Cybersecurity, learned like a practitioner.

24 learning paths · 398 modules live · every lesson written by someone who has shipped the control or run the engagement. Free to start.

24
Learning paths
398+
Live modules
0
You've completed
Free
Your tier
Browse the academy

Latest modules

Most recent practitioner playbooks across every track. Filter by topic, level, or search in the sidebar.

538 results · Page 9/54
Advanced Free

Forensic Timeline Reconstruction with Plaso

Why this module exists. An investigation has a hundred sources: event logs from five hosts, bash history, filesystem mtimes, audit logs, EDR alerts, NetFlow, cloud audit trail. Each has its own format and clock. The timeline is what merges them into one story. Without it, the investigation is fragments; with it, the investigation is a […]

May 13, 2026 35 min Open
Intermediate Free

Linux Forensics — Auditd, journalctl, Containers

Why this module exists. Linux IR responders often default to “tar up /var/log and call it done.” Modern Linux estates — especially in Indian cloud-native shops — have far richer artefacts available if you know to capture them. This module is the structured walkthrough. The first-response capture — what to grab in 5 minutes If […]

May 13, 2026 30 min Open
Advanced Free

Memory Forensics with Volatility 3

Why this module exists. Half the modern malware ecosystem never writes a payload to disk — it lives in memory, injected into legitimate processes, and dies at reboot. Without memory forensics you are flying blind on that whole class. This module is the practitioner workflow. Acquisition — get the memory before you lose it Memory […]

May 13, 2026 35 min Open
Intermediate Free

Windows Event Log Forensics — The IR Reference

Why this module exists. The defender’s biggest leverage in any Windows IR is the event log. The attacker’s biggest leverage in the same IR is knowing which events to clear. This module gives you the canonical event IDs, the queries that surface attacker activity, and the gaps that tell you something was cleaned. The seven […]

May 13, 2026 30 min Open
Intermediate Free

Disk Imaging — Forensically Sound Acquisition

Why this module exists. “We made a copy of the disk” is not the same as “we forensically imaged the disk.” The difference matters for evidence admissibility, chain of custody, and for the analyst three weeks later trying to reproduce a finding. This module is the practitioner-level disk imaging guide. What forensically sound actually means […]

May 13, 2026 30 min Open
Intermediate Free

Security Policy Architecture — Policy, Standard, Procedure, Baseline

Why this module exists. Auditors ask for “the policy.” Engineers want “the rule.” Both are right; they are asking different questions of different layers. A coherent policy architecture answers both without contradiction. This module is the four-layer model and the operational guidance for building each layer. The four-layer model Layer What it states Approval level […]

May 13, 2026 30 min Open
Advanced Free

Security Maturity Models — NIST CSF, ISO 27001, SAMM, CIS in Practice

Why this module exists. Every Indian enterprise we audit has a “maturity assessment” somewhere on file. Few have one that has been refreshed in the last 18 months; fewer still use it to drive funding decisions. The pattern is the same: a one-time scoring exercise that produced a slide, the slide got presented to the […]

May 13, 2026 35 min Open
Advanced Free

Risk Appetite Statement — Writing One That Drives Decisions

Why this module exists. Risk appetite is where governance meets engineering reality. Without a stated appetite, every risk decision becomes ad hoc — defended by whoever speaks loudest in the room. With a clear appetite stated in measurable terms, the same decision becomes mechanical: “this exceeds the stated threshold, escalation triggered.” This module walks the […]

May 13, 2026 30 min Open
Intermediate Free

First 90 Days as a Security Leader — The Practitioner Playbook

Why this module exists. CISO and security-leader transitions in Indian enterprises follow a predictable failure mode. The new leader arrives, the board asks for an “assessment”, a 60-slide deck lands six weeks later, and the operational programme drifts for the entire honeymoon period. The disciplined version instead spends the first 90 days establishing five concrete […]

May 13, 2026 30 min Open
Advanced Free

Board Reporting for Security — Metrics, Narrative, Cadence

Why this module exists. The board is not your peer audience. They are not security practitioners. The report that wins your peers’ approval — a 40-slide dive into MITRE ATT&CK coverage — is the report that loses the board. This module is the operational pattern for the inverse: the report that lets a non-technical decision-maker […]

May 13, 2026 35 min Open
02 / Why learn here

Practitioners who've
shipped the controls.

Every module is written by someone who has built the defence or run the engagement. No repackaged tutorials, no generic theory.

Why learn here

01

Practitioner-written.

Each lesson is authored by someone who has shipped the control or run the engagement in production.

02

Quiz after every module.

20+ questions with explanations. 70%+ to mark complete. Unlimited retries.

03

Progress tracked.

Completions, scores and streaks saved automatically. Resume exactly where you left off.

04

India-priced.

Start free. ₹499/mo for intermediate. ₹4,999/yr for advanced. No hidden fees, ever.