Domain
Map
One concept at a time, in public. A domain is complete at 50 pieces, and readable long before that. This is a long project on purpose: the map is meant to be mostly unfinished for a while, because that is what continuous learning actually looks like.
- IN PROGRESS
Detection Engineering
Log sources, detection logic, tuning, false positives, and the telemetry gaps nobody notices until an incident.
34/50 - PLANNED
Identity and Access
Kerberos, NTLM, SAML, OAuth, tokens and sessions, and the many ways authentication is defeated rather than broken.
0/50 - PLANNED
Incident Response
Triage, containment decisions, evidence handling, timelines, and the host and network artifacts that answer questions.
0/50 - PLANNED
Networking Foundations
TCP/IP, DNS, TLS, HTTP and routing, explained as a defender needs them rather than as a curriculum.
0/50 - PLANNED
Windows Security
Processes and tokens, LSASS, the registry, event logs, services, and the controls that constrain them.
0/50 - PLANNED
Linux Security
Permissions and SUID, systemd, auditd, namespaces and containers, and what good looks like on a server.
0/50 - PLANNED
Cloud Security
IAM models, instance metadata, storage exposure, audit logging, key management and workload identity.
0/50 - PLANNED
Application Security
Injection classes, authentication flaws, SSRF, deserialization, headers and session handling.
0/50 - PLANNED
Cryptography in Practice
Hashing versus encryption, certificates and PKI, key exchange and signing, and how each is commonly misused.
0/50 - PLANNED
Threat Intelligence
Indicators versus behaviours, ATT&CK structure, confidence language, and attribution done honestly.
0/50
34 PUBLISHED · UPDATED 2026-09-28