Source map
The course is an original synthesis. Source references point to the private iCloud library and are intentionally path-level; book text is not copied into this repository.
| Module | Source families to review | Evidence focus |
|---|---|---|
| Foundations | penetration-testing fundamentals, Windows internals, security engineering | system model and scope |
| Windows + AD | Windows/Active Directory books, OSCP/OSEP material | object relationships and logs |
| Kerberos | Windows security internals, AD tradecraft | ticket flow and provenance |
| Lateral movement | OSEP/CPTS reports, AD and red-team texts | protocol prerequisites and lab proof |
| Detection | SOC, defensive engineering, incident-response material | telemetry and false positives |
| Labs/reporting | course notes and report examples | reproducible evidence |
| SCADA and OT chapters 15–17 | Public NIST SP 800-82 Rev. 3 final, Modbus Organization specifications, MITRE EMB3D | Original fictional architecture, synthetic protocol fixture, attack-path reasoning |
The SCADA/OT chapters cite checked public primary references directly. They do not claim to be reviewed distillations of the private books. In particular, the catalog's withdrawn NIST draft is not used as the current reference. Wider source-family coverage and missing lessons are listed in the coverage map.
When the pipeline is implemented, each lesson paragraph will carry concept IDs and source references generated from the contract in contracts. Prior curriculum and audit artifacts are excluded from source ingestion and are not treated as evidence of completion.