885 guided lessons
Cybersecurity lesson catalogue
Browse every lesson by security domain and topic. Select a topic to see its practical lessons.
AI Security (55)
Advanced Agent And Api Security (4)
- AI Agent Identity Federation: Cross-System Authentication and Trust Boundaries
- AI Evaluation Pipeline Security: Securing CI/CD for Model Development
- AI-to-AI Communication Security: Protocols, Attestation, and Channel Integrity
- LLM API Security: Authentication, Rate Limiting, Input/Output Validation, and Key Management
Advanced Training Security (3)
Adversarial Ml Attacks (8)
- Adversarial Example Generation and Defensive Techniques
- Adversarial Machine Learning Fundamentals
- Backdoor and Trojan Attacks in Machine Learning Models
- Data Poisoning Attacks During AI Training
- Membership Inference Attacks Against ML Models
- Model Evasion Attacks Against Image, NLP, and Malware Detection Models
- Model Extraction and Model Stealing Attacks
- Model Inversion Attacks and Training Data Reconstruction
Ai Agent Security (7)
- AI Agent Security: Threat Models and Defensive Architecture
- AI Memory Security: Persistent Memory Poisoning and Context Manipulation
- AI Plugin and Extension Security: Third-Party Integration Risks
- AI Tool Calling Security: Function Injection, Parameter Tampering, and Tool Abuse
- Autonomous AI Agent Sandboxing and Permission Enforcement
- MCP (Model Context Protocol) Security: Trust Boundaries, Tool Isolation, and Permission Models
- Multi-Agent System Security: Agent-to-Agent Trust and Communication Risks
Ai Governance And Operations (7)
- AI Governance, Risk, and Compliance: Frameworks, Audits, and Accountability
- AI Incident Response and Recovery: Playbooks for AI Security Events
- AI Observability and Security Monitoring: Logging, Anomaly Detection, and Alerting
- AI Red Teaming Methodology: Structured Adversarial Testing Frameworks
- AI Safety vs. Security: Intersection, Conflicts, and Complementary Controls
- AI Secure Development Lifecycle: Integrating Security from Data to Deployment
- AI Security Operations (AISecOps): Detection Rules, SIEM Integration, and Threat Hunting
Ai Security Foundations (2)
Ai Supply Chain And Infrastructure (5)
- AI Identity and Authorization: Secure Access to Models, Tools, and Agents
- AI Supply Chain Security: Models, Datasets, Dependencies, and Serving Infrastructure
- Model Serialization Security: Pickle, ONNX, TensorFlow, and PyTorch Model Risks
- Secure AI Model Deployment: Containers, APIs, and Inference Services
- Secure Secret Handling in AI Agents: Preventing Credential Exposure
Ai Supply Chain Integrity (3)
Hardware And Confidential Computing (3)
Privacy Preserving Ai (5)
- Differential Privacy in Machine Learning Systems: Budgets, Calibration, and Trade-offs
- Federated Learning Security: Privacy Attacks and Byzantine-Robust Aggregation
- Homomorphic Encryption for Secure AI Inference: Schemes, Performance, and Deployment
- Privacy-Preserving Machine Learning: Techniques, Trade-offs, and Selection Criteria
- Secure Multi-Party Computation for Collaborative AI: Protocols and Privacy Guarantees
Prompt And Llm Security (5)
- AI Firewall Architecture: Prompt Filtering, Risk Scoring, and Policy Enforcement
- AI Output Validation: Guardrails, Policy Engines, and Safe Response Filtering
- Jailbreak Techniques: Taxonomy, Evaluation, and Mitigation
- Prompt Leakage and System Prompt Protection Techniques
- Sensitive Data Leakage Through LLM Responses
Rag And Knowledge Store Security (3)
Application Security (102)
Gap Filling Appsec Coverage (6)
- CI/CD Security Pipeline Integration: Assembling SAST, DAST, SCA, and Secrets Detection
- Desktop Application Security: Electron Hardening, Code Signing, and Native App Sandboxing
- Manual Security Code Review: A Developer Checklist for Pull Request Security Gates
- Threat Modeling Methodologies: STRIDE, PASTA, and DFD Analysis for Development Teams
- Abuse Case Development: Deriving Security Test Cases from User Stories
- STRIDE Threat Modeling in Practice: Classifying Threats Against a Feature Design
Appsec Program Management (5)
- AppSec KPIs and Vulnerability SLA Management: Measuring and Reporting Security Posture
- AppSec Risk Register: Classifying and Prioritising Application Security Risks
- Developer Security Training Curriculum: Role-Based Learning Paths and Effectiveness Metrics
- Security Champion Program Design: Building Developer-Led AppSec Coverage
- Security Champions Program: Design, Onboarding, and Measuring Developer Security Culture
Authentication And Authorization Implementation (9)
- API Authentication Patterns: API Keys, HMAC Signatures, and Bearer Tokens
- Implementing MFA: TOTP, FIDO2, and WebAuthn from First Principles
- JWT Secure Implementation: Algorithms, Validation, Claims, and Key Rotation
- OAuth 2.0 PKCE: Implementing Secure Authorization Code Exchange for Public Clients
- OAuth2 and OIDC Secure Implementation: A Developer's Practical Guide
- RBAC and ABAC: Building Role-Based and Attribute-Based Access Control in Code
- Secure Password Storage: Implementing bcrypt, Argon2, and scrypt Correctly
- Secure Session Management: ID Generation, Binding, Rotation, and Expiry
- Session Fixation Prevention: Regenerating Session IDs After Authentication
Cryptography In Application Code (8)
- Application-Level Key Management: Generation, Storage, and Zero-Downtime Rotation
- Authenticated Encryption: Implementing AES-GCM to Protect Data Integrity and Confidentiality
- Certificate Pinning: Implementation, Backup Pins, and Maintenance Strategy
- Cryptographically Secure Random Number Generation in Application Code
- Cryptography Library Selection and Common Developer Pitfalls
- Secure Password Hashing: Implementing Argon2id for Credential Storage
- Symmetric vs. Asymmetric Encryption in Application Code: When and How to Use Each
- TLS Configuration and Mutual TLS (mTLS) for Application Developers
Dependency And Supply Chain Security (8)
- Automated Dependency Patching: Dependabot, Renovate, and Security-First Merge Strategies
- Dependency Pinning and Lockfile Integrity: Preventing Silent Dependency Drift in CI/CD
- Dependency Version Pinning and Lockfile Security: Preventing Silent Upgrades
- Evaluating Open-Source Library Security Risk Before Adoption
- Private Package Registry Security: Scoping, Access Control, and Namespace Defense
- SBOM Generation and Consumption: Tracking Every Dependency You Ship
- Software Bill of Materials: Generating and Querying an SBOM for Supply Chain Visibility
- Software Composition Analysis (SCA): Integrating Vulnerability Scanning into the Developer Workflow
Input Validation And Output Handling (7)
- Allowlist-Based Input Validation: Designing and Implementing Safe Input Boundaries
- Canonicalization and Normalization: Defeating Encoding-Based Bypass Attacks
- Content Security Policy: Building and Deploying a CSP Header to Prevent XSS
- Context-Aware Output Encoding: HTML, JavaScript, CSS, and URL Contexts
- Safe Deserialization Patterns in Java, Python, and .NET
- Secure File Upload: Content Validation, Extension Checks, and Sandboxing
