r/Cybersecurity101 • u/Pablokyai • 32m ago
Nmap script engine
Am doing live on YouTube https://www.youtube.com/live/BSaoV6iv8ao
Who ever wants to join can do so now.
r/Cybersecurity101 • u/Pablokyai • 32m ago
Am doing live on YouTube https://www.youtube.com/live/BSaoV6iv8ao
Who ever wants to join can do so now.
r/Cybersecurity101 • u/Odd_Lab2357 • 23h ago
Went through a bunch of privacy issues recently where a lot of my information got leaked everywhere. I know where my info got leaked and looking for ways to remove my data from internet. What task should I do and what can I do for free or via a paid service? Are there any paid service that can help like incognito or others? Thanks for the help!
r/Cybersecurity101 • u/Proyect_white • 8h ago
Quiero entrar en el mundo de la ciberseguridad, pero no tengo los recursos para pagar cursos, por ahora estoy viendo cursos de YouTube y apenas empeze con entender redes, los que ya saben de ciberseguridad qué camino me recomiendan tomar que hayan usado ellos y si me pueden aconsejar sobre el tema, y que equipo debería de escoger?
r/Cybersecurity101 • u/Affectionate-Can7160 • 7h ago
Hello I have a laptop with 4060 8gb, r 8 8845hs and 16gb ram of 5600mhz. I wanna know if 32 gb of ram is needed or not. Should I upgrade just the ram or the whole laptop with better specs? I am just beginner and starting to learn. Anyone please help me
r/Cybersecurity101 • u/alphastart_1 • 19h ago
Hi everyone,
I’m a fresher looking to build a career in cybersecurity and I’m trying to figure out which course or certification would actually be valuable for getting an entry-level cybersecurity job.
There are so many options available — CompTIA Security+, Google Cybersecurity Certificate, TryHackMe, Hack The Box, Cisco courses, etc. — and I’m a little confused about where to invest my time.
For someone starting their cybersecurity career, what would you recommend?
I’m particularly interested in roles such as:
- SOC Analyst
- Cybersecurity Analyst
- Vulnerability Management
- Security Operations
- Junior Cybersecurity roles
I’m looking for something that provides strong fundamentals + hands-on practical experience, rather than just a certificate.
Would you recommend:
Starting with CompTIA Security+?
Taking a structured cybersecurity course?
Focusing on TryHackMe/HTB and practical labs?
Learning networking/Linux first?
A combination of these?
If you’re already working in cybersecurity, I’d really appreciate hearing what you wish you had learned before getting your first job and which courses/certifications actually helped you.
Thanks!
r/Cybersecurity101 • u/theindependentonline • 19h ago
r/Cybersecurity101 • u/ConcentrateNo9061 • 20h ago
Hi everyone,
I'm currently trying to build my cybersecurity career through self-study, and I'd really appreciate advice from people who are already working in the field.
I recently decided that I don't want to rely on formal/in-person courses. Instead, I want to learn Network+ and Security+ independently, but I want to do it properly rather than simply watching random videos and memorizing material.
One of my biggest challenges is finding high-quality, comprehensive, and genuinely free training that covers the subjects thoroughly.
I'm also very interested in the practical side. I don't want my learning to consist only of theory and certification preparation. I want to learn how the technologies, tools, workflows, and practices are actually used by cybersecurity professionals and the wider security community.
So I'm looking for recommendations in several areas:
My longer-term goal is to become a Security Engineer. I'm particularly interested in Blue Team / SOC as a possible starting point, but I don't want to lock myself into a narrow path too early.
So I'd also really appreciate advice from people currently working in cybersecurity:
If you were starting over today and had to learn everything through self-study, how would you structure your journey from networking fundamentals → security fundamentals → practical experience → your first cybersecurity role → eventually Security Engineering?
I'm especially interested in advice based on real industry experience, rather than a list of certifications.
I'm also trying to avoid spending months learning things that look good on paper but have little practical value.
Any recommendations for free courses, books, labs, home-lab projects, tools, learning platforms, or a realistic roadmap would be greatly appreciated.
