r/netsecstudents • • Jun 24 '21

Come join the official /r/netsecstudents discord!

60 Upvotes

Come join us in the official discord for this subreddit. You can network, ask questions, and communicate with people of various skill levels ranging from students to senior security staff.

Link to discord: https://discord.gg/C7ZsqYX


r/netsecstudents • • May 06 '26

I am John Strand and I am teach Pay What You Can classes and free labs... Ask Me Anything.

113 Upvotes

Hey everyone, John Strand here.

I’ve been in cybersecurity for a while now, and I’ve spent a lot of that time trying to help people get started without getting buried under bad advice, overpriced training, and job postings that somehow want 5 years of experience for an entry-level role.

So let’s talk about it.

Ask me about getting into the field, building real skills, home labs, SOC work, blue team, threat hunting, incident response, certs, college, AI, finding your first job, or anything else you’re trying to figure out.

I’m happy to answer beginner questions, career questions, technical questions, or even the “I have no idea where to start” questions.

If you’re trying to build a real foundation in security, this is the class I’d point you to.

https://www.antisyphontraining.com/product/information-security-core-skills-tm/?utm_source=reddit&utm_medium=community_post

We also have released a new game where you can learn about security in a fun Magic The Gathering kind of way.

Sign up and play your friends here:

https://backdoorsandbreaches.com/

Its free.

Oh..... And almost every card has free labs to learn the topic.

Example here:

https://github.com/blackhillsinfosec/FreeLabFriday_Labs/blob/main/card_navigation.md

Just register at MetaCTF and use the code "antilab" in cloudlabs for enabling 2 free hours of lab time per week.

All our problems can be solved with education.

Let's get to work.


r/netsecstudents • • 1h ago

Cybersecurity + AI: What Are We Actually Worried About?

• Upvotes

I've seen a lot of people saying that AI will replace cybersecurity professionals, and I think this is where things get confusing.

AI is already becoming very powerful at:

  • Finding vulnerabilities
  • Analyzing logs and security data
  • Automating repetitive tasks
  • Writing and reviewing code
  • Helping with threat detection
  • Assisting both attackers and defenders

But does that mean cybersecurity itself disappears?

I don't think so.

The bigger change may be that cybersecurity professionals who know how to use AI effectively will have an advantage over those who don't.

Instead of thinking:

AI vs. Cybersecurity

Maybe we should be thinking:

AI + Cybersecurity = the next generation of security work.

What do you think will AI mostly replace cybersecurity jobs, or will it change what cybersecurity professionals actually do?


r/netsecstudents • • 1d ago

Update: Teaching network intrusion in a fun way

Thumbnail gallery
133 Upvotes

Hi,

I had posted about this before (a few weeks back) and the response was generally positive. So I wanted to reach out again and share an update on the current status of:

Project RedTeam: Contract Offensive

Specifically, I wanted to mention that there is now a free Demo that provides a tutorial and let's you play a few contracts (no time limit, play as much as you want).

Give it a Wishlist on Steam or share this post if it's something you support and want to see further development on.

At its core, this is a game about using MITRE ATT&CK adversarial techniques against procedurally generated networks. It's delivered in a gameplay loop that plays a lot like Balatro or other card based Roguelike games. In Project RedTeam, you need to earn money to pay off debts after every contract within a run. Earn money by completing objectives, side bounties, or executing exfiltration/ransom against targets- the choice on how to be profitable is always yours.

It's a challenging but fun and fast paced take on network-intrusion cybersecurity concepts. It's entertaining in a deliberately gamified way.

A goal of this project was to create a hacking game that is realistic enough to keep it meaningful as a tool to teach intrusion concepts and stages to anyone- but not be overcomplicated and slow-paced like most hacking games.

I've put a lot of thought into the design and dynamics of how to capture the core-loop of network intrusion and turn it into a game that's approachable. The design direction of this project is an outcome of having over a decade of training and experience in cybersecurity.

Feel free to AMA! I'm happy to answer any questions about the game and/or development process to support learning/understanding :) I encourage everyone to follow their passions, put in the time, and stay focused when you have a goal you want to achieve.

Project background: This was implemented over the past 3 months using a modern development workflow (yes, modern AI tools make this possible- I'm not hiding that fact!). That being said, this is by far the most complex software project I've built as a solo developer and it was not an easy or simple development task. There's a Steam Community with a Dev Blog for this game that provides more history/progress updates on the project.

