OverWatch Docs
Security, understood.
Practical guides for learning how systems fail, and how to make the fix hold. Browse a topic or search the full text of the library.
- 19 field guides
- 6 topics
- Free to read, no sign-up
19 guides available.
Browse by topic
Start here
New to security assessments?
Start with the decision, not the tool. Learn which assessment fits your question, then follow an access-control example from risk to remediation. Test only in labs or with explicit authorization.
No matching guides yet.
Try a broader term, remove the topic filter, or browse the library below. This collection is growing.
Topic 01 1 guide
Assessment foundations
Decide which assessment answers your question before you scope one.
Topic 02 3 guides
Application security
Access control, workflow abuse and session handling in web applications and APIs.
Understand account boundaries, test with two users, and verify ownership checks.
Application securityBusiness logic flawsRecognize workflow abuse even when every individual endpoint works.
Application securitySessions, tokens & account accessUnderstand why protecting a password alone does not protect a session.
Topic 03 4 guides
Networks & detection
Internal networks, Active Directory, and the limits of endpoint detection.
Follow the methodology from an agreed foothold to privileged access.
Networks & detectionActive Directory Certificate ServicesUnderstand certificate-based attack paths and configuration risks.
Networks & detectionEndpoint detection limitationsUnderstand detection gaps and the value of controlled validation.
Networks & detectionAntivirus and layered defensesLearn what antivirus does, what it misses, and why layers matter.
Topic 04 2 guides
Code & delivery pipelines
Static analysis, manual code review, and credentials that leak through builds.
Topic 05 3 guides
Personal security & OPSEC
What protects you online, what does not, and where your data lingers.
Separate network privacy from browser, identity, and account exposure.
Personal security & OPSECDeletion, backups & data tracesUnderstand why deleting a file is not the same as removing every copy.
Personal security & OPSECPublic exposure and dark-web claimsAssess visibility and evidence without assuming a hidden service means anonymity.
Topic 06 6 guides
Threat intelligence
Pivot, validate and prioritize indicators without jumping to conclusions.
Use a single indicator as a starting point, not a verdict.
Threat intelligenceInvestigate suspicious infrastructureConnect domains, addresses, timelines, and source context.
Threat intelligenceValidate threat intelligenceCheck source quality, freshness, and uncertainty before acting.
Threat intelligenceConnect indicatorsFollow evidence-backed relationships without confusing correlation with attribution.
Threat intelligencePrioritize security alertsBring exposure, confidence, and operational context into triage.
Threat intelligenceReduce false positivesInvestigate conflicting evidence and tune decisions without ignoring real risk.
Put the reading to work.
Explore Forensia for threat-intelligence research, or discuss an assessment of your own environment. Guides explain the method; they do not certify a system as secure.