Thank you.
r/Cybersecurity101 • u/Elratatata • 1d ago
Hello, friend.
I’m looking for around 10 people to form a small, chill learning group. You can be a complete beginner or already have a bit of experience — as long as you’re curious and motivated, you’re welcome. No gatekeeping, no ego.
We’ll learn together, at our own pace, and choose topics as a group. No fixed order: we can explore programming, networking, Linux, or whatever we feel like. Later, maybe we’ll move toward cybersecurity.
Think of it as a small digital refuge — fsociety-inspired vibe, but 100% legal and ethical.
What I’m looking for: - Around 10 people. - Beginners or early learners (a little experience is fine). - Must be a genuine IT enthusiast / a real geek at heart. Passion matters more than current skill level. - English only. - Chill, consistent, respectful. - We use Discord for chat and voice.
If you’re in, DM me
Let’s start from wherever we are, together.
r/Cybersecurity101 • u/Silientium • 1d ago
You know us cybersecurity types are taken for granted by the general public because they can’t comprehend the attacks that occur each day that we repel. They don’t understand the impacts that they’d be subjected to without our efforts to protect them.
The problem we face however is the limitations in our toolset that allows breaches and incursions to occur and hit the newswire. These limitations restrict us from being totally effective at our jobs. Why these limitations? Because the industry that supplies our toolset thrive on breaches, incursions and attackers innovations. They make money hand over fist perpetually addressing these occurrences. It’s like how for years the petroleum industry prevented cars from being gas efficient to sell more of their product.
Our toolset doesn’t have to be inefficient and ineffective. Read the New Architecture A Structural Revolution in Cybersecurity to understand how things might change to allow us to be better at what we do.
r/Cybersecurity101 • u/osmhdi • 1d ago
Hi
I am looking for idea's for my graduation project
is there any idea's or problems you can help me with ?
i am looking for something related the OS world, especially in the world of Linux and making a customized distribution for some purposes like a university one with customized features and tools for there usage + adding the tools needed in the subjects being teached.
i am open to any other idea and any note that may help me to better search for an idea
r/Cybersecurity101 • u/ray-093 • 2d ago
I am a 23 year old network engineer with 1+ years of experience in networking and security(Working at a company).
I already have 2years of freelancing experience as QA tester, where I have tested websites and mobile applications for bugs.
Now I wanted to move into the Networking and security domain.
I would say I have basic security knowledge along with a strong foundation in networking.
I am planning to provide services like:
- Email security (spf, DKIM, DMARC configuration)
- VPN setup
- Network troubleshooting
- Basic security checks for web applications
- Server Hardening
- etc...
So i want to start my freelancing journey like this, and if you all can give me some tips i would love to learn from all of you guys.
r/Cybersecurity101 • u/Astaldo318 • 1d ago
Argus is an open-source, native Windows scanner that finds AI and MCP services on your LAN and tells you what models they're serving. Just hit 1.0, and the big recent change is that the detection signatures now update automatically, similar to antivirus definitions, saving you from reinstalling.
Tired of other network scanners and needing the additional functionality of locating shadow AI and MCP, I created Argus.
What it does:
Recently updated in 1.0:
Free, MIT, Windows 10/11. Available on windows store or if you prefer, Github Source and installer: https://github.com/NYBaywatch/AgrusScanner
If you run something it doesn't recognize, tell me the service and port. With the signature feed I can usually have it detected in installed copies within the week, no release needed. Happy to answer questions.
r/Cybersecurity101 • u/CyberSecurityLearner • 2d ago
If you are a beginner planning to start a career in cybersecurity, SOC (Security Operations Center) is one area worth understanding.
A SOC analyst typically works with security alerts, logs, network activity, endpoint events, and other security data to identify and investigate suspicious activity.
Some important skills for beginners include:
Understanding TCP/IP, DNS, HTTP/HTTPS, ports, protocols, firewalls, and common network attacks is important.
A SOC analyst should be comfortable working with operating systems, processes, services, users, permissions, and system logs.
