Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Bare Metal Cyber v0.2.3

Technical-Core Wiki Expansion

Two technical-core waves now provide 160 educational articles across networking, identity, Windows, cryptography, systems, threats, detection, forensics, web and API security, mobile security, and connected devices.

New Curriculum

160 technical-core entries

Follow a learning path

AI Security & Emerging Technology

Cyber-physical risk domain · Advanced

Automotive Cybersecurity

Automotive cybersecurity protects vehicle electronic systems, software, communications, data, update infrastructure, service tools, manufacturing, and cloud services while preserving safety, reliability, privacy, and long product lifecycles.

Embedded technology foundation · Advanced

Embedded Systems Security

Embedded systems security protects purpose-built computing devices whose software, hardware, interfaces, timing, physical environment, and long support lifecycle are tightly coupled to a product or physical process.

Cyber-physical risk domain · Advanced

Medical Device Cybersecurity

Medical device cybersecurity manages the confidentiality, integrity, availability, authenticity, resilience, and safe operation of connected or software-enabled devices throughout design, clinical use, maintenance, vulnerability response, and retirement.

Cloud, Application Security & DevSecOps

API security concept · Advanced

API Authentication and Token Validation

API authentication and token validation establish which principal is calling an API and whether the presented credential is authentic, current, intended for that audience, and permitted to support the requested action.

Application architecture concept · Advanced

API Gateway Security

An API gateway is an intermediary that routes and mediates API traffic and may enforce authentication, rate limits, schema controls, observability, transformation, and policy; securing it requires consistent edge policy without assuming the gateway can replace backend authorization.

Application security concept · Intermediate

Broken Object-Level Authorization

Broken Object-Level Authorization is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.

Cloud security concept · Intermediate

Container Runtime Security

Container Runtime Security is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Browser security control · Advanced

Content Security Policy

Content Security Policy is an HTTP response policy that tells supporting browsers which sources and execution patterns are permitted for scripts, styles, images, frames, connections, and other resources, reducing the impact of many content-injection flaws.

Web session-security concept · Intermediate

Cookies and Web Sessions

Cookies are browser-managed name-value records scoped by domain, path, security attributes, and lifetime; web applications often use them to carry a session identifier that binds requests to server-side authentication and authorization state.

Application security concept · Intermediate

Cross-Site Request Forgery

Cross-Site Request Forgery is an application-security topic involving trust boundaries, input handling, browser or API behavior, identity, authorization, or server-side processing.

Application security concept · Intermediate

Cross-Site Scripting

Cross-Site Scripting is an application-security topic involving trust boundaries, input handling, browser or API behavior, identity, authorization, or server-side processing.

Application security concept · Intermediate

File Upload Security

File Upload Security is an application-security topic involving trust boundaries, input handling, browser or API behavior, identity, authorization, or server-side processing.

API security concept · Advanced

GraphQL Security

GraphQL security protects a typed query interface in which clients select fields and traverse relationships; the server must enforce authorization, resource limits, safe resolver behavior, and controlled schema exposure for every requested object and field.

Web protocol foundation · Foundational

HTTP Methods and Status Codes

HTTP methods express the intended action on a resource, while status codes communicate the outcome; secure applications enforce authorization and state rules for every method and return responses that are accurate without disclosing unnecessary detail.

Application security concept · Intermediate

Insecure Deserialization

Insecure Deserialization is an application-security topic involving trust boundaries, input handling, browser or API behavior, identity, authorization, or server-side processing.

Mobile security foundation · Intermediate

Mobile Application Architecture

Mobile application architecture combines device code, operating-system services, local storage, backend APIs, identity providers, push services, update channels, and third-party SDKs; security depends on how trust and data move across all of those components.

Application security concept · Intermediate

REST API Security

REST API Security is an application-security topic involving trust boundaries, input handling, browser or API behavior, identity, authorization, or server-side processing.

Application security concept · Intermediate

Same-Origin Policy and Cross-Origin Resource Sharing

Same-Origin Policy and Cross-Origin Resource Sharing is an application-security topic involving trust boundaries, input handling, browser or API behavior, identity, authorization, or server-side processing.

Cloud security concept · Intermediate

Secure Access Service Edge

Secure Access Service Edge is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.