- SQL Injection Prevention: Rewriting Vulnerable Queries with Parameterized Statements
Memory Safety And Low Level Appsec (6)
- Buffer Overflow Prevention: Replacing Unsafe C String Functions with Bounds-Checked Alternatives
- Integer Overflow Security: Detecting and Preventing Arithmetic Overflows in C
- Memory-Safe Language Migration: Strategies for Moving C/C++ to Rust or Go
- Rust Secure Programming: Ownership Model, Safe Abstractions, and Foreign Function Interface
- Safe String and Buffer Handling in Modern C++: std::string, span, and Bounds Checking
- Undefined Behavior and Security: How UB in C/C++ Becomes Exploitable
Mobile Appsec Builder Perspective (6)
- Android Secure Data Storage: Keystore System, EncryptedSharedPreferences, and Room Encryption
- iOS Secure Storage: Keychain Services, Data Protection Classes, and ATS Configuration
- Mobile API Security: Implementing Proper TLS Validation and Avoiding Certificate Bypass
- Mobile App Hardening: ProGuard, R8 Obfuscation, and Runtime Integrity Checks
- Certificate Pinning on Android: Implementing Public-Key Pinning with OkHttp
- iOS Keychain Security: Storing Sensitive Tokens with the Correct Accessibility Class
Secrets Management For Developers (7)
- Eliminating Hardcoded Credentials: Auditing a Codebase and Migrating to Secrets Managers
- Environment Variables and .env Files: Secure Patterns and Common Mistakes
- HashiCorp Vault Integration: A Developer's Practical Guide to Dynamic Secrets
- HashiCorp Vault Integration: Fetching Dynamic Secrets from Vault in Application Code
- Secret Scanning in CI/CD: Preventing Credential Leakage with Gitleaks and Pre-Commit Hooks
- Secrets Detection with Pre-Commit Hooks: gitleaks and trufflehog Integration
- Zero-Downtime Secrets Rotation: Application Patterns for Live Credential Cycling
Secure Api Design And Implementation (7)
- API Key Lifecycle Management: Generating, Hashing, and Rotating API Keys Securely
- API Rate Limiting and Throttling: Implementation Patterns and Bypass Prevention
- API Versioning Security: Managing Authentication Across Versions and Deprecation
- GraphQL Secure Schema Design: Query Depth Limits, Rate Limiting, and Field-Level Authorization
- GraphQL Security: Query Depth Limiting and Per-Field Authorization to Prevent API Abuse
- Idempotency Keys and Replay Attack Prevention in API Design
- Secure REST API Design: Authentication, Authorization, and Input Validation Patterns
Secure Coding Principles And Language Standards (10)
- Defence in Depth: Implementing Layered Security Controls in a Python Web Application
- Defense in Depth: Application Design Patterns That Layer Security Controls
- Fail-Safe Defaults and Secure-by-Default: Implementing Safety at the Code Level
- OWASP Top 10 Proactive Controls: A Developer Implementation Guide
- Principle of Least Privilege in Application Code: Scopes, Roles, and API Permissions
- Secure Coding in .NET and C#: Security APIs and Dangerous Patterns
- Secure Coding in Java and Spring: OWASP Proactive Controls Applied
- Secure Coding in JavaScript and Node.js: Common Pitfalls and Safe Patterns
- Secure Coding in Python: Django and Flask Security Patterns
- Secure Defaults and Fail-Safe Design: Implementing Deny-by-Default Authorization
Secure Error Handling And Observability (6)
- Application Security Logging: What to Log, What to Redact, and Log Format Design
- Application-Level Anomaly Detection: Embedding Security Signals into Observability Pipelines
- Error Response Information Leakage: Preventing Stack Trace and Internal Detail Exposure
- PII and Credential Scrubbing in Log Pipelines: Patterns and Tooling
- Secure Error Handling: Preventing Stack Traces and Sensitive Data from Reaching Clients
- Structured Security Event Logging: Emitting Machine-Readable Audit Events for SIEM Ingestion
Secure Sdlc And Security Requirements (8)
- Abuse Case and Misuse Case Modeling for Secure Design
- Conducting a Security Design Review Before Implementation
- Integrating Security into Agile Sprints: Threat Modeling in Two-Week Cycles
- SDLC Security Gates and Checkpoints: Defining Go/No-Go Criteria
- Security Gates in CI/CD: Writing a GitHub Actions Pipeline with SAST and SCA Quality Gates
- Security Requirements Engineering: Eliciting, Writing, and Verifying Security Requirements
- Security User Stories: Writing Misuse Stories and Given/When/Then Acceptance Criteria for a Login Feature
- Writing Security User Stories and Testable Acceptance Criteria
Security Testing For Developers (9)
- Building a Security Regression Test Suite from Past Vulnerabilities
- Developer-Guided DAST: Running OWASP ZAP and Nuclei Against Dev Environments
- Fuzz Testing Application Inputs: Property-Based Testing with Hypothesis and Atheris
- Pentest Finding Remediation: A Developer's Guide to Reading and Fixing Reports
- Property-Based Fuzzing: Testing Parser Security with Hypothesis in Python
- SAST in the Developer Workflow: Semgrep, Bandit, and SpotBugs Integration
- Security Unit Testing Patterns: Boundary, Injection, and Bypass Test Cases for a Validation Function
- Security Unit Testing: Writing Test Cases That Assert Security Properties
- Threat Model-Driven Test Case Generation: From STRIDE to JUnit
Cloud Security (195)
Advanced Cloud Networking (13)
- AWS Transit Gateway and AWS Network Firewall: Architecture and Security Rules
- Azure Private Endpoints, Service Tags, and Private Link Security
- Cloud API Gateway Security: Throttling, Auth, and WAF Integration
- Cloud DDoS Protection Services: AWS Shield Advanced and Azure DDoS Protection Plans
- Cloud NAT Security, Egress Control, and Data Exfiltration Prevention
- Cloud Network Segmentation Beyond VPCs: Landing Zone and Hub-and-Spoke Design
- Cloud WAF Rule Writing, Managed Rule Groups, and Tuning (AWS WAF, Azure App GW WAF)
- DNS Security in Cloud: Route 53, Azure DNS, and Cloud DNS Hardening
- GCP Shared VPC and Private Service Connect Security
- Ingress Controller Security in Cloud: NGINX and Traefik Configuration Hardening
- IPSec VPN Configuration Security Audit Lab
- Network ACL vs Security Group Traffic Evaluation Lab
- VPC Flow Log Threat Hunting Lab
Cloud Compliance And Governance (11)
- AWS Config Rules Compliance Dashboard Lab
- CIS Cloud Benchmarks for AWS, Azure, and GCP: Scoring and Remediation
- Cloud Compliance Automation: AWS Config Rules, Azure Policy, and GCP Organization Policies
- Cloud Regulatory Requirements: HIPAA, FedRAMP, and Financial Services Compliance
- Cloud Risk Assessment and Third-Party/Supply-Chain Risk in Cloud Environments
- Cloud Risk Register & Treatment Plan Lab
- Cloud Security Audit: Evidence Collection, Automation, and Audit Trail Integrity
- Cloud Security Certifications: AWS Security Specialty, AZ-500, and GCPSE Exam Guide
- Compliance Evidence Collection & Audit Pack Lab
- Data Privacy in Cloud: GDPR, CCPA, and Cloud Data Residency Controls
- FinOps and Security: Using Cost Anomalies as Indicators of Compromise
Cloud Compute And Serverless (15)
- Auto Scaling Groups and Launch Template Security Risks
- AWS Lambda Function Security: Execution Role, Layers, and Event Injection
- Azure Functions and Logic Apps Security: Managed Identity and Trigger Abuse
