Technical Playlists & Writeups

Security Playlists & Engineering Notes

Curated sequential learning paths, DevSecOps pipeline guides, and deep-dive technical postmortems. Filter by category or explore structured playlists.

Self-Hosting NetBird Zero-Trust Mesh VPN on Azure: Traefik, Cloudflare DNS & Subnet Routing
Cloud & Networking Aug 16, 2026 18 min

Self-Hosting NetBird Zero-Trust Mesh VPN on Azure: Traefik, Cloudflare DNS & Subnet Routing

Step-by-step engineering guide to deploying a production-ready self-hosted NetBird WireGuard mesh on an Azure Ubuntu VM with Traefik TLS, embedded IdP, Cloudflare DNS-Only routing, and Proxmox LXC subnet routing.

Cloud Security & IaC Engineering: Terraform Remote State Hardening & S3 Bucket Policy Defense
Cloud Security Aug 15, 2026 14 min

Cloud Security & IaC Engineering: Terraform Remote State Hardening & S3 Bucket Policy Defense

Protect sensitive Terraform state files, configure KMS client-side encryption, lock down public S3 access, and implement CloudTrail alert playbooks.

Active Directory Enterprise Killchain: Kerberoasting, DCSync, BloodHound & Tier-0 Defense
Offensive Aug 14, 2026 20 min

Active Directory Enterprise Killchain: Kerberoasting, DCSync, BloodHound & Tier-0 Defense

In-depth enterprise guide to Active Directory security: Kerberos ticket extraction (TGT/TGS), AS-REP Roasting, DCSync abuse, BloodHound shortest-path attack graph analysis, and Tiered Administration Architecture.

Ansible Production Linux Hardening: Automated CIS Benchmarks, SSH Lockdown & SIEM Orchestration
DevSecOps Aug 14, 2026 17 min

Ansible Production Linux Hardening: Automated CIS Benchmarks, SSH Lockdown & SIEM Orchestration

Mastering infrastructure automation with Ansible: Automated Linux server hardening against CIS Level 1 benchmarks, cryptographic SSH lockdown, Fail2ban jail orchestration, and Wazuh/CyberGuard SIEM agent rollout.

Cloud Security & IaC Engineering: Secure AWS IAM Architecture & Permission Boundaries
Cloud Security Aug 14, 2026 15 min

Cloud Security & IaC Engineering: Secure AWS IAM Architecture & Permission Boundaries

Master AWS IAM architecture, Attribute-Based Access Control (ABAC), Service Control Policies (SCPs), and automated Terraform static security checks.

GitHub Actions CI/CD Security Masterclass: Hardening Workflows, OIDC & Supply Chain Defense
DevSecOps Aug 14, 2026 18 min

GitHub Actions CI/CD Security Masterclass: Hardening Workflows, OIDC & Supply Chain Defense

Comprehensive engineering guide to securing GitHub Actions: PwnRequest attack vectors, OIDC AWS federated auth, runner isolation, untrusted input expression injection, and SLSA provenance signing.

Kubernetes Runtime Threat Defense: Pod Security Standards, Calico Policies & Falco eBPF Detection
DevSecOps Aug 14, 2026 19 min

Kubernetes Runtime Threat Defense: Pod Security Standards, Calico Policies & Falco eBPF Detection

Mastering production Kubernetes security: Pod Security Standards (Restricted), Calico zero-trust NetworkPolicies, admission controller enforcement with Kyverno, and Falco eBPF kernel runtime monitoring.

Terraform Enterprise IaC Hardening: S3 State Locking, KMS CMKs & Sentinel Policies
Cloud Security Aug 14, 2026 16 min

Terraform Enterprise IaC Hardening: S3 State Locking, KMS CMKs & Sentinel Policies

Production-grade guide to hardening Terraform Infrastructure as Code: S3 remote backend encryption with customer-managed KMS keys, DynamoDB state locking, Checkov SAST gates, and least-privilege cloud IAM.

