Complete learning catalog
One curriculum.Every concept connected.
The interactive sessions create the story. These technical-learning pages slow down each durable concept with a mental model, visual explanation, decision aid, cybersecurity example, FAQ, and primary sources.
PATH 01
Agentic AI foundations
Build the mental models before adding autonomy.
8 topics
01Governed Agentic AI for CybersecurityA four-session visual learning path from LLMs and reusable skills to agentic security risks, governed orchestration, and a hands-on cybersecurity agent workshop.Interactive series02LLMs, prompts, and context: the useful mental modelUnderstand what an LLM actually does, how context shapes a response, and why confident language is not the same as verified knowledge.Session 1 · 8 min03Instructions, user requests, and data need different trust levelsLearn how instruction hierarchy works and why untrusted content must never acquire authority simply because an LLM can read it.Session 1 · 9 min04From chat to projects: preserving useful working contextChoose between an ad-hoc conversation, a persistent project, and a reusable governed capability without adding autonomy too early.Session 1 · 7 min05Cybersecurity skill anatomy: package the method, not only the promptStructure repeatable cybersecurity expertise with an operating contract, focused references, schemas, deterministic scripts, and reusable assets.Session 1 · 10 min06Function tools, MCP, and RAG solve different problemsDistinguish bounded actions, standardized capability connections, and evidence retrieval so the architecture matches the task.Session 1 · 10 min07The agentic loop: reason, act, observe, and stop safelyUnderstand the runtime loop around a model and the state, limits, validation, escalation, and termination rules that make it governable.Session 1 · 11 min08Single-agent and multi-agent orchestration: choose who owns the answerSelect manager, handoff, or code-led orchestration only when specialization and typed handoffs justify the coordination cost.Session 1 · 12 min
PATH 02
Secure agentic systems
Treat every new capability as a new trust boundary.
6 topics
01Prompt injection: when untrusted data tries to become an instructionUnderstand direct and indirect prompt injection, why prompt hardening is incomplete, and where system controls can still stop harm.Session 2 · 12 min02Excessive agency: reduce function, permission, and autonomyControl agentic risk by independently constraining what functions exist, which permissions they receive, and when autonomous execution is allowed.Session 2 · 11 min03Secure MCP, tools, retrieval, and agent memoryThreat-model capability connections, retrieved evidence, tool outputs, and durable memory as separate trust and data-governance boundaries.Session 2 · 13 min04Guardrails, human approval, and deterministic control planesPlace input, output, tool, policy, and human controls at the point where they can still prevent harm instead of relying on one filter.Session 2 · 12 min05The secure agent technology stack: choose each layer by responsibilityMap UI, API, orchestration, models, tools, state, observability, evaluations, and guardrails to the problem each layer owns.Session 2 · 14 min06Langfuse for cybersecurity: an SOC lensHow Langfuse traces, sessions, users, scores, evaluations and prompt versions help secure agentic systems—and why a SOC still needs a SIEM for correlation, incidents and response.Deep dive
PATH 03
Cybersecurity Orchestrator
Turn specialist expertise into a governed delivery system.
5 topics
01Cybersecurity Orchestrator: the control plane is the productUnderstand how one governed control spine coordinates specialist cybersecurity skills, deterministic gates, artifacts, and human decisions.Session 3 · 12 min02Specialist capability flows for documents, Sentinel, CSPM, and architecture reviewSee how intake routes to document, architecture, compliance, detection, and cloud-posture specialists without losing ownership or evidence.Session 3 · 13 min03ArchStudio through MCP: generate quickly, assure deliberatelySeparate fast diagram generation from premium architecture assurance while preserving editable artifacts, findings, and lineage.Session 3 · 10 min04Artifacts, journals, and lineage: make the run explainableUse typed artifacts for handoffs, a journal for authoritative actions and decisions, and observability traces for execution diagnosis.Session 3 · 11 min05Current-state and future-state agentic security architectureCommunicate what is implemented now, what evidence supports it, and which controls are planned without presenting a roadmap as production reality.Session 3 · 9 min
PATH 04
Build and secure an agent
Move from bounded task to defensible release evidence.
3 topics
01Build and secure your first cybersecurity agentA practical build sequence from bounded task and non-goals through skill, structured output, narrow tools, controls, attack tests, and ship decision.Session 4 · 15 min02Threat-model the agent workflow before choosing toolsMap assets, actors, trust boundaries, data flows, abuse paths, side effects, and recovery before granting an agent capabilities.Session 4 · 13 min03Agent evaluations and release readiness: prove repeatabilityCombine deterministic tests, human review, model-based evaluation, adversarial cases, operational thresholds, and rollback evidence into a ship decision.Session 4 · 14 min
PATH 05
Detection engineering
Turn detection logic into a testable, governed delivery pipeline.
2 topics
01Detection-as-Code: the pipeline & governanceHow analytic rules move from an engineer's idea to a production Sentinel workspace — repo strategy, deploy engines (ARM vs Terraform), CI vs CD, IaC vs API, and the governance case.Deep dive02Validating Sentinel detections in CI/CDThe three tiers of KQL validation — static lint, syntax/schema check, and functional 'does it fire' testing — mapped to SAST, compile, and DAST, and placed in the pipeline as a shift-left gate.Hands-on guide
PATH 06
Engineering foundations
Build the collaboration habits that make automation safe to change.
2 topics
01Git collaboration: branches, forks & conflictsHow multiple people work on one repo without colliding — the contribution flow, shared-repo vs fork model, why one branch per task, and exactly what happens when two people push to the same branch.Hands-on guide02Git worktrees: many branches at onceThe working tree explained, then git worktree — one repository with several branches checked out in parallel folders. When you need it (hotfix mid-feature, PR review, parallel builds) and how it works.Hands-on guide