Cybersecurity, learned like a practitioner.
24 learning paths · 398 modules live · every lesson written by someone who has shipped the control or run the engagement. Free to start.
Latest modules
Most recent practitioner playbooks across every track. Filter by topic, level, or search in the sidebar.
APIs — Your Mobile App Is Public Attack Surface
Every endpoint your mobile or SPA calls is exposed to the internet. Shadow endpoints, version drift, mass assignment.
Session Tokens — Where Auth Bugs Live After Login
Developers focus on login; attackers target sessions. Theft, rotation, revocation, and the edge cases that break.
The Framework-Assumption Gap
'The framework handles it' is the most dangerous phrase in modern web security. Escape hatches, third-party integrations, and non-REST transports.
BGP Security and RPKI — How the Internet Trusts Itself, and Why It Sometimes Should Not
BGP is the routing protocol of the Internet — every ISP, hyperscaler, and large enterprise speaks it. It assumes good behaviour by every participant; that assumption fails several times a year, and we get prefix hijacks, route leaks, and accidental outages. RPKI cryptographically
Microsoft Entra ID Security
Roles, attack patterns (token theft, AitM, consent phishing), Conditional Access, PIM, hybrid AD considerations.
Azure Resource Hardening
RBAC hierarchy, network security, Storage/SQL/KeyVault hardening, Defender for Cloud, common misconfigurations.
Microsoft 365 Security
Exchange + SharePoint + Teams + Power Platform hardening, Defender stack, Purview, IR in M365.
Google Cloud Platform Security
Resource hierarchy, IAM, service accounts, network, GCS/SQL/GKE/KMS hardening, Security Command Center.
GCP Advanced — VPC-SC, WIF, Confidential Computing
VPC Service Controls, Workload Identity Federation, BeyondCorp, Confidential VMs, Assured Workloads, EKM.
Insecure Deserialization
Java/.NET/Python/PHP/Ruby deserialization vulns, gadget chains, ysoserial, signed-data defense.
Practitioners who've
shipped the controls.
Every module is written by someone who has built the defence or run the engagement. No repackaged tutorials, no generic theory.
Why learn here
Practitioner-written.
Each lesson is authored by someone who has shipped the control or run the engagement in production.
Quiz after every module.
20+ questions with explanations. 70%+ to mark complete. Unlimited retries.
Progress tracked.
Completions, scores and streaks saved automatically. Resume exactly where you left off.
India-priced.
Start free. ₹499/mo for intermediate. ₹4,999/yr for advanced. No hidden fees, ever.