Formazione cybersecurity — no fuffa Cybersecurity education — no nonsense Edukacja cyberbezpieczeństwa — bez lania wody

La sicurezza
inizia dai
cittadini.
Security starts
with citizens,
not IT.
Bezpieczeństwo
zaczyna się od
obywateli.

Niente slide inutili. Niente teoria vuota. Workshop pratici dove esci con qualcosa di fatto, non con un certificato. E corsi completi per chi vuole andare in profondità — da Secure Development a Rust a AI Security.

No useless slides. No empty theory. Hands-on workshops where you leave with something done, not just a certificate. And full courses for those who want to go deep — from Secure Development to Rust to AI Security.

Żadnych bezużytecznych slajdów. Żadnej pustej teorii. Praktyczne warsztaty, po których wychodzisz z czymś gotowym. I pełne kursy dla tych, którzy chcą pogłębić wiedzę — od Secure Development do Rust i AI Security.

600+ professionisti per webinar professionals per webinar profesjonalistów na webinar
25+ anni di esperienza years of experience lat doświadczenia
8+ corsi attivi active courses aktywnych kursów
0% teoria inutile useless theory bezużytecznej teorii
Ransomware defence Threat modelling OSINT difensivo NIS2 compliance Secure Development Rust Security AI Red Teaming Prompt Injection Hacker mindset LLM Engineering Digital forensics Memory Safety Social engineering Candle + Ollama CI/CD Security Ransomware defence Threat modelling OSINT difensivo NIS2 compliance Secure Development Rust Security AI Red Teaming Prompt Injection Hacker mindset LLM Engineering Digital forensics Memory Safety Social engineering Candle + Ollama CI/CD Security
Il mercato vende paura.
Noi insegniamo come ragionare.
The market sells fear.
We teach you how to think.
Rynek sprzedaje strach.
My uczymy jak myśleć.

I corsi esistenti insegnano o troppo poco — slide su "non cliccare i link" — o troppo per chi non è un tecnico. Avvocati, medici, commercialisti, manager: nessuno ha strumenti calibrati sulla loro realtà.

E i developer? Scrivono codice insicuro non perché siano incompetenti, ma perché nessuno ha mai insegnato loro come pensa un attaccante.

Centuria School nasce da 25 anni di ricerca sul campo e una convinzione semplice: la sicurezza si insegna con casi reali, strumenti reali, scenari reali.

Existing courses teach either too little — slides about "don't click links" — or too much for non-technical professionals. Lawyers, doctors, accountants, managers: none have tools calibrated to their daily reality.

And developers? They write insecure code not because they're incompetent, but because no one ever taught them how an attacker thinks.

Centuria School is built from 25 years of field research and one conviction: security is taught with real cases, real tools, real scenarios.

Istniejące kursy uczą albo za mało — slajdy "nie klikaj w linki" — albo za dużo dla osób spoza IT.

A developerzy? Piszą niebezpieczny kod nie dlatego, że są niekompetentni, ale dlatego, że nikt nie nauczył ich myśleć jak atakujący.

Centuria School powstała z 25 lat badań i jednego przekonania: bezpieczeństwa uczy się na prawdziwych przypadkach, narzędziach i scenariuszach.

Workshop pratici — 3h online, hands-on Hands-on workshops — 3h online Warsztaty praktyczne — 3h online

Tre ore.
Risultati concreti.
Three hours.
Concrete results.
Trzy godziny.
Konkretne wyniki.

Nessuna slide che non serve. Solo azioni che puoi eseguire subito — per il tuo studio, per la tua azienda, per la tua vita digitale.

No unnecessary slides. Only actions you can take immediately — for your firm, your company, your digital life.

Żadnych niepotrzebnych slajdów. Tylko działania, które możesz podjąć natychmiast — dla swojej firmy, dla swojego życia cyfrowego.

