Advanced Cybersecurity

  1. Linux Fundamentals

    1. Kali Linux installation & VM setup
    2. Linux filesystem
    3. Terminal & shell
    4. Essential Linux commands
    5. Users & groups
    6. File permissions
    7. sudo
    8. Processes
    9. Services
    10. Environment variables
    11. Package management with apt
    12. Pipes & redirects
    13. grep
    14. awk
    15. sed
    16. sort
    17. cut
    18. xargs
    19. Bash scripting
    20. SSH
  2. Networking Fundamentals

    1. OSI model
    2. TCP/IP model
    3. IPv4 / IPv6
    4. MAC addresses
    5. ARP
    6. TCP vs UDP
    7. Ports & sockets
    8. DNS
    9. DHCP
    10. ICMP
    11. Routing
    12. NAT
    13. Subnets & CIDR
    14. Firewalls
    15. Proxies
    16. VPNs
  3. Network Analysis

    Network interfaces ip ss route ping traceroute tcpdump Wireshark Packet capture TCP handshake analysis DNS traffic analysis HTTP/HTTPS traffic analysis Network troubleshooting

  4. Reconnaissance

    1. Passive reconnaissance
    2. Active reconnaissance
    3. OSINT
    4. WHOIS
    5. DNS enumeration
    6. Subdomain discovery
    7. Certificate Transparency
    8. Search engine dorking
    9. Amass
    10. Subfinder
    11. theHarvester
    12. Maltego
    13. Attack surface discovery
  5. Port & Service Enumeration

    1. Nmap
    2. TCP scanning
    3. UDP scanning
    4. SYN scanning
    5. Service detection
    6. Version detection
    7. OS detection
    8. NSE scripts
    9. Masscan
    10. RustScan
    11. Banner grabbing
    12. Netcat
    13. Service enumeration methodology
  6. Vulnerability Assessment

    1. Vulnerability vs exploit
    2. CVE
    3. CVSS
    4. Vulnerability scanning
    5. False positives
    6. Vulnerability validation
    7. Nuclei
    8. Nikto
    9. OpenVAS / Greenbone
    10. Searchsploit
    11. Exploit-DB
    12. Manual vulnerability verification
  7. Web Fundamentals

    1. HTTP
    2. HTTPS
    3. HTTP methods
    4. HTTP status codes
    5. HTTP headers
    6. Cookies
    7. Sessions
    8. Authentication
    9. Authorization
    10. REST APIs
    11. JSON
    12. CORS
    13. Same-Origin Policy
    14. TLS
    15. Browser DevTools
  8. Web Reconnaissance

    1. Directory enumeration
    2. File enumeration
    3. ffuf
    4. Gobuster
    5. Feroxbuster
    6. robots.txt
    7. sitemap.xml
    8. Technology fingerprinting
    9. WhatWeb
    10. Wappalyzer
    11. JavaScript analysis
    12. API endpoint discovery
  9. Burp Suite

    1. Proxy
    2. HTTP interception
    3. Repeater
    4. Intruder
    5. Decoder
    6. HTTP request manipulation
    7. HTTP response analysis
    8. Scope configuration
    9. Burp extensions
    10. Automating repetitive tasks
  10. OWASP Top 10

    1. Broken Access Control
    2. Cryptographic Failures
    3. Injection
    4. Insecure Design
    5. Security Misconfiguration
    6. Vulnerable Components
    7. Authentication Failures
    8. Software and Data Integrity Failures
    9. Logging and Monitoring Failures
    10. SSRF
  11. Web Application Pentesting

    1. Authentication testing
    2. Session management testing
    3. Authorization testing
    4. Access control testing
    5. Input validation
    6. Error handling
    7. Business logic testing
    8. Parameter manipulation
    9. Request manipulation
    10. Response manipulation
  12. Web Exploitation

