Cyber Security
Outline6 topics and 295 subtopics mapped. This is the ground the track will cover — the lessons aren't written yet.
- 01
Fundamental IT Skills
32 subtopics- Computer Hardware Components
- Connection Types and their function
- OS-Independent Troubleshooting
- Understand Basics of Popular Suites
- Basics of Computer Networking
- NFC
- WiFi
- Bluetooth
- Infrared
- iCloud
- Google Suite
- MS Office Suite
- HackTheBox
- TryHackMe
- VulnHub
- picoCTF
- SANS Holiday Hack Challenge
- CompTIA A+
- CompTIA Linux+
- CompTIA Network+
- CCNA
- CompTIA Security+
- CEH
- CISA
- CISM
- GSEC
- GPEN
- GWAPT
- GIAC
- OSCP
- CREST
- CISSP
- 02
Operating Systems
11 subtopics- Windows
- Linux
- MacOS
- Installation and Configuration
- Different Versions and Differences
- Navigating using GUI and CLI
- Understand Permissions
- Installing Software and Applications
- Performing CRUD on Files
- Troubleshooting
- Common Commands
- 03
Networking Knowledge
69 subtopics- Understand the OSI Model
- Common Protocols and their Uses
- Common Ports and their Uses
- SSL and TLS Basics
- Basics of NAS and SAN
- Basics of Subnetting
- Public vs Private IP Addresses
- localhost
- loopback
- CIDR
- subnet mask
- default gateway
- VLAN
- DMZ
- ARP
- VM
- DHCP
- DNS
- NAT
- IP
- Router
- Switch
- VPN
- MAN
- LAN
- WAN
- WLAN
- DHCP
- DNS
- NTP
- IPAM
- Star
- Ring
- Mesh
- Bus
- SSH
- RDP
- FTP
- SFTP
- HTTP / HTTPS
- SSL / TLS
- VMWare
- VirtualBox
- esxi
- proxmox
- Hypervisor
- VM
- GuestOS
- HostOS
- nslookup
- iptables
- Packet Sniffers
- ipconfig
- netstat
- Port Scanners
- ping
- dig
- arp
- Protocol Analyzers
- nmap
- route
- tcpdump
- tracert
- Kerberos
- LDAP
- SSO
- RADIUS
- Certificates
- Local Auth
- 04
Security Skills and Knowledge
155 subtopics- Understand Common Hacking Tools
- Understand Common Exploit Frameworks
- Understand Concept of Defense in Depth
- Understand Concept of Runbooks
- Understand Basics of Forensics
- Basics and Concepts of Threat Hunting
- Basics of Vulnerability Management
- Basics of Reverse Engineering
- Penetration Testing Rules of Engagement
- Perimiter vs DMZ vs Segmentation
- Core Concepts of Zero Trust
- Roles of Compliance and Auditors
- Understand the Definition of Risk
- Understand Backups and Resiliency
- Cyber Kill Chain
- MFA & 2FA
- Operating System Hardening
- Understand Concept of Isolation
- Basics of IDS and IPS
- Honeypots
- Authentication vs Authorization
- Blue / Red / Purple Teams
- False Negative / False Positive
- True Negative / True Positive
- Basics of Threat Intel, OSINT
- Understand Handshakes
- Understand CIA Triad
- Privilege Escalation
- Web Based Attacks and OWASP10
- Learn how Malware works and Types
- nmap
- tracert
- nslookup
- curl
- hping
- ping
- arp
- cat
- dd
- head
- grep
- wireshark
- winhex
- memdump
- FTK Imager
- autopsy
- dig
- tail
- ipconfig
- Salting
- Hashing
- Key Exchange
- PKI
- Private vs Public Keys
- Obfuscation
- ATT&CK
- Kill Chain
- Diamond Model
- ISO
- NIST
- RMF
- CIS
- CSF
- SIEM
- SOAR
- ParrotOS
- Kali Linux
- LOLBAS
- Event Logs
- syslogs
- netflow
- Packet Captures
- Firewall Logs
- MAC-based
- NAC-based
- Port Blocking
- Group Policy
- ACLs
- Sinkholes
- Patching
- Jump Server
- Endpoint Security
- FTP vs SFTP
- SSL vs TLS
- IPSEC
- DNSSEC
- LDAPS
- SRTP
- S/MIME
- Antivirus
- Antimalware
- EDR
- DLP
- ACL
- Firewall & Nextgen Firewall
- HIPS
- NIDS
- NIPS
- Host Based Firewall
- Sandboxing
- EAP vs PEAP
- WPS
- WPA vs WPA2 vs WPA3 vs WEP
- Preparation
- Identification
- Containment
- Eradication
- Recovery
- Lessons Learned
- Zero Day
- Known vs Unknown
- APT
- VirusTotal
- Joe Sandbox
- any.run
- urlvoid
- urlscan
- WHOIS
- Phishing
- Whishing
- Whaling
- Smishing
- Spam vs Spim
- Shoulder Surfing
- Dumpster Diving
- Tailgating
- Zero day
- Social Engineering
- Reconnaissance
- Impersonation
- Watering Hole Attack
- Drive by Attack
- Typo Squatting
- Brute Force vs Password Spray
- DoS vs DDoS
- MITM
- Spoofing
- Evil Twin
- DNS Poisoning
- Deauth Attack
- VLAN Hopping
- Rogue Access Point
- Buffer Overflow
- Memory Leak
- XSS
- SQL Injection
- CSRF
- Replay Attack
- Pass the Hash
- Directory Traversal
- Stakeholders
- HR
- Legal
- Compliance
- Management
- 05
Cloud Skills and Knowledge
20 subtopics- Understand the Concept of Security in the Cloud
- Understand the basics and general flow of deploying in the cloud
- Understand the differences between cloud and on-premises
- Understand the concept of Infrastructure as Code
- Understand the Concept of Serverless
- SaaS
- PaaS
- IaaS
- Private
- Public
- Hybrid
- AWS
- GCP
- Azure
- S3
- Dropbox
- Box
- OneDrive
- Google Drive
- iCloud
- 06
Programming Skills
8 subtopics- Python
- Go
- JavaScript
- C++
- Bash
- Power Shell
- GTFOBINS
- WADCOMS
