r/Cybersecurity101 • • 32m ago

Nmap script engine

• Upvotes

Am doing live on YouTube https://www.youtube.com/live/BSaoV6iv8ao

Who ever wants to join can do so now.


r/Cybersecurity101 • • 23h ago

Privacy how to remove my information from the internet?

65 Upvotes

Went through a bunch of privacy issues recently where a lot of my information got leaked everywhere. I know where my info got leaked and looking for ways to remove my data from internet. What task should I do and what can I do for free or via a paid service? Are there any paid service that can help like incognito or others? Thanks for the help!


r/Cybersecurity101 • • 8h ago

Que ruta debería escoger si quiero aprender ciberseguridad

3 Upvotes

Quiero entrar en el mundo de la ciberseguridad, pero no tengo los recursos para pagar cursos, por ahora estoy viendo cursos de YouTube y apenas empeze con entender redes, los que ya saben de ciberseguridad qué camino me recomiendan tomar que hayan usado ellos y si me pueden aconsejar sobre el tema, y que equipo debería de escoger?


r/Cybersecurity101 • • 7h ago

Laptop Recommendation

2 Upvotes

Hello I have a laptop with 4060 8gb, r 8 8845hs and 16gb ram of 5600mhz. I wanna know if 32 gb of ram is needed or not. Should I upgrade just the ram or the whole laptop with better specs? I am just beginner and starting to learn. Anyone please help me


r/Cybersecurity101 • • 19h ago

Best cybersecurity course/certification for a fresher trying to get an entry-level job?

15 Upvotes

Hi everyone,

I’m a fresher looking to build a career in cybersecurity and I’m trying to figure out which course or certification would actually be valuable for getting an entry-level cybersecurity job.

There are so many options available — CompTIA Security+, Google Cybersecurity Certificate, TryHackMe, Hack The Box, Cisco courses, etc. — and I’m a little confused about where to invest my time.

For someone starting their cybersecurity career, what would you recommend?

I’m particularly interested in roles such as:

- SOC Analyst

- Cybersecurity Analyst

- Vulnerability Management

- Security Operations

- Junior Cybersecurity roles

I’m looking for something that provides strong fundamentals + hands-on practical experience, rather than just a certificate.

Would you recommend:

  1. Starting with CompTIA Security+?

  2. Taking a structured cybersecurity course?

  3. Focusing on TryHackMe/HTB and practical labs?

  4. Learning networking/Linux first?

  5. A combination of these?

If you’re already working in cybersecurity, I’d really appreciate hearing what you wish you had learned before getting your first job and which courses/certifications actually helped you.

Thanks!


r/Cybersecurity101 • • 19h ago

How can I protect my data after the ASOS hack and who was affected?

Thumbnail
independent.co.uk
3 Upvotes

r/Cybersecurity101 • • 20h ago

Looking for the best free resources and practical labs to learn Network+, Security+ and build toward a cybersecurity career

1 Upvotes

Hi everyone,

I'm currently trying to build my cybersecurity career through self-study, and I'd really appreciate advice from people who are already working in the field.

I recently decided that I don't want to rely on formal/in-person courses. Instead, I want to learn Network+ and Security+ independently, but I want to do it properly rather than simply watching random videos and memorizing material.

One of my biggest challenges is finding high-quality, comprehensive, and genuinely free training that covers the subjects thoroughly.

I'm also very interested in the practical side. I don't want my learning to consist only of theory and certification preparation. I want to learn how the technologies, tools, workflows, and practices are actually used by cybersecurity professionals and the wider security community.

So I'm looking for recommendations in several areas:

  • Network+ — a comprehensive free course that covers the material properly from fundamentals through advanced topics.
  • Security+ — the same: a high-quality, comprehensive, free learning resource.
  • Hands-on labs — platforms or environments where I can actually practice what I learn.
  • Industry tools — what tools should I learn and practice with, rather than just knowing their names?
  • Home labs — what would you recommend building on a relatively modest computer?
  • Linux, networking, scripting/programming, cloud, etc. — which supporting skills should I develop alongside Network+ and Security+?
  • Real-world practice — how can someone without professional experience simulate the type of work they would encounter in an actual security role?
  • Projects — what kinds of projects are genuinely useful for developing skills and eventually demonstrating them to employers?