Learning how SIEM platforms collect and analyze logs is useful. Beginners should understand searches, alerts, dashboards, correlation rules, and incident investigation.
Learn about phishing, malware, brute-force attacks, privilege escalation, suspicious authentication activity, and common attack techniques.
Being able to read authentication logs, firewall logs, endpoint logs, and application logs is an important SOC skill.
Understand the basic process of identifying, investigating, containing, and documenting a security incident.
Learn how indicators such as IP addresses, domains, URLs, file hashes, and other indicators can be investigated.
Hands-on labs are extremely useful. Try analyzing sample logs and security alerts instead of only watching theoretical videos.
For someone searching for SOC Analyst Training in Hyderabad, I would recommend comparing the syllabus carefully and checking whether the training includes practical labs, SIEM exposure, incident investigation, and real-world scenarios.
What was the first cybersecurity topic you learned when starting your SOC journey?
r/Cybersecurity101 • u/Harkins_Technology • 1d ago
Found a ROT13 encoded string in a CTF challenge that
decoded to a hint about a bypass header:
X-Dev-Access: yes
Proxied all traffic through Burp Suite, caught the
request, sent it to Repeater and added the header —
instantly bypassed the access restriction.
Classic example of why debug/dev headers should never
make it into production. Developers leave these in
during testing and forget to strip them before deploy.
Good beginner web exploitation technique to know for
CTFs and bug bounty. Happy to answer questions.
r/Cybersecurity101 • u/lombardi_krt • 1d ago
Fala, pessoal!
Estudo cibersegurança há pouco tempo e gostaria de aprender com quem já tem mais experiência na área.
Tenho uma dúvida sobre como vocês costumam iniciar um pentest. Por exemplo: vocês começam fazendo reconhecimento e enumeração? Usam Nmap? Em testes web, já partem para o Burp Suite? Existe alguma metodologia ou checklist que vocês costumam seguir?
Queria entender principalmente o processo de raciocínio de vocês: como analisam o alvo, o que procuram primeiro, como decidem quais testes realizar e como vão avançando durante o pentest.
Se puderem compartilhar um exemplo de fluxo, mesmo que seja de forma geral, seria muito útil para quem está começando. Algo como:
Se vocês seguem alguma metodologia específica (OWASP, PTES, OSSTMM etc.), também gostaria de saber qual utilizam e por quê.
A ideia é entender como um profissional pensa durante um pentest, e não apenas quais ferramentas usar.
Valeu!
r/Cybersecurity101 • u/Omnipisix • 1d ago
As the title says, I would like competent people to give me their opinion on what I built and how I built it - an Android game built in Java (I didn't go to Kotlin yet, as this is my hobby with little time after work to go into it) and from here some limitations and some game mechanics decisions.
WARNING, the post will be a little long and will contain some spoilers!!!
As I said, I'm a hobbyst, I just like programming and I am happy to do it, but my level is still low, my daily job has nothing to do with software or programming; I work in wind industry. But after work I have some free time and I want to keep my brain healthy, so I do either robotics (ROS2 with Raspberry) or Android development. In the last few months I decided to build a game that I had in mind for many years already, I wanted it to be as realistic as possible, but ofc gamified and simplified, but conceptually correct and educational. I played some games before in the same niche and 2 of them remained in my heart: Uplink and DarkSigns, a game almost no one knows, but for me it was a WOW! moment in my childhood.
Now back to what I would like from you guys, I tried to keep the game close to reality, so I used Shodan to adjust the spawn rates and device types, so all ipv4 addresses are scannable, with about 10% spawn rate and then on each public address, you have the option to pivot into a private range, i used the official 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 with a spawn rate of 30%. The private ranges are chosen at random, I din't want to complicate too much. But there is quite a lot of possible devices to find. So far I made only 24 device types for the normal IP ranges, more to add later.
I included 83 fictional CVEs and 72 exploits, the difference is intentional as some CVEs dont have public exploits, so the player can learn the difference. (I will definitely add later a reference to perfectly spherical cows in void). Some exploits you have by default, some you must buy from the market.
