Cyber Security Academy icon

Cyber Security Academy

SecurityDataSystemsBeginnerDatabaseScriptingCryptoNetworkBackendEnterprise

Protect digital systems and data with essential skills from Cyber Security Academy.

🤖 AI-Powered
Course Overview

In today's hyper-connected world, where digital transformation accelerates at an unprecedented pace, the demand for skilled cybersecurity professionals has never been higher. From safeguarding personal data to protecting global infrastructure, cybersecurity is no longer just an IT concern; it's a critical foundation for every organization and individual. Are you ready to become a guardian of the digital realm? CoddyKit's comprehensive "Learn Cyber Security" program is meticulously designed to equip you with the essential knowledge and practical skills needed to combat evolving cyber threats and build a resilient digital future. Whether you're a complete beginner or looking to enhance your existing technical expertise, our mobile-first learning platform provides an accessible and engaging pathway to master the art and science of cybersecurity.

Embark on a transformative learning journey with CoddyKit, where we break down complex cybersecurity concepts into digestible, actionable mini-courses. Our curriculum spans the entire spectrum of digital defense, from fundamental principles to advanced strategic management, ensuring you gain a holistic understanding of this vital field. Each course is crafted by industry experts, focusing on real-world applications and current best practices. Get ready to explore, understand, and defend against the sophisticated challenges of the cyber landscape.

Cybersecurity Fundamentals (Level: A1)

This foundational mini-course is your essential entry point into the world of cybersecurity. You'll gain a solid understanding of critical terminology, core principles, and the overarching importance of protecting digital assets in an increasingly vulnerable online environment. We lay the groundwork for understanding how cyber threats operate and why robust security measures are indispensable, setting a strong foundation for your future learning.

  • Introduction to Cybersecurity — Get acquainted with the basic concepts of cybersecurity, its expansive scope, and its profound relevance in today's digital world, emphasizing why every connected individual and business needs a strong defense.
  • Common Security Threats — Explore the most frequent types of cyber attacks, from phishing and malware to ransomware and DDoS, and learn how they impact individuals, businesses, and governments globally.
  • Fundamental Security Strategies — Discover essential best practices and basic guidelines to protect systems and data, including crucial steps for proactive risk mitigation and fostering a secure online presence.

Networking Basics for Security (Level: A2)

Building upon your foundational cybersecurity knowledge, this course dives into the core networking concepts that are absolutely critical for any security professional. Understanding how networks function, including protocols, ports, and various network architectures, is paramount for effectively identifying, analyzing, and preventing potential threats and vulnerabilities.

  • Core Networking Concepts — Learn about the fundamental OSI model and the TCP/IP stack, understanding how data travels across interconnected networks and the layers involved in secure communication.
  • Networking Protocols and Ports — Understand the intricacies of common protocols like HTTP, HTTPS, FTP, and SSH, and grasp why diligent port management is crucial for maintaining network security and preventing unauthorized access.
  • Basic Network Security Tools — Introduce yourself to simple yet effective tools such as firewalls and Virtual Private Networks (VPNs) that serve as primary lines of defense against unauthorized access and data interception.

Secure Network Architectures (Level: A1)

Elevate your expertise by diving deeper into the principles of designing and maintaining truly secure network environments. This course covers advanced topics like network segmentation, the deployment of intrusion detection systems (IDS), and sophisticated firewall configurations, all of which are essential components of a robust and resilient defense strategy against modern cyber threats.

  • Network Segmentation — Learn the paramount importance of logically dividing networks to isolate valuable data, critical systems, and minimize the blast radius of potential breaches, enhancing overall security posture.
  • Firewall and IDS Configuration — Gain practical insights into crafting advanced firewall rules and effectively configuring intrusion detection systems (IDS) and intrusion prevention systems (IPS) to proactively stop and alert on malicious network activity.
  • Implementing VLANs for Security — Discover how Virtual Local Area Networks (VLANs) can be strategically implemented to support both optimized network performance and enhanced security in complex, modern network infrastructures.

Cryptography Essentials (Level: A1)

Gain a solid and practical understanding of cryptographic principles, which are the backbone of secure digital communication and data storage. This course covers fundamental concepts such as encryption, hashing, and public-key infrastructure (PKI), establishing the critical role cryptography plays in securing data both in transit and at rest, ensuring confidentiality and integrity.

  • Symmetric vs. Asymmetric Encryption — Explore the operational differences between symmetric and asymmetric encryption types, understanding their respective strengths and why they are strategically used in various secure communication contexts.
  • Hashing and Digital Signatures — Understand the process of creating unique data fingerprints (hashing) to ensure data integrity, and learn how digital signatures provide authentication and non-repudiation for digital documents and communications.
  • Public-Key Infrastructure (PKI) — Learn about the ecosystem of certificates, certificate authorities, and how PKI ensures secure, authenticated communication and identity verification across diverse digital platforms.