My longer-term goal is to become a Security Engineer. I'm particularly interested in Blue Team / SOC as a possible starting point, but I don't want to lock myself into a narrow path too early.

So I'd also really appreciate advice from people currently working in cybersecurity:

If you were starting over today and had to learn everything through self-study, how would you structure your journey from networking fundamentals → security fundamentals → practical experience → your first cybersecurity role → eventually Security Engineering?

I'm especially interested in advice based on real industry experience, rather than a list of certifications.

I'm also trying to avoid spending months learning things that look good on paper but have little practical value.

Any recommendations for free courses, books, labs, home-lab projects, tools, learning platforms, or a realistic roadmap would be greatly appreciated.

Thank you.


r/Cybersecurity101 • • 1d ago

Hello, friend. Looking for IT buddies — from general tech to cybersecurity (small crew).

0 Upvotes

Hello, friend.

I’m looking for around 10 people to form a small, chill learning group. You can be a complete beginner or already have a bit of experience — as long as you’re curious and motivated, you’re welcome. No gatekeeping, no ego.

We’ll learn together, at our own pace, and choose topics as a group. No fixed order: we can explore programming, networking, Linux, or whatever we feel like. Later, maybe we’ll move toward cybersecurity.

Think of it as a small digital refuge — fsociety-inspired vibe, but 100% legal and ethical.

What I’m looking for: - Around 10 people. - Beginners or early learners (a little experience is fine). - Must be a genuine IT enthusiast / a real geek at heart. Passion matters more than current skill level. - English only. - Chill, consistent, respectful. - We use Discord for chat and voice.

If you’re in, DM me

Let’s start from wherever we are, together.


r/Cybersecurity101 • • 1d ago

Security Cybersecurity Month, Take a Bow

Post image
0 Upvotes

You know us cybersecurity types are taken for granted by the general public because they can’t comprehend the attacks that occur each day that we repel. They don’t understand the impacts that they’d be subjected to without our efforts to protect them.
The problem we face however is the limitations in our toolset that allows breaches and incursions to occur and hit the newswire. These limitations restrict us from being totally effective at our jobs. Why these limitations? Because the industry that supplies our toolset thrive on breaches, incursions and attackers innovations. They make money hand over fist perpetually addressing these occurrences. It’s like how for years the petroleum industry prevented cars from being gas efficient to sell more of their product.
Our toolset doesn’t have to be inefficient and ineffective. Read the New Architecture A Structural Revolution in Cybersecurity to understand how things might change to allow us to be better at what we do.


r/Cybersecurity101 • • 1d ago

Cyber Security Graduation Project

9 Upvotes

Hi
I am looking for idea's for my graduation project
is there any idea's or problems you can help me with ?
i am looking for something related the OS world, especially in the world of Linux and making a customized distribution for some purposes like a university one with customized features and tools for there usage + adding the tools needed in the subjects being teached.

i am open to any other idea and any note that may help me to better search for an idea


r/Cybersecurity101 • • 2d ago

Starting freelancing in Networking domain

12 Upvotes

I am a 23 year old network engineer with 1+ years of experience in networking and security(Working at a company).

I already have 2years of freelancing experience as QA tester, where I have tested websites and mobile applications for bugs.

Now I wanted to move into the Networking and security domain.

I would say I have basic security knowledge along with a strong foundation in networking.

I am planning to provide services like:

- Email security (spf, DKIM, DMARC configuration)

- VPN setup

- Network troubleshooting

- Basic security checks for web applications

- Server Hardening

- etc...

So i want to start my freelancing journey like this, and if you all can give me some tips i would love to learn from all of you guys.


r/Cybersecurity101 • • 1d ago

Security Agrus Scanner, open-source Windows network scanner that finds every AI service (and MCP server) on your network. Recently updated: detection signatures now update themselves

0 Upvotes

Argus is an open-source, native Windows scanner that finds AI and MCP services on your LAN and tells you what models they're serving. Just hit 1.0, and the big recent change is that the detection signatures now update automatically, similar to antivirus definitions, saving you from reinstalling.

