Active Directory tiering: Tier 0 in practice
How to split an environment into tiers, what really belongs to Tier 0, how to enforce the split technically and how to migrate without downtime.
Active Directory, Entra ID, authentication, PKI and privileged access: attack paths, secure configuration, detection and retesting.
How to split an environment into tiers, what really belongs to Tier 0, how to enforce the split technically and how to migrate without downtime.
How JWT verification works and where it breaks: alg confusion, kid injection, JWKS handling, iss/aud validation, revocation, testing and detection.
Credentials linked to more than 70,000 FortiGate devices were leaked. FortiBleed is not a new zero-day: learn the confirmed facts and response steps.
Protect passwords, tokens and API keys with workload identity, Vault, KMS, short TTLs, rotation, audit trails and a tested leak-response process.
PAM reduces risks from administrator accounts, secrets and sessions. Learn how to deploy JIT access, session control and meaningful metrics.
A quantum computer will break RSA and ECC, and the "collect now, decrypt later" attack is underway today. We discuss ML-KEM, ML-DSA, hybrid modes and migration plan.
Passkeys remove passwords and are phishing-resistant. We explain how they work, how they differ from MFA and how to start rolling them out.
MFA is the cheapest risk reduction we know — but only when deployed well. The differences between methods, a staged rollout plan and common traps.
Shared passwords in a spreadsheet are a ticking bomb. How a business password manager works, how to choose one and roll it out to teams.
Technical SAML 2.0 testing for XML signatures, wrapping, Audience, Destination, Recipient, replay, RelayState and identity-provider key rotation.
Audit TLS 1.3, mutual TLS and PKI: protocol negotiation, identity validation, certificate paths, revocation, 0-RTT and key rotation.
Stolen personal data lets criminals take out loans or register a company in your name. How identity theft happens and how to protect yourself.
Change your password every 30 days? Invent complex character strings? We explain which password rules are outdated myths and what really protects your accounts.
Assess Entra ID tokens, consent, roles, Conditional Access, PIM, service principals, workload identities, hybrid trust and cloud identity detection.
A technical model for NTLM relay to SMB, LDAP and HTTP, with safe assessment, signing, channel binding, EPA, detection and NTLM migration guidance.
Understand S4U2self, S4U2proxy, KCD and RBCD, then safely assess delegation ACLs, SPNs, tickets, detection and lateral-movement exposure.
Audit AD CS, certificate templates and ESC1–ESC15 paths. Understand PKINIT, strong mapping, safe validation, detection and enterprise PKI hardening.
We turn current threats into role-based training, safe exercises and a clear reporting path. The free Academy remains available for self-directed learning.