Academy Basic · 142 articles

Academy Basic

Intermediate Academy modules — Basic tier required (₹499/month)

Academy

Module 5 · Why SSRF Is Still Critical in 2026

Every URL parameter where the server fetches. Cloud metadata turned SSRF from inconvenience to catastrophe.

Apr 22, 2026 · 4 min read
Academy

Module 2 · Why Injection Still Happens — A Grammar Problem

Injection isn't about bad input. It's attackers smuggling tokens into an interpreter's grammar.

Apr 22, 2026 · 4 min read
Academy

Module 3 · Why Auth Checks Fail — Missing Gates Everywhere

Authentication is one gate. Authorization is every gate after. Most breaches live in the latter.

Apr 22, 2026 · 4 min read
Academy

Module 4 · Business Logic — Where Scanners Fail

Business logic bugs are legal sequences of actions producing illegal outcomes. Understand the product to find them.

Apr 22, 2026 · 4 min read
Academy

Module 1 · Microsoft Entra ID Security

Roles, attack patterns (token theft, AitM, consent phishing), Conditional Access, PIM, hybrid AD considerations.

Apr 22, 2026 · 5 min read
Academy

Module 2 · Azure Resource Hardening

RBAC hierarchy, network security, Storage/SQL/KeyVault hardening, Defender for Cloud, common misconfigurations.

Apr 22, 2026 · 4 min read
Academy

Module 3 · Microsoft 365 Security

Exchange + SharePoint + Teams + Power Platform hardening, Defender stack, Purview, IR in M365.

Apr 22, 2026 · 4 min read
Academy

Module 1 · Google Cloud Platform Security

Resource hierarchy, IAM, service accounts, network, GCS/SQL/GKE/KMS hardening, Security Command Center.

Apr 22, 2026 · 5 min read
Academy

Module 2 · GCP Advanced — VPC-SC, WIF, Confidential Computing

VPC Service Controls, Workload Identity Federation, BeyondCorp, Confidential VMs, Assured Workloads, EKM.

Apr 22, 2026 · 5 min read
Academy

Module 2 · ISO 27001:2022 Implementation

Required documents, the SoA, 2022 control structure, implementation timeline, common gaps for Indian implementations.

Apr 22, 2026 · 4 min read
1 6 7 8 9 10 15