DARE is a training design constraint I built for the gap between the two. A learner deconstructs a system, attacks it, watches a patched version stop the same attack cold, then switches sides to see their own attack from the defender's screen. That last part is the one most training skips.
Before anyone touches a keyboard, I make sure the learner can say, in plain language, what the system in front of them is doing. A whiteboard sketch, a live walk-through, whatever makes the shape of it visible. If the concept underneath the attack is not solid, nothing that follows will stick.
I demonstrate the attack once, narrating what I am doing and why. Then the learner runs it again on their own, same target. Then they run it on a target I have not shown them, different enough that copying my steps will not work. That third step is where I find out whether they understood stage one.
The learner runs the exact same attack against a patched version of the same application, one change made and nothing else. When it fails, I say it out loud. Failure here means the application is doing its job, and a pentester who never fails isn't testing anything.
This is the stage most people skip when they are short on time, and the one I refuse to cut. I hand the learner the logs their own attack generated and ask them to look before I explain anything. Most of them go quiet for a second. That's the moment the whole framework is built around.
A fillable session-planning worksheet, one section per stage. Saves in your browser as you go, and prints clean if you want a paper copy on the day.
Open the worksheet →Full sessions walked through stage by stage, from web and API flaws to Kerberoasting, SSRF, ARP spoofing and blue-team detection, each run through Deconstruct to Exchange. A growing library.
Read the use cases →The vulnerable-and-patched application pairs I run sessions against, with realistic data instead of a bare flag to retrieve.
Visit labs.sarathg.me →Pick a topic, a sector, and the exact minutes you have, and get a session outline built from a library spanning 36 topics across the whole field. No AI involved, just rules.
Build a session outline →Delivering CEH, Security+, OSCP, SC-200, AWS Security or another program? Map its exam objectives to DARE sessions, and turn a fixed syllabus into understanding without rewriting it.
Map your certification →