Web Application Security (Level: A1)

Focusing specifically on the vulnerabilities inherent in web applications, this crucial course delves into common attack vectors that target online services. You'll learn about prevalent threats like SQL injection, cross-site scripting (XSS), and session hijacking, alongside exploring best practices for secure coding and developing resilient web applications.

  • Understanding OWASP Top 10 — Review the Open Web Application Security Project (OWASP) Top 10, which outlines the most critical security flaws in web applications, and learn how these vulnerabilities can be exploited by attackers.
  • Secure Coding Principles — Discover essential best practices and design principles for writing secure web application code, effectively mitigating common vulnerabilities and building more robust software.
  • Authentication and Session Management — Explore robust methods to protect user identities through strong authentication mechanisms and learn how to maintain secure session management across various web platforms to prevent unauthorized access.

Endpoint Security and Threat Management (Level: A1)

Examine the vital methods for securing individual workstations, mobile devices, servers, and other endpoints that serve as common entry points for attackers. This course covers the deployment and management of antivirus software, advanced Endpoint Detection and Response (EDR) tools, and the implementation of policy-driven security practices to effectively mitigate endpoint-related risks.

  • Endpoint Security Fundamentals — Understand the core principles of how to protect individual devices, covering everything from initial secure configuration to ongoing monitoring and patch management.
  • Anti-Malware and EDR Solutions — Learn about the capabilities of modern threat detection and response technologies, including advanced anti-malware and EDR solutions, in actively defending endpoints against sophisticated attacks.
  • Policy and Compliance — Discover how organizational security policies and compliance frameworks ensure consistent protection across a diverse range of devices and enforce a standardized security posture.

Intrusion Detection and Incident Response (Level: A1)

Master the critical skills needed to detect, analyze, and respond to security incidents efficiently and effectively. This course covers established incident response frameworks, introduces the basics of digital forensics, and outlines best practices for threat containment, eradication, and post-incident remediation to minimize damage and prevent recurrence.

  • IDS/IPS Technologies — Study how Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) actively monitor networks for malicious activity, alerting security teams or automatically blocking threats.
  • Incident Response Lifecycle — Examine the structured, step-by-step processes of identifying, containing, eradicating, recovering from, and learning from security threats, adhering to industry-standard frameworks.
  • Digital Forensics Fundamentals — Explore basic techniques for preserving, collecting, and analyzing digital evidence post-breach, which is crucial for understanding attack vectors and supporting legal action.

Ethical Hacking and Penetration Testing (Level: A1)

Designed for aspiring offensive security professionals, this engaging course delves into the world of ethical hacking. You'll learn penetration testing methodologies, vulnerability assessments, and the critical ethical responsibilities that come with simulating real-world attacks to identify and fix security weaknesses before malicious actors can exploit them.

  • Pen Testing Methodologies — Gain insights into structured approaches for simulating real-world attacks on systems and networks, following established frameworks like OWASP, NIST, and PTES.
  • Reconnaissance and Vulnerability Scanning — Learn how ethical hackers gather information (reconnaissance) and identify weaknesses (vulnerability scanning) using various tools and techniques before attempting exploitation.
  • Reporting and Remediation — Understand the paramount importance of thorough documentation and clear reporting of discovered vulnerabilities, along with strategies for effective remediation and strengthening security.

Cloud Security Fundamentals (Level: A1)

As organizations increasingly migrate to the cloud, understanding its unique security challenges is paramount. This course explores cloud service models (IaaS, PaaS, SaaS), the shared responsibility framework, and the critical controls needed to maintain a robust and secure cloud ecosystem, ensuring data protection and compliance in distributed environments.

  • Cloud Service and Deployment Models — Review the core concepts of Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS), as well as public, private, and hybrid cloud setups.
  • Shared Responsibility Models — Understand the distinct roles and responsibilities between cloud providers (like AWS, Azure, GCP) and customers in maintaining security, clarifying who is responsible for what.
  • Key Cloud Security Controls — Learn about essential security measures such as identity and access management (IAM), data encryption, network security groups, and continuous monitoring in dynamic cloud environments.

Secure DevOps and Automation (Level: A1)

Marrying security with the speed and agility of DevOps, this innovative course discusses how to integrate security seamlessly into the software development lifecycle. You'll learn about secure coding practices, CI/CD pipeline integration, and automated scanning tools to proactively catch and remediate security issues early in the development process, fostering a "security-first" culture.