- Azure Virtual Machine Security and Managed Identity Attack Surface
- Cloud Function Privilege Escalation via Environment Variables and Layers
- Cloud Workload Protection Platforms (CWPP): Architecture and Deployment
- Container Image Security: Vulnerability Scanning, Signing, and Base Image Selection
- EC2 Instance Metadata Service (IMDS) Hardening Lab
- EC2 Instance Security: AMI Hardening, Instance Profiles, and IMDSv2
- EC2 User Data Script Security Analysis Lab
- Ephemeral Compute and Secrets Management in Serverless Architectures
- GCP Cloud Functions and Cloud Run Security: IAM Invokers and Env Vars
- GCP Compute Engine Security: Default Service Account and OS Login
- Lambda Layer Supply Chain Security Lab
- Serverless Attack Vectors: Event Injection, Over-Permissive Roles, and Cold Start Abuse
Cloud Foundations And Shared Responsibility (13)
- AWS/Azure/GCP Well-Architected Framework: Security Pillar Deep Dive
- Cloud Asset Inventory and Attack Surface Discovery
- Cloud Compliance Frameworks: SOC 2, ISO 27001, and PCI DSS in the Cloud
- Cloud Computing Models: IaaS, PaaS, SaaS, and the Shared Responsibility Model
- Cloud Defense-in-Depth Architecture Lab
- Cloud Provider Threat Landscape: AWS, Azure, and GCP Attack Surfaces
- Cloud Provider Trust Hierarchy Lab
- Cloud Security Architecture Patterns and Anti-Patterns
- Cloud Security Posture Management (CSPM) Fundamentals
- Cloud Shared Responsibility Boundary Mapping Lab
- Cloud-Native Security vs. Traditional On-Premises Security Approaches
- Infrastructure as Code (IaC) Security Fundamentals
- Multi-Cloud Security Architecture and Governance
Cloud Identity And Access Management (18)
- Attribute-Based Access Control (ABAC) Tag Policy Lab
- AWS IAM Deep Dive: Policies, Roles, and Permission Boundaries
- AWS IAM Permission Boundary Design Lab
- AWS Organizations and Service Control Policies (SCPs) as Security Controls
- AWS STS Temporary Credentials: Abuse, Rotation, and Detection
- Azure Active Directory Security and Privileged Identity Management
- Cloud Identity Governance: Access Reviews and Entitlement Management
- Cloud SSO and Identity Provider Integration Security
- Cross-Account and Cross-Cloud Trust Relationships and Attack Paths
- GCP IAM: Service Accounts, Predefined Roles, and Workload Identity
- IAM Policy Analysis Tools and Least Privilege Enforcement
- Identity Federation and SAML in Cloud Environments
- Instance Metadata Service (IMDS) Attacks and IMDSv2 Hardening
- Just-in-Time Privileged Access Management Lab
- Privilege Escalation via Misconfigured IAM Policies (Beyond S3/Basic)
- Privileged Access Management (PAM) for Cloud: JIT Access and Zero Standing Privilege
- Service Account Abuse and Lateral Movement in Cloud Environments
- Workload Identity and OIDC Token Federation in Cloud Pipelines
Cloud Incident Response (11)
- Cloud Incident Alert Triage Lab
- Cloud Incident Resource Containment Lab
- Post-Incident Security Hardening Lab
- Automated Cloud Incident Response with Lambda Functions and Azure Logic Apps
- Cloud Breach Timeline Reconstruction from CloudTrail, VPC Flow Logs, and App Logs
- Cloud Business Continuity and Disaster Recovery: Security Considerations
- Cloud Forensics: Acquiring and Preserving Cloud Evidence (EBS Snapshots, Disk Images)
- Cloud Incident Response Playbooks for AWS, Azure, and GCP
- Cloud Threat Intelligence: IOC Sharing and Cloud-Specific TTPs
- Memory Forensics in Cloud Instances: EC2 and VM Memory Acquisition
- Ransomware Response in Cloud: Isolation Runbooks, Recovery, and Lessons Learned
Cloud Logging And Threat Detection (13)
- AWS CloudTrail: Log Analysis, Log File Integrity, and Threat Detection Queries
- AWS GuardDuty: Full Finding Taxonomy (IAM, S3, EC2, Runtime) and Response
- Azure Monitor, Log Analytics Workspaces, and Microsoft Sentinel for Cloud Security
- Building Cloud SOC Detection Rules Mapped to MITRE ATT&CK Cloud Matrix
- Cloud SIEM Integration: Shipping Logs from AWS/Azure/GCP to Third-Party SIEMs
- Cloud-Native Behavioral Baselines and Anomaly Detection Strategies
- CloudTrail Threat Hunting Workbench Lab
- CloudWatch Log Insights Threat Query Lab
- GCP Cloud Audit Logs and Security Command Center Findings
- Log Tampering and Anti-Forensics in Cloud Environments: Techniques and Detection
- Microsoft Defender for Cloud: Threat Protection, Posture Management, and Alerts
- MITRE ATT&CK Cloud Matrix: Tactic-by-Tactic Analysis and Detection Coverage
- Security Hub Finding Aggregation Lab
Cloud Penetration Testing (15)
- Cloud Attack Surface Mapping Lab
- Cloud Secrets Discovery and Exposure Lab
- IAM Privilege Escalation Path Explorer Lab
- Assumed Breach Scenarios in Cloud: Starting from a Leaked Credential
- AWS-Specific Attack Tools: Pacu, ScoutSuite, and CloudMapper
- Azure Penetration Testing: ROADtools, MicroBurst, and AADInternals
- Cloud Attack Simulation with Stratus Red Team and MITRE ATT&CK Mapping
- Cloud Lateral Movement: Cross-Account Pivoting and Cross-Service Escalation
- Cloud Penetration Testing Methodology: Scoping, Rules of Engagement, and Reporting
- Cloud Persistence Mechanisms: Backdoor IAM Roles, EventBridge Rules, and Lambda Backdoors
- Cloud Reconnaissance: Enumerating Cloud Resources, Services, and Metadata
- Cloud Red Team Operations: Simulating APT Techniques in AWS and Azure
- Data Exfiltration from Cloud Environments: DNS, S3, and API-Based Channels
- GCP Penetration Testing: GCPBucketBrute, GCP IAM Privilege Escalation Scripts
- Post-Exploitation: Living Off the Land with AWS CLI, az CLI, and gcloud
Cloud Secrets And Key Management (11)
- Automated Secrets Rotation Workflow Lab
- AWS KMS Key Policy Access Control Lab
- AWS Secrets Manager and Parameter Store: Secure Patterns and Bypass Techniques
- Azure Key Vault: Access Policies, RBAC, and Bypass Techniques
- Cloud KMS: Key Hierarchy, Rotation Policies, and CMK Policy Misconfiguration
- Code Repository Secret Scanning Lab
- Envelope Encryption Patterns and Key Policy Attack Surfaces
- GCP Secret Manager and Cloud KMS: Security and Misconfiguration
- HashiCorp Vault in Cloud Environments: Dynamic Secrets, Leases, and Auth Methods
- HSMs in the Cloud: AWS CloudHSM, Azure Dedicated HSM, and Use Cases
- Secrets Sprawl: Detecting Hardcoded Credentials in Cloud Workloads and Repos
Cloud Storage Security (13)
- Azure Blob Storage and Data Lake Gen2 Security Controls
- Cloud Data Loss Prevention Classification Lab
- Cloud Database Exposure: RDS, Cosmos DB, and Cloud Spanner Security
- Cloud Object Storage Encryption: SSE, SSE-KMS, SSE-C, and BYOK
- Cloud Storage Access Logging, Server Access Logs, and Anomaly Detection
- Data Classification and DLP in Cloud Storage Environments
- Data Residency, Sovereignty, and Cross-Region Replication Security
- GCP Cloud Storage: IAM, ACLs, and Uniform Bucket-Level Access
- Ransomware in the Cloud: S3 Versioning, Object Lock, and Recovery Strategies
- S3 Advanced Security: Object Lock, Versioning, and Access Analyzer
- S3 Bucket Policy Access Evaluator Lab
- S3 Object Lock Ransomware Defense Lab
- Secure Data Sharing: Presigned URLs, SAS Tokens, and Temporary Access Patterns
