Companion-course connectionAttack Paths
An attack path is a sequence of reachable systems, identities, trust relationships, weaknesses, and actions that could let an adversary move from an initial foothold to a valuable objective.
Open article →Companion-course connectionCloud Misconfiguration
Cloud misconfiguration is an unsafe setting in identity, networking, storage, logging, encryption, compute, data, or organizational policy that creates unintended exposure or weakens control.
Open article →Companion-course connectionDetection Use-Case Acceptance Criteria
Detection use-case acceptance criteria define the threat behavior, data, logic, context, expected alert, performance, ownership, response path, and evidence required before a detection is treated as operational.
Open article →Companion-course connectionDigital Forensics
Digital forensics applies repeatable methods to identify, preserve, collect, examine, analyze, and communicate evidence from digital systems and services.
Open article →Companion-course connectionLiving Off the Land
Living off the land describes adversary use of legitimate system tools, interpreters, services, and administration features to blend malicious actions into ordinary operations.
Open article →Companion-course connectionLateral Movement — MITRE ATT&CK® Tactic TA0008
Adversaries move from one account, system, workload, or trust zone to another using remote services, credentials, exploits, or transferred tools.
Open article →Companion-course connectionPenetration Test Remediation Validation
Penetration test remediation validation confirms that reported attack paths are closed, compensating controls work as intended, and related weaknesses are not still exploitable.
Open article →Companion-course connectionSecurity Events, Alerts, and Incidents
A security event is an observable occurrence, an alert is a notification that selected activity may need attention, and an incident is an event or series of events that meets defined criteria for harmful or policy-violating impact.
Open article →Companion-course connectionVulnerability Remediation Verification
Vulnerability remediation verification confirms that an approved patch, configuration change, mitigation, compensating control, or removal actually reduced the intended exposure without creating a new failure.
Open article →Companion-course connectionAccountability
Accountability makes people, roles, services, and organizations answerable for security decisions and actions by assigning ownership and preserving reliable evidence.
Open article →Companion-course connectionAI Audit Analytics
AI audit analytics applies reproducible queries, statistics, visualizations, and anomaly detection to evaluate populations and focus testing without replacing professional judgment.
Open article →Companion-course connectionAI Audit Hallucination Controls
AI audit hallucination controls prevent unsupported generated statements from being treated as evidence, criteria, citations, calculations, or conclusions.
Open article →