Knowledge Hub

Practitioner-grade cybersecurity content

Technical playbooks, war stories, and how-to-think guides — written by practitioners, anchored to the Indian context.

Want structured, step-by-step learning instead? Explore the Academy (guided courses) or the AI security hub.

Latest articles

Most recent practitioner playbooks across every track. Filter by topic in the sidebar, or use search.

Academy

Module 3 · Command & Control Frameworks

Cobalt Strike, Sliver, Havoc, Mythic compared. Beacon anatomy, transports, malleable profiles, redirector architecture.

Apr 22, 2026 · 4 min read
Academy

Module 2 · Initial Access — Phishing & Beyond

Phishing infrastructure, HTML smuggling, password spray, OAuth consent, and exposed-service exploitation.

Apr 22, 2026 · 5 min read
Academy

Module 1 · Red Team Operations Fundamentals

Red team vs pentest, engagement types, objectives, rules of engagement, and what a good red team report looks like.

Apr 22, 2026 · 4 min read
Academy

Module 5 · Supply Chain Security (SBOM, SLSA, Signing)

SBOM generation with Syft, SLSA provenance levels, Cosign keyless signing, dependency pinning, and 2026 regulatory crib sheet.

Apr 22, 2026 · 5 min read
Academy

Module 4 · CI/CD Pipeline Hardening

Pipeline attack surface: config injection, pwn-requests, unpinned actions, OIDC trust policies, ephemeral runners, signing.

Apr 22, 2026 · 6 min read
Academy

Module 3 · Infrastructure-as-Code Security

Checkov, Trivy, kube-score. Terraform issue categories, Kubernetes hardening, Dockerfile patterns, Kyverno/OPA policies.

Apr 22, 2026 · 5 min read
Academy

Module 2 · SAST, DAST & SCA in CI

What each scanner class detects, tool selection for 2026, CI integration patterns, false-positive tuning, triage workflow.

Apr 22, 2026 · 5 min read
Academy

Module 1 · DevSecOps Fundamentals

Shift-left + extend-right, SDLC security map, where each control lives, metrics that matter, and the 30-day rollout.

Apr 22, 2026 · 5 min read
Academy

Module 5 · Bypassing Mobile Hardening & Exploit Chaining

Root/jailbreak detection bypass, anti-debug, RASP defeat, and chaining findings into a business-impact exploit.

Apr 22, 2026 · 5 min read
Academy

Module 4 · Mobile Backend API Testing

Why mobile APIs are weaker, device registration abuse, auth patterns, business logic, client-side validation bypasses.

Apr 22, 2026 · 5 min read
1 77 78 79 80 81 91