Cloud Specific Attack Techniques (13)
- Abuse of Cloud-Native Services: CloudShell, Systems Manager, and Automation Backdoors
- Cloud Account Takeover: Social Engineering, MFA Fatigue, and Console Access Abuse
- Cloud Backdoors: Persistent Access via Shadow Admins and Hidden Policy Attachments
- Cloud Enumeration Without Authentication: Public APIs, Metadata Leaks, and OSINT
- Cloud Persistence Technique Matrix Lab
- Cloud Resource Hijacking & Tag-Based Ownership Lab
- Cloud Resource Hijacking: Cryptojacking Detection and Illicit Mining Response
- Cloud Token Theft and Credential Replay: Access Key and OAuth Token Abuse
- Confused Deputy Attacks in Cloud Service APIs and Cross-Service Calls
- Denial of Wallet Cloud Attack Lab
- Multi-Cloud Attack Chains: Pivoting Across AWS, Azure, and GCP Tenants
- Shadow IT and Rogue Cloud Resource Discovery: Enumeration and Risk Management
- SSRF to Cloud Metadata Service: Chaining Web Vulnerabilities to IAM Credential Theft
Devsecops And Secure Pipelines (11)
- Cloud-Native Application Protection Platforms (CNAPP): Architecture and Vendor Landscape
- Container Image Vulnerability Scanning in CI/CD Pipelines: Trivy and Grype
- SAST and DAST Integration in Cloud CI/CD Pipelines: Tools and Gate Configuration
- Secret Detection in Source Code and CI/CD: GitLeaks, TruffleHog, and Detect-Secrets
- Secure Build Pipelines: Immutable Infrastructure, Reproducible Builds, and Hermetic Builds
- Secure Software Development Lifecycle (SSDLC) in Cloud-Native Environments
- Shift-Left Security: Developer-Centric Cloud Security Practices and IDE Plugins
- Software Bill of Materials (SBOM): CycloneDX, SPDX, and Cloud Artifact Signing
- CI/CD Pipeline Security Gate Configuration Lab
- Container Registry Vulnerability & Image Signing Lab
- SBOM & Software Supply Chain Security Lab
Emerging Cloud Security (14)
- LLM Prompt Injection Attack Lab
- WebAssembly Module Security Inspection Lab
- Zero Trust Policy Decision Point Lab
- AI/ML Security in Cloud: SageMaker, Azure ML, and Vertex AI Attack Surface
- Cloud Security Chaos Engineering: Fault Injection, Game Days, and Resilience Testing
- Cloud Security for IoT: AWS IoT Core, Azure IoT Hub, and Device Provisioning Security
- Cloud Supply Chain Attacks: Compromised Cloud Provider SDKs and Third-Party Integrations
- Cloud-Native AI Pipeline Security: Data Poisoning, Model Theft, and Inference Attacks
- Confidential Computing: Trusted Execution Environments (TEEs) and AWS Nitro Enclaves
- eBPF Security in Cloud-Native Environments: Cilium, Falco eBPF, and Kernel-Level Visibility
- Edge Computing and Cloud Security: AWS Outposts, Azure Arc, and GCP Anthos
- Future Cloud Threats: Serverless-Native Malware, AI-Assisted Attacks, and Predictions
- Generative AI Cloud Services Security: API Key Management and Prompt Injection at Scale
- Quantum-Safe Cryptography in Cloud KMS: Post-Quantum Algorithms and Migration
Iac Security (11)
- CloudFormation and ARM Template Security Analysis
- Drift Detection: Identifying Unauthorized Manual Changes to IaC-Managed Resources
- GitOps Security: ArgoCD and Flux CD Access Control and Supply Chain Risks
- IaC Static Analysis: tfsec, Checkov, Terrascan, and KICS in CI/CD
- IaC Supply Chain: Terraform Registry Module Poisoning and Dependency Attacks
- Policy as Code: OPA, Sentinel, and Cloud-Native Policy Enforcement
- Pulumi and AWS CDK Security Considerations
- Terraform Security: State File Exposure, Remote State, and Resource Misconfiguration
- CloudFormation Guard Rule Policy Lab
- IaC Secrets Detection and Vault Integration Lab
- Terraform IaC Security Scanner (Checkov) Lab
Kubernetes And Container Orchestration (13)
- Container Runtime Escape Detection Lab
- Container Runtime Security: Falco Rules, gVisor Sandboxing, and Kata Containers
- Container Supply Chain Security: Cosign, Sigstore, SLSA Levels, and Attestations
- Kubernetes Admission Controllers: OPA Gatekeeper, Kyverno, and Policy Enforcement
- Kubernetes Audit Logging: Policy Writing and Threat Detection Playbooks
- Kubernetes Cluster Hardening: CIS Benchmark and kube-bench Deep Dive
- Kubernetes Multi-Tenancy: Namespace Isolation, Resource Quotas, and vCluster
- Kubernetes Network Policies: Writing, Testing, and Validating Effective Rules
- Kubernetes Pod Security Standards and Admission Controllers
- Kubernetes RBAC Privilege Escalation Lab
- Kubernetes Secrets Management: etcd Encryption at Rest and External Secrets Operator
- Managed Kubernetes Security: EKS vs. AKS vs. GKE Control Plane Differences
- Service Mesh mTLS Policy Security Lab
Identity Security (54)
Access Control And Adaptive Trust (7)
- Conditional Access Policy Design: Grant Controls, Conditions, and Gap Analysis
- Continuous Adaptive Trust Evaluation: Risk signals, trust scores, and re-authentication
- Identity Provider Security Hardening: Okta, Entra ID, and Ping Configuration
- Session Token Protection and Lifecycle: Issuance, Binding, and Revocation
- MFA Bypass Vector Hardener: Closing legacy protocol and fallback authentication gaps
- Risk-Based Authentication Rules: Configuring adaptive trust signals for step-up authentication
- Zero Trust Microsegmentation: Defining identity-aware access rules to contain lateral movement
Enterprise Identity Architecture (6)
- AD ACL Privilege Escalation: Identifying DCSync-enabling ACE misconfigurations
- Enterprise Identity Architecture: Directories, Protocols, and Trust Domains
- Federation Trust Relationship Security: SAML, Metadata, and Assertion Validation
- Hybrid Identity Security: Securing the Bridge Between On-Premises and Cloud
- SAML Signature Bypass Defense: Hardening SP configuration against Golden SAML attacks
- SSO Protocol Integration Selector: Choosing the right federation protocol for each application type
Identity Attack Detection And Hunting (8)
- Identity Hunting Campaign: Designing a threat hunt for password spray and account enumeration
- Kerberoasting Event Log Analysis: Detecting TGS request spikes in Windows Security logs
- Lateral Movement Log Tracer: Reconstructing pass-the-hash attack chains from Windows event logs
- Identity Attack Path Analysis: Graph-Based Privilege Escalation Discovery
- Identity Exposure Management: Discovering and Prioritising Identity Risk
- Identity Security Posture Management: Continuous Control Validation
- Identity Threat Detection and Response: Signals, Alerts, and Playbooks
- Impossible Travel Risk Detection: Geolocation, Velocity, and False Positive Management
Identity Foundations (6)
- Credential Exposure Triage: Risk-based response to breached identity data
- Identity Proofing Assurance: NIST IAL compliance for privileged onboarding
- MFA Enrollment Hardening: Phishing-resistant authentication policy design
- Identity Security Fundamentals: Principals, Claims, and Trust
- Identity Security: Why Identity Is the New Perimeter
- Identity Threat Modeling: Applying STRIDE to Identity Systems
Identity Lifecycle And Governance (8)
- Access Certification and Periodic Access Reviews: Preventing Privilege Accumulation
- Birthright Access Design: Role-Based Entitlements Without Over-Provisioning