Application security concept · Intermediate

Server-Side Request Forgery

Server-Side Request Forgery is an application-security topic involving trust boundaries, input handling, browser or API behavior, identity, authorization, or server-side processing.

Web protocol foundation · Foundational

URLs, URIs, and HTTP Request Structure

A URI identifies a resource, a URL adds a method and location for reaching it, and an HTTP request carries a method, target, headers, and optional body that a server interprets within an application and trust context.

Real-time application security concept · Advanced

WebSocket Security

WebSocket security protects long-lived, bidirectional connections that begin with an HTTP upgrade and then carry application-defined messages outside the normal request-response pattern.

Cryptography & Data Protection

Cryptography and trust concept · Intermediate

Advanced Encryption Standard (AES)

Advanced Encryption Standard (AES) is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.

Endpoint data-protection control · Intermediate

BitLocker Drive Encryption

BitLocker is a Windows full-volume encryption capability that protects data at rest by binding volume keys to trusted startup conditions, recovery methods, and optional user authentication.

Cryptography and trust concept · Intermediate

Certificate Chain Validation

Certificate Chain Validation is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.

Cryptography and trust concept · Intermediate

Certificate Revocation Lists and OCSP

Certificate Revocation Lists and OCSP is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.

Cryptography and trust concept · Intermediate

Certificate Signing Requests

Certificate Signing Requests is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.

Cryptography and trust concept · Intermediate

Cryptographic Hash Functions

Cryptographic Hash Functions is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.

Cryptography and trust concept · Intermediate

Diffie-Hellman Key Exchange

Diffie-Hellman Key Exchange is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.

Cryptography and trust concept · Intermediate

Digital Signatures

Digital Signatures is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.

Cryptography and trust concept · Intermediate

Elliptic Curve Cryptography

Elliptic Curve Cryptography is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.

Software authenticity control · Advanced

Firmware Signing

Firmware signing uses protected private keys and verified metadata to let a bootloader, device, installer, or update service determine that firmware was authorized by the product owner and has not been modified since signing.

Cryptography and trust concept · Intermediate

Full-Disk Encryption

Full-Disk Encryption is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.

Cryptography and trust concept · Intermediate

Hardware Security Modules

Hardware Security Modules is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Cryptography and trust concept · Intermediate

Initialization Vectors and Nonces

Initialization Vectors and Nonces is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.

Cryptography and trust concept · Intermediate

Key Derivation Functions

Key Derivation Functions is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.

Mobile transport-security concept · Advanced

Mobile Certificate Validation and Pinning

Mobile certificate validation verifies that a server certificate chains to a trusted authority, matches the intended service, is valid for the current time and policy, and has not been revoked or otherwise rejected; pinning adds a narrower application trust decision for selected keys or certificates.

Cryptography and trust concept · Intermediate

Public Key Infrastructure Operations

Public Key Infrastructure Operations is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.

Cryptography and trust concept · Intermediate

RSA Cryptography

RSA Cryptography is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.

Cryptography and trust concept · Intermediate

Root and Intermediate Certificate Authorities

Root and Intermediate Certificate Authorities is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.

Mobile data-protection concept · Intermediate

Secure Mobile Data Storage

Secure mobile data storage keeps secrets and sensitive information out of inappropriate files, caches, backups, logs, screenshots, clipboards, notifications, and shared locations while using platform protection suited to the data and threat model.

Cryptography and trust concept · Intermediate

TLS Handshake

TLS Handshake is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Identity & Access Management

Identity and access concept · Intermediate

802.1X Network Access Control

802.1X Network Access Control is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.

Identity and access concept · Intermediate

Access Tokens, ID Tokens, and Refresh Tokens

Access Tokens, ID Tokens, and Refresh Tokens is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.

Identity architecture concept · Intermediate

Active Directory Domains, Trees, Forests, and Trusts

Active Directory organizes identities and resources into domains; related domains form trees, one or more trees form a forest, and trusts define which security principals may be recognized across boundaries.

Identity and access concept · Intermediate

Discretionary Access Control

Discretionary Access Control is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.

Identity and access concept · Intermediate

Federation and Trust Relationships

Federation and Trust Relationships is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Service-account security concept · Advanced

Group Managed Service Accounts

Group Managed Service Accounts are Active Directory accounts whose complex passwords are automatically managed and made available only to authorized hosts, reducing the need to store or manually rotate service credentials.

