OverWatch Docs

Security, understood.

Practical guides for learning how systems fail, and how to make the fix hold. Browse a topic or search the full text of the library.

  • 19 field guides
  • 6 topics
  • Free to read, no sign-up

Browse by topic

Start here

New to security assessments?

Start with the decision, not the tool. Learn which assessment fits your question, then follow an access-control example from risk to remediation. Test only in labs or with explicit authorization.

  1. 01Choose the right assessmentPentest or red team, and why it matters.
  2. 02Understand access controlThe most common serious web flaw, explained.
  3. 03Build your personal baselineAccounts, devices and everyday exposure.

Topic 01 1 guide

Assessment foundations

Decide which assessment answers your question before you scope one.

Topic 02 3 guides

Application security

Access control, workflow abuse and session handling in web applications and APIs.

Topic 03 4 guides

Networks & detection

Internal networks, Active Directory, and the limits of endpoint detection.

Topic 04 2 guides

Code & delivery pipelines

Static analysis, manual code review, and credentials that leak through builds.

Topic 05 3 guides

Personal security & OPSEC

What protects you online, what does not, and where your data lingers.

Topic 06 6 guides

Threat intelligence

Pivot, validate and prioritize indicators without jumping to conclusions.

Put the reading to work.

Explore Forensia for threat-intelligence research, or discuss an assessment of your own environment. Guides explain the method; they do not certify a system as secure.