Domain map
30 Domains
हर domain के अंदर modules हैं, module के अंदर chapters, chapter के अंदर topics। हर चीज़ की अपनी unique ID है — Y01-P01-D01-M01-C01-T01-L01 — ताकि आप कभी खो ना जाओ।
P01Phase 1 — मशीन और Operating System
D01कंप्यूटर की बुनियाद
ज़रूरीमशीन आपका code असल में चलाती कैसे है — transistor से लेकर उस process table तक जिसे आप रोज़ पढ़ोगे।
D02Operating Systems — Linux और Windows
ज़रूरीदो अलग security models, दोनों को ठीक से सीखना — एक को दूसरे की मिसाल से नहीं समझना।
P02Phase 2 — Network और Code
P03Phase 3 — Web, Data और Crypto
D05Web Technology
ज़रूरीWeb असल में काम कैसे करता है — उसके टूटने की बात बाद में।
D06Web Application Security
ज़रूरीहर बड़ी class, इस format में: क्या → क्यों → ROOT CAUSE → DETECT → LAB → IMPACT → FIX → PREVENT → MONITOR → VERIFY।
D07Database Security
ज़रूरीData rest पर, transit में, और query के अंदर — privilege सबसे पहला control।
D08Cryptography
ज़रूरीPrimitives, protocols, PKI — और वो misuse patterns जिनसे लगभग सारी असली failures होती हैं।
D09Security Fundamentals
ज़रूरीवो vocabulary और reasoning frameworks जो बाक़ी पूरा field आपसे पहले से expect करता है।
P04Phase 4 — Infrastructure और Identity
D10Network Security
ज़रूरीSegmentation, inspection और detection — पहले design, फिर TEST।
D11Windows Security
ज़रूरीTokens, ACLs, credential material, और वो telemetry जो abuse दिखाती है।
D12Active Directory
ज़रूरीStructure, authentication protocols, misconfiguration classes और hardening — offensive काम सिर्फ़ अपने isolated lab में।
D28Identity Security
ज़रूरीOAuth, OIDC, JWT, MFA और privileged access — आज का असली perimeter।
P05Phase 5 — Cloud और Defence
D13Cloud Security
ज़रूरीAWS, Azure और GCP — IAM को primary control plane मान कर।
D14Container और Kubernetes Security
अहमIsolation primitives, image supply chain और cluster authorisation।
D15SOC और Blue Team
ज़रूरीLog pipelines, detection engineering, triage, hunting और incident response।
D16Digital Forensics
अहमArtefacts से events reconstruct करना, defensible methodology के साथ।
P06Phase 6 — Adversary
D17Threat Intelligence
अहमRaw reporting से prioritised, testable defensive action तक।
D18Malware Analysis
अहमVerified isolation में safe triage और behavioural analysis।
D19Penetration Testing और Red Team
ज़रूरीProfessional, authorised offensive methodology — पूरी hacking pipeline: recon → scan → exploit → post-exploit → report → retest।
D20Mobile Security
स्पेशलाइज़ेशनAndroid और iOS के platform models, app storage, IPC और API security।
D31Wireless और Radio Security
स्पेशलाइज़ेशनWiFi, Bluetooth और radio — जहाँ attack surface हवा में तैरता है और perimeter का मतलब बदल जाता है।
D32OSINT और Social Engineering
अहमPublic information से intelligence, और इंसान — जो हर security chain की सबसे कमज़ोर कड़ी है।
P07Phase 7 — Engineering और Reversing
D21Reverse Engineering
अहमCompiled code का static और dynamic analysis।
D22Binary Security और Exploit Mitigation
स्पेशलाइज़ेशनMemory corruption classes और उन्हें रोकने के लिए बनी mitigations — defensive engineering की तरह, isolated educational labs में।
D23Fuzzing और Automated Discovery
स्पेशलाइज़ेशनHarness design, coverage-guided campaigns और disciplined crash triage।
D27DevSecOps और Supply Chain
अहमSecurity controls वहाँ embedded जहाँ code build और ship होता है।
D29Security Architecture
अहमऐसे systems design करना जिनकी security असली users और असली budget से टकराने के बाद भी बची रहे।
P08Phase 8 — Research
D24Vulnerability Research और Disclosure
स्पेशलाइज़ेशनHypothesis-driven research, safe proof of concept, और responsible disclosure।
D25Kernel, Browser और Isolation Security
स्पेशलाइज़ेशनवो boundaries जिन पर modern security असल में टिकी है।
D26Hardware, Firmware और IoT Security
स्पेशलाइज़ेशनBoot chains, trusted hardware और limited resources वाले devices।
D30AI और LLM Security
स्पेशलाइज़ेशनAI systems के लिए model, data, application और agent security।