Connected-device identity concept · Advanced

IoT Device Identity

IoT device identity is the set of cryptographic and lifecycle mechanisms used to distinguish one physical or logical device from another, authenticate it to services and peers, and bind actions and data to an accountable device record.

Identity and access concept · Intermediate

Just-in-Time Access

Just-in-Time Access is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.

Authentication protocol concept · Advanced

Kerberos in Active Directory

Kerberos in Active Directory is a ticket-based authentication system in which domain controllers acting as key distribution centers issue time-limited tickets that let users and services prove identity without repeatedly transmitting passwords.

Mobile platform-security concept · Foundational

Mobile App Permissions

Mobile app permissions authorize access to protected device capabilities and data such as location, camera, microphone, contacts, files, sensors, notifications, nearby devices, and background activity.

Mobile identity-security concept · Advanced

Mobile Authentication and Authorization

Mobile authentication and authorization combine user, device, application, and backend trust decisions so a mobile client can establish an identity while servers enforce what that identity may do with each resource and transaction.

Legacy authentication protocol concept · Advanced

NTLM Authentication

NTLM is a Windows challenge-response authentication family retained for compatibility when Kerberos or modern authentication cannot be used; its weaker trust properties make dependency reduction an important defensive goal.

Identity and access concept · Intermediate

OAuth 2.0 Authorization

OAuth 2.0 Authorization is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.

Identity administration concept · Intermediate

Organizational Units and Delegation

Organizational units are Active Directory containers used to organize objects, apply Group Policy, and delegate narrowly defined administrative tasks without granting broad domain privileges.

Identity and access concept · Intermediate

Privileged Access Workflows

Privileged Access Workflows is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.

Identity and access concept · Intermediate

RADIUS and TACACS+

RADIUS and TACACS+ is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Identity and access concept · Intermediate

Rule-Based Access Control

Rule-Based Access Control is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.

Identity and access concept · Intermediate

SAML Authentication

SAML Authentication is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.

Identity and access concept · Intermediate

SCIM Provisioning

SCIM Provisioning is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.

Identity and access concept · Intermediate

Session Management

Session Management is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.

Authentication architecture concept · Intermediate

Windows Authentication

Windows authentication is the collection of local and domain mechanisms Windows uses to verify identities, establish logon sessions, obtain network credentials, and authorize access to operating-system and enterprise resources.

Privileged account management control · Intermediate

Windows Local Administrator Password Solution

Windows Local Administrator Password Solution automatically generates, rotates, stores, and controls retrieval of unique local administrator passwords so a compromised password on one device cannot be reused across an entire fleet.

Networks & Protocols

Network security concept · Beginner

Address Resolution Protocol (ARP)

Address Resolution Protocol (ARP) describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.

Network security concept · Beginner

DHCP Security

DHCP Security describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.

Network security concept · Beginner

DNS Resolution Process

DNS Resolution Process describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.

Network security concept · Beginner

DNS Security Extensions (DNSSEC)

DNS Security Extensions (DNSSEC) describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.

Network security concept · Beginner

Demilitarized Zones

Demilitarized Zones is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Network security concept · Beginner

Forward Proxies

Forward Proxies is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Network security concept · Beginner

HTTP and HTTPS

HTTP and HTTPS describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.

Network security concept · Beginner

IPv6 Neighbor Discovery

IPv6 Neighbor Discovery is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Network security concept · Beginner

Internet Control Message Protocol (ICMP)

Internet Control Message Protocol (ICMP) describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.

Connected-device network control · Intermediate

IoT Network Segmentation

IoT network segmentation places connected devices into controlled zones and communication paths according to function, trust, ownership, and consequence so compromise of one device does not provide unrestricted access to users, servers, management systems, or other devices.

Network security concept · Beginner

Network Address Translation (NAT)

Network Address Translation (NAT) is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Network security concept · Beginner

Network Segmentation and Microsegmentation

Network Segmentation and Microsegmentation is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Network security concept · Beginner

Network Time Protocol Security

Network Time Protocol Security describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.

