Complete catalog

All published courses

Browse every published course, its level, lesson count, scope, and update date. Course access inside the workspace follows your invitation, entitlement, and learning route.

56 courses currently published.

beginnerFoundations

Blue Team Operations

Blue team operations connect people, evidence, decisions, and technical controls so an organization can detect harmful activity, respond proportionately, recover services, and improve. The work includes security monitoring, alert triage, incident response, detection engineering, threat hunting, vulnerability coordination, threat intelligence, forensics, platform engineering, and service ownership. Smaller organizations may combine these responsibilities; larger organizations may separate them.

6 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
beginnerFoundations

Cloud Security Foundations

Cloud security begins with the exact service, identity, data, network, configuration, telemetry, recovery, and provider boundary-not a vendor logo. Providers operate substantial infrastructure, while customers retain responsibilities that vary by service and configuration. Managed does not mean automatically secure, compliant, observable, or recoverable.

6 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
beginnerFoundations

Cryptography Essentials

Cryptography Essentials gives you a working defender's understanding of cryptography. Enough to reason about how systems protect data, why specific designs fail, and what questions to ask when reviewing a security control. You won't leave this course able to implement AES from scratch, and you don't need to. You'll leave able to read a system design and spot where cryptography is used well, where it's misused, and where it's missing entirely.

7 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
beginnerFoundations

Defensive Web Fundamentals

Defensive Web Fundamentals introduces the core ideas behind how the web works and why web systems are such common security targets. You probably use websites every day, but using them doesn't mean you understand what's happening between the browser, the server, the application, and the data behind the page. This course builds that understanding specifically for defensive work.

8 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
beginnerFoundations

Identity and Access Management

Identity and Access Management (IAM) is the discipline of managing who can access what, under which conditions, and how that access is enforced across systems. It is a high-leverage area of security work because compromised credentials, sessions, permissions, and recovery processes appear in many intrusion paths. Well-designed identity controls can prevent initial access, limit privilege, and contain incidents.

7 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
beginnerFoundations

Logging, Monitoring, and Telemetry

Security telemetry helps defenders answer what happened, where, when, to whom, and with what result. Collecting many logs is not the same as having dependable evidence. This course treats telemetry as an engineered service: define requirements, cover sources, monitor pipelines, govern records, and validate the resulting data for investigation and detection.

6 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
beginnerFoundations

Networking Foundations

Networking Foundations introduces the first layer of every cybersecurity defender's mental model: how computers actually talk to each other. Before you can make sense of firewalls, intrusion detection, web defense, cloud security, or incident investigation, you need to understand what a packet is, how addresses and names work, what a port does, and why traffic flows the way it does.

8 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
beginnerFoundations

Operating Systems for Defenders

Operating Systems for Defenders introduces the Windows and Linux internals most relevant to entry-level defensive work. It is not a complete system-administration or development course; it presents a defender's view of how operating systems organize processes, identities, files, and logs so you can interpret evidence, recognize potentially abnormal behavior, and reason about compromised endpoints.

6 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
beginnerFoundations

Security Foundations

Security Foundations gives you the mental structure that every other cybersecurity topic builds on. Before you can think clearly about web defense, identity management, system hardening, incident response, governance, or cloud security, you need a clear picture of what security is trying to protect, why it exists, and how defenders reason about risk, trust, access, and control.

8 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
beginnerFoundations

Security Governance and Program Foundations

Security governance connects organizational mission, stakeholder expectations, risk decisions, authority, resources, controls, evidence, and accountability. It does not mean that a governance team personally operates every control or decides every legal question. Good governance makes decision rights explicit, keeps claims within evidence, and routes specialist determinations to qualified owners.

6 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
beginnerFoundations

System Hardening Fundamentals

System Hardening Fundamentals is about reducing exploitable conditions before and during attacker activity. Hardening can prevent some attack paths and limit impact when prevention fails, but it does not replace visibility, response, recovery, or secure design. Its value should be evaluated through reduced exposure and tested control outcomes rather than assumed from the absence of reported incidents.

6 lessons · about 210 minutes · updated 02/09/2026

Sign in to view course
beginnerFoundations

Threat Landscape and Attacker Thinking

Controls and adversary behavior are easier to understand together. Multi-factor authentication, segmentation, and patching become more meaningful when learners can connect them to assets, failure modes, and realistic attack paths.

