x86/x64 Assembly
Read, write, and follow compiled code in a disassembler without hesitation. From CPU architecture through calling conventions, shellcode, and recognizing compiler patterns.
Readbooks --list --format=readable
A hands-on series built for detection engineers. Each book goes deep on the systems, techniques, and adversary tradecraft you'll be asked about on day one.
Read, write, and follow compiled code in a disassembler without hesitation. From CPU architecture through calling conventions, shellcode, and recognizing compiler patterns.
ReadThe Windows environment as malware sees it. PE format, process/thread internals, virtual memory, the loader, the security model, injection techniques, and kernel architecture.
ReadFull-spectrum network visibility — from raw packet capture and Wireshark to production NSM with Zeek and Suricata, NetFlow beaconing, Arkime PCAP retrieval, and cloud VPC forensics.
ReadFrom Sigma rules to live SIEM hunting. Covers SIEM platforms, EDR query languages, threat hunting workflows, cloud detection, SOAR, and interview-ready worked examples.
ReadBuild what defenders study. Shellcode, injection, EDR evasion, persistence, AD attacks, C2 architecture, rootkits, and complete APT tradecraft walkthroughs.
ReadEvidence acquisition, disk and memory forensics, artifact analysis, and timeline reconstruction. From triage imaging through full forensic workflows used in real investigations.
ReadStructured response from initial triage to containment, eradication, and lessons learned. Covers frameworks, tooling, playbooks, and hands-on walkthrough of real incident scenarios.
Read