  • DevOps Culture and Security — Learn how integrating security into the DevOps culture fosters collaboration, shared responsibility, and leads to more reliable, secure software delivery from inception to deployment.
  • CI/CD Security Integration — Discover practical ways to automate security checks, vulnerability scanning, and compliance testing throughout the Continuous Integration/Continuous Delivery (CI/CD) pipeline, shifting security left.
  • Automated Vulnerability Scanning — Explore various tools and techniques for finding and fixing security flaws, misconfigurations, and compliance issues automatically during early development stages, saving time and resources.

Cyber Threat Intelligence (Level: A1)

Build your expertise in the critical discipline of gathering, processing, and analyzing threat data to proactively anticipate and defend against cyber attacks. This course covers the complete threat intelligence lifecycle, various data collection methods, and the practical application of threat intelligence to inform defensive measures and strategic security decisions.

  • Threat Intelligence Lifecycle — Examine the structured approach to planning, collecting, processing, analyzing, and disseminating threat data to relevant stakeholders, creating actionable intelligence.
  • Data Sources and Collection Methods — Learn how to gather valuable and actionable insights from diverse sources, including open-source intelligence (OSINT), dark web monitoring, commercial threat feeds, and internal security logs.
  • Applying Threat Intelligence — See how intelligence guides defensive measures, enhances risk assessments, informs vulnerability management, and supports proactive security strategies to stay ahead of adversaries.

Cyber Security Management and Governance (Level: A1)

Culminating your advanced learning path, this strategic course emphasizes the critical aspects of strategic oversight, regulatory compliance, and robust risk management practices. Students will gain the leadership perspective needed to effectively direct and implement enterprise-wide security programs, ensuring organizational resilience and adherence to legal and industry standards.

  • Security Governance Frameworks — Understand how globally recognized frameworks like ISO 27001, NIST Cybersecurity Framework (CSF), and COBIT shape organizational security policies, strategies, and controls.
  • Risk Management and Compliance — Learn to conduct comprehensive risk assessments, develop mitigation strategies, and expertly navigate complex regulatory landscapes such as GDPR, HIPAA, CCPA, and PCI DSS.
  • Building a Security Culture — Discover effective strategies to foster security awareness, promote best practices, and instill accountability across an entire organization, turning every employee into a part of the defense team.

What You'll Learn

  • Master fundamental cybersecurity concepts and terminology.
  • Understand common cyber threats and effective mitigation strategies.
  • Grasp core networking principles essential for secure system design.
  • Learn to design and implement secure network architectures, including segmentation and IDS.
  • Develop a strong understanding of cryptographic principles like encryption, hashing, and PKI.
  • Identify and mitigate common web application vulnerabilities (OWASP Top 10).
  • Implement robust endpoint security measures and utilize EDR solutions.
  • Execute incident detection, response, and basic digital forensics procedures.
  • Explore ethical hacking methodologies and conduct penetration tests.
  • Navigate unique security challenges in cloud environments and apply key controls.
  • Integrate security into DevOps pipelines with automated scanning.
  • Utilize cyber threat intelligence for proactive defense strategies.
  • Understand security governance, risk management, and regulatory compliance frameworks.

Who Is This Course For?

The "Learn Cyber Security" program on CoddyKit is ideal for a diverse range of learners, including:

  • Aspiring Cybersecurity Professionals: Individuals looking to kickstart a career in cybersecurity, whether as security analysts, penetration testers, or incident responders.
  • Software Developers and Engineers: Those who want to build more secure applications and integrate security into their development lifecycle.
  • IT Professionals and System Administrators: Anyone responsible for managing IT infrastructure who needs to deepen their security knowledge.
  • Career Changers: Professionals from other fields seeking to transition into the high-demand cybersecurity industry.
  • Students and Graduates: Learners pursuing degrees in computer science, IT, or related fields who wish to specialize in cybersecurity.
  • Business Owners and Managers: Leaders who need to understand cybersecurity risks and implement effective governance within their organizations.
  • Anyone Concerned with Digital Safety: Individuals who want to protect their personal data and understand how to navigate the digital world securely.

The digital world needs vigilant protectors, and CoddyKit is here to empower you to become one. With our flexible, mobile-friendly platform, you can learn at your own pace, on your own terms, and build a skill set that is not only in high demand but also critical for the future. Don't just observe the digital landscape; learn to defend it. Enroll in CoddyKit's "Learn Cyber Security" program today and take the first step towards a rewarding and impactful career in protecting our digital future!

