Cybersecurity, learned like a practitioner.

24 learning paths · 398 modules live · every lesson written by someone who has shipped the control or run the engagement. Free to start.

24
Learning paths
398+
Live modules
0
You've completed
Free
Your tier
Browse the academy

Latest modules

Most recent practitioner playbooks across every track. Filter by topic, level, or search in the sidebar.

541 results · Page 16/55
Attacker Mindset — Cloud Intermediate Free

Region Isolation Is a Trust Decision

AWS regions are physically separate data centres. But your IAM is global. A user with ec2:* permission has it in every region. Attackers spin up instances in regions you don’t monitor. Crypto mining in ap-east-1 while you watch us-east-1. The mindset: enabled regions = monitored regions. Org policy: SCP that denies actions in unused regions.

Apr 27, 2026 15 min Open
Attacker Mindset — Network Intermediate Free

Encrypted But Visible

“It’s TLS; we can’t see anything.” False. TLS reveals SNI (the host being visited). JA3 fingerprints the client. Packet sizes and timing leak content type. Connection counts reveal user behaviour. Encrypted DNS (DoH/DoT) hides query content but reveals user uses encrypted DNS. That itself is a signal. The mindset: encryption hides content, not behaviour. Detection […]

Apr 27, 2026 15 min Open
Attacker Mindset — Cloud Intermediate Free

Console vs API Visibility Gap

AWS console shows curated views. Some resources only visible via API. Some metadata not in console. Attackers operate via API. They see what console hides. Defender visibility gap. The mindset: audit via Config Rules / Cloud Asset Inventory, not console clicks. The console is for humans; the API is for completeness.

Apr 27, 2026 15 min Open
Attacker Mindset — Network Intermediate Free

Reading Topology Like an Attacker

Defenders read topology as “what we built.” Attackers read it as “what paths exist.” Every line is a path. Every box is a target. The questions an attacker asks: shortest path from any DMZ host to any DC? what asset has the largest blast radius? where do trust boundaries live and where are they soft? […]

Apr 27, 2026 15 min Open
Attacker Mindset — Cloud Intermediate Free

Account Boundaries Are Negotiable

“Account boundaries protect us.” They do — until you create cross-account roles. Or federate identity. Or assume a role for a SaaS vendor. Each is a hole in the boundary. Each requires explicit authorisation. Most enterprises grant; few audit. The mindset: account boundary = sum of cross-account access. Inventory + audit quarterly.

Apr 27, 2026 15 min Open
Attacker Mindset — Network Intermediate Free

The Network Forensics Mindset

Network logs are evidentiary in regulator inquiries and lawsuits. They have weight when properly preserved. The discipline: timestamps in UTC, defined retention, chain of custody, immutable archive. Without these, “we have logs” doesn’t answer “can the regulator rely on them?” The mindset: every log is a future court exhibit. Build retention and integrity for that […]

Apr 27, 2026 15 min Open
Attacker Mindset — Cloud Intermediate Free

IAM Policies Are Contracts

An IAM policy is a contract. Effect: Allow on Action: * is a blank-cheque clause. Resource: * with NotAction negation is a “everything except” clause. Attackers read policies as contracts. Find the over-broad clauses. Exploit. The mindset: review IAM policies like legal contracts. What’s allowed? What’s explicitly denied? What’s implicitly allowed?

Apr 27, 2026 15 min Open
Attacker Mindset — Active Directory Intermediate Free

The Implicit Trust of AD

Active Directory assumes a cooperative environment. Members trust each other. Domain controllers trust members. Trusts between domains assumed friendly. Every “feature” — Kerberos delegation, ACL inheritance, group nesting — is a cooperation primitive. Each is exploitable when the cooperation assumption fails. The mindset: AD’s features are its attack surface. Each was designed for ease, not […]

Apr 27, 2026 15 min Open
Attacker Mindset — Cloud Intermediate Free

Cloud Logs Have Detection Gaps

CloudTrail records management plane by default. Data plane (S3 reads) requires explicit data events. Most teams skip it for cost. Result: attacker reads sensitive S3 buckets; no log entry. Defender has no evidence post-breach. The mindset: enabling all logs is expensive. Enabling none is more expensive. Tier by sensitivity.

Apr 27, 2026 15 min Open
Attacker Mindset — Active Directory Intermediate Free

Service Accounts Outlive Their Purpose

Service accounts get created. They stay forever. The original requester left in 2019. The service was decommissioned in 2021. The account remains, with the same permissions, the same password. Audit reveals: 30-50% of high-priv service accounts have no current owner. 20%+ haven’t had password change in 5+ years. The mindset: service accounts need lifecycle. Ownership, […]

Apr 27, 2026 15 min Open
02 / Why learn here

Practitioners who've
shipped the controls.

Every module is written by someone who has built the defence or run the engagement. No repackaged tutorials, no generic theory.

Why learn here

01

Practitioner-written.

Each lesson is authored by someone who has shipped the control or run the engagement in production.

02

Quiz after every module.

20+ questions with explanations. 70%+ to mark complete. Unlimited retries.

03

Progress tracked.

Completions, scores and streaks saved automatically. Resume exactly where you left off.

04

India-priced.

Start free. ₹499/mo for intermediate. ₹4,999/yr for advanced. No hidden fees, ever.