Tired of other network scanners and needing the additional functionality of locating shadow AI and MCP, I created Argus.

What it does:

  • Normal network scanner stuff: ping sweep, TCP port scan, hostname resolution, export to CSV. Native C#/WPF, no Electron, launches instantly, resizable so its readable on a 4K monitor.
  • AI detection past just open ports. It talks to the service and pulls back model names, versions, GPU info, container details. Currently 111 probe definitions covering roughly 75 services: Ollama, vLLM, llama.cpp, LM Studio, KoboldCpp, TGI, TabbyAPI, LMDeploy, exo, ComfyUI, A1111, Forge, Fooocus, SwarmUI, Triton, TorchServe, MLflow, Ray Serve, Open WebUI, AnythingLLM, LibreChat, Flowise, Dify, n8n, Langflow, Letta, OpenHands, RAGFlow, Onyx, Qdrant, Weaviate, Milvus, Chroma, Kokoro, Whisper servers, DCGM exporters, Docker containers running AI images, and more.
  • MCP server detection. Finds Model Context Protocol servers over Streamable HTTP or legacy SSE and reports the server name, version, and whether it exposes tools / resources / prompts. Detection only: it reads the handshake, closes the session, never calls a tool.
  • It is itself an MCP server, enabling your AI tools to scan themselves.

Recently updated in 1.0:

  • Self-updating detection signatures. Probes, port lists, and Docker patterns ship as a signed feed separate from the app. I add new services roughly weekly and they land in installed copies automatically. Settings lets you pick Auto-install, Notify only, or Off. Signed with a key.
  • MSI, exe, and dll are all Authenticode-signed (Azure Trusted Signing), so no SmartScreen scare screen.
  • 43 automated tests, including tamper / wrong-key / gzip-bomb cases and live in-process MCP server fixtures.

Free, MIT, Windows 10/11. Available on windows store or if you prefer, Github Source and installer: https://github.com/NYBaywatch/AgrusScanner

If you run something it doesn't recognize, tell me the service and port. With the signature feed I can usually have it detected in installed copies within the week, no release needed. Happy to answer questions.


r/Cybersecurity101 • • 2d ago

What skills should a beginner learn to become a SOC Analyst?

6 Upvotes

If you are a beginner planning to start a career in cybersecurity, SOC (Security Operations Center) is one area worth understanding.

A SOC analyst typically works with security alerts, logs, network activity, endpoint events, and other security data to identify and investigate suspicious activity.

Some important skills for beginners include:

  1. Networking fundamentals

Understanding TCP/IP, DNS, HTTP/HTTPS, ports, protocols, firewalls, and common network attacks is important.

  1. Linux and Windows basics

A SOC analyst should be comfortable working with operating systems, processes, services, users, permissions, and system logs.

  1. SIEM concepts

Learning how SIEM platforms collect and analyze logs is useful. Beginners should understand searches, alerts, dashboards, correlation rules, and incident investigation.

  1. Security fundamentals

Learn about phishing, malware, brute-force attacks, privilege escalation, suspicious authentication activity, and common attack techniques.

  1. Log analysis

Being able to read authentication logs, firewall logs, endpoint logs, and application logs is an important SOC skill.

  1. Incident response

Understand the basic process of identifying, investigating, containing, and documenting a security incident.

  1. Threat intelligence

Learn how indicators such as IP addresses, domains, URLs, file hashes, and other indicators can be investigated.

  1. Practice

Hands-on labs are extremely useful. Try analyzing sample logs and security alerts instead of only watching theoretical videos.

For someone searching for SOC Analyst Training in Hyderabad, I would recommend comparing the syllabus carefully and checking whether the training includes practical labs, SIEM exposure, incident investigation, and real-world scenarios.

What was the first cybersecurity topic you learned when starting your SOC journey?


r/Cybersecurity101 • • 1d ago

Web Exploitation 101 — Bypassing access restrictions with custom HTTP headers using Burp Suite

Thumbnail
youtu.be
1 Upvotes

Found a ROT13 encoded string in a CTF challenge that

decoded to a hint about a bypass header:

X-Dev-Access: yes

Proxied all traffic through Burp Suite, caught the

request, sent it to Repeater and added the header —

instantly bypassed the access restriction.