Start Learning →

How You'll Learn

🎯
Interactive Lessons
Hands-on coding exercises with real-time feedback
🤖
AI Tutor
Get instant help from our AI when you're stuck
💻
Built-in Editor
Write and run code directly in your browser
🏆
Certificate
Earn a certificate when you complete the course
Curriculum

76 Courses

Every course in the Cyber Security Academy learning path.

01

Introduction to Cybersecurity

A14 lessons

Learn what cybersecurity is, why it matters, the CIA triad, common threat actors, and how defenders think about protecting systems.

  • What is Cybersecurity?
  • The CIA Triad: Confidentiality, Integrity, Availability
  • Threat Actors and Attack Motivations
  • +1 more
02

Networking Fundamentals for Security

A14 lessonsPRO

Build a solid networking foundation: IP addressing, TCP/UDP, DNS, HTTP, and how packets flow through the internet.

  • IP Addressing and Subnets
  • TCP vs UDP: When Each Is Used
  • DNS: How Domains Resolve to IPs
  • +1 more
03

Common Attack Types

A14 lessonsPRO

Survey the most prevalent cyber attacks: phishing, malware, man-in-the-middle, denial of service, and social engineering.

  • Phishing and Spear Phishing
  • Malware: Viruses, Worms, Trojans, Ransomware
  • Man-in-the-Middle Attacks
  • +1 more
04

Password Security and Authentication

A14 lessonsPRO

Learn best practices for passwords, hashing algorithms, MFA, and how attackers crack credentials.

  • Password Strength and Policies
  • Password Hashing: bcrypt, Argon2, PBKDF2
  • Multi-Factor Authentication
  • +1 more
05

Secure Browsing and OPSEC

A14 lessonsPRO

Practice safe browsing, understand tracking and fingerprinting, use VPNs and Tor safely, and apply operational security.

  • Browser Security Settings and Extensions
  • Tracking, Cookies, and Fingerprinting
  • VPNs: What They Protect and What They Don't
  • +1 more
06

Social Engineering and Phishing Defense

A24 lessonsPRO

Social Engineering and Phishing Defense: Social Engineering Tactics, Recognizing Phishing, and more.

  • Social Engineering Tactics
  • Recognizing Phishing
  • Vishing and Smishing
  • +1 more
07

Firewalls and Network Segmentation

A24 lessonsPRO

Firewalls and Network Segmentation: Firewall Types, Rules and Policies, and more.

  • Firewall Types
  • Rules and Policies
  • Network Segmentation
  • +1 more
08

VPNs and Secure Remote Access

A24 lessonsPRO

VPNs and Secure Remote Access: How VPNs Work, VPN Protocols, and more.

  • How VPNs Work
  • VPN Protocols
  • Split vs Full Tunnel
  • +1 more
09

Linux Security Essentials

A24 lessonsPRO

Harden Linux systems: file permissions, user management, SSH security, firewalls, and basic log analysis.

  • File Permissions and Ownership
  • User and Group Management
  • SSH Hardening and Key-Based Auth
  • +1 more
10

Web Security Fundamentals

A24 lessonsPRO

Learn the OWASP Top 10 fundamentals: SQL injection, XSS, CSRF, insecure deserialization, and misconfiguration.

  • SQL Injection: How and Why It Works
  • Cross-Site Scripting (XSS)
  • Cross-Site Request Forgery (CSRF)
  • +1 more
11

Cryptography Basics

A24 lessonsPRO

Understand symmetric and asymmetric encryption, hashing, digital signatures, and TLS without deep mathematics.

  • Symmetric Encryption: AES and Stream Ciphers
  • Asymmetric Encryption: RSA and Elliptic Curves
  • Hash Functions: SHA-256 and Beyond
  • +1 more
12

Reconnaissance and OSINT

A24 lessonsPRO

Learn open-source intelligence gathering: Google dorking, Shodan, WHOIS, certificate transparency, and social media OSINT.

  • Google Dorking for Information Gathering
  • WHOIS, DNS Enumeration, and Certificates
  • Shodan: The Search Engine for Internet Devices
  • +1 more
13

Multi-Factor Authentication

A24 lessonsPRO

Multi-Factor Authentication: Authentication Factors, TOTP and HOTP, and more.

  • Authentication Factors
  • TOTP and HOTP
  • Push and Hardware Keys
  • +1 more
14

Endpoint Detection and Response

B14 lessonsPRO

Endpoint Detection and Response: What Is EDR, Telemetry and Detection, and more.

  • What Is EDR
  • Telemetry and Detection
  • Response Actions
  • +1 more
15

Incident Response Fundamentals

B14 lessonsPRO

Understand the incident response lifecycle, how to contain and eradicate threats, and write an incident report.