- Identity Governance and Administration: Policies, Workflows, and SoD Enforcement
- Identity Lifecycle Management: From Provisioning to Deprovisioning
- Joiner, Mover, Leaver: Designing Secure Identity Transition Processes
- Identity Audit Trail Reconstruction: Tracing insider exfiltration through access logs
- Role Mining and RBAC Design: Extracting least-privilege roles from entitlement sprawl
- Separation of Duties Violation Detector: Identifying toxic role combinations in financial workflows
Machine And Non Human Identities (8)
- Certificate Lifecycle Management: Automated Issuance, Renewal, and Revocation
- Enterprise PKI: Root CA, Subordinate CAs, and Certificate Policies
- Machine Identity Management: Service Accounts, Managed Identities, and API Keys
- Non-Human Identity Security: Secrets, Tokens, and the CI/CD Attack Surface
- Workload Identity Security: OIDC Federation for Kubernetes and CI/CD
- CI/CD Secret Scanning: Classifying and triaging leaked credentials in pipeline configurations
- Service Principal Least Privilege: Right-sizing Azure RBAC assignments for automated workloads
- Workload Identity Token Inspector: Detecting claim anomalies in OIDC workload tokens
Privileged Access Management (5)
- Break-Glass Access Design: Emergency privileged access without standing credentials
- PAM Credential Vault Rotation: Designing automated rotation schedules to minimize credential exposure windows
- Privileged Account Discovery: Finding shadow admins and unmanaged privileged identities
- Privileged Identity Management: Just-in-time access and standing privilege elimination
- Privileged Session Management: Recording, Proxying, and Anomaly Detection
Session And Oauth Security (6)
- Browser Session Security in the Enterprise: Cookies, CSP, and CORS
- OAuth Consent Phishing and Illicit Consent: The 2FA-Resistant Identity Attack
- Refresh Token Theft and Persistence: Maintaining Access After Initial Compromise
- OAuth App Permission Auditor: Detecting Malicious Consent Grants
- PKCE Flow Implementation: Securing OAuth Authorization Code Requests
- Session Revocation Incident Response: Complete Token Termination After Credential Compromise
Network Security (139)
Advanced Scanning And Reconnaissance (7)
- Masscan High-Speed Scanning, Shodan Dorking & Censys Queries
- Nmap Scan Strategy Builder
- Nmap Scripting Engine (NSE): Custom Scripts, Vuln Scanning
- OS Fingerprinting & TTL Analysis Lab
- Passive OS Detection (p0f), Active Fingerprinting & TTL Analysis
- Passive Recon & OSINT Aggregation Lab
- Traceroute Analysis, TTL Manipulation & AS Path Mapping
Cloud And Sdn Networking Security (11)
- ALB / NLB, SSL Termination, Session Persistence Risks
- AWS / Azure / GCP VPC Design, Security Groups vs. NACLs & Flow Logs
- CDN Security Controls, Origin IP Disclosure & Cache Key Manipulation
- CNI Plugins, Kubernetes NetworkPolicy & Pod-to-Pod Traffic Control
- Istio / Envoy, mTLS Enforcement & Service Identity Policies
- Kubernetes NetworkPolicy Enforcement Lab
- Micro-Segmentation Strategies, Service Tags & Identity-Based Policies
- OpenFlow, SDN Controller Attacks & Control Plane Isolation
- SDN Controller Security Hardening Lab
- VPC Flow Logs, Cloud-Native SIEM & GuardDuty Network Findings
- VPC Security Group Rule Analyzer
Ddos Attacks And Mitigation (9)
- Amplification Factor Analysis: NTP / DNS / SSDP / Memcached
- Anycast Routing for DDoS Distribution & Cloud Scrubbing Services
- Botnet Architecture: IRC / HTTP / P2P C2 & Takedown Techniques
- DDoS Amplification Attack Factor Calculator
- DDoS Incident Response Playbook Lab
- DDoS Taxonomy: Volumetric, Protocol Exhaustion & Application-Layer
- IP Reputation, Blocklist Integration & Automated DDoS Mitigation
- SYN Flood & SYN Cookie Defense Lab
- SYN Flood Mechanics, SYN Cookies & Half-Open Connection Defense
Emerging And Specialized Topics (11)
- 5G Architecture, gNB Threats, Network Slicing Security & IMSI Catchers
- Active Defense, Distributed Canary Tokens, Fake Credentials & HoneyBadger
- CIS Network Benchmarks, NIST SP 800-53 & PCI DSS Network Requirements
- Encrypted C2 Traffic Detection Lab
- GNS3, EVE-NG & Realistic Network Simulation for Security Training
- IoT Device Attack Surface Mapper
- IXP Architecture, Route Server Security & BGP Community Controls
- JA3/JA4 TLS Fingerprinting Lab
- JA3/JA4 TLS Fingerprinting, Encrypted C2 Detection & ESNI
- OT/IT Convergence Risks, Purdue Model & IEC 62443 Security Zones
- SD-WAN Underlay/Overlay Security, Cloud Breakout & MPLS vs. SD-WAN
Firewalls And Network Access Control (11)
- 802.1X EAP Methods, RADIUS Server & NAC Enforcement
- ACL Weakness Analysis, Rule Ordering Flaws & Evasion via Fragmentation
- Firewall ACL Rule Builder & Tester
- Fragmentation, Encoding & Polymorphism for IDS/IPS Evasion
- Honeypot Types, Cowrie / T-Pot Deployment & Attacker Behavior Analysis
- IDS/IPS: Signature vs. Anomaly Detection, Snort & Suricata
- Next-Gen Firewall Policy Simulator
- NGFW: Deep Packet Inspection, App-ID, User-ID & SSL Inspection
- Snort/Suricata IDS Signature Writer
- Stateless, Stateful, NGFW, WAF & Proxy-Based Firewall Architectures
- ZTNA Principles, Micro-Segmentation & Identity-Based Perimeter
Layer 2 Attacks And Lan Security (15)
- ARP Cache Poisoning & Man-in-the-Middle Attacks
- DHCP Snooping & Dynamic ARP Inspection (Defense)
- DHCP Starvation & Rogue DHCP Server Injection
- Dynamic ARP Inspection Defense Lab
- Ethernet Frame Structure, 802.1Q VLAN Tagging & QinQ
- IPv6 Rogue RA, NDP Spoofing & RA Flood
- LLMNR / NBT-NS / mDNS Poisoning with Responder
- MAC Flooding & CAM Table Overflow
- Router & Switch Baseline Hardening (CIS Benchmarks)
- SPAN / Mirror Ports vs. Physical Network Taps for Traffic Capture
- Spanning Tree Attack & BPDU Guard Lab
- Spanning Tree Protocol Manipulation & Root Bridge Hijacking
- Switch Port Security, MAC Limiting & 802.1X EAP
- VLAN Hopping Attack & Prevention Lab
- VLAN Hopping via Double Tagging & Switch Spoofing
Network Monitoring Siem And Forensics (11)
- Detecting SMB / RDP / WMI Lateral Movement in East-West Traffic
- DNS / HTTP Exfiltration Patterns, DLP & Encrypted Channel Analysis
- IR Playbook for Network Breaches: Containment & Eradication
- NetFlow / sFlow / IPFIX Collection, Baselining & Anomaly Detection
- NetFlow Baselining & Anomaly Detection Lab
- PCAP Evidence Chain of Custody Lab
- PCAP Evidence Chain of Custody, Artifact Extraction & Triage
- Proactive Threat Hunting with Network IOCs & MITRE ATT&CK
- SIEM Alert Triage & Correlation Lab
- SIEM Ingestion Pipeline, Correlation Rules & SOAR Fundamentals
- Statistical Baselining & ML-Based Network Anomaly Detection
Physical And Hardware Network Security (7)
- Bash Bunny, Lan Turtle, Packet Squirrel & Hardware Keyloggers
- Cable Tapping, Rogue Hardware, Tailgating & Data Center Controls
- IPMI / iDRAC / iLO Vulnerabilities, BMC Attacks & OOB Isolation
- IPMI/BMC Security Hardening Lab
- Physical Network Tap & Cable Security Lab
- Rogue Hardware Detection Lab
- Scapy-Based Protocol Fuzzing, Boofuzz & Mutation-Based Fuzzing
Protocol Specific Security (11)
- FTP Bounce Attack, Anonymous Login & TFTP Enumeration
- Modbus / DNP3 / EtherNet-IP Protocols & Shodan ICS Discovery