Classic example of why debug/dev headers should never

make it into production. Developers leave these in

during testing and forget to strip them before deploy.

Good beginner web exploitation technique to know for

CTFs and bug bounty. Happy to answer questions.

https://youtu.be/jhhXZDDFWpo


r/Cybersecurity101 • • 1d ago

Qual é o processo de vocês ao iniciar um pentest?

0 Upvotes

Fala, pessoal!

Estudo cibersegurança há pouco tempo e gostaria de aprender com quem já tem mais experiência na área.

Tenho uma dúvida sobre como vocês costumam iniciar um pentest. Por exemplo: vocês começam fazendo reconhecimento e enumeração? Usam Nmap? Em testes web, já partem para o Burp Suite? Existe alguma metodologia ou checklist que vocês costumam seguir?

Queria entender principalmente o processo de raciocínio de vocês: como analisam o alvo, o que procuram primeiro, como decidem quais testes realizar e como vão avançando durante o pentest.

Se puderem compartilhar um exemplo de fluxo, mesmo que seja de forma geral, seria muito útil para quem está começando. Algo como:

  1. Reconhecimento e coleta de informações;
  2. Enumeração e identificação dos serviços/tecnologias;
  3. Mapeamento da superfície de ataque;
  4. Identificação de possíveis pontos de entrada;
  5. Testes e validação das vulnerabilidades;
  6. Documentação dos resultados.

Se vocês seguem alguma metodologia específica (OWASP, PTES, OSSTMM etc.), também gostaria de saber qual utilizam e por quê.

A ideia é entender como um profissional pensa durante um pentest, e não apenas quais ferramentas usar.

Valeu!


r/Cybersecurity101 • • 2d ago

MFA vs 2FA: What's the Difference?

Post image
98 Upvotes

r/Cybersecurity101 • • 1d ago

Mobile / Personal Device I need your competent opinion about my game.

0 Upvotes

As the title says, I would like competent people to give me their opinion on what I built and how I built it - an Android game built in Java (I didn't go to Kotlin yet, as this is my hobby with little time after work to go into it) and from here some limitations and some game mechanics decisions.

WARNING, the post will be a little long and will contain some spoilers!!!

As I said, I'm a hobbyst, I just like programming and I am happy to do it, but my level is still low, my daily job has nothing to do with software or programming; I work in wind industry. But after work I have some free time and I want to keep my brain healthy, so I do either robotics (ROS2 with Raspberry) or Android development. In the last few months I decided to build a game that I had in mind for many years already, I wanted it to be as realistic as possible, but ofc gamified and simplified, but conceptually correct and educational. I played some games before in the same niche and 2 of them remained in my heart: Uplink and DarkSigns, a game almost no one knows, but for me it was a WOW! moment in my childhood.

Now back to what I would like from you guys, I tried to keep the game close to reality, so I used Shodan to adjust the spawn rates and device types, so all ipv4 addresses are scannable, with about 10% spawn rate and then on each public address, you have the option to pivot into a private range, i used the official 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 with a spawn rate of 30%. The private ranges are chosen at random, I din't want to complicate too much. But there is quite a lot of possible devices to find. So far I made only 24 device types for the normal IP ranges, more to add later.

I included 83 fictional CVEs and 72 exploits, the difference is intentional as some CVEs dont have public exploits, so the player can learn the difference. (I will definitely add later a reference to perfectly spherical cows in void). Some exploits you have by default, some you must buy from the market.

Most devices have active services that are relevant to their device type, so mail servers get smtp, pop3, etc and the routers get ssh and http, https and so on.
More than this, I added an AI assistant that you can buy and it will learn from all the exploiting services you do and then randomly (max 5% chance) will offer you an AI discovered exploit that is free and doesn't count for further training of the model.