6 lessons · about 180 minutes · updated 02/09/2026

Sign in to view course
intermediateGRC

Audit and Assurance

Audit and assurance includes several related but distinct disciplines. Internal audit provides independent and objective assurance and advice to the organization. External practitioners may perform audits, attestation examinations, or certification work under engagement-specific standards. Security and control assessments support risk decisions but do not automatically provide the same level or type of assurance. This course explains how to distinguish those engagements, support them effectively, evaluate evidence, and manage remediation.

7 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
intermediateGRC

Business Continuity and Disaster Recovery Planning

Recovery outcomes depend on the event, affected dependencies, architecture, people, suppliers, decisions, and preparation. Documented and exercised plans, validated recovery capabilities, and maintained backups can reduce uncertainty, but they do not guarantee a particular recovery time. This course covers business continuity and disaster recovery from impact analysis through strategy, recovery design, exercises, and continual improvement.

5 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
intermediateCloud

Cloud Compliance and Frameworks

Cloud security engineering contributes technical safeguards, while compliance and assurance evaluate applicable legal, contractual, policy, and framework requirements using evidence. Neither a certification nor a tool score proves that every relevant risk is controlled. This course covers how cloud service models, provider dependencies, scoped assurance, customer configuration, and rapidly changing services affect compliance work.

7 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
intermediateCloud

Cloud Security Engineer Fundamentals

Cloud Security Foundations covered cloud security at a conceptual level. Shared responsibility, basic identity, exposed storage, fundamental telemetry. Cloud Security Engineer Fundamentals goes deep on what cloud security engineers actually do: hands-on configuration, architecture, automation, and the operational discipline that makes cloud environments defensible.

8 lessons · about 360 minutes · updated 02/09/2026

Sign in to view course
intermediateCloud

Cloud Workload Protection

Cloud workload protection applies different safeguards to virtual machines, container artifacts and runtimes, Kubernetes, functions, and managed compute. The engineering challenge is not buying one platform or turning on every scanner. It is defining each workload’s trust boundaries, expected behavior, identities, evidence, response authority, and lifecycle, then proving that the selected controls cover those conditions.

6 lessons · about 360 minutes · updated 02/09/2026

Sign in to view course
intermediateCloud

Cloud-Native Security

Cloud-native architectures can combine containers, Kubernetes, microservices, service meshes, declarative APIs, and GitOps practices. Securing them requires understanding the selected architecture, its implementation, and its operating model rather than assuming that any one tool makes a system cloud-native or secure.

7 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
intermediateSOC

Detection Engineering

Detection engineering is the discipline of building, testing, tuning, and maintaining the rules that drive security detection. As the field has matured, this work has emerged as a distinct role with its own methodology, tooling, and career path. Where SOC analysts triage what detection produces, detection engineers shape what detection looks for.

7 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
intermediateIAM

Directory Services Security

Active Directory is a core identity system in many enterprise Windows environments and a high-value attacker target. Domain-level compromise can expose broad access, but actual reach still depends on segmentation, trust, credentials, and resource controls. This course covers securing Active Directory Domain Services and Microsoft Entra ID: hardening configurations, detecting identity attacks, and planning recovery from compromise.

5 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
intermediateGRC

GRC Analyst Fundamentals

GRC (governance, risk, and compliance) is the discipline of managing security as an organizational program rather than only as a technical practice. GRC analysts and practitioners work at the intersection of policy, regulation, risk, and operations. Depending on their mandate, they may help develop policies, assess risks, coordinate compliance work, support audits, and give decision-makers visibility into security posture.

7 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
intermediateGRC

GRC Capstone: Building a Security Program

This capstone applies governance, risk, compliance, policy, assurance, resilience, third-party risk, and executive communication to one fictional B2B software company. The goal is not to produce the biggest register or the longest policy. It is to create a traceable chain from business context and obligations to risk decisions, controls, evidence, accountable action, and leadership oversight.

6 lessons · about 360 minutes · updated 02/09/2026

Sign in to view course
intermediateIAM

IAM Capstone: Building an Identity Program

The IAM branch covered IAM engineering, directory services security, and privileged access management as separate disciplines. This capstone integrates them through a connected scenario: building an identity program for a fictional organization from an immature starting point to a functional, secure IAM program.

5 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
intermediateIAM

IAM Engineer Fundamentals

Identity and access management is both a security domain and an engineering discipline. IAM engineers design, implement, and operate the systems that determine who can access what. Their scope includes authentication, authorization, identity lifecycle, federation, and privileged access. Weak IAM can turn one compromised identity into broad access; effective IAM helps prevent, limit, and detect that abuse.

