Rooted
The rules

Ten ranks.
Nothing hidden.

Hackers climb by leaving proof: confirmed reports, reviewed write-ups, labs, peer review and external sources. No mystery multipliers. If it scores, it has a receipt.

The ladder

The ranks speak hacker without losing the room. Early levels reward curiosity and reps; the top end demands confirmed impact, clean writing, trusted review and original research.

  1. 0NoobThe handle exists. Nothing behind it yet.0
  2. 1Junior HackerFirst proof landed. Curiosity became something you can point at.1
  3. 2OperatorBreaks small things on purpose and can say why they broke.300
  4. 3HackerHas a method now, not lucky payloads.900
  5. 4Pro HackerFinds real bugs and turns them into reports somebody acted on.2,000
  6. 5Exploit HunterBuilds the tooling, chains the primitives, goes deep in one place.4,000
  7. 6Red TeamerSustained impact across reports, writing and work verified outside.8,000
  8. 7Elite HackerPut an unfamiliar surface in front of them and confirmed findings come out.14,000
  9. 8GhostPrecise, quiet and trusted. Leaves findings, not noise.22,000
  10. 9RootedOriginal research and proof nobody else had. The top of the ladder.36,000
UnissuedAccessControlMastery

How points are earned

The fastest clean climb is a mixed attack path: real reports, clear write-ups, labs, review and imported credentials.

What a report is worth

A confirmed report is worth more than any certification on this platform, and it is the only track with no ceiling. That is deliberate: an exam says you studied, a confirmed finding says somebody else's security team agreed you were right.

low
+100
medium
+300
high
+700
critical
+1500

Credentials

ceiling 4,000

External proof: certifications, platform ranks, GitHub work and credited CVEs read from the source.

Confirmed by - The issuing platform, via an ownership handshake

Reports

no ceiling

Vulnerability reports submitted through Rooted programs and confirmed by the organisation.

Confirmed by - The organisation that received the report

low
+100
medium
+300
high
+700
critical
+1500

Write-ups

ceiling 2,000

Technical write-ups published here. Scores once two reviewers approve the reasoning and reproduction steps.

Confirmed by - Peer review, two approvals at your tier or above

accepted
+80
strong
+180
exceptional
+320

Quizzes and labs

ceiling 600

Short quizzes and practical labs: read a snippet, inspect a log, find the bug, submit the answer.

Confirmed by - Automatic grading, with abuse checks

quiz
+10
easy
+25
medium
+60
hard
+110

Review

ceiling 400

Reviewing other people's write-ups and reports, once the review is accepted.

Confirmed by - The write-up author's other reviewers

Admin adjustment

ceiling 500

Manual corrections after internal review. Audited, visible and capped so discretion cannot carry a rank.

Confirmed by - Rooted internal review

Reports are the only uncapped scoring track. That is deliberate: a confirmed vulnerability is impact in the real world, not a shiny sticker you gave yourself. Admin adjustments are capped corrections, audited in the same ledger as everything else.

What points alone cannot buy

Quizzes and imported credentials help, but they cannot root the whole ladder alone. Higher ranks need confirmed work outside the app.

  • Rank 4 and above

    One verified credential or one confirmed report

  • Rank 7 and above

    One confirmed report or one credited CVE

  • Rank 9 and above

    A credited CVE at CVSS 9.0+, or three critical confirmed reports

Why it expires

A credential is current for 12 months from the last entry on your ledger. Any new entry re-issues it.

Your score never drops. What you did, you did, and the annex keeps saying so. But the document goes lapsed, and a lapsed credential leaves the default view of the board.

Offensive security from four years ago is not a claim about today. A company reading a rank needs to know somebody stood behind it recently, and you deserve a system that notices you are still working.