These do not change when a contract is renewed. CASB, SWG, SASE, ZTNA, EDR and DLP are concepts — a vendor merely implements them. Read these first; they are the vocabulary every tool page assumes.
Packets, OSI, TCP/UDP, DNS, HTTP/TLS, NAT, proxies, routing, tunnels, PKI. The single highest-leverage subject in security.
Processes, tokens, registry, services, LSASS, event logs, PowerShell, AD auth. Where most EDR detections actually fire.
launchd, TCC, Gatekeeper, XProtect, code signing, unified logs, ES framework, MDM. The fleet FinTechs actually run.
Processes, permissions, systemd, syslog, auditd, namespaces, cgroups, Docker and Kubernetes attack surface.
Shared responsibility, control vs data plane, IAM as the new perimeter, cloud logging, CSPM/CNAPP, SaaS vs IaaS risk.
IAM policy evaluation, STS & roles, VPC design, S3 exposure, CloudTrail forensics, GuardDuty, real attack paths.
AuthN vs AuthZ, Kerberos, SAML, OAuth 2.0, OIDC, SCIM, MFA types, token theft, conditional access, phishing-resistant auth.
SMTP, MX, headers, Return-Path vs From vs Reply-To, SPF, DKIM, DMARC, alignment, ARC, BEC anatomy, Google Workspace specifics.
Telemetry pipelines, normalisation, detection lifecycle, ATT&CK-driven coverage, tuning, alert quality, purple teaming.
What CASB, SWG, ZTNA, SASE, SSE, DLP, EDR/XDR, SIEM/SOAR actually mean — separated from the vendors that sell them.
Product-specific operation: consoles, query languages, policy models, and the failure modes that bite in production. Each page names the fundamentals it depends on so you know what to read first.
Steering, POPs and NewEdge, the policy hierarchy, Real-time vs API protection, NPA, SkopeIT forensics, DLP profiles.
Agent architecture, Storyline, policy modes, Deep Visibility, PowerQuery syntax, remediation and rollback, STAR rules.
UDM data model, ingestion and parsers, entity graph, UDM Search, YARA-L 2.0 rule anatomy, retrohunts, tuning.
Alerts→cases, playbooks, integrations, jobs and connectors — enough to hold your MSSP to account without operating it.
API-based deployment, behavioural baselines, attack types, Search & Respond, Abuse Mailbox, Workspace posture.
Checkpoints and drill answers are stored in this browser and restored whenever you reopen a page. Export writes a JSON file you can keep alongside the folder, back up, or import on another machine.
Every page uses the same five tiers, so you always know how deep you are.
| Tier | Question it answers | You leave able to… |
|---|---|---|
| 0 · Ground | What is this thing and why does it exist? | Explain it to a non-technical stakeholder |
| 1 · Mechanics | How does it actually work under the hood? | Trace a request/event end to end |
| 2 · Operate | How do I drive the console day to day? | Do the routine job unsupervised |
| 3 · Engineer | How do I design, query, tune and integrate it? | Build detections, policies and pipelines |
| 4 · Adversarial | How does this fail, get bypassed, or lie to me? | Challenge vendors and MSSPs credibly |