Syllabus and Policies
Draft Fall 2026 course expectations, adapted from the Fall 2025 Canvas syllabus.
Course description
Hack Lab combines lectures with hands-on labs to introduce common techniques used in cybercrime and cyber conflict. Each week begins with the technical foundations of an area and how adversaries have misused it. Students then work within a controlled course environment to investigate or reproduce those techniques safely.
By the end of the quarter, students should understand several common offensive techniques, recognize the systems and assumptions those techniques exploit, and be prepared to continue learning responsibly.
Prerequisites and equipment
No computer science background is required. Students must have a Windows, macOS, or Linux laptop capable of running the required course clients. Any remote systems, virtual machines, software, or accounts needed for labs will be provided or specified by the course.
Lecture and lab are combined in a required, in-person session on Fridays from 1:30–3:20 PM in the MIP Policy Studio (Encina Hall basement).
Learning goals
Students who complete the course should be able to:
- Explain the basic operation of network protocols, web applications, cryptography, and common enterprise systems.
- Use standard security tools within an explicitly authorized lab environment.
- Recognize common attack paths and connect technical failures to real-world cybercrime and cyber conflict.
- Document observations, validate results, and clean up an experimental environment.
- Distinguish authorized security research from unsafe, unethical, or illegal activity.
Grading
The draft grading model carries forward the Fall 2025 distribution:
- 10% weekly lecture/lab attendance
- 30% weekly lab assignments
- 25% take-home midterm exam
- 35% take-home final exam
Quizzes, exams, grades, and other course administration will remain in Canvas. The public website will contain the syllabus, schedule, lecture slides, and public resources. Lab instructions, assigned systems, and the lab workflow will be available only through the authenticated course console.
Lab work and late work
Students will receive individual invitations to the course console before the first lecture-and-lab meeting. The Fall 2025 course began each lab in class and normally required submission the following Thursday at noon Pacific Time. Late lab work was accepted for one additional week at 50% credit. This timing and the Fall 2026 console submission workflow will be confirmed before the course begins.
The goal is for every student to complete every lab. Students should use office hours, the course discussion board, and appropriate collaboration when they encounter difficulty. Extensions for illness, disability accommodations, or serious extenuating circumstances must be arranged with the instructional team. Infrastructure availability can limit how long a lab remains open.
Collaboration and submitted work
Students may discuss concepts and troubleshoot course infrastructure together unless an assignment states otherwise. Submitted answers and exam work must be the student’s own. Do not share answer keys, screenshots that reveal answers, credentials, or access to assigned systems.
Use of AI systems
Unless an assignment explicitly authorizes it, students may not use large language model or code-generation systems to write or supplement answers submitted for labs, quizzes, or exams. Permitted uses, if any, will be stated on the individual assignment.
Regrade requests
Requests to review an assignment or exam score must be made within one week of receiving the grade and should identify a specific scoring or submission issue. Requests made after that period may not be considered absent extenuating circumstances.
Responsible use
The tools and techniques used in this course can damage systems, expose private information, or violate law and policy when used outside an authorized environment.
- Test only systems and accounts explicitly assigned for a course exercise.
- Stay within the scope and time window written on the lab page or in Canvas.
- Never target Stanford production systems, public services, classmates, or third parties.
- Do not retain, publish, or share credentials, captured traffic, private data, malware, or vulnerable-system details.
- Stop immediately and notify the instructional team if a lab appears to reach an unintended system or expose real personal data.
- Complete the cleanup steps for every lab.
Violations of these boundaries may be referred under Stanford’s academic, acceptable-use, or conduct processes and may also carry civil or criminal consequences.
Accessibility
Students who may need an academic accommodation should contact Stanford’s Office of Accessible Education as early as possible. The instructional team will work with OAE accommodation letters and will provide course materials in accessible formats where practical.
Changes to this syllabus
The schedule and policies may be updated as infrastructure, guest availability, or course needs change. Material changes will be announced through the course communication channel and reflected on this site.