Available Courses

Browse our selection of courses and level up your knowledge.

DNS InvestigationsClient identity, recursive resolution, record context, time, and corroborating telemetry turn queries into defensible decisions.PRACTICAL SECURITY OPERATIONSDNS InvestigationsClientResolverRecordsCorroborationResolutionEVIDENCE → REASONING → DEFENSIBLE ACTION
intermediate Network Security Analysis

DNS Investigations: Resolution, Telemetry, and Threat Decisions

A practical analyst course for tracing DNS resolution, reading records and caches, working with resolver telemetry, and turning suspicious queries into scoped security decisions.

3 Modules View Course →
Endpoint Process-Tree AnalysisLineage, command intent, endpoint changes, connections, identity, and baseline combine into a behavior decision.PRACTICAL SECURITY OPERATIONSEndpoint Process-Tree AnalysisLineageArgumentsBehaviorImpactEVIDENCE → REASONING → DEFENSIBLE ACTION
intermediate Endpoint Security Analysis

Endpoint Process-Tree Analysis: From Alert to Behavior

A practical course for reconstructing Windows execution, reading command lines, separating signed tools from trusted behavior, and correlating process trees with endpoint impact.

3 Modules View Course →
Phishing Email TriageAn evidence path connects message preservation, authentication, content analysis, scoping, and containment.PRACTICAL SECURITY OPERATIONSPhishing Email TriageMessageIdentityContentScopeEVIDENCE → REASONING → DEFENSIBLE ACTION
intermediate Security Operations

Phishing Email Triage: From Message Evidence to Containment

A hands-on analyst course for examining suspicious email safely, interpreting authentication and routing evidence, scoping exposure, and recording a defensible disposition.

3 Modules View Course →
Security Alert TriageA normalized claim moves through telemetry verification, scope, hypothesis testing, severity, action, and learning.PRACTICAL SECURITY OPERATIONSSecurity Alert TriageClaimEvidenceScopeHandoffEVIDENCE → REASONING → DEFENSIBLE ACTION
intermediate Security Operations

Security Alert Triage: Evidence, Scope, and Handoff

A daily-practice course for turning noisy alerts into bounded evidence, tested hypotheses, proportionate severity, and case notes responders can act on.

3 Modules View Course →
Windows Sign-In EvidenceAccount, host, domain controller, protocol, session, and resource evidence combine into an authentication investigation.PRACTICAL SECURITY OPERATIONSWindows Sign-In EvidenceAccountEndpointDomain controllerSessionEVIDENCE → REASONING → DEFENSIBLE ACTION
intermediate Security Operations

Windows Sign-In Evidence: Investigating Authentication Across Hosts

A field course for reading Windows logon, Kerberos, and NTLM evidence across workstations, servers, and domain controllers without reducing investigations to event-ID lookups.

3 Modules View Course →
Introduction to Cyber Threat IntelligenceA light-theme course map showing the actual learning modules.BEGINNER • ENIntroduction to Cyber Threat IntelligenceCourse path through 3 focused modules1Module 1: The Basics ofCTI2Module 2: TheIntelligence Cycle3Module 3: Types ofIntelligence
beginner Foundations

Introduction to Cyber Threat Intelligence

A conceptual overview of Cyber Threat Intelligence for absolute beginners.

3 Modules View Course →
CVE Intelligence: Vulnerability Lifecycle, Analysis, and Defensive DecisionsA light-theme course map showing the actual learning modules.INTERMEDIATE • ENCVE Intelligence: Vulnerability Lifecycle,Analysis, and Defensive DecisionsCourse path through 4 focused modules11. The CVE Ecosystem andVulnerability Lifecycle22. CVSS, Severity, andVulnerability Risk…33. Exploitation Contextand Vulnerability…44. ProducingVulnerability…
intermediate Vulnerability Intelligence

CVE Intelligence: Vulnerability Lifecycle, Analysis, and Defensive Decisions

A practitioner-focused course on CVE identifiers, vulnerability lifecycle analysis, CVSS interpretation, exploitation context, prioritization, and intelligence-driven remediation d...

4 Modules View Course →
Cyber Threat Intelligence Foundations: From Evidence to DecisionA light-theme course map showing the actual learning modules.BEGINNER • ENCyber Threat Intelligence Foundations:From Evidence to DecisionCourse path through 6 focused modules11. Intelligence ThatServes a Decision22. Requirements and theIntelligence Workflow33. Collection, Sources,and Evidence44. Structured Analysis ofAdversary Behavior55. Intelligence Writingand Briefing66. Dissemination, Action,and Improvement
beginner Cyber Threat Intelligence

Cyber Threat Intelligence Foundations: From Evidence to Decision

Learn to turn cyber evidence into defensible, decision-relevant intelligence through requirements, collection, structured analysis, adversary behavior modeling, communication, and ...

6 Modules View Course →
Open Source Intelligence (OSINT) Foundations: From Public Data to Defensible IntelligenceA light-theme course map showing the actual learning modules.INTERMEDIATE • ENOpen Source Intelligence (OSINT)Foundations: From Public Data toDefensible IntelligenceCourse path through 4 focused modules11. Understanding OSINT:Public Information and…22. The OSINT AnalystMindset: Questions,…33. OSINT Collection andResearch Techniques44. Advanced OSINTThinking: Context,…
intermediate Open Source Intelligence

Open Source Intelligence (OSINT) Foundations: From Public Data to Defensible Intelligence

Learn how OSINT practitioners discover, evaluate, corroborate, analyze, and communicate intelligence derived from publicly available information.

4 Modules View Course →
Strategic Cyber Threat Intelligence: Risk, Scenarios, and Executive DecisionsA light-theme course map showing the actual learning modules.ADVANCED • ENStrategic Cyber Threat Intelligence: Risk,Scenarios, and Executive DecisionsCourse path through 6 focused modules11. Strategic Directionand Decision Context22. Threat Environment andOrganizational Exposure33. Scenarios andAlternative Futures44. Strategic Warning andIndicators of Change55. Risk Options andSecurity Investment…66. ExecutiveCommunication,…
advanced Cyber Threat Intelligence

Strategic Cyber Threat Intelligence: Risk, Scenarios, and Executive Decisions

Learn to transform threat trends, organizational exposure, and uncertainty into strategic scenarios, risk judgments, executive options, and defensible security investment decisions...

6 Modules View Course →
Operational Cyber Threat Intelligence: Investigations, Campaigns, and Defensive ActionA light-theme course map showing the actual learning modules.INTERMEDIATE • ENOperational Cyber Threat Intelligence:Investigations, Campaigns, and DefensiveActionCourse path through 6 focused modules11. Operational Directionand Investigation Design22. Evidence Timelines andIncident Reconstruction33. Infrastructure,Identity, and…44. Campaign Analysis andAdversary Behavior55. OperationalAssessments and…66. From Intelligence toDefensive Operations
intermediate Cyber Threat Intelligence

Operational Cyber Threat Intelligence: Investigations, Campaigns, and Defensive Action

Advance from CTI foundations to operational investigations, evidence reconstruction, infrastructure analysis, campaign assessment, time-sensitive reporting, and intelligence-led de...

6 Modules View Course →