books --list --format=readable

A hands-on series built for detection engineers. Each book goes deep on the systems, techniques, and adversary tradecraft you'll be asked about on day one.

7 Books
621 Chapters
12 Subject areas

Available now

Book 01 Complete

x86/x64 Assembly

Read, write, and follow compiled code in a disassembler without hesitation. From CPU architecture through calling conventions, shellcode, and recognizing compiler patterns.

69 Chapters
12 Parts
ASM NASM · GDB · x64dbg
Read
Book 03 Complete

Windows OS Internals

The Windows environment as malware sees it. PE format, process/thread internals, virtual memory, the loader, the security model, injection techniques, and kernel architecture.

45 Chapters
9 Parts
WIN WinDbg · PE-bear · x64dbg
Read
Book 06 Complete

Network Forensics & Traffic Analysis

Full-spectrum network visibility — from raw packet capture and Wireshark to production NSM with Zeek and Suricata, NetFlow beaconing, Arkime PCAP retrieval, and cloud VPC forensics.

75 Chapters
13 Parts
NET Zeek · Suricata · Arkime
Read
Book 07 Complete

Detection Engineering

From Sigma rules to live SIEM hunting. Covers SIEM platforms, EDR query languages, threat hunting workflows, cloud detection, SOAR, and interview-ready worked examples.

115 Chapters
12 Parts
DET Splunk · Sentinel · Elastic
Read
Book 09 Complete

Offensive Malware Dev

Build what defenders study. Shellcode, injection, EDR evasion, persistence, AD attacks, C2 architecture, rootkits, and complete APT tradecraft walkthroughs.

232 Chapters
23 Parts
OFF C · C++ · WinAPI
Read
Book 10 Complete

Digital Forensics

Evidence acquisition, disk and memory forensics, artifact analysis, and timeline reconstruction. From triage imaging through full forensic workflows used in real investigations.

52 Chapters
10 Parts
FOR Autopsy · Volatility · FTK
Read
Book 11 Complete

Incident Response

Structured response from initial triage to containment, eradication, and lessons learned. Covers frameworks, tooling, playbooks, and hands-on walkthrough of real incident scenarios.

33 Chapters
7 Parts
IR PICERL · Velociraptor · MITRE
Read