Network security concept · Beginner

Port Address Translation (PAT)

Port Address Translation (PAT) is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Network security concept · Beginner

Reverse Proxies

Reverse Proxies is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Network security concept · Beginner

Secure Shell (SSH)

Secure Shell (SSH) is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Network security concept · Beginner

Secure and Insecure Protocols

Secure and Insecure Protocols describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.

Network security concept · Beginner

Simple Network Management Protocol Security

Simple Network Management Protocol Security describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.

Network security concept · Beginner

Software-Defined Networking Security

Software-Defined Networking Security is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Network security concept · Beginner

Stateful and Stateless Firewalls

Stateful and Stateless Firewalls is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Network security concept · Beginner

TCP Three-Way Handshake

TCP Three-Way Handshake describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.

Network security concept · Beginner

Virtual LANs (VLANs)

Virtual LANs (VLANs) is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Network security concept · Beginner

Virtual Private Network Protocols

Virtual Private Network Protocols describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.

Network security concept · Beginner

Wireless Authentication and Encryption

Wireless Authentication and Encryption is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.

Security Operations & Incident Response

Security operations practice · Intermediate

Antivirus, EDR, and XDR

Antivirus, EDR, and XDR is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Detection-program assessment · Advanced

Detection Coverage and Gap Analysis

Detection coverage and gap analysis determines which priority adversary behaviors, misuse cases, control failures, and business risks are observable and actionable, and where missing telemetry, analytic logic, context, or response capacity leaves a gap.

Detection engineering practice · Advanced

Detection as Code

Detection as code manages analytic rules, queries, parsers, tests, documentation, and deployment through version-controlled engineering practices so detection changes are reviewable, reproducible, testable, and safely promoted.

Digital forensics discipline · Advanced

Disk Forensics

Disk forensics acquires and examines storage media and file-system artifacts to reconstruct user, application, operating-system, and adversary activity while preserving evidence integrity and provenance.

Endpoint monitoring concept · Advanced

Endpoint Detection and Response Telemetry

EDR telemetry records endpoint behavior such as process execution, modules, files, registry, users, network connections, scripts, drivers, security events, and response actions so analysts can detect and investigate activity in context.

Security operations practice · Intermediate

File Integrity Monitoring

File Integrity Monitoring is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Digital forensics method · Advanced

Forensic Timeline Analysis

Forensic timeline analysis orders and correlates events from systems, files, identities, networks, applications, and people to explain what happened, when it happened, how confidently it is known, and where evidence is missing or contradictory.

Security data engineering concept · Advanced

Log Quality Engineering

Log quality engineering measures and improves whether security events are complete, accurate, timely, consistent, attributable, protected, and usable for the detections and investigations that depend on them.

Security operations process · Intermediate

Log Source Onboarding

Log source onboarding is the controlled process of bringing a new event source into security monitoring with validated collection, parsing, timestamps, identifiers, access controls, retention, health checks, and documented analytic value.

Malware analysis technique · Advanced

Malware Sandboxing

Malware sandboxing executes or emulates suspicious code in a controlled environment to observe processes, files, registry changes, network activity, persistence, evasion, and other behavior without exposing production systems.

Security operations practice · Intermediate

Memory Forensics

Memory Forensics is an operational security practice used to collect evidence, detect suspicious behavior, investigate events, or guide incident decisions.

Network monitoring concept · Advanced

Network Traffic Analysis

Network traffic analysis examines packet, flow, DNS, proxy, TLS, routing, and session metadata to understand communication patterns, identify suspicious behavior, and reconstruct activity across network trust boundaries.

Security operations practice · Intermediate

Network Traffic Flow Records

Network Traffic Flow Records is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Security operations practice · Intermediate

Packet Capture and PCAP Analysis

Packet Capture and PCAP Analysis is an operational security practice used to collect evidence, detect suspicious behavior, investigate events, or guide incident decisions.

Security operations practice · Intermediate

PowerShell Security and Logging

PowerShell Security and Logging is an operational security practice used to collect evidence, detect suspicious behavior, investigate events, or guide incident decisions.

Detection-program process · Advanced

SIEM Use-Case Lifecycle

The SIEM use-case lifecycle manages a detection from threat and business requirement through data validation, analytic design, testing, deployment, triage, measurement, tuning, maintenance, and retirement.

