beginnerFoundations
Blue Team Operations
Blue Team Operations is about how defenders actually do the work of defense day to day. Threat landscape gives you the adversary view; security foundations gives you the controls vocabulary; logging and monitoring gives you the visibility infrastructure. This course brings them together into the operational practice. What the teams who defend organizations actually do, how they organize, and what makes their work effective.
6 lessons · about 240 minutes · updated 14/07/2026
Sign in to view coursebeginnerFoundations
Cloud Security Foundations
Cloud computing has fundamentally changed how organizations build and operate technology, and with it, what defenders need to know. The traditional perimeter-based model where most assets sat in corporate data centers has given way to environments distributed across public cloud platforms, SaaS applications, and hybrid combinations. Defending these environments requires understanding their unique characteristics, risks, and controls.
6 lessons · about 240 minutes · updated 14/07/2026
Sign in to view coursebeginnerFoundations
Cryptography Essentials
Cryptography Essentials gives you a working defender's understanding of cryptography. Enough to reason about how systems protect data, why specific designs fail, and what questions to ask when reviewing a security control. You won't leave this course able to implement AES from scratch, and you don't need to. You'll leave able to read a system design and spot where cryptography is used well, where it's misused, and where it's missing entirely.
7 lessons · about 240 minutes · updated 14/07/2026
Sign in to view coursebeginnerFoundations
Defensive Web Fundamentals
Defensive Web Fundamentals introduces the core ideas behind how the web works and why web systems are such common security targets. You probably use websites every day, but using them doesn't mean you understand what's happening between the browser, the server, the application, and the data behind the page. This course builds that understanding specifically for defensive work.
8 lessons · about 240 minutes · updated 14/07/2026
Sign in to view coursebeginnerFoundations
Identity and Access Management
Identity and Access Management (IAM) is the discipline of managing who can access what, under which conditions, and how that's enforced across systems. It's one of the highest-leverage areas of security work. Most modern breaches involve identity in some way, and the controls in this space prevent or contain the largest share of incidents.
7 lessons · about 240 minutes · updated 14/07/2026
Sign in to view coursebeginnerFoundations
Logging, Monitoring, and Telemetry
If hardening is about preventing incidents, logging and monitoring is about seeing them. Both the ones that succeed and the ones that fail noisily on the way. Without telemetry, defenders are blind. With well-designed telemetry, even sophisticated attacks leave traces that mature detection finds.
6 lessons · about 240 minutes · updated 14/07/2026
Sign in to view coursebeginnerFoundations
Networking Foundations
Networking Foundations introduces the first layer of every cybersecurity defender's mental model: how computers actually talk to each other. Before you can make sense of firewalls, intrusion detection, web defense, cloud security, or incident investigation, you need to understand what a packet is, how addresses and names work, what a port does, and why traffic flows the way it does.
8 lessons · about 240 minutes · updated 14/07/2026
Sign in to view coursebeginnerFoundations
Operating Systems for Defenders
Operating Systems for Defenders gives you the working knowledge of Windows and Linux internals that defensive work actually requires. Not a system administration course, not a developer course. A defender's view of how operating systems organize processes, users, files, and logs so you can read evidence, recognize abnormal behavior, and reason about compromised endpoints.
6 lessons · about 240 minutes · updated 14/07/2026
Sign in to view coursebeginnerFoundations
Security Foundations
Security Foundations gives you the mental structure that every other cybersecurity topic builds on. Before you can think clearly about web defense, identity management, system hardening, incident response, governance, or cloud security, you need a clear picture of what security is trying to protect, why it exists, and how defenders reason about risk, trust, access, and control.
8 lessons · about 240 minutes · updated 14/07/2026
Sign in to view coursebeginnerFoundations
Security Governance and Program Foundations
Technical security controls don't sustain themselves. Behind every working detection rule, every patched system, every restricted account is a program. Funded, structured, prioritized, and held accountable. Governance is the term for that program-level work. It's how organizations decide what to protect, how much to invest, what risks they'll accept, and who's responsible for what.
6 lessons · about 180 minutes · updated 14/07/2026
Sign in to view coursebeginnerFoundations
System Hardening Fundamentals
System Hardening Fundamentals is about reducing the attack surface of systems before attackers ever reach them. Hardening doesn't catch incidents. It prevents them, or limits their impact when prevention fails. The work is unglamorous but produces some of the highest returns of any security investment: incidents that don't happen don't need investigating.
