Cybersecurity, learned like a practitioner.
24 learning paths · 398 modules live · every lesson written by someone who has shipped the control or run the engagement. Free to start.
Latest modules
Most recent practitioner playbooks across every track. Filter by topic, level, or search in the sidebar.
AWS IAM Deep Dive
AWS IAM is the single largest source of cloud misconfigurations. It’s also AWS’s most powerful feature. Master it and you can architect least-privilege cleanly; fumble it and you ship the kind of blast radius that makes every new access key a production-impacting event. This module is the concrete IAM practitioner’s guide. You’ve seen the mental […]
Cloud Security Mental Models
Cloud security is often taught as a taxonomy — “AWS IAM works like this, GCP IAM works like this, Azure is different.” That’s how you end up memorising 300 service-specific checkboxes without ever understanding what matters. This module inverts the usual approach: we give you the mental models that apply across AWS, Azure, GCP, and […]
BloodHound for Attack Paths
Individual AD misconfigurations look innocuous on their own. A group with a few extra members. A computer with delegation enabled. A user with GenericWrite on a colleague’s account. In isolation, each is a “maybe low risk.” When graph-analysed together, they form attack paths — concrete, stepwise routes from any foothold to Domain Admin. BloodHound is […]
Kerberoasting in Practice
Kerberoasting is the single most common Active Directory attack encountered on pen-test engagements. It’s low-noise, low-skill, highly reliable, and when it succeeds, the attacker holds privileged service account credentials — often Domain Admin. Understanding it is essential for both the offence and defence sides. This is a hands-on module. You will see the exact attacker […]
AD Architecture Fundamentals
Active Directory is the authentication backbone of ~95% of enterprise environments in India and globally. Every enterprise breach of note — from Colonial Pipeline to Maersk to countless Indian banks — involved AD compromise somewhere on the kill chain. Understand AD and you understand enterprise attack paths; stay ignorant and you audit blind. This module […]
Advanced Routing and VLANs — Static, OSPF, EIGRP, and Where Trust Boundaries Actually Live
Routing is how packets find their way across networks larger than a single broadcast domain. This module is the working introduction to routing tables, longest-prefix match, static routes, OSPF, EIGRP, redistribution, and the VLAN model that segments a single switch into multiple
Network Protocols Deep Dive — ARP, DHCP, ICMP, DNS, HTTP and the Trust They Assume
Protocols are contracts between machines. Most of the protocols the Internet runs on were designed in the 1980s assuming everyone on the wire was friendly. They are not. This module dissects the seven protocols you must know cold — ARP, DHCP, ICMP, DNS, NTP, HTTP, TLS — and the t
Packet Analysis with Wireshark — From “Open the PCAP” to Diagnosing Real Incidents
Wireshark is the universal protocol analyser. Every IR investigation, network design review, and "this protocol is misbehaving" debug eventually becomes a Wireshark session. This module teaches the workflow that distinguishes a beginner from a practitioner: capture filters vs dis
Breach Response Tabletop
It’s 2:47 AM on a Tuesday. Your PagerDuty wakes you up. A customer has tweeted a screenshot of what looks like your production database on a Telegram channel. Your heart rate spikes. You have approximately 72 hours before the Data Protection Board of India expects to hear from you. This module is about what happens […]
Designing Consent UX
Most DPDP compliance failures don’t happen at the database layer or the security layer — they happen at the pixel layer. A pre-ticked marketing box, a bundled “I agree to everything” checkbox, an unsubscribe link buried in a footer, a cookie banner with no “reject all” option. These are product decisions, not legal decisions. Which […]
Practitioners who've
shipped the controls.
Every module is written by someone who has built the defence or run the engagement. No repackaged tutorials, no generic theory.
Why learn here
Practitioner-written.
Each lesson is authored by someone who has shipped the control or run the engagement in production.
Quiz after every module.
20+ questions with explanations. 70%+ to mark complete. Unlimited retries.
Progress tracked.
Completions, scores and streaks saved automatically. Resume exactly where you left off.
India-priced.
Start free. ₹499/mo for intermediate. ₹4,999/yr for advanced. No hidden fees, ever.