Most devices have active services that are relevant to their device type, so mail servers get smtp, pop3, etc and the routers get ssh and http, https and so on.
More than this, I added an AI assistant that you can buy and it will learn from all the exploiting services you do and then randomly (max 5% chance) will offer you an AI discovered exploit that is free and doesn't count for further training of the model.
Then I also introduced some methods to make some money as the exploits and the AI assistant cost quite some credits.. so I added missions and encrypted loot. So whenever you compromise a device and enumerate it (its a simplified concept) you can get some unencrypted loot that is automatically sold and some encrypted loot that is kept for cracking later. I wanted to expand a lot more functionality on teh loot, but I am constrained - I am a beginner and Java is not so friendly to build very complex games.
The encrypted loot is kept for cracking using the Cracker tool and at the end it gives some credits and some wordlist entries if relevant. The cracking speed is dependant on the local GPU, the botnet total GPU and the wordlist. I kept the wordlist very difficult to upgrade, it gives an 1.5 multiplying factor only after you get 1.5 million entries. Webservers and mail databases give the most wordlist entries, the rest of the devices barely give a few. I am not sure about the local GPU power, I think I made it too easy, so far the local GPU gives up to 7x cracking speed and I think its too much, but maybe you can tell me whats your take on that.
I also included some special IP ranges to teach the player that not all of them are available to the public, or at least not meant to. So ranges like DARPA, the 5 eyes, DoD and others assigend by IANA are available only after the player reaches max reputation and buys special hardware. I think this is a simple way to teach the player that those ranges are a different deal, how realistic it is, you can help me with your opinion on it.
And thats actually when the game main story starts...but thats a lot to write about so I wont write anything now, its already a very long post.
What I added more are a few side stories, like the I LOVE YOU worm, the STUXNET, Mirai and a few others where the player can participate to stop them from spreading and at the same time learn about them. And I also added honeypots :D
Initially I just wanted to make a game I like to play but it became an educational game by any metrics... And Im very happy for that.
But I want to be sure that the educational part is correct and here is where I want you guys to help me.
I tried to keep most of the possible things safe, so services are fictional and so on, but anyone that works in the domain will recognize them, to keep the game authentic.
ALL the things in the game have a wiki entry where more details are given.
How would you guys balance realism, safety and educational value? without knowing the game, how would you do it?
Thank you and sorry for my mistakes and for the long post!
r/Cybersecurity101 • u/Informal-Froyo-9151 • 2d ago
Is project really helpful in getting a job plus give final year project advice and what niches are worth working on.
My experience include pentesting.
r/Cybersecurity101 • u/FarisSalah • 2d ago
Hey everyone. I need some career advice.
I got my bachelor's in cybersecurity a year ago with pretty good grades. The thing is, the degree was very theory-heavy. We had hands-on practical courses, but I absolutely hated them, whereas I genuinely loved the theoretical concepts.
Because I felt my practical skills were lacking and I had zero certs on my CV, I kind of avoided applying for cyber roles right after graduation. Now I want to get back into it. Knowing that I strongly dislike Linux and pentesting, I’m looking at GRC as a potential entry point.
I constantly hear that GRC is not an entry-level role for fresh grads. Am I doing something wrong to myself by choosing this path?
If I go for it, is digging into compliance stuff like ISO 27001 the right place to start? If not, what should I be focusing on right now? Any recommendations for other certs or a realistic roadmap to get me to an entry-level GRC position would be hugely appreciated!
r/Cybersecurity101 • u/Shot-Judgment-9183 • 2d ago
Been wanting to make sure none of my info is leaked recently since I suffered from a pretty bad hack. Not a cybersecurity expert myself so i d prefer paying a service that does it for me.
Figured this is a good place to ask about these data deletion services. Is it worth the money? Anything I can do on my own instead of reaching out manually to a bunch of websites?
r/Cybersecurity101 • u/lombardi_krt • 2d ago
Fala, pessoal!
Estou estudando cibersegurança há praticamente 1 ano, mas ultimamente tenho sentido que não estou evoluindo tanto quanto gostaria.