  • The IR Lifecycle: Prepare, Identify, Contain
  • Evidence Collection and Chain of Custody
  • Eradication, Recovery, and Lessons Learned
  • +1 more
16

PKI and Digital Certificates

B14 lessonsPRO

PKI and Digital Certificates: Public Key Infrastructure, Certificate Authorities, and more.

  • Public Key Infrastructure
  • Certificate Authorities
  • Certificate Chains
  • +1 more
17

Identity and Access Management

B14 lessonsPRO

Identity and Access Management: IAM Fundamentals, RBAC and ABAC, and more.

  • IAM Fundamentals
  • RBAC and ABAC
  • SSO and Federation
  • +1 more
18

Network Scanning and Enumeration

B14 lessonsPRO

Use Nmap, Netcat, and service fingerprinting to map networks and identify attack surfaces.

  • Nmap Port Scanning Techniques
  • Service and OS Fingerprinting
  • Netcat: The Swiss Army Knife
  • +1 more
19

Vulnerability Assessment

B14 lessonsPRO

Use Nessus, OpenVAS, and Nikto to discover vulnerabilities; understand CVE, CVSS scoring, and prioritization.

  • CVE, CWE, and CVSS Scoring
  • Running Nessus or OpenVAS Scans
  • Web App Scanning with Nikto and OWASP ZAP
  • +1 more
20

Exploitation Basics with Metasploit

B14 lessonsPRO

Learn Metasploit's architecture, modules, payloads, and how to exploit known vulnerabilities in lab environments.

  • Metasploit Architecture and msfconsole
  • Exploiting a Known Vulnerability
  • Payloads: Staged vs Stageless, Meterpreter
  • +1 more
21

Windows Security and Active Directory

B14 lessonsPRO

Understand Windows security architecture, Active Directory attacks (Pass-the-Hash, Kerberoasting), and hardening.

  • Windows Authentication: NTLM and Kerberos
  • Pass-the-Hash and Pass-the-Ticket Attacks
  • Kerberoasting and AS-REP Roasting
  • +1 more
22

Wireless Network Security

B14 lessonsPRO

Analyze 802.11 security: WEP, WPA2, WPA3, EAP protocols, evil twin attacks, and wireless hardening.

  • 802.11 Security Protocols: WEP, WPA2, WPA3
  • WPA2 Handshake Capture and Cracking
  • Evil Twin and Captive Portal Attacks
  • +1 more
23

Log Analysis and SIEM

B14 lessonsPRO

Collect, parse, and correlate logs with a SIEM; write detection rules and investigate security alerts.

  • Log Sources: OS, Network, and Application Logs
  • SIEM Architecture and Log Ingestion
  • Writing Detection Rules and Correlation
  • +1 more
24

Cloud Security Fundamentals

B14 lessonsPRO

Secure AWS, Azure, or GCP environments: IAM least privilege, misconfiguration detection, and cloud-native security.

  • Cloud IAM: Roles, Policies, and Least Privilege
  • Common Cloud Misconfigurations
  • Cloud Security Posture Management (CSPM)
  • +1 more
25

Threat Intelligence

B14 lessonsPRO

Collect, analyze, and operationalize threat intelligence: STIX/TAXII, threat feeds, ATT&CK mapping, and sharing.

  • Threat Intelligence Types and Sources
  • MITRE ATT&CK Framework
  • STIX, TAXII, and Threat Sharing
  • +1 more
26

Database Security

B14 lessonsPRO

Database Security: SQL Injection Defense, Access Control and Encryption, and more.

  • SQL Injection Defense
  • Access Control and Encryption
  • Auditing and Monitoring
  • +1 more
27

Security Auditing and Compliance

B14 lessonsPRO

Security Auditing and Compliance: Compliance Frameworks, Security Audits, and more.

  • Compliance Frameworks
  • Security Audits
  • Policies and Procedures
  • +1 more
28

Data Loss Prevention

B14 lessonsPRO

Data Loss Prevention: What Is DLP, Classifying Data, and more.

  • What Is DLP
  • Classifying Data
  • DLP Controls
  • +1 more
29

TLS and SSL Deep Dive

B24 lessonsPRO

TLS and SSL Deep Dive: The TLS Handshake, Cipher Suites, and more.

  • The TLS Handshake
  • Cipher Suites
  • Certificate Validation
  • +1 more
30

Container Security

B24 lessonsPRO

Container Security: Container Threats, Image Scanning, and more.

  • Container Threats
  • Image Scanning
  • Runtime Security
  • +1 more
31

API Security and OWASP API Top 10

B24 lessonsPRO

API Security and OWASP API Top 10: API Attack Surface, Broken Authorization, and more.