Maggio · May · Maj
ITENPL
WS-02
Pensa come il tuo attaccante
Think like your attacker
Myśl jak Twój atakujący
Threat modelling applicato alla vita reale. Chi vuole attaccarti, cosa vuole, come ci arriva. Costruisci il tuo profilo di rischio personale e professionale.
Threat modelling applied to real life. Who wants to attack you, what they want, how they get there. Build your personal and professional risk profile.
Modelowanie zagrożeń w praktyce. Kto chce Cię zaatakować, czego chce, jak do Ciebie dotrze. Zbuduj swój profil ryzyka osobistego i zawodowego.
Maggio · May · Maj
ITENPL
WS-03
Cosa sa di te internet
What the internet knows about you
Co internet wie o Tobie
OSINT difensivo. Cerca il tuo nome, la tua azienda come farebbe un attaccante. Poi chiudi ogni porta aperta. Strumenti gratuiti, risultati immediati.
Defensive OSINT. Search your name and company as an attacker would. Then close every open door. Free tools, immediate results.
Defensywny OSINT. Wyszukaj swoje imię i firmę tak jak zrobiłby to atakujący. Potem zamknij każde otwarte drzwi. Darmowe narzędzia, natychmiastowe efekty.
Corsi estesi — per professionisti e cittadini Full courses — for professionals and citizens Kursy rozszerzone — dla profesjonalistów i obywateli

Vai in profondità.
Quando sei pronto.
Go deeper.
When you're ready.
Idź głębiej.
Kiedy jesteś gotowy.

I workshop danno le basi operative. I corsi estesi danno il metodo completo — quello che usiamo con professionisti e aziende.

Workshops give you the operational foundations. Full courses give you the complete methodology — the one we use with professionals and organizations.

Warsztaty dają podstawy operacyjne. Kursy rozszerzone dają pełną metodologię — tę, której używamy z profesjonalistami i organizacjami.

Corso flagship · IT / EN / PL
Flagship course · IT / EN / PL
Kurs flagowy · IT / EN / PL
Mentalità Hacker
Hacker Mindset
Mentalność Hakera
Ragionare come un attaccante per difendersi come un professionista
Think like an attacker to defend like a professional
Myśl jak atakujący, broń się jak profesjonalista
  • Come ragiona davvero un attaccante
  • Ricognizione: cosa cercano prima di attaccare
  • Ingegneria sociale avanzata — oltre il phishing
  • I tuoi asset digitali: cosa ha valore per gli altri
  • Costruire una difesa su misura
  • Casi reali — incidenti analizzati in diretta
  • How an attacker actually thinks
  • Reconnaissance: what they look for before attacking
  • Advanced social engineering — beyond phishing
  • Your digital assets: what has value to others
  • Building a tailored defence
  • Real cases — incidents analysed live
  • Jak naprawdę myśli atakujący
  • Rekonesans: czego szukają przed atakiem
  • Zaawansowana inżynieria społeczna — poza phishingiem
  • Twoje cyfrowe zasoby: co ma wartość dla innych
  • Budowanie obrony na miarę
  • Prawdziwe przypadki — incydenty analizowane na żywo
Per professionisti · IT / EN / PL
For professionals · IT / EN / PL
Dla profesjonalistów · IT / EN / PL
Sicurezza pratica per professionisti
Practical security for professionals
Praktyczne bezpieczeństwo dla profesjonalistów
Avvocati, medici, commercialisti, manager — il corso che mancava
Lawyers, doctors, accountants, managers — the course that was missing
Prawnicy, lekarze, księgowi, menedżerowie — kurs, którego brakowało
  • Il tuo studio come bersaglio — perché sei interessante
  • GDPR e NIS2 nella pratica quotidiana
  • Proteggere i dati dei clienti senza diventare tecnico
  • Gestire un incidente — cosa fare nelle prime 2 ore
  • Email, cloud, mobile: i vettori reali
  • Responsabilità legale e obblighi di notifica
  • Your firm as a target — why you're interesting
  • GDPR and NIS2 in daily practice
  • Protecting client data without becoming a technician
  • Managing an incident — what to do in the first 2 hours
  • Email, cloud, mobile: the real attack vectors
  • Legal liability and notification obligations
  • Twoja firma jako cel — dlaczego jesteś interesujący
  • RODO i NIS2 w codziennej praktyce
  • Ochrona danych klientów bez zostawania technikiem
  • Zarządzanie incydentem — co robić w pierwszych 2 godzinach
  • Email, chmura, mobile: prawdziwe wektory ataku
  • Odpowiedzialność prawna i obowiązki zgłoszeniowe
Prossimamente · Giugno 2025
Coming soon · June 2025
Wkrótce · Czerwiec 2025
Proteggi il tuo server
Secure your server
Zabezpiecz swój serwer
VPS, NAS, WordPress — senza essere un sysadmin
VPS, NAS, WordPress — without being a sysadmin
VPS, NAS, WordPress — bez bycia sysadminem
  • Hardening base: SSH, firewall, fail2ban
  • Aggiornamenti automatici e monitoraggio
  • Backup e ripristino rapido
  • WordPress: i 10 errori che ti fanno bucare
  • Rilevare una compromissione attiva
  • Base hardening: SSH, firewall, fail2ban
  • Automatic updates and monitoring
  • Backup and rapid recovery
  • WordPress: the 10 mistakes that get you hacked
  • Detecting an active compromise
  • Podstawowy hardening: SSH, firewall, fail2ban
  • Automatyczne aktualizacje i monitoring
  • Backup i szybkie przywracanie
  • WordPress: 10 błędów prowadzących do włamania
  • Wykrywanie aktywnego kompromitowania
// nuova area — developer & AI security // new area — developer & AI security // nowy obszar — developer & AI security
Corsi completi — Developer & AI Security Full courses — Developer & AI Security Kursy pełne — Developer & AI Security