    1. SQL Injection
    2. NoSQL Injection
    3. Cross-Site Scripting
    4. CSRF
    5. SSTI
    6. XXE
    7. SSRF
    8. Path Traversal
    9. Local File Inclusion
    10. Remote File Inclusion
    11. File Upload vulnerabilities
    12. Command Injection
    13. Deserialization vulnerabilities
    14. Prototype Pollution
    15. HTTP Request Smuggling
  13. Password & Authentication Security

    1. Password hashing
    2. Hash identification
    3. Hashcat
    4. John the Ripper
    5. Wordlists
    6. Password mutation
    7. Hash cracking concepts
    8. Password spraying
    9. Brute-force concepts
    10. Credential stuffing
    11. Hydra
    12. Authentication attack methodology
  14. Exploitation Fundamentals

    1. Vulnerability vs exploit
    2. Public exploits
    3. Exploit-DB
    4. Searchsploit
    5. Metasploit Framework
    6. Modules
    7. Payloads
    8. Exploit modules
    9. Auxiliary modules
    10. Meterpreter
    11. Manual exploitation
    12. Exploit validation
  15. Linux Privilege Escalation

    1. Linux permissions
    2. SUID
    3. SGID
    4. sudo misconfigurations
    5. Linux capabilities
    6. Cron jobs
    7. PATH hijacking
    8. Writable files
    9. Writable services
    10. Environment variables
    11. Kernel vulnerabilities
    12. LinPEAS
    13. Manual enumeration
    14. Privilege escalation methodology
  16. Windows Fundamentals

    1. Windows architecture
    2. Windows users and groups
    3. Windows services
    4. Windows Registry
    5. PowerShell
    6. NTFS permissions
    7. Windows networking
    8. SMB
    9. RDP
    10. WinRM
    11. Windows authentication
  17. Windows Privilege Escalation

    1. Service misconfigurations
    2. Unquoted service paths
    3. Weak file permissions
    4. Scheduled tasks
    5. Registry weaknesses
    6. Token privileges
    7. DLL hijacking
    8. Credential discovery
    9. WinPEAS
    10. Manual enumeration
    11. Privilege escalation methodology
  18. Active Directory

    1. Active Directory architecture
    2. Domains
    3. Domain Controllers
    4. Forests
    5. LDAP
    6. Kerberos
    7. NTLM
    8. SMB
    9. Domain users
    10. Domain groups
    11. Group Policy
    12. BloodHound
    13. LDAP enumeration
    14. Kerberos enumeration
    15. Domain attack paths
  19. Active Directory Attacks

    1. Kerberoasting
    2. AS-REP Roasting
    3. NTLM relay concepts
    4. Pass-the-Hash
    5. Pass-the-Ticket
    6. ACL abuse
    7. Delegation attacks
    8. Credential attacks
    9. Lateral movement
    10. Domain privilege escalation
  20. Post-Exploitation

    1. Situational awareness
    2. Local enumeration
    3. Credential discovery
    4. Network discovery
    5. Internal service enumeration
    6. Process enumeration
    7. User enumeration
    8. Network configuration
    9. Persistence concepts
    10. Controlled access
    11. Evidence collection
    12. Cleanup
  21. Network Pivoting

    1. Pivoting concepts
    2. Internal network mapping
    3. Routing through compromised hosts
    4. SOCKS proxies
    5. SSH tunneling
    6. Local port forwarding
    7. Remote port forwarding
    8. Proxychains
    9. Chisel
    10. Ligolo-ng
    11. Multi-hop pivoting
  22. Wireless Security

    1. Wi-Fi architecture
    2. 802.11 fundamentals
    3. Wireless interfaces
    4. Monitor mode
    5. Packet capture
    6. Aircrack-ng
    7. Wireshark
    8. WPA/WPA2/WPA3
    9. Wireless authentication
    10. Rogue access point concepts
    11. Wireless security assessment
  23. API Security

    1. REST APIs
    2. GraphQL
    3. JWT
    4. OAuth 2.0
    5. API authentication
    6. API authorization
    7. BOLA / IDOR
    8. Rate limiting
    9. Mass assignment
    10. API fuzzing
    11. API enumeration
    12. OWASP API Security Top 10
  24. Cloud Security