6 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
intermediateSOC

Incident Response Operations

Incident response turns uncertain security signals into controlled decisions. Responders must establish what is known, preserve evidence, limit harm, coordinate authorized actions, and help services recover without claiming more certainty than the evidence supports. The work is technical, but its quality also depends on authority, communication, documentation, legal and privacy handoffs, and operational judgment.

6 lessons · about 360 minutes · updated 02/09/2026

Sign in to view course
intermediateGRC

Policy Writing in Practice

Security policies record management direction, responsibilities, and requirements. Their value depends on whether the text is authorized, understandable, connected to implementable procedures and controls, communicated to the right audience, and maintained as the organization changes.

5 lessons · about 210 minutes · updated 02/09/2026

Sign in to view course
intermediateIAM

Privileged Access Management

Privileged access lets a human or workload make high-impact changes to systems, identities, data, or security controls. Compromise or misuse can create organization-wide effects, but scope depends on the role, resource boundary, and surrounding controls. Privileged Access Management (PAM) combines identity, authorization, credential or secret management, session controls, monitoring, and governance to reduce that risk. This course covers product-neutral PAM implementation and operations for enterprise environments.

5 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
intermediateGRC

Risk Management Fundamentals

GRC Analyst Fundamentals introduced risk management. This course goes deeper into what the discipline requires beyond a basic lifecycle: how practitioners establish context, select methods, communicate uncertainty, recommend treatment, and support authorized decisions. The focus is useful risk management rather than documentation for its own sake.

7 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
intermediateSOC

SIEM Query Fundamentals

SIEM platforms are a central investigation and detection tool in many SOC environments. Analysts use queries to investigate alerts, test hypotheses, and surface suspicious behavior in log data. This course treats SIEM querying as a practical skill: understanding the available telemetry, writing defensible searches, and interpreting the results without treating a query hit as proof of compromise.

5 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
intermediateSOC

SOC Analyst Capstone

This capstone integrates alert triage, SIEM analysis, detection engineering, incident coordination, threat hunting, intelligence, evidence handling, recovery, and communication through one fictional healthcare intrusion. The objective is not to guess a hidden answer. It is to make defensible decisions from incomplete evidence, preserve uncertainty, ask the next useful question, coordinate action with accountable owners, and improve the system after the incident.

6 lessons · about 360 minutes · updated 02/09/2026

Sign in to view course
intermediateSOC

SOC Analyst Fundamentals

Blue Team Operations covered what blue teams do at a high level. SOC Analyst Fundamentals examines what SOC analysts do day to day and how to do it well. The work is practical and learnable: triage alerts, investigate findings, document cases, escalate appropriately, and contribute to ongoing improvement of detection and response.

7 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
intermediateSecurity Analyst

Security Analyst Fundamentals

The security analyst role often sits between operational security (SOC) and governance, risk, and compliance (GRC). Analysts assess security posture, evaluate vulnerabilities, support risk decisions, and produce reports and recommendations that help organizations understand and improve security. This course covers the role as practiced, including the methods, mindsets, and skills that distinguish analysis from simply running tools.

6 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
intermediateSecurity Analyst

Security Assessment Methodology

Security Analyst Fundamentals introduced the analyst role, and Vulnerability Management established a risk-based remediation workflow. This course goes deeper: it covers authorized architecture and web-application assessments, evidence handling, reporting, and remediation verification from scope definition through closure.

5 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
intermediateGRC

Security Awareness and Culture

Security awareness and training are common parts of a security program, but completion records alone do not show that people can recognize risk or take the expected action. This course covers how to design a risk-based cybersecurity and privacy learning program, use simulations responsibly, evaluate multiple forms of evidence, and reinforce secure behavior through organizational systems as well as training.

4 lessons · about 210 minutes · updated 02/09/2026

Sign in to view course
intermediateGRC

Security Frameworks and Control Mapping

Security programs use standards, control catalogs, risk frameworks, laws, contractual schemes, assessment methods, and assurance reports. These sources are often grouped under the word "framework," but they do not have the same authority or produce the same evidence. This course builds the comparative fluency needed to select, map, and describe them accurately.

6 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
intermediateSOC

Threat Hunting Fundamentals

Threat hunting is a structured, analyst-initiated search for adversary activity or security-relevant behavior that has not already been resolved by routine alert handling. A hunt may begin from a threat hypothesis, a detection or visibility gap, unusual data, a changed environment, an incident pattern, or credible intelligence. What makes the work defensible is not one mandatory methodology; it is a bounded question, suitable evidence, documented analysis, calibrated conclusions, and an operational outcome.