Kubernetes Security Masterclass: Zero-Trust Microsegmentation & Falco eBPF Runtime Threat Hunting
Kubernetes Aug 13, 2026 15 min

Kubernetes Security Masterclass: Zero-Trust Microsegmentation & Falco eBPF Runtime Threat Hunting

Deploy Cilium eBPF network policies, configure real-time kernel anomaly detection with Falco, and analyze container escape mechanics.

Kubernetes Security Masterclass: Cluster Architecture Attack Surfaces & API Hardening
Kubernetes Aug 12, 2026 16 min

Kubernetes Security Masterclass: Cluster Architecture Attack Surfaces & API Hardening

Comprehensive breakdown of Kubernetes control plane security, API server authentication, RBAC authorization auditing, and securing worker node kubelets.

DevSecOps Pipeline Hardening: Automated SAST/DAST & Secret Scanning with Semgrep and TruffleHog
DevSecOps Aug 11, 2026 12 min

DevSecOps Pipeline Hardening: Automated SAST/DAST & Secret Scanning with Semgrep and TruffleHog

Implement automated static analysis security testing (SAST), secret leak detection, and inline PR security gates into your CI/CD pipeline.

DevSecOps Pipeline Hardening: Hardening GitHub Actions & OIDC Federated Auth
DevSecOps Aug 10, 2026 14 min

DevSecOps Pipeline Hardening: Hardening GitHub Actions & OIDC Federated Auth

Eliminate long-lived cloud credentials in CI/CD by configuring GitHub Actions OIDC federated authentication with AWS IAM, securing workflow triggers, and preventing script injection.

Landing Your First Cybersecurity Internship: A Student's Playbook
Career Guidance May 20, 2026 9 min

Landing Your First Cybersecurity Internship: A Student's Playbook

How to get your first security internship without prior experience: building proof of skill, writing a resume that passes the filter, and showing up ready for the interview.

How I Earned 17 Cybersecurity Certifications as a Student
Career Guidance Apr 12, 2026 9 min

How I Earned 17 Cybersecurity Certifications as a Student

An honest look at building a certification stack while in university: which certs actually matter, how to study efficiently, and how to avoid the cert collecting trap.

Wireshark Deep Dive: Hunting Threats in Packet Captures
Tools & Techniques Mar 5, 2026 11 min

Wireshark Deep Dive: Hunting Threats in Packet Captures

Beyond capture filters: how to use Wireshark to find command and control beaconing, DNS tunneling, and data exfiltration hiding inside ordinary looking traffic.

Mastering Nmap: From Host Discovery to NSE Scripting
Tools & Techniques Feb 10, 2026 10 min

Mastering Nmap: From Host Discovery to NSE Scripting

A practical deep dive into Nmap: how scan types actually work, tuning for speed and stealth, and using the scripting engine to turn a port scanner into a recon platform.

Zero Trust Architecture - A Practical Implementation Guide
Security Architecture Dec 15, 2025 12 min

Zero Trust Architecture - A Practical Implementation Guide

A comprehensive guide to understanding and implementing Zero Trust security architecture in modern enterprise environments.

Advanced Web Application Penetration Testing Methodology
Penetration Testing Nov 28, 2025 15 min

Advanced Web Application Penetration Testing Methodology

Deep dive into modern web application security testing techniques, OWASP Top 10 exploitation, and professional pentesting methodology.

Building a Red Team Lab - From Beginner to Advanced
Tutorial Nov 15, 2025 14 min

Building a Red Team Lab - From Beginner to Advanced

Step-by-step guide to building your own penetration testing and red team lab environment for security practice and skill development.

API Security Testing - Finding & Exploiting Vulnerabilities
Security Testing Oct 30, 2025 12 min

API Security Testing - Finding & Exploiting Vulnerabilities

Comprehensive guide to API security testing, covering REST, GraphQL, authentication bypass, and common API vulnerabilities.

