Field school

Learn the stack, one tool type at a time.

35short lessons, in a deliberate order. Each one explains a single kind of security tool in plain English — what it does, the attack it stops, how it actually works, and what it can't do — then hands you the real tools that do it.

First, the big picture.

No single security tool protects a company. Instead, defenders layer many specialized tools so that an attacker who slips past one runs into the next — an idea called defense in depth. A phishing email has to beat the email filter, then the user's judgment, then the endpoint agent watching what runs, then the network controls around whatever it reached — while detection tools watch everything for the noise that fight makes.

This guide organizes the whole landscape into 10 domains — the colored bands on the right, and the same colors used everywhere on this site. Every lesson below teaches one tool type from one domain. Follow them in order and each lesson builds on the ones before it; jump around freely if you already know the basics.

An attacker's path
Network & Perimeter
Endpoint & Device
Identity & Access
Cloud Security
Application Security
Data Security
Security Operations
Resilience & Recovery
GRC & Human Layer
AI Security
Your data & systems
10 domains of layered defense. No layer is perfect — the stack works because an attacker has to beat several in a row.

The guided path.

  1. Part 1

    Foundations

    The controls almost every organization deploys first, in the order an attack usually meets them — and the concepts every later lesson builds on.

    1. 01NGFW
      How a firewall decides what gets throughUnderstanding next-generation firewallLesson + 9 tools
    2. 02EPP
      How your laptop blocks malware before it runsUnderstanding endpoint protection platformLesson + 6 tools
    3. 03EDR/XDR
      The flight recorder for every laptop and serverUnderstanding endpoint & extended detection and responseLesson + 12 tools
    4. 04IAM/SSO
      How one login safely opens every app at workUnderstanding identity & access management / single sign-onLesson + 4 tools
    5. 05MFA
      Why a stolen password no longer means game overUnderstanding mfa & passwordless authenticationLesson + 2 tools
    6. 06Email Security
      How a scam email gets caught before you see itUnderstanding email securityLesson + 9 tools
    7. 07SAT
      Why companies phish their own employeesUnderstanding security awareness trainingLesson + 6 tools
    8. 08SIEM
      How a million boring logs become one urgent alertUnderstanding security information & event managementLesson + 12 tools
    9. 09VM
      Why you can't patch everything, and how to chooseUnderstanding vulnerability managementLesson + 6 tools
    10. 10BCDR
      The copy of your data ransomware can't touchUnderstanding backup & cyber recoveryLesson + 9 tools
  2. Part 2

    Controlling access & devices

    Who gets in, with how much privilege, from which devices — the identity-driven controls that have replaced the office network as the real perimeter.

    1. 11MDM/UEM
      Keeping a thousand devices safe from one screenUnderstanding mobile & unified endpoint managementLesson + 3 tools
    2. 12PAM
      Guarding the accounts that could burn it all downUnderstanding privileged access managementLesson + 5 tools
    3. 13IGA
      Proving nobody kept keys they shouldn't haveUnderstanding identity governance & administrationLesson + 3 tools
    4. 14SASE/ZTNA
      Why remote work broke the corporate VPNUnderstanding sase, sse & zero trust network accessLesson + 6 tools
    5. 15CASB
      Finding the apps your IT team never approvedUnderstanding cloud access security brokerLesson + 5 tools
  3. Part 3

    Protecting networks, apps & data

    Deeper, more specialized protection for the traffic you carry, the software you build and depend on, and the sensitive data you hold.

    1. 16IDS/NDR
      Catching intruders the firewall already let inUnderstanding intrusion detection & network detection and responseLesson + 18 tools
    2. 17DDoS Protection
      Surviving a flood of a million fake visitorsUnderstanding ddos protectionLesson + 4 tools
    3. 18WAF
      How a web app tells a real request from an attackUnderstanding waf & api securityLesson + 7 tools
    4. 19SAST
      Catching security bugs by reading code, not running itUnderstanding static application security testingLesson + 10 tools
    5. 20DAST
      Attacking your own app before someone else doesUnderstanding dynamic application security testingLesson + 8 tools
    6. 21SCA
      What's really inside the software you shipUnderstanding software composition analysis & supply chain securityLesson + 8 tools
    7. 22DLP
      Catching secrets on their way out the doorUnderstanding data loss preventionLesson + 5 tools
    8. 23DSPM
      Finding the sensitive data you forgot you hadUnderstanding data security posture managementLesson + 5 tools
    9. 24KMS
      Encryption is easy — guarding the keys is hardUnderstanding encryption & key managementLesson + 8 tools
    10. 25CLM
      The expiring passports every machine carriesUnderstanding certificate lifecycle managementLesson + 8 tools
  4. Part 4

    Cloud & security operations

    Securing cloud-native infrastructure, and the practices a maturing security team layers on top of everything else: intelligence, automation, testing, and response.

    1. 26CNAPP/CSPM
      Why cloud breaches start with a checkboxUnderstanding cloud-native application protection / posture managementLesson + 14 tools
    2. 27Container & Kubernetes Security
      How a bad container gets stopped at the cluster doorUnderstanding container & kubernetes securityLesson + 8 tools
    3. 28TI
      How defenders learn an attacker's next moveUnderstanding threat intelligenceLesson + 6 tools
    4. 29SOAR
      How an alert gets answered while analysts sleepUnderstanding security orchestration, automation & responseLesson + 10 tools
    5. 30ASM/BAS
      Seeing your network the way an attacker doesUnderstanding attack surface management & breach/attack simulationLesson + 7 tools
    6. 31DFIR
      What happens after a breach is confirmedUnderstanding digital forensics & incident responseLesson + 7 tools
    7. 32GRC
      How a company proves it's actually secureUnderstanding grc & compliance automationLesson + 9 tools
  5. Part 5

    Securing AI systems

    A lifecycle view of the controls used to inventory, test, and protect models, generative-AI applications, and agents without confusing AI security with ordinary AI-enabled tooling.

    1. 33AI-SPM
      Finding and governing the AI you actually useUnderstanding ai security posture & governanceLesson + 4 tools
    2. 34AI Red Teaming
      How defenders break an AI system before attackers doUnderstanding ai security testing & model assuranceLesson + 7 tools
    3. 35AI Runtime
      Putting guardrails around AI applications and agentsUnderstanding ai application & agent securityLesson + 5 tools

Search Cyber Tool Stack

Jump to any tool, vendor, category, or glossary term.