🧩 Prep Hub — Security Technologies Central
Comprehensive deep-dive guides for Qualys, Tanium, Tenable, GRC, AppSec, DevSecOps, Checkmarx, and Wiz
🔵QualysVulnerability & Cloud
Cloud Platform (VMDR, CSAM, WAS, TotalCloud, Patch Management, TruRisk)
Core Topics & Deep Dives
- VMDR 2.0 with QDS & TruRisk scoring
- CSAM asset inventory & EOL tracking
- Cloud Agent continuous endpoint scanning
- Qualys WAS for DAST web app security
- TotalCloud CNAPP & posture management
- Qualys Patch Management automated fixes
🟦TaniumEndpoint & XEM
Converged Endpoint Management (Linear Chain, Threat Response, Comply, Deploy)
Core Topics & Deep Dives
- Linear Chain peer-to-peer architecture (15s query)
- Tanium Comply (CIS & DISA STIG benchmarks)
- Threat Response IR & live endpoint hunting
- Discover & Map (unmanaged asset detection)
- Tanium Protect (OS hardening & bitlocker)
- Python API & automation integrations
🔴TenableExposure Management
Tenable.io, Tenable.sc, Nessus Scanner, OT Security, Identity Exposure
Core Topics & Deep Dives
- VPR scoring (dynamic threat-aware priority)
- Tenable.io (SaaS) vs Tenable.sc (Air-gapped on-prem)
- Nessus Professional scanner plugin architecture
- Tenable OT Security (passive ICS/SCADA scanning)
- Identity Exposure (Active Directory attack paths)
- Cyber Exposure Score (ACR + AES risk matrix)
⚖️GRCGovernance & Risk
NIST CSF 2.0, ISO 27001, SOC 2 Type II, PCI-DSS v4.0, Risk Management & TPRM
Core Topics & Deep Dives
- NIST CSF 2.0 (GOVERN, Identify, Protect, Detect...)
- ISO 27001:2022 ISMS & Statement of Applicability
- SOC 2 Type II 5 Trust Services Criteria
- PCI-DSS v4.0 12 requirements & CDE scope
- 5x5 Risk Matrix & Risk Register management
- TPRM vendor tiering (ServiceNow, OneTrust, Vanta)
🛡️AppSecApplication Security
SAST, DAST, SCA, IAST, RASP, OWASP Top 10, STRIDE Threat Modeling
Core Topics & Deep Dives
- SAST vs DAST vs SCA vs IAST vs RASP comparison
- OWASP Top 10 (2021) deep dive with code fixes
- STRIDE Threat Modeling framework
- 6-stage Secure SDLC integration checklist
- SCA & SBOM reachability analysis
- Tool comparison (Checkmarx, Veracode, Snyk, Burp)
🔄DevSecOpsPipeline & Infra
Shift-Left Security, CI/CD Gates, Container Security, IaC Scanning, Supply Chain
Core Topics & Deep Dives
- 5 DevSecOps pillars (Pipeline, Container, IaC, Secrets, Supply Chain)
- GitHub Actions complete security pipeline template
- Container image hardening & distroless base images
- IaC static security analysis (Checkov & tfsec)
- Software Supply Chain: SBOM, SLSA, Sigstore/cosign
- Kubernetes Security & Falco runtime rules
🔐CheckmarxAppSec Platform
Checkmarx One (SAST, SCA, DAST, API Security, Supply Chain, Codebashing)
Core Topics & Deep Dives
- Checkmarx SAST & CxQL custom detection rules
- Checkmarx One unified risk correlation engine
- Checkmarx SCA & CXA proprietary advisories
- OWASP API Security Top 10 testing
- Codebashing developer micro-learning platform
- Checkmarx vs Veracode vs Snyk head-to-head
🪄WizCloud Security (CNAPP)
CSPM, CWPP (Agentless), CIEM, DSPM, Security Graph, Toxic Combinations
Core Topics & Deep Dives
- Agentless disk snapshot scanning (zero overhead)
- Wiz Security Graph multi-dimensional risk model
- Toxic Combinations multi-factor risk clusters
- CIEM effective permissions & IAM blast radius
- DSPM sensitive data discovery & classification
- Wiz vs Prisma Cloud vs Orca vs Defender comparison