- NFS Export Enumeration, rpcinfo & Unauthenticated Mount Attacks
- RDP Attack Surface & Defense Lab
- RDP Brute Force, BlueKeep CVE, NLA Bypass & Credential Theft
- SIP Enumeration, Call Interception, VoIP Fuzzing & SIPVicious
- SMTP Open Relay, STARTTLS Stripping & Email Header Forensics
- SNMP Enumeration & Hardening Lab
- SNMPv1/v2/v3, Community Strings, MIB Enumeration & snmpwalk
- SSH Server Hardening Configurator
- sshd_config Hardening, Key Management, Fail2ban & AllowUsers
Routing And Wan Protocol Security (11)
- BGP Prefix Hijacking, RPKI & Route Origin Validation
- BGP Route Hijacking & RPKI Validation Lab
- DNS Amplification Attack & Mitigation Lab
- DNS Amplification DDoS & DNSSEC Deployment
- ICMP Flood, Redirect Manipulation & Covert Channel Tunneling
- IPv6 Extension Headers, 6to4 / Teredo / ISATAP Vulnerabilities
- MPLS Label Switching Security & WAN Attack Surface
- NTP Amplification (monlist), Stratum Hierarchy & Hardening
- OSPF Neighbor Hijacking & Defense Lab
- OSPF Neighbor Hijacking & RIP Route Poisoning
- SSDP Amplification & UPnP Router Attack Surface
Vpn Tunneling And Anonymization (11)
- DNS Exfiltration with Iodine & DNScat2, Detection Techniques
- GRE Tunneling, VXLAN Encapsulation & Overlay Network Attacks
- IPsec VPN Tunnel Configuration Lab
- IPsec: IKEv1/v2, Tunnel vs. Transport Mode, ESP vs. AH
- Onion Routing, Hidden Services, Circuit Analysis & Exit Node Risks
- OpenVPN & WireGuard Configuration Hardening & DNS Leak
- SOCKS5 Proxies, Proxy Chains & Traffic Anonymization Strategies
- SSH Local / Remote / Dynamic Port Forwarding & Jump Hosts
- SSH Tunneling & Port Forwarding Lab
- VPN DNS & WebRTC Leak Detection Lab
- VPN Split Tunneling Risks, Rogue VPN & Traffic Interception
Windows Networking And Active Directory Attacks (11)
- Active Directory Attack Path Analyzer
- AD DS Architecture, Forests / Domains / Trusts & Replication Topology
- ADCS ESC1–ESC8 Misconfigurations & Certificate Template Abuse
- BloodHound / SharpHound, Attack Path Analysis & LDAP Enumeration
- Kerberoasting Attack & Detection Lab
- Kerberoasting, AS-REP Roasting, Pass-the-Ticket & Overpass-the-Hash
- Net Commands, PowerView, CrackMapExec for Active Directory Recon
- NTLM Challenge-Response Abuse & NTLM Relay with Impacket
- NTLM Relay & SMB Signing Defense Lab
- SMB Signing Bypass, PsExec, WMI & WinRM Lateral Movement
- TGT / TGS Forgery with Mimikatz & Kerberos Persistence Techniques
Wireless Network Security (13)
- 802.11 Deauthentication Frames, PMF & Wireless DoS
- 802.11 PMF Deauthentication Protection Lab
- BlueSnarfing, BlueBorne, BLE Recon & KNOB Attack
- Evil Twin / Rogue AP & Captive Portal Credential Phishing
- Evil Twin & Rogue AP Detection Lab
- RFID Cloning, NFC Relay Attacks & Proxmark Usage
- Wi-Fi Encryption Standards: WPA2/WPA3 & 4-Way Handshake
- WIDS Architecture, Rogue AP Detection & 802.11 Anomaly Analysis
- Wireless PCAP Analysis, Association Timeline & Key Material Recovery
- WPA2 4-Way Handshake Analyzer
- WPA2 Handshake Capture, PMKID Attack & Aircrack-ng
- WPS PIN Brute Force: Pixie Dust Attack with Reaver / Bully
- Zigbee Protocol Vulnerabilities & IoT Wireless Enumeration
Operating System Security (182)
Boot Firmware Hardware Security (10)
- BIOS/UEFI Hardening: Configuration Management and Vulnerability Mitigation
- Bootkit Malware: MBR/VBR/UEFI Bootkits and Detection Techniques
- Firmware Reverse Engineering: Extraction Methods and Analysis with Binwalk
- Hardware Security Modules (HSM): Local Key Management and Integration
- Physical Memory Attacks: Cold Boot Attacks, DMA Attacks, and Countermeasures
- Secure Boot Chain Tampering and Detection Lab
- Secure Boot: Key Management, Key Hierarchy, and Bypass Techniques
- TPM 2.0 Attestation Workflow: Interactive Lab
- TPM 2.0 Fundamentals: PCRs, Attestation, Sealed Storage, and TPM Attacks
- UEFI/BIOS Security: Architecture, Vulnerabilities, and Secure Boot Chain
Cross Platform Specialized Os (7)
- Container-Optimized OS Security: CoreOS vs Bottlerocket vs Talos Lab
- RTOS Attack Surface Mapping: FreeRTOS and VxWorks Lab
- Air-Gapped System Security: Offline OS Hardening and Data Diode Controls
- Container-Optimized OS Security: CoreOS, Bottlerocket, and Talos Linux Hardening
- Emerging OS Security: eBPF Applications, Capability-Based OS Design, and Confidential Computing OS
- OS Security in CI/CD: Hardened Build Agents, Ephemeral Runners, and Build Environment Security
- Real-Time Operating System (RTOS) Security: FreeRTOS, VxWorks, and Embedded OS Security
Exploit Mitigation Binary Exploitation (17)
- Address Space Layout Randomization (ASLR): Implementation and Bypass Techniques
- Control Flow Integrity (CFI): Forward-Edge and Backward-Edge Protections
- Data Execution Prevention (DEP/NX): Hardware and Software Implementation
- Exploit Mitigation Decision Matrix: Evaluating Defense Layers
- Format String Vulnerabilities: Exploiting printf-Family Functions
- Heap Exploitation: Use-After-Free, Heap Spray, and Modern Allocator Security
- Integer Overflow and Underflow: Exploitation and Secure Coding
- Kernel Exploitation Fundamentals: Ring Transitions, Kernel Object Abuse, and ret2usr
- Memory Safety Fundamentals: Stack vs. Heap, Memory Layout, and Buffer Overflows
- Position-Independent Executables (PIE) and RELRO: Exploit Mitigation Analysis
- Race Conditions and TOCTOU in OS Context: Kernel and System Call Exploitation
- Return-Oriented Programming (ROP): Gadget Chaining and ASLR Bypass
- ROP Chain Construction: Gadget Selection and Chain Building Lab
- SafeStack and ShadowCallStack: Compiler-Based Exploit Mitigations
- SMEP, SMAP, and Kernel Self-Protection: Bypassing Kernel Exploit Mitigations
- Stack Canaries and Stack Smashing Protector (SSP): Bypass Techniques
- Stack-Based Buffer Overflow Exploitation: x86 and x64 Techniques
Linux Hardening Access Control (17)
- SELinux Policy Decision Engine: Allow/Deny Simulation Lab
- Systemd Unit File Security Hardening: Directive Configuration Lab
- AppArmor: Profile Development, Confined Applications, and Audit Mode
- Linux Access Control Lists (ACLs) and Extended Attributes (xattr)
- Linux Audit Framework (auditd): Rule Writing, Log Analysis, and AUREPORT
- Linux Capabilities: Fine-Grained Privilege Management and Capability Exploitation
- Linux CIS Benchmark Hardening: Level 1 and Level 2 Controls
- Linux File System Permissions: DAC, SUID/SGID Bits, and Sticky Bit Security
- Linux Kernel Hardening: sysctl Parameters, kptr_restrict, and dmesg_restrict
- Linux Mount Options and Filesystem Hardening: noexec, nosuid, nodev
- Linux Namespaces and cgroups: Isolation Primitives and Security Implications
- Linux Package Management Security: GPG Verification, Repository Pinning, and Dependency Auditing
- Linux User and Group Management: UID/GID Security, /etc/shadow, and Account Policies
- PAM (Pluggable Authentication Modules): Architecture, Modules, and Password Policy Enforcement
- SELinux: Mandatory Access Control, Policies, Modes, and Troubleshooting
- sudo Configuration and Privilege Delegation: Sudoers Best Practices and Pitfalls
