Learn to operate and reverse macOS like the people who break it.

Deep tracks built for Apple Silicon and iOS research. Build toward MRTO operator certification through native macOS tradecraft, then advance toward MRTE with modern EDR pressure, advanced evasion, and multi-Mac movement scenarios. Reverse engineer applications down to ARM64 and the debugger, build agentic operator workflows, and move toward iOS Vulnerability Research. Every technique is grounded in lab evidence, not slides.

5
Course tracks
800+
Modules and labs
Lifetime
Single purchase
Integrated Mac labs

A first-in-class Mac lab experience inside the training portal.

Mac labs usually mean a separate VPN, an SSH client, local setup drift, and course notes living somewhere else. MacSec Labs is bringing that workflow into one place: open the lesson, launch a real browser-based macOS terminal, validate the technique on a managed Mac host, and keep moving without leaving the platform.

500 Red Team lab hours

For a limited time, macOS Red Team Tradecraft enrollment includes 500 Mac lab hours valid for 30 days. Existing and new Red Team course owners receive the promotional lab window from the portal.

No VPN, no rebuild

Use the browser terminal beside the training flow instead of rebuilding a local range or jumping between disconnected tools.

Built for paid labs

Access is course-gated, usage-aware, and designed for hands-on validation on real macOS systems as the lab program rolls out.

managed macOS lab

lab-terminal$ whoami

course-lab-user

lab-terminal$ clang --version | head -1

Apple clang version 21.0.0

lab-terminal$ lldb -b -o "target create ./training-app"

Current executable set to training-app arm64.

Course catalog

Pick the security research direction you want to build into.

Start with operator tradecraft, reverse-engineering workflow, kernel research, iOS pentesting, iOS vulnerability research, or macOS detection engineering. The full Courses page shows the exact path, modules, launch status, and track roadmap.

View course tracks

Red team

Build from macOS red-team fundamentals into advanced evasion and human-commanded agentic operations.

Reverse engineering

Learn app triage, Mach-O, ARM64, LLDB, Objective-C, Swift, runtime proof, and structured analysis workflow.

Vulnerability research

Build toward Apple kernel and iOS vulnerability research: XNU internals, IOKit, ARM64 handlers, crash triage, variant discovery, exploitability analysis, and evidence-driven reporting.

iOS pentesting

Planned path for iOS application assessment, platform behavior, instrumentation, jailbreak-aware testing, and mobile security workflow.

Detection engineering

Build macOS defender skills from telemetry foundations into Endpoint Security sensors, Sigma rules, validation workflow, hunting, and advanced evasion visibility.

How the platform works

Proof, not trivia.

You prove what you find

Every technique ends in real output: logs, files, debugger state, captured behavior. You leave able to defend the finding, not just describe it.

Real labs, not slideware

Each concept ships with a working macOS lab you run yourself on Apple Silicon. You break it, watch it, and reset it, as many times as it takes.

Built on the real platform

Swift, Objective-C, C, LLDB, and native macOS internals, not borrowed cross-platform tooling. You learn the system the way attackers actually meet it.

Both sides of the signal

Every offensive move is paired with the artifacts and telemetry it leaves behind, so you understand exactly how a defender would catch it.

Lifetime access

Pay once. Keep it for good.

No subscription, no renewal. Buy a track and every future module and lab added to it is yours as the curriculum grows. The price goes up as more content ships, so early access is the cheapest this gets.