Academy Pro · 81 articles

Academy Pro

Medium and Hard Academy modules — Pro tier required

Academy

Module 7 · Trusts — Legacy Merger Paths

Trust types, SIDHistory attacks, cross-forest paths. Mergers leave trust relationships with security debt.

Apr 22, 2026 · 4 min read
Academy

Module 8 · Kerberos Delegation Abuse

Unconstrained, constrained, RBCD. S4U2Self + S4U2Proxy, MachineAccountQuota, PetitPotam coercion.

Apr 22, 2026 · 4 min read
Academy

Module 9 · Hybrid AD — On-Prem Meets Cloud

Entra Connect crown jewel, Golden SAML, Azure AD attacks, AZUREADSSOACC$ legacy, PRT theft.

Apr 22, 2026 · 5 min read
Academy

Module 10 · AD Detection — What Good Looks Like

Event IDs, Sigma rules, Defender for Identity, Sentinel KQL queries. From generic SIEM to mature AD detection.

Apr 22, 2026 · 5 min read
Academy

Module 6 · VPN Appliances — The Crown Jewel

Ivanti, Fortinet, Citrix, Palo Alto — every year a critical CVE. Patching speed vs attacker speed.

Apr 22, 2026 · 6 min read
Academy

Module 7 · BGP, DNS, CAs — Internet-Scale Trust Failures

BGP hijack + DNS poisoning + TLS cert abuse = traffic interception at scale. Real breaches, real tools.

Apr 22, 2026 · 6 min read
Academy

Module 8 · OT / ICS at the Network Layer

Stuxnet, Industroyer, Triton, Oldsmar. Why PLCs reachable from IT is catastrophic and common.

Apr 22, 2026 · 6 min read
Academy

Module 9 · Wireless — The Perimeter That Moves

Evil Twin, KRACK, PMKID, rogue 802.1X, BLE. $40 of hardware extends the perimeter past the building.

Apr 22, 2026 · 6 min read
Academy

Module 10 · Why Network Detection Underperforms

Encrypted traffic, volume overload, alert fatigue. Why attacker dwell time is weeks to months on average.

Apr 22, 2026 · 6 min read
Academy

Module 6 · Why XSS Persists — Context Is Everything

Framework defaults cover one HTML context. Every other context — URL, CSS, JSON-in-script — is fresh attack surface.

Apr 22, 2026 · 4 min read