Cybersecurity, learned like a practitioner.
24 learning paths · 398 modules live · every lesson written by someone who has shipped the control or run the engagement. Free to start.
Attacker Mindset — Active Directory · modules
Fragile-by-design AD, BloodHound graphs, ACL abuse, ADCS (ESC1-16), trusts, delegation, hybrid attacks — end-to-end AD compromise mindset.
Module 1 · Why AD Is Fragile by Design
AD's defaults accumulated risk for 20 years — authenticated-read-everything, NTLM, RC4, backwards compat.
Module 2 · AD Enumeration — Seeing Everything
BloodHound, SharpHound, Impacket, CrackMapExec, PowerView. Any authenticated user sees the whole directory.
Module 3 · BloodHound — Graph Theory Meets AD
Edges, queries, custom Cypher. Why BloodHound changed offensive AD since 2017.
Module 4 · AD ACL Abuse — Twenty Years of Accumulated Trust
GenericAll, GenericWrite, WriteDacl, AddMember, ForceChangePassword. Delegation sprawl = privilege escalation.
Module 5 · Group Policy Preferences — The Gift That Keeps Giving
cPassword in SYSVOL still found in 2026. MS14-025 didn't remove legacy files. Plus SYSVOL credential hunting.
Module 6 · ADCS — ESC1 through ESC16
Active Directory Certificate Services attacks (Certified Pre-Owned). Template misconfigurations → domain compromise.
Module 7 · Trusts — Legacy Merger Paths
Trust types, SIDHistory attacks, cross-forest paths. Mergers leave trust relationships with security debt.
Module 8 · Kerberos Delegation Abuse
Unconstrained, constrained, RBCD. S4U2Self + S4U2Proxy, MachineAccountQuota, PetitPotam coercion.
Module 9 · Hybrid AD — On-Prem Meets Cloud
Entra Connect crown jewel, Golden SAML, Azure AD attacks, AZUREADSSOACC$ legacy, PRT theft.
Module 10 · AD Detection — What Good Looks Like
Event IDs, Sigma rules, Defender for Identity, Sentinel KQL queries. From generic SIEM to mature AD detection.
Practitioners who've
shipped the controls.
Every module is written by someone who has built the defence or run the engagement. No repackaged tutorials, no generic theory.
Why learn here
Practitioner-written.
Each lesson is authored by someone who has shipped the control or run the engagement in production.
Quiz after every module.
20+ questions with explanations. 70%+ to mark complete. Unlimited retries.
Progress tracked.
Completions, scores and streaks saved automatically. Resume exactly where you left off.
India-priced.
Start free. ₹499/mo for intermediate. ₹4,999/yr for advanced. No hidden fees, ever.