Spaced repetition · offensive security
Learn the exploit once.
Remember the decision forever.
CyberReps drills web-security skill the way it actually sticks: acquire a technique on a hands-on exercise, then rehearse it on a spaced-repetition schedule until the move is reflex.
Why it exists
You solve a lab, feel the click of understanding — and three weeks later you can’t reconstruct the payload. Courses are built for acquisition; almost nothing is built for retention. Flashcard apps go the other way and drill trivia you never actually apply under pressure.
Real offensive skill isn’t a pile of facts. It’s a set of decisions — “I see this response, so I try that.” Decisions decay like anything else without rehearsal. CyberReps was built to close that gap: fuse the moment you learn a technique with a system that resurfaces it before you forget.
How it works
Fix it blind
Vulnerable code lands in your deck with the flaw unnamed. You diagnose the class yourself and patch it — no hints, no label.
A sandbox grades it
Your patch runs in a locked-down container against a hidden exploit and the feature's own tests. It passes only if the attack stops working and the feature still does.
Then you rate it
Solved it? Rate how hard it was — Again, Hard, Good, Easy — and FSRS schedules exactly when the exercise comes back, Anki-style.
The core idea
Decisions, not facts.
Each time a pattern resurfaces it wears a fresh disguise — a new snippet, a new request — so you rehearse the underlying decision instead of memorizing one example. That’s the difference between having seen SQL injection and knowing it cold.
Personal-first, built for practitioners. No fluff, no gamification — just the reps.