Practitioner-grade cybersecurity content
Technical playbooks, war stories, and how-to-think guides — written by practitioners, anchored to the Indian context.
Want structured, step-by-step learning instead? Explore the Academy (guided courses) or the AI security hub.
Latest articles
Most recent practitioner playbooks across every track. Filter by topic in the sidebar, or use search.
Module 6 · Anti-Analysis Techniques and How to Defeat Them
Why this module exists. A sandbox report that shows “did nothing” or a debugger that crashes when you single-step are not bugs…
AcademyModule 5 · Unpacking Packed Malware — UPX, ASPack, Custom Packers
Why this module exists. Roughly 70% of malware samples in the wild are packed in some form. Without unpacking, your analysis stops…
AcademyModule 4 · Reverse Engineering Windows Malware with Ghidra
Why this module exists. When static and dynamic analysis are not enough — the sample is too novel, the obfuscation is too…
AcademyModule 3 · Dynamic Malware Analysis & Sandboxing
Why this module exists. Sandboxes are not magic — sophisticated malware checks for them and either does nothing or does something different.…
AcademyModule 2 · Static Malware Analysis — Strings, Imports, YARA
Why this module exists. Running unknown malware on your laptop is how new IR responders become old IR responders. Static analysis is…
AcademyModule 6 · Forensic Timeline Reconstruction with Plaso
Why this module exists. An investigation has a hundred sources: event logs from five hosts, bash history, filesystem mtimes, audit logs, EDR…
AcademyModule 5 · Linux Forensics — Auditd, journalctl, Containers
Why this module exists. Linux IR responders often default to “tar up /var/log and call it done.” Modern Linux estates — especially…
AcademyModule 4 · Windows Event Log Forensics — The IR Reference
Why this module exists. The defender’s biggest leverage in any Windows IR is the event log. The attacker’s biggest leverage in the…
AcademyModule 3 · Memory Forensics with Volatility 3
Why this module exists. Half the modern malware ecosystem never writes a payload to disk — it lives in memory, injected into…
AcademyModule 2 · Disk Imaging — Forensically Sound Acquisition
Why this module exists. “We made a copy of the disk” is not the same as “we forensically imaged the disk.” The…