6 lessons · about 210 minutes · updated 14/07/2026
Sign in to view coursebeginnerFoundations
Threat Landscape and Attacker Thinking
Most new defenders learn controls before they learn attackers. That's backwards. Multi-factor authentication, segmentation, and patching are easier to understand, and easier to prioritize, when you already know what they're defending against.
6 lessons · about 180 minutes · updated 14/07/2026
Sign in to view courseintermediateGRC
Audit and Assurance
Audit and assurance is a substantial discipline. Internal audit provides independent oversight; external audits produce attestation reports; specific assessments support risk-informed decisions. This course covers audit and assurance work from the practitioner perspective. What auditors actually do, how to support audits effectively, how to lead assessments, and how to operate audit-mature programs.
7 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseintermediateGRC
Business Continuity and Disaster Recovery Planning
The difference between organizations that recover from disruptive incidents in hours and those that spend weeks rebuilding is almost entirely in preparation: documented plans, tested procedures, validated backups, and practiced response. This course covers BC/DR as practiced by organizations that take resilience seriously, from business impact analysis through backup design, plan writing, testing, and ongoing program operations.
5 lessons · about 240 minutes · updated 14/07/2026
Sign in to view courseintermediateCloud
Cloud Compliance and Frameworks
Cloud security engineering produces the technical posture; compliance demonstrates it meets regulatory and contractual requirements. This course covers cloud compliance as practiced. Specific frameworks (SOC 2, PCI-DSS, HIPAA, FedRAMP, ISO 27001), how cloud changes compliance work, the shared responsibility implications for compliance, and what cloud security engineers and GRC practitioners actually do to achieve and maintain compliance.
7 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseintermediateCloud
Cloud Security Engineer Fundamentals
Cloud Security Foundations covered cloud security at a conceptual level. Shared responsibility, basic identity, exposed storage, fundamental telemetry. Cloud Security Engineer Fundamentals goes deep on what cloud security engineers actually do: hands-on configuration, architecture, automation, and the operational discipline that makes cloud environments defensible.
8 lessons · about 360 minutes · updated 14/07/2026
Sign in to view courseintermediateCloud
Cloud Workload Protection
Cloud Security Engineer Fundamentals covered workload protection at engineering depth across VM, container, and serverless workloads. This course goes deeper. Focusing specifically on the protection patterns, the specific tools and techniques, and the operational practices that produce defensible workloads in cloud environments.
7 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseintermediateCloud
Cloud-Native Security
Cloud-native architectures: kubernetes, microservices, service mesh, GitOps represent how modern applications are increasingly built. Securing these architectures requires understanding both the technologies and the cultural patterns surrounding them. This course goes deep on cloud-native security as an integrated discipline rather than just Kubernetes hardening.
7 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseintermediateSOC
Detection Engineering
Detection engineering is the discipline of building, testing, tuning, and maintaining the rules that drive security detection. As the field has matured, this work has emerged as a distinct role with its own methodology, tooling, and career path. Where SOC analysts triage what detection produces, detection engineers shape what detection looks for.
7 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseintermediateIAM
Directory Services Security
Active Directory is the identity foundation of most enterprise Windows environments, and the primary target of sophisticated attackers. Domain compromise gives attackers access to every system in the domain. This course covers securing Active Directory and Azure AD/Entra ID: hardening configurations, detecting attacks in progress, and recovering from compromise.
5 lessons · about 240 minutes · updated 14/07/2026
Sign in to view courseintermediateGRC
GRC Analyst Fundamentals
GRC: governance, Risk, and Compliance is the discipline of managing security as organizational program rather than purely technical practice. GRC analysts and practitioners work at the intersection of policy, regulation, risk, and operations. They produce the policies, assess risks, manage compliance, support audits, and provide visibility to leadership about security posture and decisions.
7 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseintermediateGRC
GRC Capstone: Building a Security Program
The GRC Capstone integrates everything from the GRC branch into a single applied scenario: building a complete security program for a fictional company from the ground up. Rather than covering new concepts, the capstone applies existing skills to realistic, connected problems. The kind GRC practitioners actually face.
11 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseintermediateIAM
IAM Capstone: Building an Identity Program
The IAM branch covered IAM engineering, directory services security, and privileged access management as separate disciplines. This capstone integrates them through a connected scenario: building an identity program for a fictional organization from an immature starting point to a functional, secure IAM program.
