Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Bare Metal Cyber Wiki

Cyber Wiki Learning Paths

Use guided paths to move from foundational vocabulary into architecture, operations, investigation, application security, and resilience.

Guided Study

46 paths through the Wiki

Technical-core collection
80 linked articles

Cybersecurity Foundations

Build the vocabulary and mental models needed to understand systems, risk, controls, attacks, and resilience.

Open learning path →
84 linked articles

Network Defense

Follow network communication from packets and protocols through segmentation, access control, monitoring, and secure remote access.

Open learning path →
87 linked articles

Identity, Authentication, and PKI

Learn how identities are created, authenticated, authorized, federated, monitored, and supported by certificates and cryptographic keys.

Open learning path →
19 linked articles

Windows and Active Directory Security

Understand enterprise Windows identity, policy, logging, credential protection, and common defensive priorities.

Open learning path →
39 linked articles

Endpoint and Operating System Security

Harden operating systems, endpoints, hypervisors, boot chains, storage, services, and administrative workflows.

Open learning path →
84 linked articles

Threats and Attack Techniques

Trace how adversaries gain access, persist, evade defenses, move laterally, command systems, and remove data.

Open learning path →
91 linked articles

Security Operations and Detection Engineering

Move from telemetry and logs to normalized data, detections, triage, enrichment, automation, and coverage measurement.

Open learning path →
84 linked articles

Digital Forensics and Incident Response

Collect and preserve evidence, analyze systems and memory, investigate incidents, and guide containment and recovery.

Open learning path →
40 linked articles

Web and API Security

Understand browser security boundaries, web vulnerabilities, API authorization failures, secure input handling, and modern application defenses.

Open learning path →
80 linked articles

Cloud and Container Security

Secure virtualized, containerized, cloud, and software-defined infrastructure through identity, isolation, configuration, and monitoring.

Open learning path →
19 linked articles

IoT, OT, and Embedded Security

Apply asset, identity, update, segmentation, firmware, and monitoring principles to connected and specialized devices.

Open learning path →
80 linked articles

Governance, Privacy, and Resilience

Connect technical decisions to risk, data handling, continuity, recovery, retention, and accountable governance.

Open learning path →
21 linked articles

Active Directory Defense

Build a defensible Active Directory environment from trust architecture and delegated administration through credential protection, monitoring, and common attack techniques.

Open learning path →
16 linked articles

Windows Endpoint Defense

Protect Windows startup, credentials, privilege, local configuration, storage, firewalling, remote administration, and endpoint evidence.

Open learning path →
13 linked articles

Web Protocol Security

Follow a browser request from URL and method through cookies, browser policy, input processing, server routing, and common web attack paths.

Open learning path →
7 linked articles

API Security Engineering

Design and test authentication, authorization, gateway policy, object access, resource controls, and real-time API behavior.

Open learning path →
9 linked articles

Mobile Application Security

Connect mobile architecture, platform permissions, protected storage, transport trust, authentication, backend authorization, and repeatable security testing.

Open learning path →
19 linked articles

Detection Engineering

Turn trustworthy telemetry into tested, versioned, measurable detections and operational response decisions.

Open learning path →
7 linked articles

Digital Forensics

Preserve and correlate storage, memory, network, endpoint, cloud, and timeline evidence to support defensible incident conclusions.

Open learning path →
13 linked articles

Embedded and Connected Device Security

Secure device identity, networks, firmware, boot, debug interfaces, updates, healthcare devices, and vehicle ecosystems across long product lifecycles.

Open learning path →
16 linked articles

MITRE ATT&CK® Foundations

Learn the ATT&CK data model, object relationships, matrix, platforms, defensive content, mapping methods, versioning, Navigator, assessments, and responsible coverage analysis.

Open learning path →
46 linked articles

MITRE ATT&CK®: Reconnaissance

Explore all active Enterprise ATT&CK v19.2 techniques and sub-techniques associated with the Reconnaissance objective, with defensive explanations and linked BMC learning resources.

Open learning path →
50 linked articles

MITRE ATT&CK®: Resource Development

Explore all active Enterprise ATT&CK v19.2 techniques and sub-techniques associated with the Resource Development objective, with defensive explanations and linked BMC learning resources.

Open learning path →
22 linked articles

MITRE ATT&CK®: Initial Access

Explore all active Enterprise ATT&CK v19.2 techniques and sub-techniques associated with the Initial Access objective, with defensive explanations and linked BMC learning resources.

Open learning path →
64 linked articles

MITRE ATT&CK®: Execution

Explore all active Enterprise ATT&CK v19.2 techniques and sub-techniques associated with the Execution objective, with defensive explanations and linked BMC learning resources.

