Learn
Practice the habits behind better security decisions.
Make decisions in synthetic phishing scenarios, learn safe verification steps, build command-line fundamentals, and follow every research claim to its source.
Decision-first practice
Phishing exercises and guides
Decide before the answer is revealed, compare strong evidence with weak heuristics, and verify suspicious messages through known channels.
Choose a phishing scenario →Guided track
OverTheWire: Bandit
Build Linux and security fundamentals one level at a time. Progress stays in this browser.
Start or continue the track →Source-aligned study plans
Certification guides
Diagnose weak areas and plan review for SCS-C03, CISSP, SAP-C02, and AIP-C01. Progress stays on this device.
Curated reading
Research briefs
whitepaperCapability × Authority × ReachA provider-neutral systems-security framework for constraining autonomous AI agents through capability assessment, effective authority, bounded reach, exposure-path analysis, and runtime trajectory assurance.whitepaperSecure AWS Architecture: Decisions, Controls, Evidence, and RecoveryA decision model for multi-account AWS security: trust boundaries, identity, preventive and detective controls, evidence, containment, and recovery.whitepaperThreat Modeling AI Agents: Trust Boundaries, Controls, and EvidenceA vendor-neutral threat model for AI agents that separates model behavior from authorization and maps threats to controls, evidence, tests, and residual risk.whitepaperThreat Modeling That Produces Testable ControlsA practical method for turning system boundaries and abuse paths into owned controls, observable evidence, and repeatable tests.