6 lessons · about 360 minutes · updated 02/09/2026

Sign in to view course
intermediateSOC

Threat Intelligence for SOC Analysts

Threat intelligence is analyzed information about threats that supports a decision. It may address actors, capabilities, infrastructure, campaigns, opportunities, intent, targeting, or likely impact. For SOC analysts, incident responders, hunters, and detection engineers, relevant intelligence can help shape what to detect, what to hunt for, what to prioritize, and how to interpret findings. This course focuses on practical use while preserving uncertainty, source limitations, and decision context.

6 lessons · about 240 minutes · updated 02/09/2026

Sign in to view course
intermediateSecurity Analyst

Vulnerability Management

Vulnerability management is a continuous risk-reduction discipline, not a scanner report. It connects reliable asset knowledge, safe assessment, finding validation, threat and business context, owned remediation, verification, exception governance, and measurable outcomes. A scanner can provide evidence, but the program must decide whether an asset is affected, what action is appropriate, who owns it, and how closure will be proved.

6 lessons · about 360 minutes · updated 02/09/2026

Sign in to view course
intermediateSOC

Writing Detections with ATT&CK

MITRE ATT&CK is a versioned knowledge base of adversary behavior, not a ready-made list of production rules. Detection engineering uses ATT&CK to describe relevant behavior, research defensive opportunities, connect analytics to evidence, and communicate tested coverage. A technique label does not prove that a rule detects every procedure, platform, sub-technique, or stage of that behavior.

6 lessons · about 360 minutes · updated 02/09/2026

Sign in to view course
advancedSOC

Advanced Threat Hunting

Threat hunting is a proactive, evidence-driven search for malicious or risky activity that existing detections may have missed. Advanced hunting is not an unbounded search for anything unusual. It defines a question, determines whether available telemetry can answer it, measures the population actually examined, validates suspicious results, and turns knowledge into response, better data, detections, or safer system design.

6 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
advancedSOC

Applied Malware Analysis for Defenders

Malware analysis helps defenders explain what a suspicious artifact is capable of, what it did in a specific incident, and which evidence can support containment and detection. The objective is not to reverse every instruction. It is to answer prioritized response questions with controlled methods, preserve uncertainty, and stop when the remaining analysis will not improve a decision.

6 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
advancedSecurity Analyst

Applied Threat Modeling

Threat modeling analyzes representations of a system to identify security and privacy concerns, decide what to do about them, and evaluate whether the analysis was good enough. It is useful early, when design options remain open, and throughout the system’s life as architecture, users, dependencies, incidents, and business consequences change.

6 lessons · about 420 minutes · updated 02/09/2026

Sign in to view course
advancedCloud

Cloud Incident Response

Cloud incident response applies familiar response principles to identities, control planes, managed services, short-lived workloads, and evidence that may exist only when logging was configured beforehand. The responder must know what each provider record includes, what it omits, how long it remains available, and which containment action could destroy evidence or interrupt critical service.

6 lessons · about 360 minutes · updated 02/09/2026

Sign in to view course
advancedCloud

Cloud Security Architecture

Cloud security architecture turns business, security, resilience, and regulatory requirements into a governed platform that workload teams can use safely. The work is broader than drawing a network diagram or enabling a provider security service. Architects must decide where boundaries sit, how identities and workloads cross them, which controls are inherited, how evidence is preserved, how exceptions expire, and how the design will evolve without creating unmanaged paths around it.

6 lessons · about 360 minutes · updated 02/09/2026

Sign in to view course
advancedSecurity Analyst

Cloud Security Assessment

Cloud security assessment determines whether identities, policies, resources, workloads, data, logs, and recovery capabilities enforce the organization’s intended boundaries across cloud control planes. It combines examination of configuration and architecture with interviews, observation, and carefully authorized tests. A posture scanner can support this work, but it cannot establish ownership, business purpose, effective exposure, or control effectiveness on its own.

6 lessons · about 420 minutes · updated 02/09/2026

Sign in to view course
advancedGRC

Compliance Program Design and Operations

An attestation, certification, authorization, validation, or legal compliance obligation is not a one-time badge. Each has a different issuer, scope, test, period, and assurance meaning. This course covers the operating system behind defensible compliance: obligation and scope management, control ownership, automation limits, evidence quality, independent assessment, framework mapping, and accurate customer assurance. It does not treat SOC 2, ISO certification, HIPAA obligations, PCI validation, or government authorization as interchangeable.