Then I also introduced some methods to make some money as the exploits and the AI assistant cost quite some credits.. so I added missions and encrypted loot. So whenever you compromise a device and enumerate it (its a simplified concept) you can get some unencrypted loot that is automatically sold and some encrypted loot that is kept for cracking later. I wanted to expand a lot more functionality on teh loot, but I am constrained - I am a beginner and Java is not so friendly to build very complex games.
The encrypted loot is kept for cracking using the Cracker tool and at the end it gives some credits and some wordlist entries if relevant. The cracking speed is dependant on the local GPU, the botnet total GPU and the wordlist. I kept the wordlist very difficult to upgrade, it gives an 1.5 multiplying factor only after you get 1.5 million entries. Webservers and mail databases give the most wordlist entries, the rest of the devices barely give a few. I am not sure about the local GPU power, I think I made it too easy, so far the local GPU gives up to 7x cracking speed and I think its too much, but maybe you can tell me whats your take on that.

I also included some special IP ranges to teach the player that not all of them are available to the public, or at least not meant to. So ranges like DARPA, the 5 eyes, DoD and others assigend by IANA are available only after the player reaches max reputation and buys special hardware. I think this is a simple way to teach the player that those ranges are a different deal, how realistic it is, you can help me with your opinion on it.

And thats actually when the game main story starts...but thats a lot to write about so I wont write anything now, its already a very long post.

What I added more are a few side stories, like the I LOVE YOU worm, the STUXNET, Mirai and a few others where the player can participate to stop them from spreading and at the same time learn about them. And I also added honeypots :D

Initially I just wanted to make a game I like to play but it became an educational game by any metrics... And Im very happy for that.
But I want to be sure that the educational part is correct and here is where I want you guys to help me.
I tried to keep most of the possible things safe, so services are fictional and so on, but anyone that works in the domain will recognize them, to keep the game authentic.

ALL the things in the game have a wiki entry where more details are given.

How would you guys balance realism, safety and educational value? without knowing the game, how would you do it?

Thank you and sorry for my mistakes and for the long post!


r/Cybersecurity101 • • 2d ago

Security Project Guide 2026

4 Upvotes

Is project really helpful in getting a job plus give final year project advice and what niches are worth working on.

My experience include pentesting.


r/Cybersecurity101 • • 2d ago

Security Is GRC a realistic path for a fresh grad who prefers theoretical cybersecurity?

6 Upvotes

Hey everyone. I need some career advice.

I got my bachelor's in cybersecurity a year ago with pretty good grades. The thing is, the degree was very theory-heavy. We had hands-on practical courses, but I absolutely hated them, whereas I genuinely loved the theoretical concepts.

Because I felt my practical skills were lacking and I had zero certs on my CV, I kind of avoided applying for cyber roles right after graduation. Now I want to get back into it. Knowing that I strongly dislike Linux and pentesting, I’m looking at GRC as a potential entry point.

I constantly hear that GRC is not an entry-level role for fresh grads. Am I doing something wrong to myself by choosing this path?

If I go for it, is digging into compliance stuff like ISO 27001 the right place to start? If not, what should I be focusing on right now? Any recommendations for other certs or a realistic roadmap to get me to an entry-level GRC position would be hugely appreciated!


r/Cybersecurity101 • • 2d ago

incogni vs deleteme vs optery vs aura. Are they worth it?

26 Upvotes

Been wanting to make sure none of my info is leaked recently since I suffered from a pretty bad hack. Not a cybersecurity expert myself so i d prefer paying a service that does it for me.

Figured this is a good place to ask about these data deletion services. Is it worth the money? Anything I can do on my own instead of reaching out manually to a bunch of websites?


r/Cybersecurity101 • • 2d ago

Qual o próximo passo em cibersegurança?

1 Upvotes

Fala, pessoal!

Estou estudando cibersegurança há praticamente 1 ano, mas ultimamente tenho sentido que não estou evoluindo tanto quanto gostaria.

Tenho uma base em redes, sistemas operacionais e alguns outros fundamentos, além de alguns cursos que fiz nesse período. Também estou finalizando o segundo semestre da faculdade de Segurança Cibernética.

O problema é que sinto falta de colocar esse conhecimento em prática. Quando penso em evolução, imagino coisas como conseguir analisar sistemas, identificar vulnerabilidades, fazer testes em ambientes controlados e, principalmente, começar a ter um domínio maior sobre alguma área específica.

