Learn
Practice the habits behind better security decisions.
Make decisions in synthetic phishing scenarios, learn safe verification steps, build command-line fundamentals, and follow every research claim to its source.
Decision-first practice
Phishing exercises and guides
Decide before the answer is revealed, compare strong evidence with weak heuristics, and verify suspicious messages through known channels.
Choose a phishing scenario →Guided track
OverTheWire: Bandit
Build Linux and security fundamentals one level at a time. Progress stays in this browser.
Start or continue the track →Curated reading
Research briefs
whitepaperNIST SP 800-61r2: Computer Security Incident Handling GuideThe classic incident-response playbook: definitions, lifecycle phases, and what to operationalize before you get hit.repoRepo Brief: Open Policy Agent (OPA) — Policy-as-code for authorization and guardrailsOPA lets you centralize policy decisions (Rego) for authz and compliance across microservices, Kubernetes, CI, and more.repoRepo Brief: SigmaHQ/Sigma (Portable Detection Rules)Sigma is a detection-rule format that lets you write once and translate to multiple SIEM backends (Splunk, Sentinel, etc.).whitepaperSLSA: Supply-chain Levels for Software Artifacts (What to actually implement)SLSA is a maturity model for build provenance and tamper resistance. The real value is disciplined build pipelines and signed attestations.