Security operations planning concept · Intermediate

Security Telemetry Strategy

A security telemetry strategy defines which events, states, and contextual data an organization must collect to prevent, detect, investigate, respond to, and learn from priority threat and failure scenarios.

Security operations practice · Intermediate

Sigma Rules

Sigma Rules is an operational security practice used to collect evidence, detect suspicious behavior, investigate events, or guide incident decisions.

Network detection concept · Advanced

Snort and Suricata Rules

Snort and Suricata rules describe network traffic conditions that an intrusion detection or prevention engine can alert on, record, reject, or otherwise handle using protocol, flow, content, metadata, and state-aware inspection.

Security operations practice · Intermediate

Sysmon

Sysmon is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Behavioral analytics concept · Advanced

User and Entity Behavior Analytics

User and Entity Behavior Analytics models activity for users, devices, workloads, applications, and other entities to identify statistically or contextually unusual behavior that may indicate compromise, misuse, control failure, or operational change.

Security operations practice · Intermediate

Windows Event Logs

Windows Event Logs is an operational security practice used to collect evidence, detect suspicious behavior, investigate events, or guide incident decisions.

Malware detection concept · Advanced

YARA Rules

YARA is a pattern-matching language used to classify files, memory, and other byte or text content by combining strings, metadata, modules, and Boolean conditions into reusable detection rules.

Systems, Endpoints & Infrastructure

Systems security concept · Intermediate

Active Directory Fundamentals

Active Directory Fundamentals concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.

Systems security concept · Intermediate

BIOS and UEFI Security

BIOS and UEFI Security concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.

Systems security concept · Intermediate

Endpoint Application Control

Endpoint Application Control concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.

Systems security concept · Intermediate

Group Policy Security

Group Policy Security concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.

Systems security concept · Intermediate

Host-Based Firewalls

Host-Based Firewalls is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Systems security concept · Intermediate

Internet of Things Security

Internet of Things Security is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Connected-device lifecycle control · Advanced

IoT Secure Update Mechanisms

IoT secure update mechanisms let a device authenticate update metadata and payloads, verify integrity and authorization, install changes safely, resist rollback, recover from failure, and report update state throughout a long product lifecycle.

Hardware interface security concept · Advanced

JTAG and UART Security

JTAG and UART security controls debug, test, programming, and serial interfaces that can expose firmware, memory, boot state, credentials, consoles, and privileged device control when physically accessible.

Windows credential-protection concept · Advanced

LSASS and Credential Protection

The Local Security Authority Subsystem Service enforces local security policy, validates certain logons, creates access tokens, and handles credential material; protecting LSASS is central to limiting credential theft from Windows endpoints.

Systems security concept · Intermediate

Operating System Fundamentals

Operating System Fundamentals concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.

Systems security concept · Intermediate

Processes, Services, and Daemons

Processes, Services, and Daemons is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Remote administration security concept · Advanced

Remote Desktop Security

Remote Desktop security protects Windows interactive administrative sessions by controlling who can connect, how endpoints authenticate, where credentials are exposed, which channels are redirected, and how activity is monitored and contained.

Systems security concept · Intermediate

Removable Media Security

Removable Media Security is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Systems security concept · Intermediate

Secure Boot

Secure Boot concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.

Embedded platform-security control · Advanced

Secure Boot for Embedded Devices

Secure boot for embedded devices creates a chain of verified software from an initial trusted component through bootloader, operating system, firmware, and application so unauthorized code is not executed during startup.

Systems security concept · Intermediate

Secure Configuration Management

Secure Configuration Management concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.

Systems security concept · Intermediate

Security Baselines and Benchmarks

Security Baselines and Benchmarks is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Systems security concept · Intermediate

System Hardening

System Hardening concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.

Systems security concept · Intermediate

Type 1 and Type 2 Hypervisors

Type 1 and Type 2 Hypervisors concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.

Windows privilege-boundary control · Intermediate

User Account Control

User Account Control limits routine use of administrative privileges by giving administrators a filtered standard token and requiring an elevation decision before a process receives the full administrative token.

Systems security concept · Intermediate

Virtual Machine Security

Virtual Machine Security concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.

