← Back

Knowledge bases

What our agents know, and where they got it from.

An agent that reviews someone else's infrastructure needs a standard of reference, not intuition. Ours is built on the syllabi of these certifications: they define what to look for, how to verify it, and when a finding deserves to be called critical.

So there is no room for doubt: this page lists the syllabi we use as a guide, not a trophy wall. The certifications the team actually holds are on the main page, with their badge. Drawing that line is part of how we treat evidence everywhere else.

Block 1

Security

Twelve syllabi from INE Security (formerly eLearnSecurity), spread across the three capabilities an audit needs: understanding how attacks happen, knowing how to defend, and being able to reconstruct what happened.

Offensive How someone gets in, so we know what to look for
eJPT

Junior Penetration Tester

The foundation of the craft: reconnaissance, service enumeration and fundamental exploitation. It's the common ground everything else stands on.

Feeds M9 · exposed surface
eCPPT

Certified Professional Penetration Tester

Deep intrusion on a realistic scenario, with lateral movement and post-exploitation. It's what teaches you to think like someone who is already inside.

Feeds M5 · M9 · M10
eWPT

Web Application Penetration Tester

Web application security: injections, authentication, sessions and business logic. The bulk of code findings comes from here.

Feeds M1 · code
eWPTX

Web Application Penetration Tester eXtreme

The advanced level of the previous one: filter evasion, exploitation chains and the cases automated scanners don't see.

Feeds M1 · M9
eMAPT

Mobile Application Penetration Tester

Mobile application security: local storage, communication with the backend and client-side controls.

Feeds M1 · if there is a mobile app
Defense and operations What should exist and almost never does
eSOC

Security Operations Center

Running a security operations center: what gets monitored, what alerts whom, and how to triage a signal without drowning in noise.

Feeds M11 · detection and response
eEDA

Enterprise Defense Administrator

Fundamentals of secure engineering, risk and compliance, and security administration in a real organization.

Feeds M5 · M7
eIAMA

Identity & Access Management Technologist

Identity and access with a zero-trust mindset: least privilege, service accounts, federation and account lifecycle.

Feeds M6 · identity and access
Response and forensics What to do once it already happened — and how to prove it
eCIR

Certified Incident Responder

Incident handling: containment, advanced detection and analysis. It's where the rules about what not to touch while something is ongoing come from.

Feeds M11 · response
eCTHP

Certified Threat Hunting Professional

Proactive threat hunting on scenarios modeled with real malware. It's the discipline behind comparing states instead of waiting for alerts.

Feeds the engine · baseline and diff
eCDFP

Certified Digital Forensics Professional

Scenario-based digital forensics: preserving evidence, reconstructing a timeline and backing a conclusion with proof.

Feeds M11 · timeline and evidence
eAIS

AI Systems Security Specialist

Security of AI systems: fundamentals, attack techniques against models and agents, and the defensive controls that go with them.

Feeds M12 · AI and agents

Block 2

Architecture and cloud

Auditing a cloud requires understanding how it's designed, not just which switch is set wrong. These are the syllabi from the three providers, on both fronts: how to build well and how to secure.

Architecture How it should be built
AWS

Solutions Architect — Professional

Architecture design on AWS: networking, isolation between environments, resilience and the cost decisions that later show up on the bill.

Feeds M5 · M10 · M13
GCP

Professional Cloud Architect

Design on Google Cloud: projects and hierarchy, service identities, networking and business continuity.

Feeds M5 · M10 · M13
AZURE

Azure Solutions Architect Expert

Design on Azure: subscription governance, identity with Entra, networking and disaster recovery.

Feeds M5 · M10
Cloud security How it's secured and how it's audited
AWS

Certified Security — Specialty

Security on AWS: identity and permission management, encryption, audit logging and incident response in the cloud.

Feeds M5 · M6 · M7 · M11
GCP

Google Cloud Cybersecurity

Security on Google Cloud: shared responsibility model, access controls, data protection and detection.

Feeds M5 · M6 · M7
AZURE

Azure Security Engineer Associate

Security on Azure: identity, platform protection, secrets management and security operations.

Feeds M5 · M6 · M7

How this is used

A syllabus is not a finding.

These knowledge bases define what to look at and by what standard to judge it. They don't replace evidence: every finding in one of our reports arrives with the command that produced it, its output and its date, so anyone can repeat it.

What they provide

Judgment, not intuition

They define what counts as a finding, how it's verified and when something deserves to be called critical. Without that, an agent just has opinions.

What they don't provide

No certainty on their own

No syllabus proves anything about your infrastructure. What proves something is the command that ran and its result, with a date.

How they're reviewed

They change with the craft

When a syllabus is updated, or a new one appears that adds value, it goes in here. This page is the living list, not a decoration.

And the human

Signs the report

The agent proposes using this judgment; a person reviews it, decides what matters in your context and puts their name under it.

Shall we look at your infrastructure?

Let's talk for 30 minutes. No commitment and nothing to install: just the right questions and a concrete scope in writing.

Schedule a conversation