x86/x64 Assembly
Read, write, and follow compiled code in a disassembler without hesitation. From CPU architecture through calling conventions, shellcode, and recognizing compiler patterns.
Readbooks --list --format=readable
A hands-on series built for detection engineers. Each book goes deep on the systems, techniques, and adversary tradecraft you'll be asked about on day one.
Read, write, and follow compiled code in a disassembler without hesitation. From CPU architecture through calling conventions, shellcode, and recognizing compiler patterns.
ReadThe Windows environment as malware sees it. PE format, process/thread internals, virtual memory, the loader, the security model, injection techniques, and kernel architecture.
ReadFrom Sigma rules to live SIEM hunting. Covers SIEM platforms, EDR query languages, threat hunting workflows, cloud detection, SOAR, and interview-ready worked examples.
ReadBuild what defenders study. Shellcode, injection, EDR evasion, persistence, AD attacks, C2 architecture, rootkits, and complete APT tradecraft walkthroughs.
Read