Cybersecurity, learned like a practitioner.
24 learning paths · 398 modules live · every lesson written by someone who has shipped the control or run the engagement. Free to start.
Advanced · modules
Modules tagged Advanced. Use the sidebar to narrow by track or topic.
Security Maturity Models — NIST CSF, ISO 27001, SAMM, CIS in Practice
Why this module exists. Every Indian enterprise we audit has a “maturity assessment” somewhere on file. Few have one that has been refreshed in the last 18 months; fewer still use it to drive funding decisions. The pattern is the same: a one-time scoring exercise that produced a slide, the slide got presented to the […]
Risk Appetite Statement — Writing One That Drives Decisions
Why this module exists. Risk appetite is where governance meets engineering reality. Without a stated appetite, every risk decision becomes ad hoc — defended by whoever speaks loudest in the room. With a clear appetite stated in measurable terms, the same decision becomes mechanical: “this exceeds the stated threshold, escalation triggered.” This module walks the […]
Board Reporting for Security — Metrics, Narrative, Cadence
Why this module exists. The board is not your peer audience. They are not security practitioners. The report that wins your peers’ approval — a 40-slide dive into MITRE ATT&CK coverage — is the report that loses the board. This module is the operational pattern for the inverse: the report that lets a non-technical decision-maker […]
AD Trust Relationships Deep Dive — Forest, External, Shortcut
Why this module exists. AD has six distinct trust types. Each has different transitivity, SID Filtering defaults, Kerberos behaviour, and attacker-reachable abuse pattern. The median Indian-bank AD environment we audit has at least one trust whose properties the owning team cannot explain. This module is the missing reference. The six trust types — at a […]
AdminSDHolder & SDProp Persistence
Why this module exists. AdminSDHolder is one of the cleanest persistence primitives in AD because it abuses a feature, not a bug. Microsoft built SDProp to protect privileged accounts from accidental ACL drift. Attackers turned that protection into a self-healing backdoor. If you have ever seen an environment where the IR team cleaned up the […]
Quantum-Safe Blockchain — Bitcoin BIP-360, Ethereum PQ Roadmap, and the Custodial Migration Plan
Bitcoin and Ethereum both fall to Shor when CRQC arrives. BIP-360, Ethereum account abstraction for PQ signing, custodial implications, the lost-key coin recovery question. Module 15.
Post-Quantum PKI — Migrating Internal CAs, Certificate Hierarchies, and Trust Stores
Migrating PKI to PQ is the most operationally complex part. Algorithm choices per layer (root SLH-DSA, intermediate ML-DSA, leaf ML-DSA), parallel hierarchy strategy, EJBCA/Vault/step-ca tools, trust-store distribution. Module 14.
Crypto-Agility Engineering — Designing Systems for Algorithm Replacement Beyond Post-Quantum
Crypto-agility makes algorithm changes routine. Pluggable algorithm registries, multi-algorithm certificates, hybrid signatures, automated key rotation. The patterns and anti-patterns. Module 13.
Side-Channel Attacks on Post-Quantum Implementations — Kyber Timing Leaks and Constant-Time Defences
PQ algorithms are quantum-resistant but vulnerable to classical side-channel attacks if implemented carelessly. Documented Kyber/Dilithium timing leaks, constant-time defences, and how to verify your PQ libraries. Module 12.
Migrating to Post-Quantum Cryptography in Production — TLS, SSH, JWT, S/MIME (24-Month Playbook)
Operational playbook for enterprise PQ migration: cryptographic inventory, hybrid pilot, vendor coordination, JWT/SSH/PKI rollout phases. The 24-month engineering plan. Module 11.
Practitioners who've
shipped the controls.
Every module is written by someone who has built the defence or run the engagement. No repackaged tutorials, no generic theory.
Why learn here
Practitioner-written.
Each lesson is authored by someone who has shipped the control or run the engagement in production.
Quiz after every module.
20+ questions with explanations. 70%+ to mark complete. Unlimited retries.
Progress tracked.
Completions, scores and streaks saved automatically. Resume exactly where you left off.
India-priced.
Start free. ₹499/mo for intermediate. ₹4,999/yr for advanced. No hidden fees, ever.