Cyber Threat Intelligence (CTI)
Turning raw data about adversaries into decisions: the intelligence cycle, ATT&CK, the Diamond Model, actor tracking, and how CTI feeds detection engineering.
Syllabus draft live Open syllabus →Syllabus-style reference hub
A structured, zero-to-hero reference across every major cybersecurity domain: core terminology, frameworks, tools, and the way each discipline actually connects to the others. Built as a study path, not a blog — each domain below gets its own syllabus page.
This module is being built out domain by domain. CTI is live; the remaining syllabus pages are in progress.
Ten domains cover the field end to end, from understanding an adversary's intent to writing the code that keeps them out. Each card links to a dedicated syllabus page with terminology, frameworks, and a recommended learning order.
Turning raw data about adversaries into decisions: the intelligence cycle, ATT&CK, the Diamond Model, actor tracking, and how CTI feeds detection engineering.
Syllabus draft live Open syllabus →Adversary emulation, penetration testing, and exploit tradecraft: recon, initial access, privilege escalation, lateral movement, and reporting.
In progress Open syllabus →SOC operations, detection engineering, threat hunting, and incident handling: the discipline of finding and stopping what red team simulates.
In progress Open syllabus →Finding and understanding software flaws: fuzzing, memory corruption classes, static/dynamic analysis, and responsible disclosure.
In progress Open syllabus →Static and dynamic triage, unpacking, disassembly, and behavioral analysis of malicious code, from first-look triage to full reverse engineering.
In progress Open syllabus →Building software that resists attack: the OWASP Top 10, secure SDLC, threat modeling, SAST/DAST, and dependency/supply-chain hygiene.
In progress Open syllabus →Evidence handling, disk/memory/network forensics, timeline reconstruction, and the incident response lifecycle from detection to lessons learned.
In progress Open syllabus →Shared-responsibility models, IAM misconfiguration, container/Kubernetes security, and cloud-native detection across AWS, Azure, and GCP.
In progress Open syllabus →Risk assessment, security frameworks (NIST CSF, ISO 27001), audit, and the policy/compliance layer that funds and governs everything else.
In progress Open syllabus →Open-source intelligence gathering: search operators, infrastructure enumeration, social/corporate footprinting, and OPSEC while collecting.
In progress Open syllabus →