Advanced Cybersecurity
-
Linux Fundamentals
- Kali Linux installation & VM setup
- Linux filesystem
- Terminal & shell
- Essential Linux commands
- Users & groups
- File permissions
- sudo
- Processes
- Services
- Environment variables
- Package management with apt
- Pipes & redirects
- grep
- awk
- sed
- sort
- cut
- xargs
- Bash scripting
- SSH
-
Networking Fundamentals
- OSI model
- TCP/IP model
- IPv4 / IPv6
- MAC addresses
- ARP
- TCP vs UDP
- Ports & sockets
- DNS
- DHCP
- ICMP
- Routing
- NAT
- Subnets & CIDR
- Firewalls
- Proxies
- VPNs
-
Network Analysis
Network interfaces ip ss route ping traceroute tcpdump Wireshark Packet capture TCP handshake analysis DNS traffic analysis HTTP/HTTPS traffic analysis Network troubleshooting
-
Reconnaissance
- Passive reconnaissance
- Active reconnaissance
- OSINT
- WHOIS
- DNS enumeration
- Subdomain discovery
- Certificate Transparency
- Search engine dorking
- Amass
- Subfinder
- theHarvester
- Maltego
- Attack surface discovery
-
Port & Service Enumeration
- Nmap
- TCP scanning
- UDP scanning
- SYN scanning
- Service detection
- Version detection
- OS detection
- NSE scripts
- Masscan
- RustScan
- Banner grabbing
- Netcat
- Service enumeration methodology
-
Vulnerability Assessment
- Vulnerability vs exploit
- CVE
- CVSS
- Vulnerability scanning
- False positives
- Vulnerability validation
- Nuclei
- Nikto
- OpenVAS / Greenbone
- Searchsploit
- Exploit-DB
- Manual vulnerability verification
-
Web Fundamentals
- HTTP
- HTTPS
- HTTP methods
- HTTP status codes
- HTTP headers
- Cookies
- Sessions
- Authentication
- Authorization
- REST APIs
- JSON
- CORS
- Same-Origin Policy
- TLS
- Browser DevTools
-
Web Reconnaissance
- Directory enumeration
- File enumeration
- ffuf
- Gobuster
- Feroxbuster
- robots.txt
- sitemap.xml
- Technology fingerprinting
- WhatWeb
- Wappalyzer
- JavaScript analysis
- API endpoint discovery
-
Burp Suite
- Proxy
- HTTP interception
- Repeater
- Intruder
- Decoder
- HTTP request manipulation
- HTTP response analysis
- Scope configuration
- Burp extensions
- Automating repetitive tasks
-
OWASP Top 10
- Broken Access Control
- Cryptographic Failures
- Injection
- Insecure Design
- Security Misconfiguration
- Vulnerable Components
- Authentication Failures
- Software and Data Integrity Failures
- Logging and Monitoring Failures
- SSRF
-
Web Application Pentesting
- Authentication testing
- Session management testing
- Authorization testing
- Access control testing
- Input validation
- Error handling
- Business logic testing
- Parameter manipulation
- Request manipulation
- Response manipulation
-
Web Exploitation
- SQL Injection
- NoSQL Injection
- Cross-Site Scripting
- CSRF
- SSTI
- XXE
- SSRF
- Path Traversal
- Local File Inclusion
- Remote File Inclusion
- File Upload vulnerabilities
- Command Injection
- Deserialization vulnerabilities
- Prototype Pollution
- HTTP Request Smuggling
-
Password & Authentication Security
- Password hashing
- Hash identification
- Hashcat
- John the Ripper
- Wordlists
- Password mutation
- Hash cracking concepts
- Password spraying
- Brute-force concepts
- Credential stuffing
- Hydra
- Authentication attack methodology
-
Exploitation Fundamentals
- Vulnerability vs exploit
- Public exploits
- Exploit-DB
- Searchsploit
- Metasploit Framework
- Modules
- Payloads
- Exploit modules
- Auxiliary modules
- Meterpreter
- Manual exploitation
- Exploit validation
-
Linux Privilege Escalation
- Linux permissions
- SUID
- SGID
- sudo misconfigurations
- Linux capabilities
- Cron jobs
- PATH hijacking
- Writable files
- Writable services
- Environment variables
- Kernel vulnerabilities
- LinPEAS
- Manual enumeration
- Privilege escalation methodology
-
Windows Fundamentals
- Windows architecture
- Windows users and groups
- Windows services
- Windows Registry
- PowerShell
- NTFS permissions
- Windows networking
- SMB
- RDP
- WinRM
- Windows authentication
-
Windows Privilege Escalation
- Service misconfigurations
- Unquoted service paths
- Weak file permissions
- Scheduled tasks
- Registry weaknesses
- Token privileges
- DLL hijacking
- Credential discovery
- WinPEAS
- Manual enumeration
- Privilege escalation methodology
-
Active Directory
- Active Directory architecture
- Domains
- Domain Controllers