  • API Attack Surface
  • Broken Authorization
  • Rate Limiting and Abuse
  • +1 more
32

Web Application Pentesting

B24 lessonsPRO

Perform a structured web app pentest: intercept traffic with Burp Suite, exploit injection flaws, and test auth.

  • Burp Suite Proxy and Intercepting Requests
  • Testing for Injection Vulnerabilities
  • Authentication and Session Testing
  • +1 more
33

Malware Analysis Fundamentals

B24 lessonsPRO

Perform static and dynamic malware analysis: PE structure, strings, sandbox behavior, and YARA rules.

  • Static Analysis: Strings, Hashes, and PE Headers
  • Dynamic Analysis in a Sandbox
  • Behavioral IOCs: Registry, Network, and File Artifacts
  • +1 more
34

Mobile Application Security

B24 lessonsPRO

Mobile Application Security: Mobile Threat Landscape, Insecure Data Storage, and more.

  • Mobile Threat Landscape
  • Insecure Data Storage
  • Reverse Engineering Apps
  • +1 more
35

IoT and Embedded Security

B24 lessonsPRO

IoT and Embedded Security: IoT Attack Surface, Firmware Analysis, and more.

  • IoT Attack Surface
  • Firmware Analysis
  • Default Credentials
  • +1 more
36

Honeypots and Deception

B24 lessonsPRO

Honeypots and Deception: Deception Technology, Types of Honeypots, and more.

  • Deception Technology
  • Types of Honeypots
  • Deploying Honeypots
  • +1 more
37

Application Security and DevSecOps

B24 lessonsPRO

Integrate security into CI/CD pipelines: SAST, DAST, SCA, secrets scanning, container security, and security champions.

  • SAST and DAST in CI/CD Pipelines
  • Software Composition Analysis (SCA)
  • Secrets Scanning and Hardcoded Credentials
  • +1 more
38

Zero Trust Architecture

B24 lessonsPRO

Design Zero Trust networks: identity verification, microsegmentation, BeyondCorp model, and continuous validation.

  • Zero Trust Principles and the BeyondCorp Model
  • Identity and Device Verification
  • Microsegmentation and Network Policy
  • +1 more
39

Secure Coding Practices

B24 lessonsPRO

Write secure code: input validation, output encoding, secure dependency management, OWASP ASVS, and code review.

  • Input Validation and Output Encoding
  • Secure Dependency Management
  • OWASP ASVS: Application Security Verification Standard
  • +1 more
40

Bug Bounty and Responsible Disclosure

B24 lessonsPRO

Participate effectively in bug bounty programs: scope analysis, reporting quality, vulnerability chaining, and ethics.

  • Reading Bug Bounty Scopes and Rules
  • Writing High-Quality Bug Reports
  • Vulnerability Chaining for Higher Impact
  • +1 more
41

Penetration Test Reporting

B24 lessonsPRO

Penetration Test Reporting: Report Structure, Risk Scoring, and more.

  • Report Structure
  • Risk Scoring
  • Writing Findings
  • +1 more
42

Burp Suite Mastery

B24 lessonsPRO

Burp Suite Mastery: Proxy and Interception, Repeater and Intruder, and more.

  • Proxy and Interception
  • Repeater and Intruder
  • Scanner and Extensions
  • +1 more
43

Network Traffic Analysis

B24 lessonsPRO

Network Traffic Analysis: Capturing Packets, Reading Protocols, and more.

  • Capturing Packets
  • Reading Protocols
  • Detecting Anomalies
  • +1 more
44

Advanced Exploitation Techniques

C14 lessonsPRO

Master buffer overflows, ROP chains, format string vulnerabilities, and heap exploitation in a lab setting.

  • Stack Buffer Overflows
  • Return-Oriented Programming (ROP)
  • Format String Vulnerabilities
  • +1 more
45

Reverse Engineering

C14 lessonsPRO

Reverse engineer binaries with Ghidra and GDB: control flow, data structures, calling conventions, and deobfuscation.

  • Ghidra: Navigating and Annotating Binaries
  • x86/x64 Assembly Essentials for Reversers
  • Dynamic Analysis with GDB and pwndbg
  • +1 more
46

Red Team Operations

C14 lessonsPRO

Plan and execute red team engagements: C2 infrastructure, living-off-the-land techniques, and evasion.

  • C2 Frameworks: Cobalt Strike and Sliver
  • Living-Off-the-Land Binaries (LOLBins)
  • Lateral Movement Techniques
  • +1 more
47

Forensics and Memory Analysis

C14 lessonsPRO

Perform digital forensics: disk imaging, file carving, memory analysis with Volatility, and timeline reconstruction.

