Credentials
ceiling 4,000External proof: certifications, platform ranks, GitHub work and credited CVEs read from the source.
Confirmed by - The issuing platform, via an ownership handshake
Hackers climb by leaving proof: confirmed reports, reviewed write-ups, labs, peer review and external sources. No mystery multipliers. If it scores, it has a receipt.
The ranks speak hacker without losing the room. Early levels reward curiosity and reps; the top end demands confirmed impact, clean writing, trusted review and original research.
The fastest clean climb is a mixed attack path: real reports, clear write-ups, labs, review and imported credentials.
A confirmed report is worth more than any certification on this platform, and it is the only track with no ceiling. That is deliberate: an exam says you studied, a confirmed finding says somebody else's security team agreed you were right.
External proof: certifications, platform ranks, GitHub work and credited CVEs read from the source.
Confirmed by - The issuing platform, via an ownership handshake
Vulnerability reports submitted through Rooted programs and confirmed by the organisation.
Confirmed by - The organisation that received the report
Technical write-ups published here. Scores once two reviewers approve the reasoning and reproduction steps.
Confirmed by - Peer review, two approvals at your tier or above
Short quizzes and practical labs: read a snippet, inspect a log, find the bug, submit the answer.
Confirmed by - Automatic grading, with abuse checks
Reviewing other people's write-ups and reports, once the review is accepted.
Confirmed by - The write-up author's other reviewers
Manual corrections after internal review. Audited, visible and capped so discretion cannot carry a rank.
Confirmed by - Rooted internal review
Reports are the only uncapped scoring track. That is deliberate: a confirmed vulnerability is impact in the real world, not a shiny sticker you gave yourself. Admin adjustments are capped corrections, audited in the same ledger as everything else.
Quizzes and imported credentials help, but they cannot root the whole ladder alone. Higher ranks need confirmed work outside the app.
One verified credential or one confirmed report
One confirmed report or one credited CVE
A credited CVE at CVSS 9.0+, or three critical confirmed reports
A credential is current for 12 months from the last entry on your ledger. Any new entry re-issues it.
Your score never drops. What you did, you did, and the annex keeps saying so. But the document goes lapsed, and a lapsed credential leaves the default view of the board.
Offensive security from four years ago is not a claim about today. A company reading a rank needs to know somebody stood behind it recently, and you deserve a system that notices you are still working.