Follow the thread.
Start with the foundations. Go deep on a topic.
Connect what you learn along the way.
Foundation Series
The fundamentals beneath every exploit. Build your understanding of networks, systems, trust, and security thinking.
AppSec Series
Follow the data from request to response. Learn to find, understand, and prevent application vulnerabilities.
Product Security Series
Make security part of the product, from the first design decision to the last release check.
Cloud / IAM Series
Understand who can do what, where, and why. Explore cloud architecture, identity, and permission boundaries.
AI / LLM / RAG Security Series
Explore the attack surface where language becomes logic. Prompt injection, retrieval boundaries, and practical defenses.
Agentic / MCP Security Series
When AI can take action, the boundaries matter more. Study agents, tool permissions, and the Model Context Protocol.
Certification Study Series
Turn exam objectives into lasting understanding with focused notes, recall practice, and practical connections.
Labs and experiments
Small, controlled experiments that make security ideas tangible. Reproduce the behavior, change one variable, learn why.
CTF learning notes / permitted write-ups
The reasoning behind the solve. Learning notes and write-ups published only where the challenge rules permit.
Bug Bounty / VDP learning and sanitized analysis
Learn the craft of scoped testing and clear reporting through sanitized analysis and responsible disclosure practices.
Research / Writing deep dives
Slow down, question assumptions, and connect the evidence. Longer explorations of security ideas and open questions.
Quarterly trend and roadmap updates
A regular pause to review the learning path, examine emerging themes, and choose the next questions to investigate.