ETHICAL SECURITY RESEARCH · CONTRIBUTION RANKING

Recognize safe contribution, from kyu to dan

Mithril Dojo is a learning and practice program for white-hat researchers working with AI agents. Learn to define authorization, constrain agent capabilities, supervise decisions, and produce verifiable evidence and remediation plans.

AI Agent White-Hat Learning Path

Learn from fundamentals to a team capstone using synthetic data and a paper-based tabletop. No testing of real third-party systems is included.

  1. 0 · Authorization and scope
    Confirm target, methods, time window, exclusions, and stop conditions
  2. 1 · How AI agents work
    Understand models, tools, memory, delegation, and human accountability
  3. 2 · Safe agent setup
    Least privilege, read-only defaults, network limits, and approval gates
  4. 3 · Threat modelling
    Recognize untrusted input, excessive authority, and data exposure
  5. 4 · Evidence to conclusions
    Separate observations, hypotheses, reproduction, impact, and uncertainty
  6. 5 · Safe, reproducible Proof
    Prepare sufficient evidence without risky execution
  7. 6 · Remediation and retest
    Define mitigation, owner, acceptance condition, and retest
  8. 7 · Responsible disclosure
    Protect sensitive data and use the authorized channel
  9. 8 · Team capstone
    Create scope, agent policy, evidence ledger, and report from a synthetic case

Assessment covers authorization and scope, safe agent control, evidence quality, and remediation/collaboration. A safety-gate failure cannot be offset by points elsewhere.

Video lessons

Start with the English cyber-defense walkthrough below. The three foundation videos have Japanese synthetic narration and selectable English captions.

Cyber Defense with Mithril App and Desktop

An English illustrated exercise for whitehats and engineers: scope, synthetic log review, local work, remediation, and retest. English synthetic narration and captions; no live incident or automatic-defense demonstration.

Follow the English step-by-step exercise · Read the video transcript

1 · Authorization is the first security control (49 sec)

Do not start until target, time window, exclusions, and stop contact are explicit.

2 · Constrain the agent before it helps (50 sec)

Use least privilege, synthetic data, short-lived access, input isolation, and human approval.

3 · Build verifiable Proof (51 sec)

Separate observation from inference and connect safe, reproducible evidence to remediation.

Read the English scripts and storyboard

Enterprise White-Hat Training

A shared, practical method for security, engineering, and AI governance teams to supervise AI agents safely. Pricing is scoped to cohort size, language, and delivery requirements.

Foundation · 2 hours

Briefing, scope clinic, three short videos, and team checklist.

Practitioner · 1 day

Facilitated synthetic tabletop, agent policy, evidence review, and capstone.

Cohort · 4 weeks

Weekly workshops, guided practice, office hours, and portfolio review.

Enterprise · scoped

Tailored audience, language, accessibility, and approved scenarios.

Includes facilitator guide, learner workbook, paper-based synthetic lab pack, assessment rubric, and completion record. Completion is not professional certification or compliance attestation. English page and written materials are available. The cyber-defense walkthrough has English narration and captions; the three foundation videos have Japanese narration with selectable English captions.

CISSP® / CISA® domain mapping and original mini-checks are learning orientation only, not exam preparation, official items, or credentials. Dojo does not award or guarantee CPE hours. No individual instructor credential is currently listed as verified.

Synthetic targets only. No production testing, exploit deployment, persistence, stealth, credential theft, or destructive activity. No live vulnerable service is included in the current lab pack.

Curriculum · Learner workbook · Facilitator guide · Synthetic lab pack · Disclosure worksheet · CISSP/CISA guide · Original knowledge check · Attendance record · Offer

Discuss adoption with Mithril

Ethical hacker ranking

Ranking data is not connected. No individual positions or scores are shown until verified contribution data is available.

Axes: overall · verified reports · remediation contribution · Proof quality. Only public work explicitly approved by its author may appear.

Contribution points (1,000)

Verified reports
Novel findings with validated reproducibility
400 pts
Remediation
Contribution to fixes and mitigation
250 pts
Proof quality
Reproducibility, completeness, and safety
200 pts
Ethics and collaboration
Scope, responsible disclosure, and teamwork
100 pts
Sustained contribution
Consistent work over up to 12 months
50 pts

Token spend or usage is optional profile information. It never earns points or affects promotion.

Promotion rules

Points are guidance. Each promotion also requires review of report validity, scope compliance, safe Proof, and conduct. Duplicate and invalid reports earn no points.

Verified identity is required to apply for shodan and above. Identity verification is private and adds no points.

Kyu and dan guide

Cumulative points and titles. Dan ranks require review.
Rank Points Title
White belt 0–99 Learner
10th kyu 100 Explorer
9th kyu 150 Explorer
8th kyu 200 Explorer
7th kyu 250 Investigator
6th kyu 300 Investigator
5th kyu 350 Investigator
4th kyu 400 Researcher
3rd kyu 450 Researcher
2nd kyu 500 Researcher
1st kyu 550 Researcher
Shodan 600 Verified researcher
Nidan 640 Experienced researcher
Sandan 680 Experienced researcher
Yondan 720 Senior researcher
Godan 760 Senior researcher
Rokudan 800 Senior researcher
Nanadan 840 Mentor
Hachidan 880 Mentor
Kudan 920 Mentor
Judan 960 Honorary mentor · individual review

Shodan (black belt) requires practical foundations in both technical and business competencies. Nidan and above require advanced practice integrating both axes.

Competency map: from amateur learner to field-leading practitioner · Compensation and experience by rank · Promotion exam design

Privacy and responsible research

Aliases are allowed. Identity documents and verification details are never public. Profile and award information appears only when the researcher chooses to publish it.

Confirm authorization before research and follow responsible disclosure procedures. This ranking does not authorize or encourage exploitation or testing outside scope.