Ten chapters covering the core concepts every other domain in H3AD-LEARN builds on: the CIA triad, authentication and access control, cryptography basics, common attack patterns, security frameworks and compliance, risk and vulnerability management, SOC operations basics, identity federation, threat modeling, and how it all maps to a career track. Built for anyone starting a SOC analyst, threat hunting, or detection engineering path with no assumed background.
No chapters match “”.
Confidentiality, integrity, and availability as the core security model, the Parkerian Hexad extension, AAA, and the vocabulary of threat, vulnerability, risk, and attack surface every other chapter assumes.
The three authentication factors, MFA mechanics from TOTP to passkeys, RBAC and ABAC authorization models, least privilege, and why Zero Trust replaced the perimeter model.
Symmetric and asymmetric encryption, hashing and integrity, digital signatures, PKI and certificate chains, and how a TLS handshake ties all of it together.
Malware taxonomy, phishing and social engineering tradecraft, common web and network attack patterns, and the Cyber Kill Chain and ATT&CK as shared vocabulary for describing an intrusion.
NIST CSF, ISO 27001, and CIS Controls as prioritization frameworks, plus a practical walkthrough of PCI-DSS, HIPAA, and GDPR obligations analysts actually encounter.
Risk as likelihood times impact, CVSS scoring mechanics, the full vulnerability management lifecycle, and patch prioritization under real operational constraints.
How a SOC is structured across tiers, what SIEM and EDR actually do, the alert triage workflow from ticket to disposition, and escalation and shift realities.
How these fundamentals map onto SOC analyst, threat hunter, CTI, detection engineer, and IR career tracks, plus a suggested study order through the rest of H3AD-LEARN.
SSO, SAML assertions, OAuth 2.0 grant types, OpenID Connect, and JWTs, the identity backbone of real enterprise environments and real federation attacks like Golden SAML.
STRIDE, attack trees, DREAD, and PASTA, threat modeling as a practice done before code is written, closing the module by tying every prior chapter together.
WHAT YOU SHOULD KNOW
WHAT YOU WILL KNOW AFTER
H3AD-SEC tools that pair directly with this module's content.
The SOC analyst console. See how CIA, AAA, and access control concepts from this module show up as real fields in a real investigation workflow.
The lowest-friction way to see indicator confidence scoring and attack vocabulary from Chapter 1 and Chapter 4 applied to a live IOC lookup.
Browse real detection rules to see how the Cyber Kill Chain and ATT&CK vocabulary from Chapter 4 becomes an actual, production-ready query.
A library of AI prompts for security work. Useful once you know the terminology in this module well enough to judge whether an AI answer is right.