5 lessons · about 240 minutes · updated 14/07/2026
Sign in to view courseintermediateIAM
IAM Engineer Fundamentals
Identity and access management is both a security domain and an engineering discipline. IAM engineers design, implement, and operate the systems that determine who can access what. Authentication, authorization, identity lifecycle, federation, and privileged access. Poor IAM is the root cause of a large fraction of security breaches; effective IAM is foundational to every other security control.
6 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseintermediateSOC
Incident Response Operations
Blue Team Operations covered the incident lifecycle conceptually. SOC Analyst Fundamentals covered how analysts hand off to incident response. This course goes inside what happens after that handoff. The actual practice of responding to confirmed incidents through their lifecycle.
7 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseintermediateGRC
Policy Writing in Practice
Policy documents are foundational governance artifacts, and most organizations have policies nobody reads, follows, or updates. The gap between having policies and having policies that work is where GRC practitioners earn their keep.
5 lessons · about 210 minutes · updated 14/07/2026
Sign in to view courseintermediateIAM
Privileged Access Management
Privileged accounts: administrative credentials with elevated access are the most targeted accounts in any organization. Compromise of a single privileged account can cascade to full organizational compromise. Privileged Access Management (PAM) is the discipline of securing, managing, and monitoring these highest-risk credentials. This course covers PAM implementation and operations for enterprise environments.
5 lessons · about 240 minutes · updated 14/07/2026
Sign in to view courseintermediateGRC
Risk Management Fundamentals
GRC Analyst Fundamentals introduced risk management. This course goes deeper. What risk management actually requires beyond basic methodology, how to do it well, and what mature risk programs look like. The course covers the discipline of risk management as practitioners do it, with focus on producing useful decisions rather than just documentation.
7 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseintermediateSOC
SIEM Query Fundamentals
SIEM platforms are the operational core of most SOC environments. Analysts spend the majority of their working time writing queries, investigating alerts, and building searches that surface attacker behavior in log data. This course covers SIEM querying as a practical skill. Not the theory of log analysis, but the mechanics of writing queries that find real threats in real data.
5 lessons · about 240 minutes · updated 14/07/2026
Sign in to view courseintermediateSOC
SOC Analyst Capstone
The SOC branch has covered analyst fundamentals, detection engineering, incident response, threat hunting, threat intelligence, SIEM querying, and ATT&CK-based detection writing as separate disciplines. This capstone integrates them through a connected multi-week scenario: a sophisticated attack against a fictional organization that requires the full SOC skillset to detect, investigate, and respond to.
6 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseintermediateSOC
SOC Analyst Fundamentals
Blue Team Operations covered what blue teams do at a high level. SOC Analyst Fundamentals goes deep on what one specific role. The SOC analyst. Actually does day-to-day, and how to do it well. The work is practical and learnable: triage alerts, investigate findings, document cases, escalate appropriately, and contribute to ongoing improvement of detection and response.
7 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseintermediateSecurity Analyst
Security Analyst Fundamentals
The security analyst role sits between operational security (SOC) and governance (GRC). Analysts assess security posture, evaluate vulnerabilities, support risk decisions, and produce the reports and recommendations that help organizations understand and improve their security. This course covers the analyst role as practiced. The methodologies, mindsets, and skills that distinguish effective analysts from those who just run tools.
5 lessons · about 240 minutes · updated 14/07/2026
Sign in to view courseintermediateSecurity Analyst
Security Assessment Methodology
Security Assessment Fundamentals introduced the analyst role and basic vulnerability assessment. This course goes deeper: structured methodologies for different assessment types, how to conduct effective security architecture reviews, how web application assessments work, and how to handle the full engagement lifecycle from scoping through remediation verification.
5 lessons · about 240 minutes · updated 14/07/2026
Sign in to view courseintermediateGRC
Security Awareness and Culture
Security awareness programs are one of the most widely implemented, and most widely ineffective. Security controls. Annual compliance training that employees click through to get their certificate doesn't change behavior. This course covers what actually works: how to design programs that produce behavioral change, how to run phishing simulations effectively, how to measure culture, and how to embed security into organizational systems rather than just training calendars.
4 lessons · about 210 minutes · updated 14/07/2026
Sign in to view courseintermediateGRC
Security Frameworks and Control Mapping
Security frameworks are the organizing structures of GRC work. Practitioners need to be fluent across multiple frameworks. Understanding what each covers, how they differ, when each is appropriate, and how they connect. This course provides that fluency: a practitioner-level comparative view of the major frameworks a GRC analyst encounters.
