Field school
Learn the stack, one tool type at a time.
35short lessons, in a deliberate order. Each one explains a single kind of security tool in plain English — what it does, the attack it stops, how it actually works, and what it can't do — then hands you the real tools that do it.
First, the big picture.
No single security tool protects a company. Instead, defenders layer many specialized tools so that an attacker who slips past one runs into the next — an idea called defense in depth. A phishing email has to beat the email filter, then the user's judgment, then the endpoint agent watching what runs, then the network controls around whatever it reached — while detection tools watch everything for the noise that fight makes.
This guide organizes the whole landscape into 10 domains — the colored bands on the right, and the same colors used everywhere on this site. Every lesson below teaches one tool type from one domain. Follow them in order and each lesson builds on the ones before it; jump around freely if you already know the basics.
The guided path.
Part 1
Foundations
The controls almost every organization deploys first, in the order an attack usually meets them — and the concepts every later lesson builds on.
- 01NGFWHow a firewall decides what gets throughUnderstanding next-generation firewallLesson + 9 tools
- 02EPPHow your laptop blocks malware before it runsUnderstanding endpoint protection platformLesson + 6 tools
- 03EDR/XDRThe flight recorder for every laptop and serverUnderstanding endpoint & extended detection and responseLesson + 12 tools
- 04IAM/SSOHow one login safely opens every app at workUnderstanding identity & access management / single sign-onLesson + 4 tools
- 05MFAWhy a stolen password no longer means game overUnderstanding mfa & passwordless authenticationLesson + 2 tools
- 06Email SecurityHow a scam email gets caught before you see itUnderstanding email securityLesson + 9 tools
- 07SATWhy companies phish their own employeesUnderstanding security awareness trainingLesson + 6 tools
- 08SIEMHow a million boring logs become one urgent alertUnderstanding security information & event managementLesson + 12 tools
- 09VMWhy you can't patch everything, and how to chooseUnderstanding vulnerability managementLesson + 6 tools
- 10BCDRThe copy of your data ransomware can't touchUnderstanding backup & cyber recoveryLesson + 9 tools
Part 2
Controlling access & devices
Who gets in, with how much privilege, from which devices — the identity-driven controls that have replaced the office network as the real perimeter.
- 11MDM/UEMKeeping a thousand devices safe from one screenUnderstanding mobile & unified endpoint managementLesson + 3 tools
- 12PAMGuarding the accounts that could burn it all downUnderstanding privileged access managementLesson + 5 tools
- 13IGAProving nobody kept keys they shouldn't haveUnderstanding identity governance & administrationLesson + 3 tools
- 14SASE/ZTNAWhy remote work broke the corporate VPNUnderstanding sase, sse & zero trust network accessLesson + 6 tools
- 15CASBFinding the apps your IT team never approvedUnderstanding cloud access security brokerLesson + 5 tools
Part 3
Protecting networks, apps & data
Deeper, more specialized protection for the traffic you carry, the software you build and depend on, and the sensitive data you hold.
- 16IDS/NDRCatching intruders the firewall already let inUnderstanding intrusion detection & network detection and responseLesson + 18 tools
- 17DDoS ProtectionSurviving a flood of a million fake visitorsUnderstanding ddos protectionLesson + 4 tools
- 18WAFHow a web app tells a real request from an attackUnderstanding waf & api securityLesson + 7 tools
- 19SASTCatching security bugs by reading code, not running itUnderstanding static application security testingLesson + 10 tools
- 20DASTAttacking your own app before someone else doesUnderstanding dynamic application security testingLesson + 8 tools
- 21SCAWhat's really inside the software you shipUnderstanding software composition analysis & supply chain securityLesson + 8 tools
- 22DLPCatching secrets on their way out the doorUnderstanding data loss preventionLesson + 5 tools
- 23DSPMFinding the sensitive data you forgot you hadUnderstanding data security posture managementLesson + 5 tools
- 24KMSEncryption is easy — guarding the keys is hardUnderstanding encryption & key managementLesson + 8 tools
- 25CLMThe expiring passports every machine carriesUnderstanding certificate lifecycle managementLesson + 8 tools
Part 4
Cloud & security operations
Securing cloud-native infrastructure, and the practices a maturing security team layers on top of everything else: intelligence, automation, testing, and response.
- 26CNAPP/CSPMWhy cloud breaches start with a checkboxUnderstanding cloud-native application protection / posture managementLesson + 14 tools
- 27Container & Kubernetes SecurityHow a bad container gets stopped at the cluster doorUnderstanding container & kubernetes securityLesson + 8 tools
- 28TIHow defenders learn an attacker's next moveUnderstanding threat intelligenceLesson + 6 tools
- 29SOARHow an alert gets answered while analysts sleepUnderstanding security orchestration, automation & responseLesson + 10 tools
- 30ASM/BASSeeing your network the way an attacker doesUnderstanding attack surface management & breach/attack simulationLesson + 7 tools
- 31DFIRWhat happens after a breach is confirmedUnderstanding digital forensics & incident responseLesson + 7 tools
- 32GRCHow a company proves it's actually secureUnderstanding grc & compliance automationLesson + 9 tools
Part 5
Securing AI systems
A lifecycle view of the controls used to inventory, test, and protect models, generative-AI applications, and agents without confusing AI security with ordinary AI-enabled tooling.
- 33AI-SPMFinding and governing the AI you actually useUnderstanding ai security posture & governanceLesson + 4 tools
- 34AI Red TeamingHow defenders break an AI system before attackers doUnderstanding ai security testing & model assuranceLesson + 7 tools
- 35AI RuntimePutting guardrails around AI applications and agentsUnderstanding ai application & agent securityLesson + 5 tools