Open learning path →
113 linked articles

MITRE ATT&CK®: Persistence

Explore all active Enterprise ATT&CK v19.2 techniques and sub-techniques associated with the Persistence objective, with defensive explanations and linked BMC learning resources.

Open learning path →
96 linked articles

MITRE ATT&CK®: Privilege Escalation

Explore all active Enterprise ATT&CK v19.2 techniques and sub-techniques associated with the Privilege Escalation objective, with defensive explanations and linked BMC learning resources.

Open learning path →
148 linked articles

MITRE ATT&CK®: Stealth

Explore all active Enterprise ATT&CK v19.2 techniques and sub-techniques associated with the Stealth objective, with defensive explanations and linked BMC learning resources.

Open learning path →
56 linked articles

MITRE ATT&CK®: Defense Impairment

Explore all active Enterprise ATT&CK v19.2 techniques and sub-techniques associated with the Defense Impairment objective, with defensive explanations and linked BMC learning resources.

Open learning path →
67 linked articles

MITRE ATT&CK®: Credential Access

Explore all active Enterprise ATT&CK v19.2 techniques and sub-techniques associated with the Credential Access objective, with defensive explanations and linked BMC learning resources.

Open learning path →
49 linked articles

MITRE ATT&CK®: Discovery

Explore all active Enterprise ATT&CK v19.2 techniques and sub-techniques associated with the Discovery objective, with defensive explanations and linked BMC learning resources.

Open learning path →
23 linked articles

MITRE ATT&CK®: Lateral Movement

Explore all active Enterprise ATT&CK v19.2 techniques and sub-techniques associated with the Lateral Movement objective, with defensive explanations and linked BMC learning resources.

Open learning path →
41 linked articles

MITRE ATT&CK®: Collection

Explore all active Enterprise ATT&CK v19.2 techniques and sub-techniques associated with the Collection objective, with defensive explanations and linked BMC learning resources.

Open learning path →
45 linked articles

MITRE ATT&CK®: Command and Control

Explore all active Enterprise ATT&CK v19.2 techniques and sub-techniques associated with the Command and Control objective, with defensive explanations and linked BMC learning resources.

Open learning path →
19 linked articles

MITRE ATT&CK®: Exfiltration

Explore all active Enterprise ATT&CK v19.2 techniques and sub-techniques associated with the Exfiltration objective, with defensive explanations and linked BMC learning resources.

Open learning path →
33 linked articles

MITRE ATT&CK®: Impact

Explore all active Enterprise ATT&CK v19.2 techniques and sub-techniques associated with the Impact objective, with defensive explanations and linked BMC learning resources.

Open learning path →
89 linked articles

MITRE ATT&CK® for Windows

Focus ATT&CK study on Windows behavior, defensive context, telemetry, investigation, and architecture.

Open learning path →
73 linked articles

MITRE ATT&CK® for Linux

Focus ATT&CK study on Linux behavior, defensive context, telemetry, investigation, and architecture.

Open learning path →
67 linked articles

MITRE ATT&CK® for macOS

Focus ATT&CK study on macOS behavior, defensive context, telemetry, investigation, and architecture.

Open learning path →
60 linked articles

MITRE ATT&CK® for Cloud and IaaS

Focus ATT&CK study on IaaS behavior, defensive context, telemetry, investigation, and architecture.

Open learning path →
17 linked articles

MITRE ATT&CK® for Identity Providers and SaaS

Focus ATT&CK study on Identity Provider and SaaS behavior, defensive context, telemetry, investigation, and architecture.

Open learning path →
39 linked articles

MITRE ATT&CK® for Containers

Focus ATT&CK study on Containers behavior, defensive context, telemetry, investigation, and architecture.

Open learning path →
52 linked articles

MITRE ATT&CK® for Network Devices

Focus ATT&CK study on Network Devices behavior, defensive context, telemetry, investigation, and architecture.

Open learning path →
52 linked articles

MITRE ATT&CK® for ESXi

Focus ATT&CK study on ESXi behavior, defensive context, telemetry, investigation, and architecture.

Open learning path →
68 linked articles

MITRE ATT&CK® Detection Strategies

Move from behavior hypotheses to data requirements, analytics, testing, tuning, investigation, and measurable operational coverage.

Open learning path →
70 linked articles

MITRE ATT&CK® Mitigations and Defensive Design

Connect relevant adversary behaviors to layered architecture, identity, configuration, monitoring, containment, and recovery controls.

Open learning path →