Il codice che scrivi
è già un bersaglio.
The code you write
is already a target.
Kod który piszesz
jest już celem.

Per developer che vogliono capire la sicurezza e per security professional che vogliono capire il codice. Percorsi multi-sessione con esercizi reali, non CTF teorici.

For developers who want to understand security and security professionals who want to understand code. Multi-session tracks with real exercises, not theoretical CTFs.

Dla developerów, którzy chcą rozumieć bezpieczeństwo, i specjalistów bezpieczeństwa, którzy chcą rozumieć kod. Wielosesyjne ścieżki z prawdziwymi ćwiczeniami.

Secure Dev · Sviluppo SicuroSecure DevelopmentBezpieczne Programowanie new
Sviluppo Sicuro
Secure Development
Bezpieczne Programowanie
Threat modeling · code review · SAST/DAST · CI/CD security
Threat modeling · code review · SAST/DAST · CI/CD security
Threat modeling · code review · SAST/DAST · CI/CD security
  • Threat modeling applicato — STRIDE, Attack Trees su codice reale
  • Secure code review — injection, auth flaws, business logic bugs
  • SAST/DAST nel pipeline CI/CD — Semgrep, Trivy, secrets scanning
  • Dependency security e supply chain attacks
  • Casi reali: come le vulnerabilità entrano in produzione
  • Lab finale: audit completo su una codebase reale
  • Applied threat modeling — STRIDE, Attack Trees on real code
  • Secure code review — injection, auth flaws, business logic bugs
  • SAST/DAST in CI/CD — Semgrep, Trivy, secrets scanning
  • Dependency security and supply chain attacks
  • Real cases: how vulnerabilities reach production
  • Final lab: full audit on a real codebase
  • Threat modeling — STRIDE, Attack Trees na prawdziwym kodzie
  • Bezpieczny code review — injection, auth flaws, błędy logiki
  • SAST/DAST w CI/CD — Semgrep, Trivy, secrets scanning
  • Bezpieczeństwo zależności i supply chain attacks
  • Prawdziwe przypadki: jak podatności trafiają na produkcję
  • Lab końcowy: pełny audit prawdziwej codebazy
Rust · Da ZeroFrom ZeroOd Zera new
Rust da Zero
Rust from Zero
Rust od Zera
Ownership · Borrowing · Async · Security-first mindset · Nessuna conoscenza Rust richiesta
Ownership · Borrowing · Async · Security-first mindset · No Rust knowledge required
Ownership · Borrowing · Async · Security-first mindset · Bez znajomości Rust
  • Ownership, borrowing, lifetime — il modello che elimina i bug di memoria
  • Structs, enums, pattern matching, error handling idiomatico
  • Traits e generics — astrarre senza sacrificare le performance
  • Async/await e tokio — concorrenza sicura da zero
  • Scrittura di tool CLI e networking di base
  • Progetto finale: tool di security scritto in Rust
  • Ownership, borrowing, lifetime — the model that eliminates memory bugs
  • Structs, enums, pattern matching, idiomatic error handling
  • Traits and generics — abstracting without sacrificing performance
  • Async/await and tokio — safe concurrency from scratch
  • CLI tools and basic networking
  • Final project: a security tool written in Rust
  • Ownership, borrowing, lifetime — model eliminujący błędy pamięci
  • Structs, enums, pattern matching, idiomatyczna obsługa błędów
  • Traits i generics — abstrakcja bez utraty wydajności