6 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
advancedIAM

Customer Identity and Access Management

Customer Identity and Access Management governs how consumers, citizens, patients, customers, customer-organization members, and other external users register, authenticate, recover, link identities, manage privacy choices, and access digital services. CIAM shares protocols and security principles with workforce IAM, but external populations introduce self-service enrollment, anonymous abuse, uncertain identity evidence, diverse devices, high availability, fraud, tenant boundaries, privacy choices, customer support, and rapid abandonment when journeys fail.

6 lessons · about 360 minutes · updated 02/09/2026

Sign in to view course
advancedCloud

DevSecOps and Secure SDLC

DevSecOps integrates security work into the way software is designed, built, tested, released, operated, and improved. It is not a scanner added at the end of a delivery pipeline. A mature program combines engineering practices, protected build systems, risk-based automation, accountable human decisions, and feedback from production. This course develops that operating model across application code, dependencies, secrets, containers, infrastructure as code, dynamic testing, runtime signals, and CI/CD identities.

6 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
advancedIAM

Identity Governance and Administration

Identity governance and administration turns identity data and access policy into controlled, reviewable decisions across an organization. It does not replace directories, identity providers, application authorization, privileged-access controls, or human accountability. It coordinates authoritative identity sources, account and entitlement data, lifecycle changes, requests, approvals, reviews, role and segregation-of-duties models, remediation, evidence, and control measurement.

6 lessons · about 360 minutes · updated 02/09/2026

Sign in to view course
advancedSOC

Incident Response Leadership

Incident Response Practice taught how to execute technical response activities. This course covers what happens when an incident exceeds one analyst's scope: coordinating multiple teams, communicating with leaders under uncertainty, working with qualified legal and regulatory specialists, and turning evidence into lasting program improvement. It focuses on incident-command discipline, documented decision authority, and post-incident learning.

6 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
advancedGRC

Privacy Law and GDPR Practice

Privacy compliance is an operational discipline, not a one-time legal review. It connects product design, data governance, identity, security, procurement, records management, incident response, and communication with individuals. This course uses the EU General Data Protection Regulation (GDPR) as its principal working model while showing how practitioners build a repeatable process for any applicable privacy regime.

6 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
advancedGRC

Risk Quantification with FAIR

Qualitative categories can screen and route risks, but an ordinal label cannot by itself estimate probable loss or compare a control's lifecycle cost with the uncertainty it may reduce. FAIR (Factor Analysis of Information Risk) decomposes a defined loss-event scenario into the probable frequency and probable magnitude of future loss. FAIR is commonly used for financial quantification, although the current model can also support non-financial or qualitative measurement.

6 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
advancedGRC

Security Architecture Review

Security architecture review examines whether a system's design can satisfy its security, privacy, resilience, and operational requirements under credible threat conditions. It complements code review, configuration assessment, penetration testing, and operational monitoring. Done early, it finds costly design problems before teams build dependencies around them; done on an existing system, it helps expose systemic risk and guide a realistic target state.

6 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
advancedSOC

Security Operations Program Design

SOC Analyst Capstone taught what individual analysts do. This course examines the system that SOC leaders design around that work: operating models, staffing and fatigue controls, alert ownership, service objectives, detection governance, measures, and investment decisions. The goal is not to copy an industry template. It is to create an accountable operating model that matches the organization's threats, services, legal duties, data, people, and recovery needs.

5 lessons · about 300 minutes · updated 02/09/2026

Sign in to view course
advancedSecurity Analyst

Web Application Penetration Testing

Web application penetration testing is an authorized, evidence-led assessment of how an application behaves when its security assumptions are challenged. The objective is not to run the largest number of tools or produce the most dramatic exploit. It is to give the owner reliable findings, bounded proof of impact, and practical remediation without causing avoidable harm.

6 lessons · about 420 minutes · updated 02/09/2026

Sign in to view course
advancedIAM

Zero Trust Architecture

Zero trust is an enterprise security model that protects resources without granting implicit trust solely because a subject or asset is inside a network, owned by the organization, or previously authenticated. A zero trust architecture evaluates access to a specific resource using enterprise policy and available subject, asset, resource, environment, threat, and activity information, then establishes, monitors, and can terminate the authorized path.

6 lessons · about 360 minutes · updated 02/09/2026

Sign in to view course