQ
Yes. All versions of DaemonCore Academy—including Windows (Microsoft Store) and Linux—are completely free and include FieldOps.
No. DaemonCore Academy is completely free on Windows and Linux, with no subscription or purchase required.
Yes. Ongoing Academy curriculum updates are included without separate course fees.
The Founding Fathers offer provides operators with DaemonCore Academy’s complete package—including FieldOps. All versions are free on Windows and Linux. There is no separate FieldOps purchase or license unlock.
Yes. DaemonCore Academy’s complete package includes FieldOps on all platforms with no separate purchase or license unlock required.
They provide access to the Academy learning experience, but native desktop capabilities and system requirements vary by platform. Consult the current documentation for compatibility details.
Check the official Linux download channel for the currently available release.
Yes—public external systems or exact internal systems when they are explicitly included in an active, attested engagement. FieldOps enforces the declared targets, ports, network boundary, and testing window.
No. It orchestrates fixed evidence-collection modules through FieldOps’ authorization boundary. Unrestricted command execution remains inside disposable, contained Academy ranges.
No. The latest-download URL always resolves to the installer attached to the newest published GitHub release.
Cloud Classroom is currently in beta and is planned as a premium educator feature beginning Q1 2027. Schools and instructors interested in early deployment should contact support@daemoncore.app for official access.
DaemonCore certification is in development and planned for Q1 2027. Current completion records and candidate dossiers are not certifications and do not represent accreditation.
Yes. FieldOps is designed exclusively for systems and environments the operator owns or has explicit permission to test.
DaemonCore Trust Authority provides device-key attribution and tamper-evident records. It does not independently verify that a typed identity or authorization claim is truthful, and it never replaces written permission from the system owner.
DAEMONCORE v10 // CHANGE INTELLIGENCE
//THE ACADEMY IS GROWING DAILY. CHECK OUT THE FIELD NOTES FROM TECHS HERE AT THE ACADEMY
TRAINING SOFTWARE IS NOT AUTHORIZATION.
USE ONLY ON SYSTEMS YOU OWN OR HAVE EXPLICIT PERMISSION TO TEST.