6 lessons · about 240 minutes · updated 14/07/2026
Sign in to view courseintermediateSOC
Threat Hunting Fundamentals
Threat hunting is the proactive search for adversaries in the environment. Looking for what detection didn't catch, what alerts didn't surface, what hasn't been triggered yet. Where SOC analysts work reactively from alerts, threat hunters work proactively from hypotheses. Where detection engineers build rules to find known patterns, hunters find patterns that don't yet have rules.
7 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseintermediateSOC
Threat Intelligence for SOC Analysts
Threat intelligence is information about adversaries. Who they are, what they do, what they want, and how they operate. For SOC analysts, IR specialists, hunters, and detection engineers, threat intelligence shapes the work fundamentally. It informs what to detect, what to hunt for, what to prioritize, and how to interpret findings. This course covers threat intelligence as it actually applies to security operations. Practical use rather than abstract theory.
6 lessons · about 240 minutes · updated 14/07/2026
Sign in to view courseintermediateSecurity Analyst
Vulnerability Management
Vulnerability management is a continuous operational process. Not a periodic scan. Organizations that treat vulnerability management as "run Nessus quarterly and export the report" have vulnerability programs that don't reduce risk. This course covers vulnerability management as the operational discipline it actually is: continuous discovery, risk-based prioritization, SLA-driven remediation, and closed-loop verification.
5 lessons · about 240 minutes · updated 14/07/2026
Sign in to view courseintermediateSOC
Writing Detections with ATT&CK
Detection Engineering introduced the discipline of building detections systematically. SIEM Query Fundamentals covered the mechanics of querying log data. This course brings them together with MITRE ATT&CK as the organizing framework. Using ATT&CK to map detection coverage, identify gaps, and write detections for specific techniques that produce resilient, documented coverage.
5 lessons · about 240 minutes · updated 14/07/2026
Sign in to view courseadvancedSOC
Advanced Threat Hunting
Threat Hunting Fundamentals introduced the concept and basic approaches to hunting. This advanced course covers hypothesis-driven hunting at scale. Building hunting programs rather than individual hunts, hunting in cloud environments and across identity telemetry, detecting sophisticated living-off-the-land techniques, and converting hunt findings into durable detections.
6 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseadvancedSOC
Applied Malware Analysis for Defenders
Vulnerability scanners and EDR tools tell you what they detected. Malware analysis tells you what that thing actually does. How it persists, what it communicates with, what data it accesses, and what its capabilities are. That knowledge transforms incident response from reactive cleanup to informed eradication, and turns individual incidents into threat intelligence.
6 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseadvancedSecurity Analyst
Applied Threat Modeling
Threat modeling is design-time security analysis. Identifying threats and required mitigations before code is written, before architecture is finalized, before deployment. Done well, threat modeling prevents entire classes of vulnerabilities from existing. Done poorly, it becomes documentation theater that doesn't change designs. This course covers threat modeling as practice: methodologies, facilitation, integration with SDLC, and producing outputs that drive secure design.
5 lessons · about 240 minutes · updated 14/07/2026
Sign in to view courseadvancedCloud
Cloud Incident Response
Incident response in cloud environments uses different data sources, investigation techniques, and containment approaches than on-premises IR. Cloud IR professionals must understand cloud-native telemetry, ephemeral resource challenges, forensic collection methods, and the cloud-specific incident types that differ from traditional breaches. Compromised IAM credentials, storage exposure, cryptomining, and supply chain compromise through CI/CD pipelines.
6 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseadvancedCloud
Cloud Security Architecture
The intermediate cloud branch covered cloud security engineering. How to secure individual cloud services and workloads. This course covers cloud security architecture. Designing the foundational structure of cloud environments before workloads land in them. Landing zone design, multi-account strategy, network architecture, security tooling integration, multi-tenant SaaS security, and architectures for regulated industries. The decisions covered here shape every workload that subsequently runs in the environment.
6 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseadvancedSecurity Analyst
Cloud Security Assessment
Web application penetration testing assesses applications. Cloud security assessment evaluates cloud environments. The AWS, Azure, or GCP infrastructure where applications run. Cloud assessment uses different tools, looks for different issues, and produces different findings than traditional security assessment.
6 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseadvancedGRC
Compliance Program Design and Operations
Achieving initial compliance certification (SOC 2, ISO 27001, HIPAA) is a project. Maintaining compliance continuously while supporting business growth is a program. This course covers building and operating a multi-framework compliance program at scale. Automation tooling, evidence collection, audit management, framework mapping to reduce duplication, and using compliance as a competitive differentiator for B2B SaaS companies. Practical guidance for the GRC professional building a real program, not just understanding the frameworks.
