Skip to content
Obfuscation Hub
Foundation Self-paced · 8 modules 4 of 8 modules open now

IT Administrator to Security Practitioner

You already run the systems attackers target. This path converts daily administration experience into deliberate security skill — identity, endpoints, logs, and the evidence habits that define the role.

Most security practitioners were something else first — and IT administration is the strongest starting point there is. You already understand how identity, endpoints, networks, and SaaS platforms behave in production. What this path adds is the security frame: how those systems fail, how attackers use them, and how to produce the documentation and evidence that separates “I secured it” from “I can show you.”

The path alternates between analysis and hands-on work. The articles build the operating concepts; the labs make you do the job — reviewing real-shaped access data and reconstructing an incident from the kind of fragmentary evidence real responders get.

Modules marked available are open now in Release 0.1 as articles and labs. Modules marked coming in the next release will ship as full guided lessons; their subjects are listed so you can see the whole arc before committing.

Module sequence

Modules marked “Open now” link to working material. The rest arrive as guided lessons in the next release.

  1. 01

    The security mindset for administrators

    Coming in the next release

    Assets, threats, and controls as a way of seeing systems you already know — and why administrators make strong security hires.

  2. 02

    Identity is the perimeter

    Coming in the next release

    Accounts, sessions, tokens, and MFA mechanics across Google Workspace and Microsoft 365 — where account takeover actually happens.

  3. 03

    Scope, extract, decide, remediate, evidence: the quarterly cycle that doubles as your first audit artifact.

  4. 04

    A hands-on review of admin roles in a realistic SaaS estate — finding the stale, the shared, and the excessive.

  5. 05

    Building an incident timeline from mixed, messy sources — the core analyst skill of sequencing what happened.

  6. 06

    Endpoint baselines you can verify

    Coming in the next release

    Updates, encryption, screen lock, and endpoint protection enforced through management tooling — and reported on.

  7. 07

    Vendor accounts, integrations, and MSP access — inventorying and constraining the risk you inherit.

  8. 08

    Positioning for the security role

    Coming in the next release

    Translating administration experience into security language for resumes and interviews — without exaggeration.

What you will produce

  • A completed access-review worksheet with documented decisions
  • An incident timeline built from mixed evidence sources
  • A personal endpoint-hardening baseline checklist
  • A vendor-access inventory for a realistic environment