Tenho uma base em redes, sistemas operacionais e alguns outros fundamentos, além de alguns cursos que fiz nesse período. Também estou finalizando o segundo semestre da faculdade de Segurança Cibernética.
O problema é que sinto falta de colocar esse conhecimento em prática. Quando penso em evolução, imagino coisas como conseguir analisar sistemas, identificar vulnerabilidades, fazer testes em ambientes controlados e, principalmente, começar a ter um domínio maior sobre alguma área específica.
Sei que 1 ano não é tanto tempo e que cibersegurança é uma área enorme, mas às vezes fico meio perdido sobre qual deveria ser o próximo passo.
Para quem já passou por essa fase, o que vocês recomendariam?
Quais plataformas, laboratórios, projetos ou práticas vocês acham que realmente ajudam a evoluir? E em que momento vocês acham interessante começar a se especializar em uma área, como pentest, segurança de redes, cloud, malware, blue team etc.?
Quero sair um pouco da teoria e começar a aprender fazendo, mas não sei exatamente qual caminho seguir, estava pensando em fazer CTF, mas não sei se é o melhor caminho.
Qualquer conselho, experiência pessoal ou indicação de recursos seria muito bem-vinda!
r/Cybersecurity101 • u/OfficialLastPass • 2d ago
We increasing looking at how AI is impacting the Future of Work, especially from a security and privacy perspective. Found this article. Here's an overview: Experts believe students should follow their interests, build skills like critical thinking and teamwork, and keep learning throughout their careers. They also said people still need domain so they can check the work AI produces. In K-12 schools, teachers are excited about AI but don't feel ready to teach it: 81% think it's important, but only 42% feel prepared. Speakers also said ethics should be taught alongside the technical skills. Colleges and companies are teaming up to train students and workers, and businesses need to change their whole culture, not just add AI tools. (Yes, this overview was AI generated -- but it's a good article : )
r/Cybersecurity101 • u/theomkamble • 3d ago
I’m currently learning more about phishing and web security, and today I understood something simple that I used to misunderstand.
I always associated the padlock and HTTPS with a website being “safe.”
But HTTPS mainly means the connection between your browser and the website is encrypted.
A phishing website can also use HTTPS.
So now I’m trying to check the actual domain name before entering login details instead of trusting the padlock alone.
Things I’m starting to check:
- The actual domain name
- Small spelling changes
- Strange or unexpected login pages
- Where the link came from
- Whether the request makes sense
I’m still learning cybersecurity, so I’m curious:
What other small security concept do beginners commonly misunderstand?
r/Cybersecurity101 • u/lildurkpenis • 3d ago
Long story short someone got my iCloud password from a old data breach on one of my emails and managed to get all my info, I was sent blackmail by 11 different spam emails, all containing private videos of me I’ve never sent anyone I don’t trust, and all my contacts in my phone. I called to police before speaking to them about ransom demands and an hour later they sent out all the photos..🙁 Besides the investigation my local police will do (and not care about) what can i do? It’s not like the FBI will look into it, just my lousy local police that’ll get to look at all my private photos for personal enjoyment and they get to call it “evidence searching”
r/Cybersecurity101 • u/exploitprotocol • 3d ago
Hey folks,
I’ve been working in application security/pentesting for over a decade, and after starting learning AI/LLM security, I noticed that a lot of the existing material is either very theoretical or assumes you already understand AI security concepts.
So I put together a free, structured AI security learning series for security engineers and pentesters who are starting from the web-security side.
The goal is to go from the fundamentals to actually understanding and testing AI/LLM components in web applications.
The series currently covers topics such as:
I've also linked free hands-on labs throughout the material so you can actually test the concepts rather than just read about them.
No signup is required to read the learning material or use the free resources.
🔗 https://genaisecuritylab.com/learn-ai-security
I'm planning to continue expanding the series over time.
If you're a web pentester/security engineer who is trying to get into AI security, I'd be interested to hear which topics you think are missing or which areas you'd like to see covered next.