books --list --format=readable

A hands-on series built for detection engineers. Each book goes deep on the systems, techniques, and adversary tradecraft you'll be asked about on day one.

4 Books
461 Chapters
9 Subject areas

Available now

Book 01 Complete

x86/x64 Assembly

Read, write, and follow compiled code in a disassembler without hesitation. From CPU architecture through calling conventions, shellcode, and recognizing compiler patterns.

69 Chapters
12 Parts
ASM NASM · GDB · x64dbg
Read
Book 03 Complete

Windows OS Internals

The Windows environment as malware sees it. PE format, process/thread internals, virtual memory, the loader, the security model, injection techniques, and kernel architecture.

45 Chapters
9 Parts
WIN WinDbg · PE-bear · x64dbg
Read
Book 07 Complete

Detection Engineering

From Sigma rules to live SIEM hunting. Covers SIEM platforms, EDR query languages, threat hunting workflows, cloud detection, SOAR, and interview-ready worked examples.

115 Chapters
12 Parts
DET Splunk · Sentinel · Elastic
Read
Book 09 Complete

Offensive Malware Dev

Build what defenders study. Shellcode, injection, EDR evasion, persistence, AD attacks, C2 architecture, rootkits, and complete APT tradecraft walkthroughs.

232 Chapters
23 Parts
OFF C · C++ · WinAPI
Read