Learning

Practical security knowledge, written the way the work actually happens.

Most security training teaches the textbook version. This is the version from the alert queue, the incident bridge, and the box that would not give up root. Each track is built around how the work is actually done: the decisions, the order you make them in, and the mistakes that cost the most time.

Everything here is free, and every track stands on its own. Read it, then go apply it. That second step is where the learning happens.


Who It's For

Everyone. Security is a team sport, and every seat on the team needs a different part of the playbook.

New to security

Students, career changers, and the curious. Each track starts from the fundamentals, so start at the beginning and work through in order.

Security practitioners

Analysts and engineers already in the field. Jump straight to the page you need and use the frameworks and walkthroughs as a reference.

Engineers and IT

The people who own the systems. Learn what a security team needs from you when an alert fires or an incident is declared, and why.

Leaders and non-technical readers

Managers, executives, and partners in legal, comms, and HR. Learn how the work is run, who makes which calls, and what good looks like.


Tracks

Each track stands on its own. If you are new to the field, take them in order. If you already have ground under you, jump straight to the one you need.

Defense Investigations & Triage

How alerts get worked: from a claim that something bad happened to a decision backed by evidence.

  • Playbooks and the questions to ask before you touch a single log
  • Where the evidence lives and how to land on a disposition
  • Walkthroughs: user-reported phishing, EDR malware detection, Okta suspicious activity
Start the track →
Defense Security Incident Response

What happens once triage confirms impact, and how to run it so the response holds up under pressure.

  • Incident management vs incident response, and why they are different roles
  • The lifecycle from declaration to lessons learned, and the incident command structure
  • Executive summaries and postmortems, with templates
Start the track →
Offense Offensive Security

The attacker's side of the same problem. Understanding it is what makes triage and incident response sharper.

  • Attack methodology from reconnaissance to root
  • Where to practice: HackTheBox and TryHackMe
  • Going further: automating your attack chains and publishing writeups
Start the track →

How to use this material: read the track, then apply it. Triage a real alert using the disposition framework. Run a postmortem on a real incident using the templates. Root a box and write up the methodology instead of just moving to the next one. What separates people is whether they used it. More tracks are on the way.