  • Disk Imaging and File System Forensics
  • Memory Acquisition and Volatility Framework
  • Timeline Analysis and Artifact Correlation
  • +1 more
48

Security Architecture and Risk Management

C14 lessonsPRO

Design secure architectures: threat modeling, risk frameworks (NIST, ISO 27001), control selection, and audit.

  • Threat Modeling with STRIDE and PASTA
  • Risk Frameworks: NIST CSF and ISO 27001
  • Security Control Selection and Gap Analysis
  • +1 more
49

Advanced Malware and APT Campaigns

C14 lessonsPRO

Analyze advanced persistent threat campaigns: multi-stage loaders, fileless malware, C2 over HTTPS, and TTPs.

  • APT Lifecycle: Initial Access to Exfiltration
  • Fileless Malware and Living-in-Memory Techniques
  • C2 Over HTTPS and DNS Tunneling
  • +1 more
50

Cyber Threat Hunting

C14 lessonsPRO

Cyber Threat Hunting: Threat Hunting Mindset, Hypothesis-Driven Hunting, and more.

  • Threat Hunting Mindset
  • Hypothesis-Driven Hunting
  • Using Logs and Telemetry
  • +1 more
51

SOC Analyst Operations and Triage

B14 lessonsPRO

SOC Analyst Operations and Triage: The SOC and Its Tiers, Alert Triage Workflow, and more.

  • The SOC and Its Tiers
  • Alert Triage Workflow
  • Playbooks and Ticketing
  • +1 more
52

Threat Modeling with STRIDE

B14 lessonsPRO

Threat Modeling with STRIDE: Why Threat Modeling Matters, The STRIDE Framework, and more.

  • Why Threat Modeling Matters
  • The STRIDE Framework
  • Data Flow Diagrams and Trust Boundaries
  • +1 more
53

Email Security: SPF, DKIM and DMARC

B14 lessonsPRO

Email Security: SPF, DKIM and DMARC: How Email Spoofing Works, SPF Records, and more.

  • How Email Spoofing Works
  • SPF Records
  • DKIM Signing
  • +1 more
54

DNS Security and Attacks

B14 lessonsPRO

DNS Security and Attacks: How DNS Works and Its Risks, DNS Spoofing and Cache Poisoning, and more.

  • How DNS Works and Its Risks
  • DNS Spoofing and Cache Poisoning
  • DNS Tunneling and Exfiltration
  • +1 more
55

Vulnerability Management Programs

B14 lessonsPRO

Vulnerability Management Programs: The Vulnerability Management Lifecycle, Scanning and Asset Inventory, and more.

  • The Vulnerability Management Lifecycle
  • Scanning and Asset Inventory
  • Prioritization: CVSS, EPSS and KEV
  • +1 more
56

Detection Engineering with Sigma

B24 lessonsPRO

Detection Engineering with Sigma: Detection-as-Code Principles, Writing Sigma Rules, and more.

  • Detection-as-Code Principles
  • Writing Sigma Rules
  • Mapping to MITRE ATT&CK
  • +1 more
57

Network Security Monitoring with IDS/IPS

B24 lessonsPRO

Network Security Monitoring with IDS/IPS: IDS vs IPS Concepts, Signature Rules with Snort and Suricata, and more.

  • IDS vs IPS Concepts
  • Signature Rules with Snort and Suricata
  • Anomaly and Behavioral Detection
  • +1 more
58

YARA Rules for Malware Detection

B24 lessonsPRO

YARA Rules for Malware Detection: What YARA Is For, YARA Rule Syntax, and more.

  • What YARA Is For
  • YARA Rule Syntax
  • Hunting with Strings and Hex
  • +1 more
59

Security Automation with SOAR

B24 lessonsPRO

Security Automation with SOAR: Why SOAR Matters, Playbook Design, and more.

  • Why SOAR Matters
  • Playbook Design
  • Integrations and Enrichment
  • +1 more
60

Risk Frameworks: NIST CSF and ISO 27001

B14 lessonsPRO

Risk Frameworks: NIST CSF and ISO 27001: Why Security Frameworks Exist, The NIST Cybersecurity Framework, and more.

  • Why Security Frameworks Exist
  • The NIST Cybersecurity Framework
  • ISO 27001 and the ISMS
  • +1 more
61

Active Directory and Kerberos Attacks

C14 lessonsPRO

Active Directory and Kerberos Attacks: Active Directory Attack Surface, Kerberos and Kerberoasting, and more.

