Course content and missing chapters
The complete course is still being written. The site currently contains fifteen developed lessons and three short outlines. A book appearing in the source catalog means it was inventoried; it does not mean its knowledge is taught here. The five-book AD distillation queue is also only one part of the wider curriculum.
Lessons you can use now
| Lesson | Material available | Exercise type |
|---|---|---|
| 00 · Learning with evidence | Predictions, contradictory observations, first session and mastery evidence | Claim-calibration worksheet |
| 01 · Foundations | Actor/action/object/policy, positive and negative controls, bounded impact | Local vulnerable/fixed comparisons |
| 07 · Linux and networking | Process identity, temporary-file modes, transport versus HTTP, address mapping | Local POSIX and HTTP experiments |
| 02 · Windows and AD | Directory/context/resource separation, tokens, path prerequisites | Six-case synthetic policy worksheet; optional native identity inspection |
| 03 · Kerberos | Exchanges, service identity, validity and authentication versus authorization | Five synthetic cases; optional current-session cache inspection |
| 05 · Detection | Labels, confusion matrices, precision/recall and telemetry gaps | Bundled six-case offline evaluator and counterexample |
| 06 · Reporting | Reproduction, bounded findings, evidence checksums and remediation retests | End-to-end report from the web fixture |
| 08 · Web authorization | Request lifecycle, object authorization, vulnerable/fixed comparison, finding writeup | Bundled local HTTP app |
| 04 · Remote administration | Reachability, authentication, endpoint authorization and execution evidence | Five synthetic cases; optional bounded Windows remoting query |
| 09 · Cloud and containers | Exact policy decisions, control/data authority and workload boundaries | Local Python evaluator and synthetic configuration review; optional Docker inspection |
| 10 · Code and byte analysis | Byte order, length contracts, data flow, rejected ambiguity and mutation limits | Bundled six-case binary decoder and finite mutation exercise |
| 14 · Cryptography | Hash trust, HMAC test vectors, key ownership and replay limits | Bundled offline integrity experiment and public-test-key counterexample |
| 15 · SCADA architecture | Controllers, HMI, historian, control authority, dependencies and attack prerequisites | Fictional topology and assessment model |
| 16 · Industrial protocols | Modbus requests, register interpretation, policy comparison and detector blind spots | Bundled offline decoder with seven synthetic records |
| 17 · OT investigation | Attack-path reasoning, maintenance correlation, detection counterexamples, response and recovery decisions | Evidence timeline and scenario investigation |
“Developed” means a substantial explanation and a specified exercise are written. It does not mean independently reviewed, exhaustive, certification-equivalent, or demonstrated by a student. The setup guides and evidence templates are also available; they are supporting material rather than additional technical chapters.
The wider path
These gaps come from comparing the current chapter pages with the library's source families and the stated broad course scope. They are work still to do, not hidden pages that will appear after refreshing.