- Systemd Security: Unit File Hardening, Sandboxing Directives, and Service Isolation
Linux Monitoring Detection (10)
- eBPF Security Monitoring: Writing and Testing Detection Rules Lab
- Seccomp BPF Filter Design: Syscall Allowlist Construction Lab
- eBPF for OS Security Monitoring: BPFTrace, Tetragon, and Kernel-Level Visibility
- Linux Host-Based IDS: AIDE File Integrity Monitoring and Tripwire
- Linux Memory Analysis: /proc/mem, Volatility, and Live Forensics
- Linux Process Monitoring: /proc Filesystem, ps, lsof, and Anomaly Detection
- Linux System Call Auditing with strace and seccomp Filters
- Linux System Logging: syslog, rsyslog, and journald Security Configuration
- OSSEC/Wazuh Agent on Linux: Real-Time Threat Detection and FIM
- Rootkit Detection on Linux: chkrootkit, rkhunter, and Manual Indicators of Compromise
Linux Persistence Evasion (9)
- Linux Persistence Mechanism Hunt: Identification and Eradication Lab
- LKM Rootkit Analysis: Kernel Symbol Comparison and Detection Lab
- Linux Credential Theft: /etc/shadow, PAM Backdoors, and Memory Credential Dumping
- Linux Malware Analysis: ELF Binary Analysis, Reverse Engineering, and Sandbox Techniques
- Linux Persistence Mechanisms: Cron, Systemd Units, .bashrc, and SSH Authorized Keys
- Linux Process Injection: /proc/mem Injection, ptrace API, and LD_PRELOAD
- Linux Rootkits: LKM-Based Rootkits, Preload Hijacking, and Process Hiding
- Living Off the Land on Linux: LOLBins and Built-In Tools for Post-Exploitation
- Log Tampering and Anti-Forensics on Linux
Linux Privilege Escalation (12)
- Cron Job and Scheduled Task Abuse for Linux Privilege Escalation
- GTFOBins Exploitation Lab: SUID, Sudo, and Shell Escape Techniques
- Linux Container Escape: Privileged Containers and Docker Socket Abuse
- Linux Kernel Exploitation: Dirty COW, Dirty Pipe, and Kernel CVE Analysis
- Linux Privilege Escalation Decision Tree: Interactive Methodology Lab
- Linux Privilege Escalation Methodology: Enumeration with LinPEAS and Manual Techniques
- NFS no_root_squash and Weak Export Exploitation
- Shared Library Hijacking and LD_LIBRARY_PATH Manipulation
- Sudo Misconfiguration Exploitation: Sudoers Abuse and LD_PRELOAD Tricks
- SUID/SGID Binary Abuse: GTFOBins and Custom SUID Exploitation
- Weak File Permissions and World-Writable Critical Files
- Writable PATH and Environment Variable Hijacking for Privilege Escalation
Macos Security (10)
- macOS Code Signing and Notarization: Security Benefits and Bypass Techniques
- macOS Endpoint Detection: XProtect, MRT, and Third-Party EDR Integration
- macOS Gatekeeper Bypass Techniques: Analysis and Detection Lab
- macOS Hardening: CIS macOS Benchmark and Security Configuration
- macOS Malware Analysis: .app Bundles, Launch Daemons, and Mach-O Binary Analysis
- macOS Persistence Mechanisms: Launch Agents, Launch Daemons, and cron
- macOS Privilege Escalation: Local Techniques and CVE-Based Exploits
- macOS Security Architecture: Gatekeeper, System Integrity Protection (SIP), and TCC
- macOS TCC (Transparency Consent Control): Abuse Techniques and Privacy Protections
- macOS TCC Permission Matrix: Abuse and Defense Lab
Malware Analysis Endpoint Protection (12)
- AMSI and EDR Bypass Techniques: In-Memory Patching and API Unhooking
- Antivirus Evasion Techniques: Encoding, Packing, and Polymorphism
- Code Obfuscation and Packing: Unpacking Techniques with UPX and Custom Packers
- Dynamic Malware Analysis: Sandbox Execution, API Monitoring, and Behavioral Analysis
- Endpoint Detection and Response (EDR): Architecture, Telemetry, and Detection Logic
- Linux Malware Families: Botnets, Coin Miners, and Backdoor Persistence
- Malware Behavioral Profiling: IOC Extraction and ATT&CK Mapping Lab
- Static Malware Analysis: PE/ELF Headers, Strings, and Disassembly with Ghidra
- Threat Intelligence Integration with Endpoint Security: IOC Management and MISP
- Windows Malware Families: RATs, Ransomware, Droppers, and Loader Techniques
- YARA Rule Builder: Malware Signature Development and Testing Lab
- YARA Rule Writing: Malware Signature Development and Testing
Mobile Os Security (9)
- Android App Permission Risk Calculator: Audit and Analysis Lab
- Android Malware Analysis: APK Reverse Engineering, Smali, and Dynamic Analysis
- Android Privilege Escalation and Rooting: Kernel Exploits and Bootloader Unlocking
- Android Security Architecture: Permission Model, Binder IPC, and Application Sandboxing
- iOS Entitlement Abuse and Sandbox Escape Analysis Lab
- iOS Jailbreaking: Techniques, Security Implications, and Enterprise Risk
- iOS Security Model: Secure Enclave, Code Signing, and Application Sandboxing
- Mobile OS Forensics: Acquisition Methods, Artifacts, and Tool Comparison
- Mobile OS Hardening: Android Enterprise and iOS MDM Security Profiles
Os Benchmarks Compliance (7)
- CIS Benchmark Control Prioritization: Risk-Based Remediation Lab
- Multi-Framework OS Compliance Gap Analysis Lab
- Automated OS Compliance Scanning: OpenSCAP, Ansible Hardening, and Compliance as Code
- DISA STIG Implementation: Defense-in-Depth OS Hardening Standards
- Operating System Security Benchmarks: CIS Benchmarks Framework and Scoring
- OS Security Metrics and KPIs: Measuring and Reporting OS Security Posture
- OS Vulnerability Management: CVE Lifecycle, Patch Prioritization, and Tracking
Os Forensics Incident Response (14)
- Bootkit and Rootkit Forensics: MBR/VBR Analysis and Memory Artifacts
- Digital Evidence Acquisition and Triage: Chain of Custody Lab
- Disk Forensics: Partition Analysis, File System Artifacts, and Deleted File Recovery
- File System Forensics: NTFS, ext4, APFS, and Artifact Deep Dive
- Linux Forensics: Artifact Locations, Log Analysis, and Timeline Reconstruction
- Linux Incident Response: Volatile Data Collection, Process Analysis, and Containment
- Log Timeline Reconstruction: Multi-Source Event Correlation Lab
- macOS Forensics: Unified Log, FSEvents, and Artifact Analysis
- Memory Forensics Fundamentals: Volatility Framework and Plugin Usage
- OS Forensics Methodology: Evidence Acquisition, Chain of Custody, and Triage
- OS-Level Threat Hunting: Hypothesis-Based Investigation on Endpoints
- Timeline Analysis and Supertimeline Creation with Plaso
- Windows Forensics: Registry Hives, Event Logs, Prefetch, and Shellbags Analysis
- Windows Incident Response: Rapid Triage, Autoruns Analysis, and Lateral Movement Detection
Virtualization Hypervisor Security (10)
- Hyper-V Security: Architecture, Virtualization-Based Security (VBS), and Hardening
- Hypervisor Attack Surface Mapping: Component Analysis Lab
- Hypervisor Security Architecture: Type 1 vs. Type 2 Hypervisors and Attack Surface
- KVM/QEMU Security: Attack Surface, Hardening, and CVE Review
- Side-Channel Attacks on VMs: Spectre, Meltdown, and Microarchitectural Attacks
- Snapshot Security and VM Forensics: Evidence Acquisition and Analysis
- Virtual Machine Hardening: Guest OS Security, vTPM, and Secure Configuration
- VM Escape Technique Analysis: Hypervisor Vulnerability Lab
- VM Escape Techniques: Hypervisor Vulnerabilities and CVE Analysis (VENOM, Escape Chains)
- VMware ESXi Security: Hardening, vSphere Security, and Exploit History