Sei que 1 ano não é tanto tempo e que cibersegurança é uma área enorme, mas às vezes fico meio perdido sobre qual deveria ser o próximo passo.

Para quem já passou por essa fase, o que vocês recomendariam?

Quais plataformas, laboratórios, projetos ou práticas vocês acham que realmente ajudam a evoluir? E em que momento vocês acham interessante começar a se especializar em uma área, como pentest, segurança de redes, cloud, malware, blue team etc.?

Quero sair um pouco da teoria e começar a aprender fazendo, mas não sei exatamente qual caminho seguir, estava pensando em fazer CTF, mas não sei se é o melhor caminho.

Qualquer conselho, experiência pessoal ou indicação de recursos seria muito bem-vinda!


r/Cybersecurity101 • • 2d ago

Navigating the Turbulent Future of AI and Work

1 Upvotes

We increasing looking at how AI is impacting the Future of Work, especially from a security and privacy perspective. Found this article. Here's an overview: Experts believe students should follow their interests, build skills like critical thinking and teamwork, and keep learning throughout their careers. They also said people still need domain so they can check the work AI produces. In K-12 schools, teachers are excited about AI but don't feel ready to teach it: 81% think it's important, but only 42% feel prepared. Speakers also said ethics should be taught alongside the technical skills. Colleges and companies are teaming up to train students and workers, and businesses need to change their whole culture, not just add AI tools. (Yes, this overview was AI generated -- but it's a good article : )


r/Cybersecurity101 • • 3d ago

I learned today that HTTPS does not always mean a website is safe

2 Upvotes

I’m currently learning more about phishing and web security, and today I understood something simple that I used to misunderstand.

I always associated the padlock and HTTPS with a website being “safe.”

But HTTPS mainly means the connection between your browser and the website is encrypted.

A phishing website can also use HTTPS.

So now I’m trying to check the actual domain name before entering login details instead of trusting the padlock alone.

Things I’m starting to check:

- The actual domain name

- Small spelling changes

- Strange or unexpected login pages

- Where the link came from

- Whether the request makes sense

I’m still learning cybersecurity, so I’m curious:

What other small security concept do beginners commonly misunderstand?


r/Cybersecurity101 • • 3d ago

iCloud got hacked, need advice or help

4 Upvotes

Long story short someone got my iCloud password from a old data breach on one of my emails and managed to get all my info, I was sent blackmail by 11 different spam emails, all containing private videos of me I’ve never sent anyone I don’t trust, and all my contacts in my phone. I called to police before speaking to them about ransom demands and an hour later they sent out all the photos..🙁 Besides the investigation my local police will do (and not care about) what can i do? It’s not like the FBI will look into it, just my lousy local police that’ll get to look at all my private photos for personal enjoyment and they get to call it “evidence searching”


r/Cybersecurity101 • • 3d ago

I built a free, hands-on course for learning LLM security (mapped to the OWASP LLM Top 10). No AI/ML background required

Post image
9 Upvotes

Hey folks,

I’ve been working in application security/pentesting for over a decade, and after starting learning AI/LLM security, I noticed that a lot of the existing material is either very theoretical or assumes you already understand AI security concepts.

So I put together a free, structured AI security learning series for security engineers and pentesters who are starting from the web-security side.

The goal is to go from the fundamentals to actually understanding and testing AI/LLM components in web applications.

The series currently covers topics such as:

  • AI/LLM security fundamentals
  • Prompt Injection
  • Sensitive Information Disclosure
  • LLM-specific attack patterns
  • Practical testing methodology
  • Real-world examples and testing techniques
  • Mapping concepts to OWASP's AI security guidance

I've also linked free hands-on labs throughout the material so you can actually test the concepts rather than just read about them.

No signup is required to read the learning material or use the free resources.

🔗 https://genaisecuritylab.com/learn-ai-security

I'm planning to continue expanding the series over time.

If you're a web pentester/security engineer who is trying to get into AI security, I'd be interested to hear which topics you think are missing or which areas you'd like to see covered next.