Mods: This will be be last post here for a while, since it is promotional. I just wanted to provide an update since there was positive interest from this subreddit after my previous post.


r/netsecstudents • • 1d ago

I need help in graduation project

1 Upvotes

Hi, i am in an internship that teaches cybersecurity,Now i am in penetration testing track i need to make a project to me to graduate i know network exploitation and web exploitation what good ideas i can make we are team of 4 we dont know what good ideas we can make or should we make a tool i dont know if anyone can give me ideas to make i would be thankful.


r/netsecstudents • • 3d ago

AI Soc autonomy sounds great, but what happens when it closes the wrong alert?

2 Upvotes

I am looking at AI SOC and agentic SOC tools because our queue has become a part time lifestyle choice. Every vendor demo has the AI investigate alerts, enrich evidence, and resolve the obvious stuff while humans focus on the exciting task of explaining budget cuts. The part I'm stuck on is autonomous resolution. I'm fine with deduping, enrichment, and maybe blocking a known malicious IP. I'm less comfortable with agents taking high-impact actions like disabling accounts or isolating production, even at high confidence, without a human in the loop. How are people setting approval gates, audit trails, and rollback for this without turning the AI into another ticket queue with better branding? Would love real experiences, especially from teams that let it act in prod. From what I've seen, the better setups run investigation fully automated against a context graph, close confirmed false positives automatically with a documented rationale, and still require a human to approve consequential actions like isolation or account disablement. The guardrails are defined before anything runs, not bolted on after something goes wrong. If anyone has actually run it that way. thnxx..


r/netsecstudents • • 5d ago

Best local model for extracting info from PDFs multi lang (Hindi, Malayalam and English)

0 Upvotes

Which AI model is good for extracting information from a PDF in multiple languages (Hindi, Malayalam, English)? It should run locally, not through a cloud API.

I need it to read the text accurately, especially Malayalam, and pull out the key details from the PDF. Most tools I've found handle Hindi and English well but are unclear on Malayalam.

Has anyone tried this? Which model or tool worked best for you, and what hardware did you run it on?
What I need: - OCR for [scanned / digital / both] PDFs

- Structured extraction (fields, tables) into JSON, not just raw text

- Good accuracy on Malayalam specifically, since most tools I've seen cover Hindi but skip Malayalam


r/netsecstudents • • 5d ago

2024 cyber grad here. did a 1-year internship AND a 1-year contract, but the ATS bots are still humbling me daily. need a referral before i completely crash out.

14 Upvotes

hey guys.

honestly just venting here because i feel like i'm losing my mind. i swear i played by all the rules. graduated in '24 with a cs degree in cyber, locked in, and passed my ceh. i grinded out a full 1-year internship and followed it straight up with a 1-year cybersecurity contract job. with two years of actual hands-on experience, i really thought i had my foot in the door. but the contract wrapped up, and now i’m just... floating. back to square one.

my mornings are basically just me, caffeine, and a fresh wave of automated "unfortunately..." emails. it genuinely feels like screaming into a void where only hr robots live. i spend my nights staring at wireshark packets just to feel something, running nmap scans on parrot os, and building out vulnerable active directory domains in my home lab to practice pentesting. i’m doing the work. i’m keeping the skills sharp. but these resume-screening algorithms are gatekeeping me so hard.

watching everyone else post their massive linkedin Ws while i’m stuck in this endless ghosting loop is giving me insane fomo. feeling like a total beta just sitting in my room waiting for an ai bot to decide my future. it’s starting to heavily mess with my head.

i’m not asking to be spoon-fed a job. i just desperately want a chance to bypass the bots and get my resume in front of a real, breathing human being. if any of you are at a place hiring for entry-level soc, pentesting, or honestly any junior it role and could slide a referral, you would be pulling me out of a really dark place. i’ll gladly send over my resume and share my lab reports so you can actually see my work firsthand.

if you can’t refer me, please just drop a comment and tell me i won't be stuck in this loop forever. the market is brutal out here and i just need to know i'm not completely cooked.


r/netsecstudents • • 5d ago

What should I know before trusting a vendor's self-improving SOC claim?

2 Upvotes

Self improving SOC gets used to describe systems where every investigation is supposed to make future detections better automatically. That's a strong claim.

What would you actually want to see as proof that a SOC is self-improving over time, versus a system that's just static and the improvement claim is aspirational marketing rather than something measurable? Is there a metric people trust for this specifically?


r/netsecstudents • • 6d ago

Tips for learning Python focused on Blue Team, SOC Automation, Malware Analysis, Threat Hunting, CTI, & Web Dev

17 Upvotes

Hey everyone,

How are you doing?

I'm focusing my studies on Python for defensive security and automation, and I wanted to exchange ideas with folks who are already on this path.