  • Async/await i tokio — bezpieczna współbieżność od zera
  • Narzędzia CLI i podstawy networkingu
  • Projekt końcowy: narzędzie security w Rust
Rust Security · Sistemi CriticiCritical SystemsSystemy Krytyczne new
Rust per la Sicurezza
Rust for Security
Rust dla Bezpieczeństwa
Memory safety avanzata · Unsafe code · Cryptography · Fuzzing · Prerequisito: Rust base
Advanced memory safety · Unsafe code · Cryptography · Fuzzing · Prerequisite: basic Rust
Zaawansowana memory safety · Unsafe code · Kryptografia · Fuzzing · Wymagania: podstawy Rust
  • Unsafe Rust — quando, come, e ogni insidia documentata
  • Come Rust è usato in Linux kernel, Windows e Android
  • Cryptography in Rust — RustCrypto, ring, implementazioni corrette
  • Fuzzing e property-based testing con cargo-fuzz
  • Analisi di vulnerabilità reali in codice Rust unsafe
  • Unsafe Rust — when, how, and every documented pitfall
  • How Rust is used in Linux kernel, Windows and Android
  • Cryptography in Rust — RustCrypto, ring, correct implementations
  • Fuzzing and property-based testing with cargo-fuzz
  • Real vulnerability analysis in unsafe Rust code
  • Unsafe Rust — kiedy, jak i każda udokumentowana pułapka
  • Jak Rust jest używany w jądrze Linux, Windows i Android
  • Kryptografia w Rust — RustCrypto, ring, poprawne implementacje
  • Fuzzing i testy property-based z cargo-fuzz
  • Analiza prawdziwych podatności w unsafe Rust
AI Security · Red TeamingRed TeamingRed Teaming new
Sicurezza dei Sistemi AI
AI Systems Security
Bezpieczeństwo Systemów AI
LLM attacks · Prompt injection · RAG poisoning · AI threat modeling
LLM attacks · Prompt injection · RAG poisoning · AI threat modeling
Ataki LLM · Prompt injection · RAG poisoning · AI threat modeling
  • Prompt injection diretta e indiretta — bypass reali documentati
  • Jailbreak sistematici — meccanismi, perché funzionano, come prevenirli
  • RAG poisoning e data exfiltration via LLM
  • AI threat modeling — STRIDE applicato a sistemi generativi
  • Red teaming su deployment LLM reali
  • Difese: guardrail, input sanitization, monitoring
  • Direct and indirect prompt injection — documented real bypasses
  • Systematic jailbreaks — mechanisms, why they work, how to prevent them
  • RAG poisoning and data exfiltration via LLM
  • AI threat modeling — STRIDE applied to generative systems
  • Red teaming real LLM deployments
  • Defences: guardrails, input sanitisation, monitoring
  • Prompt injection bezpośredni i pośredni — udokumentowane bypassy
  • Systematyczne jailbreaki — mechanizmy i zapobieganie
  • RAG poisoning i eksfiltracja danych przez LLM
  • AI threat modeling — STRIDE dla systemów generatywnych
  • Red teaming prawdziwych wdrożeń LLM
  • Obrony: guardrails, sanityzacja wejścia, monitoring
AI-Assisted · Security OperationsSecurity OperationsSecurity Operations new
AI per la Difesa
AI-Assisted Security
AI w Operacjach Security
Detection · OSINT · Automazione SOC · Ollama locale · Privacy-first
Detection · OSINT · SOC automation · Local Ollama · Privacy-first
Detection · OSINT · Automatyzacja SOC · Lokalny Ollama · Privacy-first
  • LLM per analisi di log e triage alert — workflow pratici reali
  • AI-powered OSINT e threat intelligence enrichment
