Learning-Paths / Security Engineering
Curriculum map

Security
Engineering Two shelves. Fundamentals are the durable internals — how machines, networks, identities and mail actually work. Tools are the products that execute those ideas in this stack. Learn the shelf on the left and the shelf on the right becomes configuration rather than magic.

zero → senior mobile-first hover any dotted term
Shelf 01durable knowledge

Fundamentals

These do not change when a contract is renewed. CASB, SWG, SASE, ZTNA, EDR and DLP are concepts — a vendor merely implements them. Read these first; they are the vocabulary every tool page assumes.

01 · the wire

Networking

Packets, OSI, TCP/UDP, DNS, HTTP/TLS, NAT, proxies, routing, tunnels, PKI. The single highest-leverage subject in security.

02 · the endpoint

Windows internals

Processes, tokens, registry, services, LSASS, event logs, PowerShell, AD auth. Where most EDR detections actually fire.

03 · the endpoint

macOS internals

launchd, TCC, Gatekeeper, XProtect, code signing, unified logs, ES framework, MDM. The fleet FinTechs actually run.

04 · the server

Linux & containers

Processes, permissions, systemd, syslog, auditd, namespaces, cgroups, Docker and Kubernetes attack surface.

05 · the platform

Cloud fundamentals

Shared responsibility, control vs data plane, IAM as the new perimeter, cloud logging, CSPM/CNAPP, SaaS vs IaaS risk.

06 · the platform

AWS deep dive

IAM policy evaluation, STS & roles, VPC design, S3 exposure, CloudTrail forensics, GuardDuty, real attack paths.

07 · the perimeter

Identity & authentication

AuthN vs AuthZ, Kerberos, SAML, OAuth 2.0, OIDC, SCIM, MFA types, token theft, conditional access, phishing-resistant auth.

08 · the channel

Email & message security

SMTP, MX, headers, Return-Path vs From vs Reply-To, SPF, DKIM, DMARC, alignment, ARC, BEC anatomy, Google Workspace specifics.

09 · the craft

Logging & detection engineering

Telemetry pipelines, normalisation, detection lifecycle, ATT&CK-driven coverage, tuning, alert quality, purple teaming.

10 · the concepts

Security architecture concepts

What CASB, SWG, ZTNA, SASE, SSE, DLP, EDR/XDR, SIEM/SOAR actually mean — separated from the vendors that sell them.

Shelf 02this stack

Tools

Product-specific operation: consoles, query languages, policy models, and the failure modes that bite in production. Each page names the fundamentals it depends on so you know what to read first.

Progresssaved locally

Your progress

Checkpoints and drill answers are stored in this browser and restored whenever you reopen a page. Export writes a JSON file you can keep alongside the folder, back up, or import on another machine.

How to usemethod

The path structure

Every page uses the same five tiers, so you always know how deep you are.

TierQuestion it answersYou leave able to…
0 · GroundWhat is this thing and why does it exist?Explain it to a non-technical stakeholder
1 · MechanicsHow does it actually work under the hood?Trace a request/event end to end
2 · OperateHow do I drive the console day to day?Do the routine job unsupervised
3 · EngineerHow do I design, query, tune and integrate it?Build detections, policies and pipelines
4 · AdversarialHow does this fail, get bypassed, or lie to me?Challenge vendors and MSSPs credibly
Interaction: dotted teal terms show a definition on hover, tap or keyboard focus, and every page ends with a searchable glossary built from those same terms. Checkpoints at the end of each tier and answered drills are saved automatically and restored when you return, with per-path totals shown on the cards above.