Windows Architecture Access Control (14)
- Windows Access Token Anatomy: Privilege Inspection and Abuse Lab
- Windows AppLocker and WDAC: Application Whitelisting and Policy Enforcement
- Windows Credential Storage: LSA Secrets, DPAPI, SAM Database, and Credential Manager
- Windows DACL Effective Rights Calculator: Permission Inheritance Lab
- Windows Group Policy Security: Computer and User Configuration Security Settings
- Windows Mandatory Integrity Control (MIC): Integrity Levels and Privilege Separation
- Windows NTFS Permissions: DACLs, SACLs, Permission Inheritance, and Effective Rights
- Windows Registry Security: ACLs, Auditing, and Security-Critical Registry Keys
- Windows Scheduled Tasks Security: Task Scheduler Abuse and Detection
- Windows Security Account Manager (SAM): Local Authentication and Offline Cracking
- Windows Security Architecture: Security Reference Monitor, Access Tokens, and Privilege Model
- Windows Service Security: Service Binary Permissions, Service Control Manager, and DACLs
- Windows Token Manipulation: Impersonation, Delegation, and Token Duplication
- Windows User Account Control (UAC): Architecture, Bypass Techniques, and Hardening
Windows Hardening Features (12)
- PowerShell Security Policy Configuration: Logging, CLM, and AMSI Lab
- Windows Attack Surface Reduction (ASR) Rules: Configuration and Bypass Techniques
- Windows BitLocker: Full Disk Encryption, TPM Integration, and Recovery Key Management
- Windows CIS Benchmark Hardening: Security Baseline Configuration
- Windows Credential Guard and Device Guard: VSM-Based Credential Protection
- Windows Defender and AMSI: Architecture and Bypass Techniques
- Windows Event Logging and Auditing: Policy Configuration and EVTX Analysis
- Windows Firewall Advanced Security: Rule Management and Domain vs. Local Policy
- Windows Patch Management: WSUS, Windows Update, and Vulnerability Lifecycle
- Windows PowerShell Security: Constrained Language Mode, ScriptBlock Logging, and AMSI
- Windows Secure Boot and TPM: UEFI Secure Boot Chain and TPM 2.0 Integration
- Windows Security Baseline Compliance: Registry and GPO Audit Lab
Windows Privilege Escalation (12)
- Windows Potato Attacks: Token Impersonation Privilege Escalation Lab
- WinPEAS Output Analysis: Identifying and Prioritizing Privesc Paths Lab
- AlwaysInstallElevated and Windows Installer Privilege Escalation
- Windows Credential Dumping: Mimikatz, LSA Dump, and DPAPI Decryption
- Windows DLL Hijacking: Search Order Hijacking and DLL Planting
- Windows Exploit Mitigation Bypass: DEP, ASLR, SEHOP, and CFG Circumvention
- Windows Persistence: COM Hijacking, WMI Subscriptions, and Bootkit Techniques
- Windows Privilege Escalation Methodology: Enumeration with WinPEAS and Seatbelt
- Windows Process Injection: DLL Injection, Process Hollowing, and Reflective Loading
- Windows Registry Run Key Persistence and Autorun Security
- Windows Service Exploitation: Unquoted Service Paths and Weak Binary Permissions
- Windows Token Impersonation: Potato Attacks (JuicyPotato, PrintSpoofer, RoguePotato)
Web Security (158)
Apis Emerging Technologies (8)
Authentication Credentials (8)
Business Logic Operations Capstone (8)
Xss Client Side (7)
Cryptography Data Protection (6)
Data Crypto Db Foundations (6)
Exploitation Fuzzing Tools (9)
- Advanced Burp Suite Workflows: Macros, Session Handling, Match-and-Replace, Extensions
- Fuzzing and Brute-Forcing with Burp Intruder and OWASP ZAP
- Hashcat Cracking Lab
- Hydra & Medusa: Online Brute-Forcing of Web Logins
- Manual Payload Fuzzing Lab
- Metasploit Framework Fundamentals for Web Exploitation
- Netcat, Listeners, and Reverse/Web Shells
- searchsploit & Exploit-DB: From Version to Proof-of-Concept
- sqlmap: Automating SQL Injection
Forgery Redirects Ssrf Uploads (8)
Introduction (12)
- Broken Access Control — IDOR in a Note-Taking App
- Broken Authentication: Credential Attacks & Registration Bypass
- Components With Known Vulnerabilities: CVE Exploitation
- Insecure Deserialization: Cookie Manipulation & RCE
- Insufficient Logging & Monitoring — Brute-Force Log Analysis
- OWASP Top 10 Mapping Lab
- Security Misconfiguration: Default Credential Exploitation
- Sensitive Data Exposure — SQLite & Hash Cracking
- SQL Injection Login Bypass
- Web Vulnerability Quick-Fire Lab
- XSS Playground — Reflected, Stored & DOM
- XXE File Disclosure via Malicious XML
Methodology Secure Design (7)
- CVSS 3.1 Scoring Lab
- Cybersecurity First Principles and the Security Mindset
- Penetration Testing Methodology and the Engagement Lifecycle
- STRIDE Threat Modeling Lab
- The OWASP Top 10 - A Guided Tour and Risk Framing
- Threat Modeling and Secure Design (STRIDE)
- Web Hacking Ethics, Authorization, and Rules of Engagement
Osint Metadata Hidden Data (6)
Other Injection Classes (5)
Professional Practice Lab (9)
- Bug Bounty Hunting Methodology and Workflow
- Building a Testing Lab: Docker and Kali Linux Concepts
- Capture the Flag Strategy and Practical Problem-Solving
- Cybersecurity Careers, Certifications, and Continuous Learning
- Getting Started with Kali Linux for Web Application Testing
- Virtualization and Building a Safe Practice Lab
- Vulnerability Reporting, CVSS, and Coordinated Disclosure
- Bug Report Writer Lab
- Responsible Disclosure Lab
Recon Scanning Traffic Tools (8)
- Automated Vulnerability Scanning and Triage
- Intercepting Proxies: Burp Suite and OWASP ZAP
- Nikto and WhatWeb: Web Server Fingerprinting and Quick Scanning
- Nmap Simulator Lab
- Nmap: Service and Port Discovery for Web Targets
- Traffic Analysis Lab
- Wireshark & tcpdump: Capturing and Analysing Web Traffic
- WPScan: Scanning WordPress and CMS Targets
Reconnaissance Discovery (6)
Security Misconfiguration Hardening (6)
Server Side Injection (9)
- Command Injection Chain Lab
- Input Validation and Output Encoding (Secure Coding)
- Local and Remote File Inclusion (LFI/RFI)
- NoSQL Injection - Operator and $where Manipulation
- OS Command Injection and Remote Code Execution
- Path Traversal and Arbitrary File Access
- Server-Side Template Injection (SSTI)
- SQL Injection - Data Extraction with UNION
- SSTI Sandbox Lab
Sessions Sso Access Control (6)
Smuggling Caching Evasion (6)
Systems Programming Foundations (8)
- Bash Scripting Primer
- Linux and Command-Line Fundamentals for Security
- Linux Basics, Part 1: The Shell, Filesystem, and Navigation
- Linux Basics, Part 2: Permissions, Packages, and Text Processing
- Programming and Scripting for Penetration Testers
- Python Primer for Penetration Testers
- Bash Pentesting Lab
- Python Exploit Lab
Web Networking Foundations (10)
- Anatomy of a Modern Web Application
- How Networks Work, Part 1: TCP/IP, IP Addressing, Ports, and Sockets
- How Networks Work, Part 2: DNS, TLS, and Certificate Trust
- How the Web Is Built: HTML, CSS, JavaScript, and the Client-Server Model
- HTTP and the Web Request–Response Model
- Reading a Connection: URL, Port, and Certificate Inspection
- The Browser as a Security Boundary: Origins and the Same-Origin Policy
- The Browser Security Model: CORS, CSP, and Security Headers
- DNS Rebinding Lab
- HTTP Request Dissector Lab