Practitioner-grade cybersecurity content
Technical playbooks, war stories, and how-to-think guides — written by practitioners, anchored to the Indian context.
Want structured, step-by-step learning instead? Explore the Academy (guided courses) or the AI security hub.
Latest articles
Most recent practitioner playbooks across every track. Filter by topic in the sidebar, or use search.
Module 3 · Command & Control Frameworks
Cobalt Strike, Sliver, Havoc, Mythic compared. Beacon anatomy, transports, malleable profiles, redirector architecture.
AcademyModule 2 · Initial Access — Phishing & Beyond
Phishing infrastructure, HTML smuggling, password spray, OAuth consent, and exposed-service exploitation.
AcademyModule 1 · Red Team Operations Fundamentals
Red team vs pentest, engagement types, objectives, rules of engagement, and what a good red team report looks like.
AcademyModule 5 · Supply Chain Security (SBOM, SLSA, Signing)
SBOM generation with Syft, SLSA provenance levels, Cosign keyless signing, dependency pinning, and 2026 regulatory crib sheet.
AcademyModule 4 · CI/CD Pipeline Hardening
Pipeline attack surface: config injection, pwn-requests, unpinned actions, OIDC trust policies, ephemeral runners, signing.
AcademyModule 3 · Infrastructure-as-Code Security
Checkov, Trivy, kube-score. Terraform issue categories, Kubernetes hardening, Dockerfile patterns, Kyverno/OPA policies.
AcademyModule 2 · SAST, DAST & SCA in CI
What each scanner class detects, tool selection for 2026, CI integration patterns, false-positive tuning, triage workflow.
AcademyModule 1 · DevSecOps Fundamentals
Shift-left + extend-right, SDLC security map, where each control lives, metrics that matter, and the 30-day rollout.
AcademyModule 5 · Bypassing Mobile Hardening & Exploit Chaining
Root/jailbreak detection bypass, anti-debug, RASP defeat, and chaining findings into a business-impact exploit.
AcademyModule 4 · Mobile Backend API Testing
Why mobile APIs are weaker, device registration abuse, auth patterns, business logic, client-side validation bypasses.