Knowledge Hub

Practitioner-grade cybersecurity content

Technical playbooks, war stories, and how-to-think guides — written by practitioners, anchored to the Indian context.

Want structured, step-by-step learning instead? Explore the Academy (guided courses) or the AI security hub.

Latest articles

Most recent practitioner playbooks across every track. Filter by topic in the sidebar, or use search.

Security Guides

theHarvester and Recon-ng: OSINT Toolchain in 2026

theHarvester for breadth-of-source aggregation; Recon-ng for workflow continuity across investigation. Where they fit alongside modern tools (subfinder, amass, SpiderFoot, Maltego) in 2026…

Apr 25, 2026 · 2 min read
Security Guides

SharePoint CVE-2024-38094: Why On-Prem SharePoint Stays a Target

SharePoint Server's recent CVE roster — 2019-0604, 2023-29357 chain, 2024-38094 — shows the on-prem attack surface persists. Detection, mitigation, and the migration…

Apr 25, 2026 · 3 min read
Blue Team

Modern Phishing Kits: Tycoon, Greatness, EvilProxy, Mamba 2FA

Phishing-as-a-Service kits dominate 2024-26 attacks against Indian fintech and BFSI. Tycoon, Greatness, EvilProxy / Caffeine, Mamba 2FA, Robin Banks. IoCs to monitor,…

Apr 25, 2026 · 3 min read
Security Guides

Maltego for OSINT: Graph-Based Investigation

Maltego turns scattered OSINT into structured intelligence. Entity types, transform ecosystem, practical workflow for phishing-campaign investigation, threat-actor profiling, supply-chain mapping. Pro vs…

Apr 25, 2026 · 3 min read
Security Guides

GraphQL Authorisation Bypass: The Deep-Dive

GraphQL's most consequential bug class isn't injection — it's authorisation bypass. Field-level over-exposure, resolver-level IDOR, mutation field injection, connection traversal, batched-query tenant…

Apr 25, 2026 · 4 min read
Security Guides

Email Security in 2026: SPF, DKIM, DMARC, MTA-STS, BIMI

The modern email-authentication stack — SPF for IP authorisation, DKIM for cryptographic signing, DMARC for enforcement and reporting, MTA-STS for TLS enforcement,…

Apr 25, 2026 · 3 min read
Security Guides

Indian Phishing in 2026: SMS, Vishing, and UPI Scams

The Indian phishing landscape has distinct shapes — SMS-led, mobile-first, UPI-integrated. Bank impersonation, KYC scams, UPI fraud patterns, vishing with AI voice…

Apr 25, 2026 · 3 min read
Red Teaming

Browser-in-the-Browser (BitB) Phishing: Why Users Still Fall for It

BitB renders fake browser popup windows inside the actual browser tab. Users see legitimate URLs in the fake popup and trust them.…

Apr 25, 2026 · 3 min read
Red Teaming

Evilginx2 + AiTM Phishing: How Modern Attacks Defeat MFA

Adversary-in-the-Middle phishing captures both credentials and session cookies during auth flow — defeating traditional MFA. How AiTM works, detection limits, and why…

Apr 25, 2026 · 3 min read
Blue Team

Detecting C2 Traffic from Network Telemetry: The Layered Approach

C2 detection from network telemetry — beaconing analysis with RITA, JA3/JA4 fingerprinting, DNS analytics for tunneling and DGA, HTTP/HTTPS anomalies, threat-intel destination…

Apr 25, 2026 · 3 min read
1 61 62 63 64 65 91