Knowledge Hub

Practitioner-grade cybersecurity content

Technical playbooks, war stories, and how-to-think guides — written by practitioners, anchored to the Indian context.

Want structured, step-by-step learning instead? Explore the Academy (guided courses) or the AI security hub.

Latest articles

Most recent practitioner playbooks across every track. Filter by topic in the sidebar, or use search.

Academy

Module 2 · Layer 2/3 Trust — ARP, DNS, LLMNR Poisoning

Responder, mitm6, NTLM relay. Protocols designed in 1990 still farming credentials in 2026.

Apr 22, 2026 · 5 min read
Academy

Module 1 · The Network Is Never Flat

Segmentation on paper vs reality. Every network has exceptions attackers exploit for lateral movement.

Apr 22, 2026 · 5 min read
Academy

Module 10 · The Framework-Assumption Gap

'The framework handles it' is the most dangerous phrase in modern web security. Escape hatches, third-party integrations, and non-REST transports.

Apr 22, 2026 · 5 min read
Academy

Module 9 · Session Tokens — Where Auth Bugs Live After Login

Developers focus on login; attackers target sessions. Theft, rotation, revocation, and the edge cases that break.

Apr 22, 2026 · 4 min read
Academy

Module 8 · APIs — Your Mobile App Is Public Attack Surface

Every endpoint your mobile or SPA calls is exposed to the internet. Shadow endpoints, version drift, mass assignment.

Apr 22, 2026 · 4 min read
Academy

Module 7 · File Upload — Three Attacks in One

Upload = attack at parsing + storage + serving. All three have their own rules, and mistakes compound.

Apr 22, 2026 · 4 min read
Academy

Module 6 · Why XSS Persists — Context Is Everything

Framework defaults cover one HTML context. Every other context — URL, CSS, JSON-in-script — is fresh attack surface.

Apr 22, 2026 · 4 min read
Academy

Module 5 · Why SSRF Is Still Critical in 2026

Every URL parameter where the server fetches. Cloud metadata turned SSRF from inconvenience to catastrophe.

Apr 22, 2026 · 4 min read
Academy

Module 4 · Business Logic — Where Scanners Fail

Business logic bugs are legal sequences of actions producing illegal outcomes. Understand the product to find them.

Apr 22, 2026 · 4 min read
Academy

Module 3 · Why Auth Checks Fail — Missing Gates Everywhere

Authentication is one gate. Authorization is every gate after. Most breaches live in the latter.

Apr 22, 2026 · 4 min read
1 72 73 74 75 76 91