    1. Cloud fundamentals
    2. IAM
    3. AWS fundamentals
    4. Azure fundamentals
    5. GCP fundamentals
    6. Object storage
    7. Security groups
    8. Cloud metadata services
    9. Access keys
    10. Cloud misconfigurations
    11. ScoutSuite
    12. Trivy
    13. Cloud enumeration
  25. Container Security

    1. Docker architecture
    2. Docker images
    3. Dockerfiles
    4. Container networking
    5. Container privileges
    6. Docker socket
    7. Container secrets
    8. Image vulnerabilities
    9. Trivy
    10. Docker Bench
    11. Container escape concepts
  26. Source Code Security

    1. Git fundamentals
    2. Git history analysis
    3. Secret discovery
    4. API key exposure
    5. Environment variables
    6. Dependency vulnerabilities
    7. SAST
    8. Semgrep
    9. Gitleaks
    10. TruffleHog
  27. Security Automation

    1. Python for security
    2. Bash automation
    3. PowerShell automation
    4. Requests
    5. Scapy
    6. Nmap automation
    7. API automation
    8. Custom enumeration scripts
    9. Result parsing
    10. JSON
    11. CSV
    12. Reusable security tools
  28. Exploit Development

    1. Python for exploit development
    2. C fundamentals
    3. Memory layout
    4. Stack
    5. Heap
    6. Registers
    7. Assembly basics
    8. GDB
    9. Buffer overflows
    10. Shellcode concepts
    11. ASLR
    12. DEP / NX
    13. Stack canaries
    14. Basic binary exploitation
  29. Binary Analysis

    1. ELF
    2. PE
    3. Executable formats
    4. Static analysis
    5. Dynamic analysis
    6. Strings analysis
    7. Ghidra
    8. x64dbg
    9. Process analysis
    10. Debugging
    11. Reverse engineering fundamentals
  30. Malware Analysis

    1. Malware fundamentals
    2. Static malware analysis
    3. Dynamic malware analysis
    4. PE analysis
    5. ELF analysis
    6. Indicators of Compromise
    7. Sandboxing
    8. Process monitoring
    9. Network behavior analysis
    10. Reverse engineering
  31. Professional Pentesting Methodology

    1. Rules of engagement
    2. Scope definition
    3. Asset discovery
    4. Attack surface mapping
    5. Threat modeling
    6. Reconnaissance
    7. Enumeration
    8. Vulnerability analysis
    9. Exploitation
    10. Privilege escalation
    11. Lateral movement
    12. Pivoting
    13. Impact assessment
    14. Evidence collection
    15. Cleanup
    16. Documentation
  32. Pentest Reporting

    1. Executive summary
    2. Technical findings
    3. Evidence
    4. Reproduction steps
    5. Risk rating
    6. CVSS
    7. Business impact
    8. Remediation
    9. Proof of Concept
    10. Retesting
    11. Final report
  33. Real-World Pentesting Workflow

    1. Scope
    2. Reconnaissance
    3. Attack surface discovery
    4. Enumeration
    5. Service identification
    6. Vulnerability discovery
    7. Manual validation
    8. Initial access
    9. Privilege escalation
    10. Credential discovery
    11. Lateral movement
    12. Pivoting
    13. Impact validation
    14. Evidence collection
    15. Cleanup
    16. Reporting
    17. Remediation
    18. Retesting
  34. Practice Labs

    1. OverTheWire
    2. PortSwigger Web Security Academy
    3. TryHackMe
    4. Hack The Box
    5. VulnHub
    6. OWASP Juice Shop
    7. DVWA
    8. Metasploitable
    9. Damn Vulnerable API
    10. Self-hosted vulnerable environments
  35. Advanced Red Team Concepts

    1. Adversary simulation
    2. Initial access
    3. Command and Control
    4. C2 frameworks
    5. Evasion concepts
    6. OPSEC
    7. Identity attacks
    8. Active Directory attack paths
    9. Cloud attack paths
    10. Detection engineering
    11. Purple Team methodology