Knowledge Base

Fast, accessible security reference notes.

Quick technical summaries covering protocols, tools, and defense principles. Real-time client-side search with zero external queries.

Networking

OSI & TCP/IP Models

A structured framework for categorizing protocol interactions, PDUs, and layer-specific defensive controls.

Study Module 2 →

Networking

Ethernet & ARP Spoofing

Layer 2 frame anatomy, CAM tables, broadcast domains, and mitigating unauthenticated ARP poison attacks with DAI.

Study Module 3 →

Networking

IPv4, CIDR & Subnetting

Header fields (TTL, flags), RFC 1918 private spaces, NAT/PAT translation, and CIDR prefix arithmetic.

Study Module 4 →

Networking

TCP Handshake & SYN Floods

3-way handshake mechanics, sequence numbers, control flags, and mitigating backlog exhaustion with SYN Cookies.

Study Module 5 →

Networking

DNS Architecture & Tunneling

Root/TLD/Authoritative hierarchy, SPF/DKIM TXT records, and detecting high-entropy DNS exfiltration queries.

Study Module 6 →

Operations

SIEM Architecture

Pipeline design for ingesting Sysmon and security logs, normalising events, and building alert triage workflows.

Operations

Wazuh EDR/XDR

Deploying host agents, manager cluster architecture, file integrity monitoring (FIM), and active response playbooks.

Hunting

Threat Hunting Methodology

Formulating falsifiable hypotheses, mapping to MITRE ATT&CK techniques, and documenting evidence trails.

Defensive

Zero Trust & Microsegmentation

Moving beyond perimeter security: continuous verification, least privilege access, and host isolation.