  • Automazione SOC con agenti AI locali (Ollama) — zero cloud
  • Generazione di regole SIEM e detection rules via LLM
  • Limiti dell'AI in security — quando non fidarsi del modello
  • LLM for log analysis and alert triage — real practical workflows
  • AI-powered OSINT and threat intelligence enrichment
  • SOC automation with local AI agents (Ollama) — zero cloud
  • SIEM rule and detection rule generation via LLM
  • Limits of AI in security — when not to trust the model
  • LLM do analizy logów i triażu alertów — praktyczne workflow
  • AI-powered OSINT i wzbogacanie threat intelligence
  • Automatyzacja SOC z lokalnymi agentami AI (Ollama) — zero cloud
  • Generowanie reguł SIEM i detection rules przez LLM
  • Ograniczenia AI w security — kiedy nie ufać modelowi
AI Engineering · Costruisci il Tuo ModelloBuild Your Own ModelZbuduj Własny Model new
Costruisci il Tuo Modello AI
Build Your Own AI Model
Zbuduj Własny Model AI
Candle (Rust) · Ollama · Fine-tuning LoRA · RAG · Agenti · Deployment locale privacy-first — Prerequisito: Python o Rust base
Candle (Rust) · Ollama · LoRA fine-tuning · RAG · Agents · Local privacy-first deployment — Prerequisite: basic Python or Rust
Candle (Rust) · Ollama · Fine-tuning LoRA · RAG · Agenty · Lokalne wdrożenie privacy-first — Wymagania: podstawy Python lub Rust
  • Architetture transformer — attention, tokenization, inference da zero
  • Candle (Rust) — inferenza locale, quantizzazione Q4/Q8, ottimizzazione
  • Ollama — deployment, model management, API integration locale
  • Fine-tuning con LoRA/QLoRA su hardware consumer reale
  • RAG — architettura completa, vector DB, pipeline di retrieval
  • Agenti AI e tool use — sistemi autonomi che ragionano e agiscono
  • Sicurezza dei modelli locali — isolamento, accesso, audit log
  • Caso pratico: modello specializzato per security analysis
  • Transformer architectures — attention, tokenization, inference from scratch
  • Candle (Rust) — local inference, Q4/Q8 quantisation, optimisation
  • Ollama — deployment, model management, local API integration
  • Fine-tuning with LoRA/QLoRA on real consumer hardware
  • RAG — full architecture, vector DB, retrieval pipeline
  • AI agents and tool use — autonomous systems that reason and act
  • Security of local models — isolation, access, audit logging
  • Real case: specialised model for security analysis
  • Architektury transformer — attention, tokenization, inference od zera
  • Candle (Rust) — lokalne wnioskowanie, kwantyzacja Q4/Q8, optymalizacja
  • Ollama — deployment, zarządzanie modelami, lokalna integracja API
  • Fine-tuning z LoRA/QLoRA na prawdziwym sprzęcie konsumenckim
  • RAG — pełna architektura, vector DB, pipeline retrieval
  • Agenty AI i tool use — autonomiczne systemy rozumujące i działające
  • Bezpieczeństwo modeli lokalnych — izolacja, dostęp, audit log
  • Przypadek praktyczny: wyspecjalizowany model do analizy security
Chi insegna Your instructor Prowadzący
// identity record
Giovanni Battista Caria
[ Harpocrates ]
Role
Lead Security Architect
Centuria Labs ISO
Experience
25+ anni · years · lat
Location
Wrocław / Dubai
Reference
Fonti internazionali
Web
centurialabs.pl

