Skip to content

Course content and missing chapters

The complete course is still being written. The site currently contains fifteen developed lessons and three short outlines. A book appearing in the source catalog means it was inventoried; it does not mean its knowledge is taught here. The five-book AD distillation queue is also only one part of the wider curriculum.

Lessons you can use now

Lesson Material available Exercise type
00 · Learning with evidence Predictions, contradictory observations, first session and mastery evidence Claim-calibration worksheet
01 · Foundations Actor/action/object/policy, positive and negative controls, bounded impact Local vulnerable/fixed comparisons
07 · Linux and networking Process identity, temporary-file modes, transport versus HTTP, address mapping Local POSIX and HTTP experiments
02 · Windows and AD Directory/context/resource separation, tokens, path prerequisites Six-case synthetic policy worksheet; optional native identity inspection
03 · Kerberos Exchanges, service identity, validity and authentication versus authorization Five synthetic cases; optional current-session cache inspection
05 · Detection Labels, confusion matrices, precision/recall and telemetry gaps Bundled six-case offline evaluator and counterexample
06 · Reporting Reproduction, bounded findings, evidence checksums and remediation retests End-to-end report from the web fixture
08 · Web authorization Request lifecycle, object authorization, vulnerable/fixed comparison, finding writeup Bundled local HTTP app
04 · Remote administration Reachability, authentication, endpoint authorization and execution evidence Five synthetic cases; optional bounded Windows remoting query
09 · Cloud and containers Exact policy decisions, control/data authority and workload boundaries Local Python evaluator and synthetic configuration review; optional Docker inspection
10 · Code and byte analysis Byte order, length contracts, data flow, rejected ambiguity and mutation limits Bundled six-case binary decoder and finite mutation exercise
14 · Cryptography Hash trust, HMAC test vectors, key ownership and replay limits Bundled offline integrity experiment and public-test-key counterexample
15 · SCADA architecture Controllers, HMI, historian, control authority, dependencies and attack prerequisites Fictional topology and assessment model
16 · Industrial protocols Modbus requests, register interpretation, policy comparison and detector blind spots Bundled offline decoder with seven synthetic records
17 · OT investigation Attack-path reasoning, maintenance correlation, detection counterexamples, response and recovery decisions Evidence timeline and scenario investigation

“Developed” means a substantial explanation and a specified exercise are written. It does not mean independently reviewed, exhaustive, certification-equivalent, or demonstrated by a student. The setup guides and evidence templates are also available; they are supporting material rather than additional technical chapters.

The wider path

These gaps come from comparing the current chapter pages with the library's source families and the stated broad course scope. They are work still to do, not hidden pages that will appear after refreshing.

Track Current page and depth Chapters or depth still needed
Security foundations and assessment 01, 06: developed introductory sequence Broader threat models, assessment methodologies, production risk analysis and independent report review
Linux and operating systems 07: developed process/file introduction Services, storage, ACLs, capabilities, namespaces and Linux privilege escalation labs
Networking 07: developed HTTP diagnostic exercises Ethernet, addressing, routing, full DNS/TCP/TLS teaching, packet analysis and service enumeration
Programming, computer science and mathematics 10: developed byte/parser introduction Broader Python automation, shell/PowerShell, C and memory, data structures and probability
Windows internals 02: developed token/context introduction Native token lab validation, services, registry, credential storage and local privilege boundaries
Active Directory and identity 02, 03: developed introductory worksheets Native AD lab validation, directory ACLs, delegation, policy, trusts, certificate services and NTLM
Remote administration and lateral movement 04: developed path reasoning; native execution pending Validated two-host Windows lab, SMB/RDP/service/task mechanisms, controlled pivoting and credential hygiene
Web applications and APIs 08: developed authorization lesson only HTTP state, authentication, sessions, injection, XSS, SSRF, file handling, business logic and API authorization
Bug bounty and vulnerability research Web lesson provides one reporting example Scope triage, duplicate assessment, reproducible evidence, disclosure workflow and research methodology
Cloud security 09: developed policy/boundary introduction Provider-specific AWS/Azure/GCP labs, full policy evaluation, workload identity, data exposure and logging
Containers and Kubernetes 09: developed configuration review; runtime inspection pending Reproducible container lab, image verification, namespaces, Kubernetes RBAC and network policy
Reverse engineering 10: developed byte/data-flow introduction Assembly, executable formats, disassembly, debugging and compiled static/dynamic comparison
Exploit development Mentioned in the broader source family; no developed chapter Memory corruption, mitigations, crash triage, fuzzing and reproducible exploitability analysis in owned fixtures
Malware and ransomware analysis 10: data/code distinction only; malware teaching still missing Analysis environment, behavior attribution, unpacking, persistence evidence and recovery implications
Wireless security 11: outline Radio fundamentals, WLAN roles, authentication, encryption, capture interpretation and dedicated lab procedures
Mobile security No dedicated chapter yet Android/iOS app models, storage, permissions, IPC, transport and device-lab setup
Hardware and IoT 11: outline Firmware extraction/analysis, boot trust, debug interfaces, update mechanisms and embedded identity
SCADA, ICS and OT 1517: developed introductory sequence Instrumentation and control loops, PLC programming, DNP3/OPC UA and other protocols, simulator configuration, safety-system boundaries and equipment-specific validation
OSINT 12: combined outline Source validation, temporal reasoning, entity resolution, evidence preservation and scoped investigation
Social engineering and human factors 12: combined outline Authorized exercise design, consent, measurement, defensive controls and debriefing
SOC and threat hunting 05: developed detector-evaluation lesson; 13: outline Telemetry engineering, query languages, larger detection tests, baseline design and hunting
Digital forensics and incident response 13: combined outline Acquisition, chain of custody, filesystem/memory artifacts, timelines, containment and recovery exercises
AI and adversarial ML security 13: combined outline Prompt/data/tool boundaries, evaluation, retrieval risks, model/data provenance and adversarial ML foundations
Cryptography 14: developed hash/HMAC and replay introduction Encryption, signatures, password hashing, TLS, production key management and protocol analysis
Security engineering and supply chain 14: developed primitive-contract testing Broader secure design, dependency provenance, build integrity and supply-chain exercises
Learning methods, career and certification material 00: developed orientation; program and assessment scaffolding Independent reviewer feedback, portfolios and explicit mapping to any chosen certification objectives

The source catalog also contains course/report filenames and research notes outside these broad families. Their presence is not approval to copy them, proof of quality, or a separate lesson. Prior experimental curricula remain excluded.

How new content reaches the site

  1. Inventory/extraction: source paths and text become available to the private pipeline.
  2. Distillation: selected excerpts become private model drafts.
  3. Review and synthesis: factual support, context, contradictions, originality and examples are checked; overlapping drafts are combined into a coherent explanation.
  4. Lesson authoring: the explanation receives prerequisites, a reproducible exercise, expected results, limitations and assessment questions.
  5. Publication: reviewed material is committed into the course Markdown and deployed here.

Processing more books advances the first two steps. It does not automatically finish the last three. Meanwhile, developed lessons can be authored from checked public references and original synthetic examples, as the core and OT sequences are, without waiting for the entire library.

What the 24-week plan means

The weekly plan is a proposed route through these subjects, not a claim that 24 complete weeks of teaching material already exist. Follow developed lessons now if they fit your prerequisites. Use outline pages to understand intended scope; do not mistake them for a complete independent course.

No date for completing every track has been validated. Progress will be reported as newly published lessons, tested exercises, reviewed source coverage and actual learner evidence—not as raw draft volume.