Each guide has one canonical purpose and links to the neighboring disciplines that consume or produce
its evidence. Every page includes a table of contents, practical workflows, case studies or worked
examples, labs, source links, AI-use boundaries, and acceptance criteria.
Domain 01
Turning raw data about adversaries into decisions: the intelligence cycle, ATT&CK, the Diamond Model, actor tracking, and how CTI feeds detection engineering.
10 modules
~55 min
Foundation to practitioner
Version 1.0
Reviewed 27 Jul 2026
For: Intelligence analysts, threat hunters, and detection engineers
- intelligence requirements
- ATT&CK
- actor research
- detection handoff
Practitioner guide live
Open syllabus →
Domain 02
Adversary emulation, penetration testing, and exploit tradecraft: recon, initial access, privilege escalation, lateral movement, and reporting.
14 modules
~112 min
Practitioner to advanced
Version 1.0
Reviewed 27 Jul 2026
For: Authorised security testers, red teams, and purple teams
- authorization
- adversary emulation
- validation
- reporting
Practitioner guide live
Open syllabus →
Domain 03
SOC operations, detection engineering, threat hunting, and incident handling: the discipline of finding and stopping what red team simulates.
14 modules
~55 min
Foundation to practitioner
Version 1.0
Reviewed 27 Jul 2026
For: SOC analysts, detection engineers, and threat hunters
- SOC operations
- detection engineering
- threat hunting
- validation
Practitioner guide live
Open syllabus →
Domain 04
Finding and understanding software flaws: fuzzing, memory corruption classes, static/dynamic analysis, and responsible disclosure.
14 modules
~44 min
Practitioner to advanced
Version 1.0
Reviewed 27 Jul 2026
For: Security researchers, exploit developers, and product-security teams
- fuzzing
- static analysis
- exploitability
- disclosure
Practitioner guide live
Open syllabus →
Domain 05
Static and dynamic triage, unpacking, disassembly, and behavioral analysis of malicious code, from first-look triage to full reverse engineering.
14 modules
~29 min
Practitioner to advanced
Version 1.0
Reviewed 27 Jul 2026
For: Malware analysts, reverse engineers, and incident responders
- reverse engineering
- debugging
- YARA
- defensive handoff
Practitioner guide live
Open syllabus →
Domain 06
Secure design, threat modeling, identity, authorization, API and browser controls, supply-chain assurance, AI-system boundaries, testing, release evidence, and remediation.
14 modules
~27 min
Foundation to practitioner
Version 1.0
Reviewed 27 Jul 2026
For: Application-security engineers, developers, and product teams
- threat modeling
- authorization
- supply chain
- secure delivery
Practitioner guide live
Open syllabus →
Domain 07
Incident readiness, defensible evidence handling, endpoint, disk, memory, network, cloud, identity and malware forensics, timeline reconstruction, containment, recovery, reporting, labs, and controlled AI assistance.
14 modules
~32 min
Practitioner to advanced
Version 1.0
Reviewed 27 Jul 2026
Baseline: NIST SP 800-61 Rev. 3
For: Incident responders, forensic analysts, and SOC leads
- evidence integrity
- memory forensics
- cloud evidence
- incident response
Practitioner guide live
Open syllabus →
Domain 08
Shared responsibility, landing zones, human and workload IAM, network and data protection, IaC, containers, Kubernetes, multi-cloud detection and response, SaaS, suppliers, and AI workloads.
14 modules
~35 min
Practitioner
Version 1.0
Reviewed 27 Jul 2026
For: Cloud-security engineers, architects, and incident responders
- IAM
- Kubernetes
- cloud detection
- incident response
Practitioner guide live
Open syllabus →
Domain 09
Cyber governance, scenario-based risk, frameworks, policy and control design, evidence and audit, legal and contractual obligations, suppliers, privacy, resilience, metrics, product assurance, and AI governance.
14 modules
~36 min
Foundation to practitioner
Version 1.0
Reviewed 27 Jul 2026
For: Security leaders, risk owners, auditors, and control operators
- governance
- risk assessment
- control evidence
- AI governance
Practitioner guide live
Open syllabus →
Domain 10
Authorized and ethical collection, search and archives, DNS/RDAP/certificates, internet exposure, applications, organizations, public code, media verification, threat infrastructure, automation, AI assistance, evidence, and reporting.
14 modules
~42 min
Foundation to practitioner
Version 1.0
Reviewed 27 Jul 2026
For: OSINT investigators, intelligence analysts, and security researchers
- public-source collection
- infrastructure
- verification
- evidence
Practitioner guide live
Open syllabus →
Domain 11
Securing the whole AI system: threat modeling, data and retrieval integrity, model supply chain, prompt injection, agents and MCP, adversarial testing, monitoring, incident response, and governance.
14 modules
~20 min
Practitioner to advanced
Version 1.0
Reviewed 27 Jul 2026
Baseline: NIST AI RMF, OWASP GenAI Security Project, MITRE ATLAS
For: AI engineers, application-security teams, security architects, red teams, defenders, and risk owners
- AI threat modeling
- prompt injection
- agent security
- AI assurance
Practitioner guide live
Open syllabus →