- Forests
- LDAP
- Kerberos
- NTLM
- SMB
- Domain users
- Domain groups
- Group Policy
- BloodHound
- LDAP enumeration
- Kerberos enumeration
- Domain attack paths
-
Active Directory Attacks
- Kerberoasting
- AS-REP Roasting
- NTLM relay concepts
- Pass-the-Hash
- Pass-the-Ticket
- ACL abuse
- Delegation attacks
- Credential attacks
- Lateral movement
- Domain privilege escalation
-
Post-Exploitation
- Situational awareness
- Local enumeration
- Credential discovery
- Network discovery
- Internal service enumeration
- Process enumeration
- User enumeration
- Network configuration
- Persistence concepts
- Controlled access
- Evidence collection
- Cleanup
-
Network Pivoting
- Pivoting concepts
- Internal network mapping
- Routing through compromised hosts
- SOCKS proxies
- SSH tunneling
- Local port forwarding
- Remote port forwarding
- Proxychains
- Chisel
- Ligolo-ng
- Multi-hop pivoting
-
Wireless Security
- Wi-Fi architecture
- 802.11 fundamentals
- Wireless interfaces
- Monitor mode
- Packet capture
- Aircrack-ng
- Wireshark
- WPA/WPA2/WPA3
- Wireless authentication
- Rogue access point concepts
- Wireless security assessment
-
API Security
- REST APIs
- GraphQL
- JWT
- OAuth 2.0
- API authentication
- API authorization
- BOLA / IDOR
- Rate limiting
- Mass assignment
- API fuzzing
- API enumeration
- OWASP API Security Top 10
-
Cloud Security
- Cloud fundamentals
- IAM
- AWS fundamentals
- Azure fundamentals
- GCP fundamentals
- Object storage
- Security groups
- Cloud metadata services
- Access keys
- Cloud misconfigurations
- ScoutSuite
- Trivy
- Cloud enumeration
-
Container Security
- Docker architecture
- Docker images
- Dockerfiles
- Container networking
- Container privileges
- Docker socket
- Container secrets
- Image vulnerabilities
- Trivy
- Docker Bench
- Container escape concepts
-
Source Code Security
- Git fundamentals
- Git history analysis
- Secret discovery
- API key exposure
- Environment variables
- Dependency vulnerabilities
- SAST
- Semgrep
- Gitleaks
- TruffleHog
-
Security Automation
- Python for security
- Bash automation
- PowerShell automation
- Requests
- Scapy
- Nmap automation
- API automation
- Custom enumeration scripts
- Result parsing
- JSON
- CSV
- Reusable security tools
-
Exploit Development
- Python for exploit development
- C fundamentals
- Memory layout
- Stack
- Heap
- Registers
- Assembly basics
- GDB
- Buffer overflows
- Shellcode concepts
- ASLR
- DEP / NX
- Stack canaries
- Basic binary exploitation
-
Binary Analysis
- ELF
- PE
- Executable formats
- Static analysis
- Dynamic analysis
- Strings analysis
- Ghidra
- x64dbg
- Process analysis
- Debugging
- Reverse engineering fundamentals
-
Malware Analysis
- Malware fundamentals
- Static malware analysis
- Dynamic malware analysis
- PE analysis
- ELF analysis
- Indicators of Compromise
- Sandboxing
- Process monitoring
- Network behavior analysis
- Reverse engineering
-
Professional Pentesting Methodology
- Rules of engagement
- Scope definition
- Asset discovery
- Attack surface mapping
- Threat modeling
- Reconnaissance
- Enumeration
- Vulnerability analysis
- Exploitation
- Privilege escalation
- Lateral movement
- Pivoting
- Impact assessment
- Evidence collection
- Cleanup
- Documentation
-
Pentest Reporting
- Executive summary
- Technical findings
- Evidence
- Reproduction steps
- Risk rating
- CVSS
- Business impact
- Remediation
- Proof of Concept
- Retesting
- Final report
-
Real-World Pentesting Workflow
- Scope
- Reconnaissance
- Attack surface discovery
- Enumeration
- Service identification
- Vulnerability discovery
- Manual validation
- Initial access
- Privilege escalation
- Credential discovery
- Lateral movement
- Pivoting
- Impact validation
- Evidence collection
- Cleanup
- Reporting
- Remediation
- Retesting
-
Practice Labs
- OverTheWire
- PortSwigger Web Security Academy
- TryHackMe
- Hack The Box
- VulnHub
- OWASP Juice Shop
- DVWA
- Metasploitable
- Damn Vulnerable API
- Self-hosted vulnerable environments
-
Advanced Red Team Concepts
- Adversary simulation
- Initial access
- Command and Control
- C2 frameworks
- Evasion concepts
- OPSEC
- Identity attacks
- Active Directory attack paths
- Cloud attack paths
- Detection engineering
- Purple Team methodology