A foothold is not a compromise. This course is about the distance between them. You will work Linux escalation through SUID binaries, sudo misconfiguration, capabilities, cron abuse, and kernel exploits, then do the same on Windows via token impersonation, unquoted service paths, DLL hijacking, and abusive ACLs. Beyond configuration, you will learn how memory corruption actually works: stack overflows, shellcode, and the modern mitigations of ASLR, DEP, and stack canaries, plus return-oriented programming as the answer to them. Antivirus and EDR evasion is covered at a conceptual level with an emphasis on why detection engineering works. Everything is practised in an isolated lab against systems you are authorised to attack.