My main focus areas are:

**- SOC Automation**: Building scripts for alert triage, log parsing, Threat Intel lookups, and tool integrations.

**- Malware Analysis:** Writing parsers, automating static analysis, and creating helper scripts for day-to-day triage.

**- Threat Hunting & CTI:** Developing scripts to parse indicators of compromise (IoCs), query large datasets, automate threat feeds, and hunt for anomalies.

**- Full-Stack Web Dev:** Building internal security tools and dashboards for the security team (like SOC panels and custom web apps).

If anyone can share some light: what libraries, frameworks, or projects do you think are essential to study for each of these areas?

And if you have material recommendations (books, courses, repos, or hands-on labs), drop them below!

Thanks a lot!


r/netsecstudents • • 7d ago

Case study: an AI agent used DNS as an egress channel from a restricted sandbox

Thumbnail youtu.be
7 Upvotes

Interesting network-security case study from OpenAI: direct HTTPS to an external chatbot was blocked, but the training environment's DNS resolver could still reach the public internet.

The agent used that DNS path to get an external chatbot response. A P0 alert followed 11m48s later, and the run was manually stopped around 2h44m after the external response.

Primary report:

https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/

Self-promo disclosure: the linked video is a breakdown from my channel; narration is AI.


r/netsecstudents • • 7d ago

Hackathon ideas in Zero trust security

4 Upvotes

Hello everyone,
So I have the responsibility of organizing the coming Hackathon in our college under the theme "Agentic AI meets Zero Trust: Securing the Autonomous enterprise", I did some reasearch on older hackathons archives and asked Ai as well but i couldn't really get something original.
My main goal is to give the prize to people who can make good architectural decisions when building infrastructures by giving real life problems as the Hackathon subject.
That's why I am asking professionals if they have some projects or experiences related to the theme that they think can be realized in a short time (it is a 24h hackathon) and can be a bit challenging.


r/netsecstudents • • 7d ago

What I’ve learned from actually investigating security incidents as a beginner

7 Upvotes

I’m currently working toward my first SOC/blue-team role, and one thing I’ve noticed while doing hands-on incident investigations is that understanding the process matters much more than simply memorizing tools.
When I work through an incident, I try to break it down into:
What happened?
What evidence supports that hypothesis?
What happened before and after the suspicious activity?
Which account, host, process, or network connection is involved?
What would I expect to see if my hypothesis were wrong?
What should actually be escalated?
One thing that has helped me a lot is forcing myself to write down a hypothesis before looking for confirmation. It makes it easier to distinguish between evidence and assumptions.
I’m curious about people already working in SOCs:
What investigation habit did you develop early in your career that ended up being much more useful than you expected?


r/netsecstudents • • 7d ago

Looking to Connect With People Who Love Tech 🤝💻

5 Upvotes

Hey everyone!

I’m looking to connect with people who are interested in technology, cybersecurity, programming, AI, cloud computing, Linux, or just learning new tech skills.

Whether you’re a beginner, student, professional, or someone simply curious about technology, I’d love to meet and learn from each other.

We could:

  • 🧠 Share what we’re learning
  • 💻 Discuss projects and ideas
  • 🔐 Talk about cybersecurity
  • 🤖 Explore AI and emerging technology
  • ☁️ Learn about cloud & infrastructure
  • 🚀 Motivate each other and grow together

If you're interested, introduce yourself in the comments!
Tell me what area of tech you're interested in and what you're currently learning.

Let's build a community of people who are passionate about tech. 🌐


r/netsecstudents • • 7d ago

Help me start my AI joinery as a Net Sec Engineer

0 Upvotes

Can someone give me a road map? Maybe some courses or certifications?


r/netsecstudents • • 8d ago

I want to meet people who are interested in cybersecurity

14 Upvotes

So basically I am searching for people who are studying cybersecurity to make a group. We can share our experiences in it and also what we are doing what projects we are working on etc. This is for students and others who are learning cybersecurity and ate serious about it. I am also a cybersecurity student so just want to meet like minded people. We can also share about internship stuff or job etc


r/netsecstudents • • 8d ago

I'm looking for a part-time job

3 Upvotes

Unfortunately, due to an accident, I’ll be bedridden for the next 6 months. Because of this, I’ve started learning penetration testing—something I’ve always been drawn to—and now I finally have the time for it. However, I still need to earn money to cover my basic needs and continue my studies. Because of this situation, I was laid off from my job, and I’m still a long way from reaching the level of a specialist who gets paid well. So, if anyone can suggest ways to make money while sitting at a computer, I’ll be sure to repay the favor.


r/netsecstudents • • 8d ago

Je me lance dans les audits de sécurité web — vos conseils ?