  • Active Directory Attack Surface
  • Kerberos and Kerberoasting
  • Pass-the-Hash and Pass-the-Ticket
  • +1 more
62

Cloud Penetration Testing

C14 lessonsPRO

Cloud Penetration Testing: Cloud Attack Surface, Enumerating Cloud Resources, and more.

  • Cloud Attack Surface
  • Enumerating Cloud Resources
  • Exploiting IAM Misconfigurations
  • +1 more
63

Kubernetes Security

B24 lessonsPRO

Kubernetes Security: Kubernetes Threat Model, RBAC and Service Accounts, and more.

  • Kubernetes Threat Model
  • RBAC and Service Accounts
  • Pod Security and Network Policies
  • +1 more
64

Disk and Network Forensics

C14 lessonsPRO

Disk and Network Forensics: Forensic Fundamentals and Chain of Custody, Disk Imaging and File System Analysis, and more.

  • Forensic Fundamentals and Chain of Custody
  • Disk Imaging and File System Analysis
  • Network Forensics with PCAP
  • +1 more
65

Privacy and Data Protection

B14 lessonsPRO

Privacy and Data Protection: Why Data Privacy Matters, GDPR and KVKK Essentials, and more.

  • Why Data Privacy Matters
  • GDPR and KVKK Essentials
  • Data Classification and Minimization
  • +1 more
66

Software Supply Chain Security and SBOM

B24 lessonsPRO

Software Supply Chain Security and SBOM: Supply Chain Threats, Software Bill of Materials (SBOM), and more.

  • Supply Chain Threats
  • Software Bill of Materials (SBOM)
  • Dependency and Artifact Signing
  • +1 more
67

Ransomware Defense and Response

B24 lessonsPRO

Ransomware Defense and Response: How Ransomware Works, Prevention and Hardening, and more.

  • How Ransomware Works
  • Prevention and Hardening
  • Detection and Early Indicators
  • +1 more
68

OT, ICS and SCADA Security

C14 lessonsPRO

OT, ICS and SCADA Security: Industrial Control Systems Basics, OT vs IT Security Differences, and more.

  • Industrial Control Systems Basics
  • OT vs IT Security Differences
  • Common ICS Protocols and Risks
  • +1 more
69

Secrets Management and Key Rotation

B24 lessonsPRO

Secrets Management and Key Rotation: The Secrets Sprawl Problem, Vaults and Secret Stores, and more.

  • The Secrets Sprawl Problem
  • Vaults and Secret Stores
  • Dynamic Secrets and Leasing
  • +1 more
70

Steganography and Data Hiding

B14 lessonsPRO

Steganography and Data Hiding: What Steganography Is, Image and Audio Steganography, and more.

  • What Steganography Is
  • Image and Audio Steganography
  • Detecting Hidden Data (Steganalysis)
  • +1 more
71

AI and LLM Security

B24 lessonsPRO

AI and LLM Security: Prompt Injection and Jailbreaks, The OWASP LLM Top 10, and more.

  • Prompt Injection and Jailbreaks
  • The OWASP LLM Top 10
  • Securing AI Agents and Tool Use
  • +1 more
72

Purple Teaming

C14 lessonsPRO

Purple Teaming: Why Purple Teaming, Mapping Attacks to Detections, and more.

  • Why Purple Teaming
  • Mapping Attacks to Detections
  • Running a Purple Team Exercise
  • +1 more
73

Authentication Protocols: OAuth, OIDC and SAML

B24 lessonsPRO

Authentication Protocols: OAuth, OIDC and SAML: OAuth 2.0 Flows, OpenID Connect (OIDC), and more.

  • OAuth 2.0 Flows
  • OpenID Connect (OIDC)
  • SAML and Federation
  • +1 more
74

RF and Wireless Hacking

C14 lessonsPRO

RF and Wireless Hacking: RF and SDR Fundamentals, Bluetooth and BLE Attacks, and more.

  • RF and SDR Fundamentals
  • Bluetooth and BLE Attacks
  • RFID and NFC Security
  • +1 more
75

CTF and Practical Hacking Skills

B14 lessonsPRO

CTF and Practical Hacking Skills: CTF Categories and Mindset, Web and Crypto Challenges, and more.

  • CTF Categories and Mindset
  • Web and Crypto Challenges
  • Reversing and Pwn Basics
  • +1 more
76

Mobile Forensics

C14 lessonsPRO

Mobile Forensics: Mobile Forensics Fundamentals, Android Acquisition and Analysis, and more.

  • Mobile Forensics Fundamentals
  • Android Acquisition and Analysis
  • iOS Acquisition and Analysis
  • +1 more

Start Cyber Security Academy Now

Join thousands of learners mastering programming with AI-powered lessons.

Get Started Free →Browse All Courses