Skip to content

THE DEADWIRE COURSE

This course is under construction. There are fifteen developed lessons and three short outlines; the complete private-library synthesis is not published yet. The content and coverage map identifies what you can study now and the chapters still missing.

Read developed lessons now

  1. 00 · Learn with evidence: prediction, observation and a first 90-minute session.
  2. 01 · Security foundations: actors, objects, policy and controlled comparisons.
  3. 07 · Linux and networking: process identity, file modes and HTTP diagnosis.
  4. 02 · Windows and Active Directory: tokens, directory relationships and an access worksheet.
  5. 03 · Kerberos: ticket flow, metadata interpretation and competing explanations.
  6. 08 · Web authorization: reproduce a vulnerable/fixed boundary.
  7. 05 · Detection: run two rules against six labeled synthetic requests.
  8. 06 · Reporting: preserve evidence, bound impact and verify remediation.

Extend the core route with these available lessons:

Then branch into industrial systems:

Three remaining numbered pages are scope outlines. The route above is available now; it does not require waiting for book distillation. Each page names its depth at the top. Book processing does not automatically turn drafts into complete lessons.

AD pilot prerequisite path: Foundations, Windows and AD, Kerberos, lateral movement, detection, reporting, then capstone.

The diagram is the AD pilot path. The 24-week learner plan describes the wider intended curriculum and brings Linux and networking forward before identity work. Use the available route above for material that is already written. Lesson numbers are stable topic identifiers, not calendar weeks.

Completion contract

For each lesson, save four pieces of evidence in your private Hacking/Deadwire/learning/ area: a one-paragraph explanation, a lab transcript with secrets removed, a detection or defensive observation, and a short reflection on what failed. A reading check alone is not completion.

Set up the disposable environment with the student lab manual before starting an active exercise.

Current state

The prose below is the initial authored spine. It is not a claim that every source has already been distilled. Source coverage is tracked in source map; model-generated expansions must pass the review and provenance gates in evaluation.

The learner route

Phase Lessons Evidence you leave behind
Orient 00 Scope, lab readiness, and a baseline explanation
Build the model 01–03 Concepts, identity flow, and a short teach-back
Operate 04–06 One bounded technique, telemetry, and a report
Expand 07–14 Domain-specific drills selected by the reviewed plan
Prove Capstone End-to-end assessment with reproducible evidence

The stable spine is intentionally predictable. Adaptive ordering may move a learner forward or back after evidence is recorded, but it cannot skip prerequisites or convert reading into mastery.

Read the status labels correctly

  • Outline: intended scope with a short introduction; teaching depth remains incomplete.
  • Developed: an explanation and exercise are written; this does not establish independent review or student outcomes.
  • Generated: a draft produced by the distillation pipeline and awaiting review.
  • Approved: a canonical note accepted with source references.
  • Verified: a command or technique demonstrated in an authorized lab with saved evidence.

These labels are separate on purpose. A green build badge or a complete lesson page does not mean the five-book pilot or the learner outcome gates have passed.