Fondatore di Centuria Labs Independent Security Observatory, Giovanni Battista Caria opera da oltre 25 anni nell'intersezione tra sicurezza offensiva e difensiva, threat intelligence, cyberwarfare e analisi forense. Il suo approccio è quello dell'intelligence: analisi tecnica profonda combinata con una visione strategica e legale della difesa digitale.

Autore di numerosi libri — tra cui Cybersecurity e Cyberwarfare (EPC Editore) e The Invisible Front — il suo lavoro è citato da fonti autorevoli in Italia e a livello internazionale. Relatore a conferenze internazionali su temi quali AI, blockchain e sicurezza digitale. I suoi webinar raccoglievano regolarmente 600–1000 professionisti tra giudici, avvocati e tecnici.

Founder of Centuria Labs Independent Security Observatory, Giovanni Battista Caria has worked for over 25 years at the intersection of offensive and defensive security, threat intelligence, cyberwarfare, and digital forensics. His approach is rooted in intelligence methodology: deep technical analysis combined with strategic and legal perspective on digital defence.

Author of several books — including Cybersecurity e Cyberwarfare (EPC Editore) and The Invisible Front — his work is referenced by authoritative sources in Italy and internationally. Speaker at international conferences on AI, blockchain, and digital security. His webinars consistently attracted 600–1000 professionals — judges, lawyers, and technical specialists.

Założyciel Centuria Labs Independent Security Observatory, Giovanni Battista Caria działa od ponad 25 lat na styku bezpieczeństwa ofensywnego i defensywnego, threat intelligence, cyberwojny i kryminalistyki cyfrowej. Jego podejście wywodzi się z metodologii wywiadowczej: głęboka analiza techniczna połączona ze strategiczną i prawną perspektywą obrony cyfrowej.

Autor wielu książek — m.in. Cybersecurity e Cyberwarfare (EPC Editore) i The Invisible Front — jego praca jest cytowana przez uznane źródła w Polsce, Włoszech i na całym świecie. Prelegent na międzynarodowych konferencjach poświęconych AI, blockchain i bezpieczeństwu cyfrowemu. Jego webinary regularnie gromadziły 600–1000 profesjonalistów — sędziów, prawników i specjalistów technicznych.

  • Autore, EPC Editore — cybersecurity e intelligence
  • Published author, EPC Editore — cybersecurity and intelligence
  • Opublikowany autor, EPC Editore — cyberbezpieczeństwo i wywiad
  • Citato da fonti autorevoli — Italia e internazionale
  • GAMA Methodology — disinformation & malware research framework
  • Relatore a conferenze militari e istituzionali internazionali
  • Speaker at international military and institutional conferences
  • Prelegent na międzynarodowych konferencjach wojskowych i instytucjonalnych
  • Ricerca attiva: Android zero-day, Rust security tooling, FIMI analysis
  • Active research: Android zero-day, Rust security tooling, FIMI analysis
  • Aktywne badania: Android zero-day, Rust security tooling, analiza FIMI
  • infosec.exchange/@Harpocrates

Vuoi sapere quando apre il prossimo corso? Want to know when the next course opens? Chcesz wiedzieć, kiedy otwiera się kolejny kurs?

Lascia la tua email. Niente spam — solo la notifica quando una nuova sessione è disponibile.

Leave your email. No spam — just a notification when a new session opens.

Zostaw swój email. Żadnego spamu — tylko powiadomienie, gdy dostępna będzie nowa sesja.

oppure scrivi direttamente a or write directly to lub napisz bezpośrednio na  school@centurialabs.pl