Cybersecurity, learned like a practitioner.

24 learning paths · 398 modules live · every lesson written by someone who has shipped the control or run the engagement. Free to start.

24
Learning paths
398+
Live modules
0
You've completed
Free
Your tier
Browse the academy

Latest modules

Most recent practitioner playbooks across every track. Filter by topic, level, or search in the sidebar.

541 results · Page 2/55
Red Team Operations Advanced Free

Beyond Cobalt Strike — Sliver, Mythic, Brute Ratel, Havoc

The C2 landscape Framework Licence Notes Cobalt Strike Commercial (Fortra) Industry standard; highly detected Sliver Open-source (Bishop Fox) Go-based; mTLS / DNS / WireGuard transport Mythic Open-source Modular agent framework; multiple agents Brute Ratel Commercial Newer; modern evasion features Empire / Starkiller Open-source PowerShell-centric; widely detected Havoc Open-source Modern; community-active Why teams move beyond Cobalt […]

May 14, 2026 35 min Open
Red Team Operations Expert Free

EDR Evasion in 2026

The EDR detection stack User-mode hooks: EDR hooks key API calls (CreateRemoteThread, NtMapViewOfSection, etc.) to inspect arguments. Kernel-mode callbacks: PsSetCreateProcessNotifyRoutine, PsSetCreateThreadNotifyRoutine notify EDR of process / thread events. ETW (Event Tracing for Windows): provides telemetry stream EDR consumes. AMSI: Antimalware Scan Interface; PowerShell / WSH content sent to AV for inspection. File-based scanning: classic signature […]

May 14, 2026 40 min Open
Red Team Operations Advanced Free

Adversary Emulation Plans — TTPs from Threat Intel to Engagement

Why emulate vs. just pentest Generic pentests find generic findings. Adversary emulation tests whether you can withstand the specific groups that target your industry / geography: APT29 / Cozy Bear for government / defence. FIN7 / FIN8 for retail / hospitality. APT41 for telecom and travel. Specific groups targeting Indian financial sector. The sources MITRE […]

May 14, 2026 35 min Open
Blue Team / SOC Operations Intermediate Free

SOC Metrics That Actually Drive Improvement

The bad metrics Total alerts processed — measures volume, not value. Encourages keeping noisy rules. Alerts per analyst per shift — encourages superficial triage. Closed-without-investigation rate — encourages closure, not analysis. Mean-time-to-acknowledge alone — encourages clicking without thinking. The good metrics For analysts Mean Time To Detect (MTTD): from compromise to detection. Hard to measure […]

May 14, 2026 30 min Open
Blue Team / SOC Operations Advanced Free

Purple Team — Operationalising Adversary Emulation

Red vs purple — what differs Red team Purple team Adversary emulation, blue blind Adversary emulation, blue collaborating Goal: demonstrate impact Goal: improve detection Output: detailed report; blue may not see techniques used Output: detection rules + visibility-gap remediation Annual or quarterly engagement Continuous or monthly cadence The purple-team operating model Red team executes a […]

May 14, 2026 35 min Open
Blue Team / SOC Operations Advanced Free

Threat Hunting Operationalised — Hypotheses, Pivots, Dashboards

What threat hunting is Proactive search for adversary presence based on hypothesis, not alert. The defender assumes a sophisticated attacker may already be present and searches for traces that current detection rules would miss. The hunt cycle Hypothesis: state what you’re looking for. “Adversaries may be using WMI for lateral movement.” Data sources: identify what […]

May 14, 2026 35 min Open
Blue Team / SOC Operations Advanced Free

Detection Engineering — Sigma, ATT&CK Coverage, Validation

What detection engineering is Design rules that fire on adversary behaviour, not noise. Test rules against historical data and red-team data. Tune to acceptable signal-to-noise. Deploy with documentation. Maintain — update when adversary techniques evolve. The detection-engineering lifecycle Source: hunt finding, TI report, red-team exercise, ATT&CK coverage gap. Hypothesis: state what the rule should catch. […]

May 14, 2026 35 min Open
Blue Team / SOC Operations Advanced Free

SOAR — Security Orchestration, Automation, Response

What SOAR does Orchestration: connect security tools via API; trigger actions across them. Automation: execute repeatable workflows without human intervention. Case management: structured incident workflow with audit trail. Playbook execution: pre-defined response runbooks triggered by alert type. The platforms Splunk SOAR (formerly Phantom), Palo Alto XSOAR (Demisto), IBM QRadar SOAR, Microsoft Sentinel SOAR, Tines, Torq. […]

May 14, 2026 35 min Open
Cloud Security Practitioner Advanced Free

Serverless Security — Functions, Event Sources, API Gateway

The serverless threat model What you no longer manage: OS patches, container runtime, network firewall (mostly). What becomes more critical: function code, IAM permissions, event sources, dependencies. The recurring vulnerability classes Over-privileged function roles: function role can do far more than the function actually needs. Compromise of function = wide IAM access. Injection via event […]

May 14, 2026 30 min Open
Cloud Security Practitioner Advanced Free

Cloud Workload Protection (CWPP) — VMs, Containers, Serverless

CWPP vs CSPM CSPM CWPP Configuration of cloud resources What is running on those resources Public buckets, broad SGs, unencrypted volumes Malware, intrusion, suspicious processes, file integrity Agentless (mostly) Agent or eBPF probe per workload Mature programmes deploy both. CNAPP (Cloud-Native Application Protection Platform) is the converged offering — CSPM + CWPP + CIEM (identity […]

May 14, 2026 35 min Open
02 / Why learn here

Practitioners who've
shipped the controls.

Every module is written by someone who has built the defence or run the engagement. No repackaged tutorials, no generic theory.

Why learn here

01

Practitioner-written.

Each lesson is authored by someone who has shipped the control or run the engagement in production.

02

Quiz after every module.

20+ questions with explanations. 70%+ to mark complete. Unlimited retries.

03

Progress tracked.

Completions, scores and streaks saved automatically. Resume exactly where you left off.

04

India-priced.

Start free. ₹499/mo for intermediate. ₹4,999/yr for advanced. No hidden fees, ever.