Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, individual lessons, and BMC Cyber Challenge activities.

GIAC · Free, ad-free audio course

GIAC GSEC

A structured, audio-first learning route for GIAC GSEC, designed for focused review and practical understanding.

Every Bare Metal Cyber audio course is free and 100% ad-free.

PUT IT INTO PRACTICE

Practice GIAC GSEC concepts

Try 50 original BMC questions, review every explanation, and return to the lessons behind the answer. No login is required. Earn Challenge achievements and share your progress as you go.

50 original questionsExplanation after every answerAchievements and sharing

Independent BMC learning practice—not official exam items, a full mock exam, or an exam-readiness score.

Certification practice in the BMC Cyber Challenge

Companion Books

Study with the audio course, then reinforce it in print.

The study guide helps you organize and revisit the material. The flashcards book adds active recall and rapid review across the course objectives.

Complete Lesson Directory

Choose the exact subject you want to study.

Search by topic or narrow the directory by exam domain. Courses with multiple editions are organized below so every season remains easy to find. Each lesson includes its own audio player, full description, transcript when available, and previous-or-next navigation.

90 lessons available

A Practical Study Routine

Listen, read, and review in the order that works for you.

01

Listen

Use the free audio course during a commute, walk, workout, or focused study session.

02

Read

Use the study guide to organize the material, annotate key ideas, and build a reference you can return to.

03

Review

Use the flashcards book to practice active recall and quickly revisit weak areas.

Related Magazine Features

Connect the course to current cybersecurity analysis.

Cover art for The Post-Breach Boardroom: How Leaders Really Behave After the Headline
Issue 12 · March 25, 2026The Post-Breach Boardroom: How Leaders Really Behave After the HeadlineRead the feature →

Related Cyber Wiki

Continue with the concepts behind the course.

ATT&CK Software Analysis

AADInternals (S0677)

A defensive guide to the Enterprise ATT&CK software record S0677, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a PowerShell framework used to administer, enumerate, and test Azure Active Directory environments.

ATT&CK Software Analysis

ACAD/Medre.A (S1000)

A defensive guide to the Enterprise ATT&CK software record S1000, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a worm that collects AutoCAD drawings and can expose operational or engineering information.

AI safety engineering

AI Guardrail Engineering

AI guardrail engineering implements enforceable limits around model inputs, outputs, tools, data, and operating conditions.

Generative AI application security

AI Output Validation

AI output validation treats generated text, code, commands, queries, and structured data as untrusted until the consuming system verifies it.

ATT&CK Software Analysis

ASPXSpy (S0073)

A defensive guide to the Enterprise ATT&CK software record S0073, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a web shell that can provide remote administration of a compromised web server.

ATT&CK Software Analysis

AbstractEmu (S1061)

A defensive guide to the Enterprise ATT&CK software record S1061, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing Android malware reported in applications that abused known exploits to obtain root permissions.