6 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseadvancedIAM
Customer Identity and Access Management
Enterprise IAM (covered in the IAM branch) handles employees, contractors, and partners. Customer Identity and Access Management (CIAM) is the distinct discipline of managing identity for an application's end users. Consumers, citizens, business customers. The scale is different (millions of users vs thousands of employees), the UX requirements are different (consumers won't tolerate enterprise-style friction), the security model is different (account takeover and fraud are primary threats), and the business model is different (CIAM directly impacts conversion and retention).
5 lessons · about 240 minutes · updated 14/07/2026
Sign in to view courseadvancedCloud
DevSecOps and Secure SDLC
Security that's bolted on after development is expensive, disruptive, and incomplete. DevSecOps integrates security throughout the development lifecycle. Not as a gate at the end, but as a continuous practice embedded in the same pipelines and workflows developers already use. This course covers DevSecOps as practiced: security in CI/CD, dependency management, container security, infrastructure-as-code scanning, and building security culture with engineering teams.
6 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseadvancedIAM
Identity Governance and Administration
The IAM Capstone covered identity engineering. Building the systems that authenticate users, provision accounts, and control access. This course covers identity governance. The policy, process, and oversight layer that ensures identity systems are used appropriately at enterprise scale. IGA platforms (SailPoint, Saviynt, Omada) provide the technological backbone for governance activities: access certification campaigns, role mining and engineering, segregation of duties enforcement, identity analytics, and compliance reporting.
6 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseadvancedSOC
Incident Response Leadership
Incident Response Practice taught how to execute the technical incident response lifecycle. This course covers what comes when an incident is bigger than one analyst. Leading a coordinated response across multiple teams, communicating with executives during a crisis, navigating legal and regulatory implications, and turning incidents into lasting program improvement. The Incident Commander role, the communication discipline, and the post-incident leadership work that determines whether the organization actually gets safer.
6 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseadvancedGRC
Privacy Law and GDPR Practice
Privacy compliance has shifted from a legal formality to an operational discipline. Organizations that process personal data face a patchwork of global privacy regulations. GDPR, CCPA, LGPD, PDPA, and dozens of others. Each with specific requirements, enforcement mechanisms, and penalties. This course covers privacy as a practice: how to operationalize compliance, not just understand it conceptually.
6 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseadvancedGRC
Risk Quantification with FAIR
Security risk management runs on qualitative ratings. High, Medium, Low. That can't answer the questions boards and executives actually have: "How much should we spend on this control?" "Which of these two initiatives reduces our risk more?" "What is our cybersecurity risk exposure in dollars?" Qualitative ratings produce defensible-looking documentation but don't support financial decision-making.
6 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseadvancedGRC
Security Architecture Review
Vulnerability scans find weaknesses in deployed code. Penetration testing finds exploitable issues in running systems. Security architecture review finds problems in the design. Before deployment, in the structure of the system itself. A flaw in architecture (authentication that's bypassable by design, data flows that route sensitive information through unprotected intermediaries, trust relationships built on assumptions) often can't be fixed by a patch. It requires redesign.
6 lessons · about 300 minutes · updated 14/07/2026
Sign in to view courseadvancedSOC
Security Operations Program Design
SOC Analyst Capstone taught what individual analysts do. This course covers what SOC leaders design and operate. The structural, operational, and strategic decisions that determine whether a SOC delivers consistent value. Staffing models, shift structures, alert management, SLA design, detection program governance, metrics that matter, and building the business case for SOC investment.
5 lessons · about 240 minutes · updated 14/07/2026
Sign in to view courseadvancedSecurity Analyst
Web Application Penetration Testing
Web application penetration testing is the disciplined practice of finding security vulnerabilities in applications. Before attackers do. Within a defined, authorized scope. This course covers the full methodology: from engagement scoping through systematic vulnerability discovery, exploitation (to demonstrate impact), and clear reporting that drives remediation.
6 lessons · about 360 minutes · updated 14/07/2026
Sign in to view courseadvancedIAM
Zero Trust Architecture
Zero Trust is a security model, not a product. It rejects the historical assumption that everything inside the network perimeter is trusted and instead requires continuous verification of every request regardless of source. This course covers Zero Trust as an architectural discipline. How to design, implement, and mature a Zero Trust program using the NIST SP 800-207 framework as the organizing structure.
6 lessons · about 300 minutes · updated 14/07/2026
Sign in to view course