Command Palette

Search for a command to run...

Hectal

DevSecOps · threat, detect, defend

Understand the threat.
Then make it impossible.

Security checklists are forgettable; seeing your own AWS key come out of your own Docker image is not. Each of these labs starts from a real class of weakness in a setup you run yourself, shows the tool or alert that catches it, hardens the configuration side by side, and verifies the fix with the same checks.

4 chapters16 labs23 threat walkthroughs

Every lab, four phases

  1. Threat

    How the weakness is abused in the real world, what it exposes, and the incidents that made it famous.

  2. Detect

    The scanner, CI check, or runtime alert that would have caught it, and its real output.

  3. Defend

    The vulnerable config and the hardened one, side by side, with why each line matters.

  4. Verify

    Run the same scanners and checks again. A fix you haven't verified is a fix you're only hoping works.

Everything in this course targets a lab on your own machine or account. Using these techniques against systems you aren't authorised to test is illegal, and the course never asks you to.

Chapters