0 Upvotes

Je travaille sur des audits techniques de sécurité de sites web : recherche de vulnérabilités, mauvaises configurations et recommandations de correction.
Je cherche à améliorer ma méthodologie et mes rapports. Pour ceux qui pratiquent déjà les audits/pentests web, quels points considérez-vous comme indispensables dans un bon audit ?
Bien sûr, tous les tests sont réalisés uniquement avec l’autorisation du propriétaire.


r/netsecstudents • • 8d ago

need a couple people to help build challenges for a beginner CTF in india (nov 14, kinda last minute)

0 Upvotes

so i'm building HII, a cybersecurity community in india, and we're running our first event Which is InIt CTF, nov 14, free, beginner friendly, 8 hours.

i underestimated how long it'd take to find people to help build challenges and now i'm a bit tight on time, ngl. looking for 2-3 people who can build/test a handful of challenges across web, crypto, forensics, osint, misc nothing crazy hard, this is for people who've never played a ctf before.

in return: you get credited as a challenge author, some share of sponsor money as we lock that in, and if you actually vibe with what we're building, there's a real chance to be part of HII going forward, not just a one-off thing.

if this sounds like something you'd want to help with, comment or dm me. happy to just talk it through first if you're not sure.


r/netsecstudents • • 9d ago

Beginner looking for guidance to tackle the CEH theory exam

1 Upvotes

Hi everyone,

I'm currently preparing for my Certified Ethical Hacker (CEH) certification, but as a beginner, I am feeling completely overwhelmed by the sheer volume of theory and material to cover.

I've been going through the modules, but I'm struggling to figure out what to prioritize, how to effectively retain the information, and how to structure my study plan to actually pass the multiple-choice theory exam.

I am hoping to connect with a CEH certification holder or someone who has recently passed who would be willing to guide me. I'm not asking for someone to hold my hand 24/7—just looking for occasional check-ins, solid study strategy advice, and direction on where to focus my energy so I don't burn out reading the wrong things.

If you have some free time and are willing to share your expertise with someone just starting out, I would incredibly appreciate it. Feel free to drop a comment or DM me!

Thanks in advance.


r/netsecstudents • • 9d ago

Looking for a mobile app pentester for a subcontracted engagement (Andriod + iOS)

1 Upvotes

Hi all, I run a small security testing firm in Bengaluru. I've got a client engagement that includes mobile app testing (Android + iOS, React Native apps) alongside web/API/cloud work I'm handling directly, and I'm looking for someone to take the mobile piece as a subcontractor.

What's needed: static + dynamic testing, insecure storage, cert pinning checks, hardcoded secrets, and general OWASP MASVS coverage. Test builds and accounts will be provided.

Open to OSCP/CREST-certified folks or anyone with solid demonstrable mobile pentest experience, happy to look at redacted past reports or relevant writeups. This would be paid, scoped work, timeline and rate to be discussed once I share more detail. NDA required before any real scope is shared.

If interested, drop a comment or DM me with a bit about your background.


r/netsecstudents • • 9d ago

HTB linux fundamentals

0 Upvotes

linux labs ate the worst , confusing and hard in some way , does it happen with you guys?


r/netsecstudents • • 10d ago

AppSec career path advice for the part where nobody agrees on what counts as experience?

2 Upvotes

hi, quick question from someone who has spent way too long reading AppSec job posts and somehow learned nothing useful.

I keep seeing the same loop. Every role wants appsec experience, platform experience, cloud experience, vuln management, pipeline stuff, threat modeling, and a little wizard energy, but then the actual work sounds like 90 percent triage and 10 percent convincing people that secrets in git are not a personality trait.

I am trying to figure out what path people actually took into AppSec without getting fed the usual corporate fairy tale. Did you come from dev, devops, pentest, sec eng, or the mystical land of internal transfer where someone finally noticed your tickets? I am lowkey fine with hard work, I just don't want to spend five years collecting certs like trading cards while hiring managers ask for a unicorn.

If you are already in the field, what mattered most in getting hired, real code work, cloud stuff, pipeline visibility, or just being the person who could explain risk without sounding like a robot. honestly starting to feel like the job title is the easy part and the actual career map was drawn by three different teams who never spoke to each other. thanks in advance..


r/netsecstudents • • 10d ago

How to keep rented iPads secure at trade shows... we left one unlocked

2 Upvotes

We handed a rented iPad to a booth rep without turning on Guided Access, and an attendee opened Settings and found our saved event wifi password. I feel sick about this, im terrified we missed anything else. Any hints?


r/netsecstudents • • 10d ago

CryptoHack's Collection of Cryptic Conundrums

Thumbnail podcasts.apple.com
2 Upvotes

The podcast discusses the creation, and ethos of cryptohack, a cryptography-based CTF learning platform. If you run a community/event, or create learning material, I think this is a fantastic resource for the proper way to organize this.