Cybersecurity, learned like a practitioner.

24 learning paths · 398 modules live · every lesson written by someone who has shipped the control or run the engagement. Free to start.

24
Learning paths
398+
Live modules
0
You've completed
Free
Your tier
Browse the academy

Cloud Security Practitioner · modules

AWS → Azure → GCP → Kubernetes. Real hardening, not checklists.

23 results · Page 2/3
Cloud Security Practitioner Intermediate Free

Module 13 · Cloud SSRF & IMDS — IMDSv2 and Beyond

Why this module exists. Capital One. Capital One. Capital One. Every cloud security training references it because the chain is iconic: external SSRF → IMDS → IAM credentials → S3 dump. Six years later, IMDSv1 is still enabled on enough EC2 fleets to keep the attack practical. And Azure / GCP have their own metadata-service […]

Apr 27, 2026 30 min Open
Cloud Security Practitioner Intermediate Free

Module 15 · CloudTrail Forensics — Reading the Audit Log

Why this module exists. If you can’t read CloudTrail, you can’t do cloud incident response. CloudTrail is to AWS what Windows Event Logs are to AD: every action by every principal is recorded. Most defenders skim the volume; experienced cloud-IR practitioners write surgical Athena queries that crack open incidents in 20 minutes. What CloudTrail records […]

Apr 27, 2026 35 min Open
Cloud Security Practitioner Intermediate Free

Module 16 · Cost-Based Denial of Service

Why this module exists. Modern cloud architectures auto-scale. Auto-scaling means an attacker who can drive load can drive your bill — to bankruptcy levels — without taking the service down. The 2020-2024 wave of “DenialOfWallet” attacks demonstrated that autoscaling without circuit breakers is a financial DoS. Indian SaaS, especially YC-funded startups with low cash runway, […]

Apr 27, 2026 25 min Open
Cloud Security Practitioner Advanced Free

Module 17 · Multi-Cloud Identity Federation Attack Surface

Why this module exists. Indian enterprises in 2026 are multi-cloud. Workloads on AWS, identity in Entra ID, data lakes in GCP, kubernetes on multiple clouds. Each integration uses identity federation — and each federation is a trust boundary that attackers can pivot across. The bugs that matter are at the seams between clouds, not within […]

Apr 27, 2026 35 min Open
Cloud Security Practitioner Advanced Members

Zero Trust Architecture — From VPN to Identity-Aware Access

What Zero Trust actually is, the five CISA pillars, the reference stack for Indian mid-market organisations, and a realistic 12 to 18 month rollout sequence — identity, devices, conditional access, ZTNA, workload identity, data classification.

Apr 25, 2026 75 min Open
Cloud Security Practitioner Intermediate Free

Module 3 · Infrastructure-as-Code Security

Checkov, Trivy, kube-score. Terraform issue categories, Kubernetes hardening, Dockerfile patterns, Kyverno/OPA policies.

Apr 22, 2026 90 min Open
Cloud Security Practitioner Advanced Members

Module 7 · Cloud Incident Response

Cloud incidents move fast. An attacker with a leaked access key can enumerate the account in minutes and begin exfiltration. Response time matters. This module covers a practitioner-grade cloud IR workflow — what to do in the first 30 minutes, 2 hours, and 24 hours after suspecting compromise. The cloud-specific challenges Speed — API-based actions […]

Apr 19, 2026 120 min Open
Cloud Security Practitioner Advanced Members

Module 6 · Cross-Account Attacks in AWS

Multi-account AWS (or multi-subscription Azure / multi-project GCP) is the norm. Production in one account, staging in another, security tooling in a third, sometimes dozens of accounts across business units. Each cross-account boundary is a potential attack surface — and when misconfigured, a path from one compromised account to many. Why multi-account Blast-radius limitation — […]

Apr 19, 2026 90 min Open
Cloud Security Practitioner Intermediate Members

Module 5 · Secrets Management

Every application has secrets — database passwords, API keys, TLS certs, encryption keys, third-party tokens. Where you store them determines whether a compromise is contained or catastrophic. This module covers secrets-management patterns for modern cloud applications. The problem Secrets historically lived in: environment variables, config files, source code, shared spreadsheets, Slack messages, CI/CD logs. Each […]

Apr 19, 2026 90 min Open
Cloud Security Practitioner Advanced Members

Module 4 · Kubernetes Attack Surface

Kubernetes is where 2024-2026 cloud security action is happening. Every Indian fintech, every serious SaaS, and most mature enterprises now run workloads on Kubernetes. And Kubernetes, by design, has the most complex security surface of any modern platform. The control plane, the worker nodes, the network fabric, the service mesh, the supply chain, the secrets, […]

Apr 19, 2026 120 min Open
02 / Why learn here

Practitioners who've
shipped the controls.

Every module is written by someone who has built the defence or run the engagement. No repackaged tutorials, no generic theory.

Why learn here

01

Practitioner-written.

Each lesson is authored by someone who has shipped the control or run the engagement in production.

02

Quiz after every module.

20+ questions with explanations. 70%+ to mark complete. Unlimited retries.

03

Progress tracked.

Completions, scores and streaks saved automatically. Resume exactly where you left off.

04

India-priced.

Start free. ₹499/mo for intermediate. ₹4,999/yr for advanced. No hidden fees, ever.