| Track | Current page and depth | Chapters or depth still needed |
|---|---|---|
| Security foundations and assessment | 01, 06: developed introductory sequence | Broader threat models, assessment methodologies, production risk analysis and independent report review |
| Linux and operating systems | 07: developed process/file introduction | Services, storage, ACLs, capabilities, namespaces and Linux privilege escalation labs |
| Networking | 07: developed HTTP diagnostic exercises | Ethernet, addressing, routing, full DNS/TCP/TLS teaching, packet analysis and service enumeration |
| Programming, computer science and mathematics | 10: developed byte/parser introduction | Broader Python automation, shell/PowerShell, C and memory, data structures and probability |
| Windows internals | 02: developed token/context introduction | Native token lab validation, services, registry, credential storage and local privilege boundaries |
| Active Directory and identity | 02, 03: developed introductory worksheets | Native AD lab validation, directory ACLs, delegation, policy, trusts, certificate services and NTLM |
| Remote administration and lateral movement | 04: developed path reasoning; native execution pending | Validated two-host Windows lab, SMB/RDP/service/task mechanisms, controlled pivoting and credential hygiene |
| Web applications and APIs | 08: developed authorization lesson only | HTTP state, authentication, sessions, injection, XSS, SSRF, file handling, business logic and API authorization |
| Bug bounty and vulnerability research | Web lesson provides one reporting example | Scope triage, duplicate assessment, reproducible evidence, disclosure workflow and research methodology |
| Cloud security | 09: developed policy/boundary introduction | Provider-specific AWS/Azure/GCP labs, full policy evaluation, workload identity, data exposure and logging |
| Containers and Kubernetes | 09: developed configuration review; runtime inspection pending | Reproducible container lab, image verification, namespaces, Kubernetes RBAC and network policy |
| Reverse engineering | 10: developed byte/data-flow introduction | Assembly, executable formats, disassembly, debugging and compiled static/dynamic comparison |
| Exploit development | Mentioned in the broader source family; no developed chapter | Memory corruption, mitigations, crash triage, fuzzing and reproducible exploitability analysis in owned fixtures |
| Malware and ransomware analysis | 10: data/code distinction only; malware teaching still missing | Analysis environment, behavior attribution, unpacking, persistence evidence and recovery implications |
| Wireless security | 11: outline | Radio fundamentals, WLAN roles, authentication, encryption, capture interpretation and dedicated lab procedures |
| Mobile security | No dedicated chapter yet | Android/iOS app models, storage, permissions, IPC, transport and device-lab setup |
| Hardware and IoT | 11: outline | Firmware extraction/analysis, boot trust, debug interfaces, update mechanisms and embedded identity |
| SCADA, ICS and OT | 15–17: developed introductory sequence | Instrumentation and control loops, PLC programming, DNP3/OPC UA and other protocols, simulator configuration, safety-system boundaries and equipment-specific validation |
| OSINT | 12: combined outline | Source validation, temporal reasoning, entity resolution, evidence preservation and scoped investigation |
| Social engineering and human factors | 12: combined outline | Authorized exercise design, consent, measurement, defensive controls and debriefing |
| SOC and threat hunting | 05: developed detector-evaluation lesson; 13: outline | Telemetry engineering, query languages, larger detection tests, baseline design and hunting |
| Digital forensics and incident response | 13: combined outline | Acquisition, chain of custody, filesystem/memory artifacts, timelines, containment and recovery exercises |
| AI and adversarial ML security | 13: combined outline | Prompt/data/tool boundaries, evaluation, retrieval risks, model/data provenance and adversarial ML foundations |
| Cryptography | 14: developed hash/HMAC and replay introduction | Encryption, signatures, password hashing, TLS, production key management and protocol analysis |
| Security engineering and supply chain | 14: developed primitive-contract testing | Broader secure design, dependency provenance, build integrity and supply-chain exercises |
| Learning methods, career and certification material | 00: developed orientation; program and assessment scaffolding | Independent reviewer feedback, portfolios and explicit mapping to any chosen certification objectives |
The source catalog also contains course/report filenames and research notes outside these broad families. Their presence is not approval to copy them, proof of quality, or a separate lesson. Prior experimental curricula remain excluded.
How new content reaches the site
- Inventory/extraction: source paths and text become available to the private pipeline.
- Distillation: selected excerpts become private model drafts.
- Review and synthesis: factual support, context, contradictions, originality and examples are checked; overlapping drafts are combined into a coherent explanation.
- Lesson authoring: the explanation receives prerequisites, a reproducible exercise, expected results, limitations and assessment questions.
- Publication: reviewed material is committed into the course Markdown and deployed here.
Processing more books advances the first two steps. It does not automatically finish the last three. Meanwhile, developed lessons can be authored from checked public references and original synthetic examples, as the core and OT sequences are, without waiting for the entire library.
What the 24-week plan means
The weekly plan is a proposed route through these subjects, not a claim that 24 complete weeks of teaching material already exist. Follow developed lessons now if they fit your prerequisites. Use outline pages to understand intended scope; do not mistake them for a complete independent course.
No date for completing every track has been validated. Progress will be reported as newly published lessons, tested exercises, reviewed source coverage and actual learner evidence—not as raw draft volume.