Windows platform-security control · Advanced

Windows Credential Guard

Windows Credential Guard uses virtualization-based security to isolate selected domain credentials from the normal operating system so that compromise of the host is less likely to expose reusable NTLM hashes and Kerberos ticket-granting tickets.

Host firewall control · Intermediate

Windows Defender Firewall

Windows Defender Firewall is a stateful host firewall that applies profile-aware inbound and outbound rules to programs, services, ports, protocols, interfaces, users, and network conditions.

Windows configuration-security concept · Intermediate

Windows Registry Security

The Windows Registry is a hierarchical configuration database whose keys and values influence operating-system, service, application, security, persistence, and user behavior; protecting it requires permission control, change monitoring, and recovery discipline.

Threats, Malware & Adversaries

Credential attack technique · Advanced

AS-REP Roasting

AS-REP roasting targets Active Directory accounts that do not require Kerberos preauthentication, allowing an attacker to request an authentication response containing password-derived material and attempt offline password guessing.

Threat and attack concept · Intermediate

Advanced Persistent Threats

Advanced Persistent Threats is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Threat and attack concept · Intermediate

Bootkits

Bootkits describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.

Threat and attack concept · Intermediate

Command and Control Channels

Command and Control Channels is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Threat and attack concept · Intermediate

Credential Stuffing

Credential Stuffing is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.

Active Directory credential-access technique · Advanced

DCSync

DCSync is an abuse of Active Directory replication rights in which an attacker makes a system act like a domain controller and requests password-derived credential data through normal directory replication protocols.

Threat and attack concept · Intermediate

Data Staging and Exfiltration

Data Staging and Exfiltration describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.

Threat and attack concept · Intermediate

Fileless Malware

Fileless Malware describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.

Credential attack technique · Advanced

Kerberoasting

Kerberoasting is an attack technique in which an authenticated domain user requests Kerberos service tickets for service principal names and attempts to crack the ticket material offline to recover weak service-account passwords.

Threat and attack concept · Intermediate

Living-off-the-Land Techniques

Living-off-the-Land Techniques is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Threat and attack concept · Intermediate

On-Path Attacks

On-Path Attacks describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.

Credential replay technique · Advanced

Pass-the-Hash

Pass-the-Hash is a credential replay technique in which an attacker uses a captured NTLM password hash to authenticate without learning or typing the original plaintext password.

Threat and attack concept · Intermediate

Password Attacks

Password Attacks describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.

Threat and attack concept · Intermediate

Password Spraying

Password Spraying describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.

Threat and attack concept · Intermediate

Replay Attacks

Replay Attacks describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.

Threat and attack concept · Intermediate

Rootkits

Rootkits describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.

Threat and attack concept · Intermediate

Session Hijacking

Session Hijacking is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.

Threat and attack concept · Intermediate

Supply Chain Compromise

Supply Chain Compromise is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Vulnerabilities & Security Testing

Browser interface attack · Intermediate

Clickjacking

Clickjacking overlays or frames a legitimate interface so a user’s visible click lands on a hidden or disguised control, causing an unintended action in the user’s authenticated session.

Application vulnerability class · Advanced

Command Injection

Command injection occurs when untrusted data is incorporated into an operating-system command or shell expression and changes the command’s intended structure, arguments, control flow, or executed program.

Embedded security testing practice · Advanced

Firmware Analysis

Firmware analysis examines the software image and supporting metadata that control an embedded device to identify architecture, components, configuration, secrets, services, update logic, vulnerabilities, and runtime behavior.

Security testing practice · Advanced

Mobile Application Security Testing

Mobile application security testing evaluates architecture, storage, cryptography, authentication, network communication, platform interaction, code quality, resilience, privacy, backend APIs, and release integrity across supported mobile platforms.

Security testing practice · Intermediate

Patches, Updates, and Upgrades

Patches, Updates, and Upgrades is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.

Application vulnerability class · Intermediate

Path Traversal

Path traversal occurs when untrusted input influences a file or directory path and allows access outside the application’s intended storage boundary through relative segments, alternate encodings, symbolic links, or platform-specific path behavior.

Application vulnerability class · Advanced

XML External Entity Processing

XML External Entity risk arises when an XML parser resolves attacker-controlled external entities or related document features, potentially reading local resources, making server-side requests, disclosing data, or consuming excessive resources.