Cybersecurity, learned like a practitioner.

24 learning paths · 398 modules live · every lesson written by someone who has shipped the control or run the engagement. Free to start.

24
Learning paths
398+
Live modules
0
You've completed
Free
Your tier
Browse the academy

Latest modules

Most recent practitioner playbooks across every track. Filter by topic, level, or search in the sidebar.

541 results · Page 8/55
Intermediate Free

Qualitative Risk Assessment — ISO 27005 / NIST 800-30 Done Well

Why this module exists. Done well, qualitative risk assessment is cheap, repeatable, and good enough for 90% of decisions. Done badly, it is theatre. The difference is in the scoring rigour, not the framework choice. What ISO 27005 and NIST SP 800-30 actually prescribe Both frameworks define a process: identify assets, identify threats, identify vulnerabilities, […]

May 14, 2026 30 min Open
Intermediate Free

Building a Risk Register That Drives Decisions

Why this module exists. Every Indian enterprise has a risk register. Few have one anyone uses to decide what to fund. The difference is in the operating model around the register, not the spreadsheet template. This module covers the operating model. What a working risk register actually does Drives the quarterly budget conversation — “what […]

May 14, 2026 30 min Open
Advanced Free

Quantitative Risk Analysis with FAIR

Why this module exists. Boards make decisions in money. Heat maps in red, amber, green do not translate to “should we spend ₹2 Cr on this control?” FAIR translates. This module is the operational introduction. The FAIR ontology — the building blocks FAIR decomposes “risk” into measurable components: Loss Event Frequency (LEF) — how often […]

May 14, 2026 35 min Open
Beginner Free

Awareness Programmes That Change Behaviour

Why this module exists. Awareness training is the single most-funded, least-effective security investment in most Indian enterprises. The right structure — frequent, targeted, feedback-driven — produces measurable behaviour change. The wrong structure — annual hour-long video — produces compliance-checkbox theatre. This module is how to build the right one. What does not work Annual one-hour […]

May 14, 2026 25 min Open
Intermediate Free

Physical Social Engineering — Tailgating, Badge Cloning, USB Drops

Why this module exists. Physical access still beats remote-only attacks for certain target classes — server-room access to a regulated bank, badge-room access to a stock exchange, network-port access in a coffee-shop floor. This module is the physical-channel social engineering practitioner reference. The attacker toolkit Tailgating — follow an authorised employee through a secured door. […]

May 14, 2026 30 min Open
Intermediate Free

Vishing, Smishing & WhatsApp Pretext — The Indian Voice Channel

Why this module exists. The corporate phishing-defence stack — DMARC, anti-phishing platforms, FIDO2 — does not protect against an attacker calling the help desk. India’s PSTN and SMS infrastructure make voice-channel social engineering particularly cheap. This module covers what defenders can actually do. The vishing playbook The canonical Indian-enterprise vishing attack: OSINT to identify a […]

May 14, 2026 25 min Open
Intermediate Free

Business Email Compromise (BEC) — Four Variants and the Defender Stack

Why this module exists. BEC does not need malware, credential theft, or AiTM phishing. It only needs to convince one finance person to send money to the wrong account. The defence is mostly process, not technology. This module is the practitioner pattern. The four BEC variants Variant Attacker pose Target CEO fraud CEO/CFO Finance team […]

May 14, 2026 30 min Open
Intermediate Free

Phishing — AiTM, MFA Bypass, and the 2026 Defender Stack

Why this module exists. Email-borne phishing is no longer “click this link, enter password.” Modern kits proxy the entire login flow, capture session cookies post-MFA, and let the attacker step into the authenticated session. The defender’s playbook has evolved correspondingly. This module is the current state. The 2026 attacker playbook The modern phishing kit is […]

May 14, 2026 30 min Open
Advanced Free

Unpacking Packed Malware — UPX, ASPack, Custom Packers

Why this module exists. Roughly 70% of malware samples in the wild are packed in some form. Without unpacking, your analysis stops at “calls VirtualAlloc, calls VirtualProtect, jumps somewhere.” With unpacking, the actual payload is in your disassembler. This module is the structured approach to getting from packed to unpacked. What packing actually is A […]

May 14, 2026 40 min Open
Expert Free

Anti-Analysis Techniques and How to Defeat Them

Why this module exists. A sandbox report that shows “did nothing” or a debugger that crashes when you single-step are not bugs in your tooling — they are the malware authors’ deliberate design. Knowing the catalogue of anti-analysis techniques lets you recognise them and respond appropriately. The four classes of anti-analysis Anti-VM / sandbox detection. […]

May 14, 2026 35 min Open
02 / Why learn here

Practitioners who've
shipped the controls.

Every module is written by someone who has built the defence or run the engagement. No repackaged tutorials, no generic theory.

Why learn here

01

Practitioner-written.

Each lesson is authored by someone who has shipped the control or run the engagement in production.

02

Quiz after every module.

20+ questions with explanations. 70%+ to mark complete. Unlimited retries.

03

Progress tracked.

Completions, scores and streaks saved automatically. Resume exactly where you left off.

04

India-priced.

Start free. ₹499/mo for intermediate. ₹4,999/yr for advanced. No hidden fees, ever.