Malware Analysis for Beginners - Static & Dynamic Techniques
Malware Analysis Oct 15, 2025 16 min

Malware Analysis for Beginners - Static & Dynamic Techniques

Introduction to malware analysis techniques including static analysis, dynamic analysis, behavioral analysis, and practical case studies.

Cloud Security - Securing AWS, Azure, and GCP
Cloud Security Sep 28, 2025 14 min

Cloud Security - Securing AWS, Azure, and GCP

Comprehensive guide to cloud security best practices across AWS, Azure, and GCP, covering IAM, misconfigurations, and multi-cloud security strategies.

Active Directory Attacks & Defense - A Complete Guide
Windows Security Sep 15, 2025 18 min

Active Directory Attacks & Defense - A Complete Guide

In-depth guide to Active Directory attack techniques and defense strategies, covering enumeration, lateral movement, persistence, and detection.

Bug Bounty Hunting - From Zero to First Bounty
Bug Bounty Aug 30, 2025 13 min

Bug Bounty Hunting - From Zero to First Bounty

Complete guide to starting your bug bounty hunting journey, from choosing platforms to writing reports and earning your first bounty.

Network Security Monitoring with Wireshark & Zeek
Network Security Aug 15, 2025 12 min

Network Security Monitoring with Wireshark & Zeek

Practical guide to network security monitoring using Wireshark and Zeek for traffic analysis, threat hunting, and incident detection.

Docker & Kubernetes Security - Container Hardening
DevSecOps Jul 30, 2025 15 min

Docker & Kubernetes Security - Container Hardening

Advanced guide to securing Docker containers and Kubernetes clusters, covering image scanning, RBAC, runtime security, and incident response.

SIEM Deployment & Threat Detection - Wazuh & Splunk
SOC / SIEM Jul 15, 2025 14 min

SIEM Deployment & Threat Detection - Wazuh & Splunk

Practical guide to deploying SIEM solutions using Wazuh and Splunk for threat detection, custom rules, and incident response workflows.

Mobile Application Security Testing (Android & iOS)
Mobile Security Jun 28, 2025 16 min

Mobile Application Security Testing (Android & iOS)

Comprehensive guide to mobile application security testing for Android and iOS, covering static analysis, dynamic analysis, and reverse engineering.

Incident Response Playbook - Ransomware Attack
Incident Response Jun 15, 2025 14 min

Incident Response Playbook - Ransomware Attack

Step-by-step incident response playbook for handling ransomware attacks, covering detection, containment, eradication, recovery, and forensic analysis.

Secure Code Review - Finding Vulnerabilities in Source Code
Application Security May 30, 2025 15 min

Secure Code Review - Finding Vulnerabilities in Source Code

Guide to secure code review methodology, common vulnerability patterns across languages, and automated SAST tools for application security.

Career in Cybersecurity - From Student to Professional
Career Guidance May 15, 2025 12 min

Career in Cybersecurity - From Student to Professional

Personal guide to building a successful cybersecurity career, covering learning paths, certifications, portfolio building, and job search strategies.

Building a Professional SOC Lab with Wazuh and ELK Stack
Tutorial Feb 1, 2025 11 min

Building a Professional SOC Lab with Wazuh and ELK Stack

A practical blueprint for a home SOC lab: Wazuh plus the Elastic Stack, telemetry generation with Atomic Red Team, and your first real detection rule and dashboard.

My Path to Top 3% on TryHackMe
Career Guidance Jan 15, 2025 9 min

My Path to Top 3% on TryHackMe

How consistent practice, structured note taking, and a repeatable methodology took me into the top 3 percent on TryHackMe, and how those skills carried into real security work.

Practical MITRE ATT&CK Framework for SOC Analysts
SOC Jan 1, 2025 10 min

Practical MITRE ATT&CK Framework for SOC Analysts

A hands-on guide to using MITRE ATT&CK in a real SOC: mapping alerts to techniques, writing detections, and finding coverage gaps with ATT&CK Navigator.