Cybersecurity, learned like a practitioner.
24 learning paths · 398 modules live · every lesson written by someone who has shipped the control or run the engagement. Free to start.
Latest modules
Most recent practitioner playbooks across every track. Filter by topic, level, or search in the sidebar.
Data Mapping Workshop
Every DPDP compliance failure begins with the same sentence: “We didn’t know we had that data.” Data mapping is the discipline of finding out — comprehensively, systematically, and in a format you can defend to a Data Protection Board inquiry. If you read only one module from this path before your organisation’s DPDP compliance programme […]
DPDP Act Foundations
You’ve heard the name. “DPDP Act.” Somebody in your organisation has mentioned it in a meeting. Maybe legal sent a memo. Maybe your startup accelerator flagged it. This module is where you go from “I’ve heard of it” to “I can explain it and act on it.” The Digital Personal Data Protection Act, 2023 is […]
Networking Fundamentals — OSI, TCP/IP, and Why Layers Actually Matter
OSI is a teaching model. TCP/IP is what actually runs on the wire. Most "OSI questions" in interviews are really about how data physically moves between two computers — frames, packets, segments, sockets. This module gives you the working mental model: the four layers that matter
API Security (OWASP API Top 10)
OWASP API Top 10 in practice, GraphQL testing, gRPC, SSRF, LLM-integrated API attacks. The 2026 API attack surface. Pro module.
Business Logic Flaws
Race conditions, workflow manipulation, price/quantity attacks, coupon abuse, TOCTOU. The findings scanners cannot find. Pro module.
IDOR & Authorization Bypass
Horizontal and vertical IDOR, mass assignment, multi-tenant boundary violations, GraphQL authorization. The highest-yield SaaS bug class. Pro module.
Cross-Site Scripting (XSS) in 2026
Reflected, stored, and DOM-based XSS in 2026. Filter bypasses, CSP deep-dive, and the real impact beyond alert(1). Pro module.
SQL Injection in 2026
How SQLi works at the query level, UNION-based extraction, blind SQLi (boolean and time), out-of-band exfiltration, NoSQL injection, sqlmap practice.
Authentication Attacks
Username enumeration, password spraying, credential stuffing, session attacks, JWT vulnerabilities, OAuth/SAML flaws, MFA bypasses.
Web Enumeration & Recon
Subdomain enumeration, technology fingerprinting, directory brute-forcing, JavaScript bundle analysis, and Wayback reconnaissance.
Practitioners who've
shipped the controls.
Every module is written by someone who has built the defence or run the engagement. No repackaged tutorials, no generic theory.
Why learn here
Practitioner-written.
Each lesson is authored by someone who has shipped the control or run the engagement in production.
Quiz after every module.
20+ questions with explanations. 70%+ to mark complete. Unlimited retries.
Progress tracked.
Completions, scores and streaks saved automatically. Resume exactly where you left off.
India-priced.
Start free. ₹499/mo for intermediate. ₹4,999/yr for advanced. No hidden fees, ever.