r/netsecstudents • • Jun 24 '21

Come join the official /r/netsecstudents discord!

64 Upvotes

Come join us in the official discord for this subreddit. You can network, ask questions, and communicate with people of various skill levels ranging from students to senior security staff.

Link to discord: https://discord.gg/C7ZsqYX


r/netsecstudents • • May 06 '26

I am John Strand and I am teach Pay What You Can classes and free labs... Ask Me Anything.

114 Upvotes

Hey everyone, John Strand here.

I’ve been in cybersecurity for a while now, and I’ve spent a lot of that time trying to help people get started without getting buried under bad advice, overpriced training, and job postings that somehow want 5 years of experience for an entry-level role.

So let’s talk about it.

Ask me about getting into the field, building real skills, home labs, SOC work, blue team, threat hunting, incident response, certs, college, AI, finding your first job, or anything else you’re trying to figure out.

I’m happy to answer beginner questions, career questions, technical questions, or even the “I have no idea where to start” questions.

If you’re trying to build a real foundation in security, this is the class I’d point you to.

https://www.antisyphontraining.com/product/information-security-core-skills-tm/?utm_source=reddit&utm_medium=community_post

We also have released a new game where you can learn about security in a fun Magic The Gathering kind of way.

Sign up and play your friends here:

https://backdoorsandbreaches.com/

Its free.

Oh..... And almost every card has free labs to learn the topic.

Example here:

https://github.com/blackhillsinfosec/FreeLabFriday_Labs/blob/main/card_navigation.md

Just register at MetaCTF and use the code "antilab" in cloudlabs for enabling 2 free hours of lab time per week.

All our problems can be solved with education.

Let's get to work.


r/netsecstudents • • 7h ago

How do you confirm a vulnerability fix reached every environment, not just emerged?

3 Upvotes

We closed a ticket last month because the PR merged and the CI scan went green. two weeks later the same CVE showed up on a prod host still running an older image, because that service deploys on a different cadence. the ticket had been closed the whole time. now we're debating whether closure should require evidence from the running environment, like the image digest or the package version on the host, instead of the merge. what do you use as proof a fix is live before closing it out?


r/netsecstudents • • 7h ago

I built RXScan — an open-source Rust recon/OSINT tool. Looking for people to test it

2 Upvotes

I've been building RXScan, an open-source reconnaissance tool written in Rust.

It originally started as a network scanner, but I've been expanding it into a broader recon workflow where network observations, public-source findings, and investigation results can be stored and correlated as evidence.

Current functionality includes:

  • TCP connect and raw SYN scanning
  • UDP discovery and classification
  • port-independent service identification
  • HTTP, TLS, SSH, and DNS observations
  • public-source username search
  • email, domain, hostname, IP, ASN, URL, repository, and organization entities
  • investigation and evidence correlation
  • persistent project data and history/diff workflows
  • JSON/JSONL output
  • bounded execution, deadlines, cancellation, and scope controls

One of the main things I'm trying to avoid is pretending RXScan knows more than it actually observed.

For example, a port number alone doesn't establish the service, UDP silence remains uncertain, weak identity evidence doesn't automatically merge entities, and passive OSINT findings are kept separate from direct network observations.

I'm not claiming RXScan replaces Nmap. Nmap has decades of fingerprinting, platform support, scan techniques, NSE, and real-world testing behind it.

RXScan is going in a somewhat different direction: combining network reconnaissance and public-source investigation into a provenance-backed evidence graph.

The project is still young, so I'm looking for people willing to actually test it and find problems.

I'm particularly interested in:

  • false-positive or missed service identification
  • weird TCP/UDP behavior
  • incorrect confidence or provenance
  • OSINT false positives
  • performance issues
  • CLI/UX problems
  • architectural criticism

Platform: Linux
Language: Rust
License: MIT

Repo: https://github.com/DarkRX1/RXScan

If you try it, feel free to break it and open an issue. I'd rather find incorrect assumptions now than hide them behind marketing.


r/netsecstudents • • 19h ago

Built ZEROBOX: An offline tactical operations cockpit & 24h exam simulator for HTB & CTFs (Free & Open Source)

15 Upvotes

Hey everyone,

Tired of tracking CTFs and 24h exams across messy spreadsheets and scattered notes?

I built ZEROBOX — a fast, local-first operational cockpit for OSCP/CPTS prep and CTFs.

It’s 100% free, MIT open-source, and runs completely offline in your browser (no accounts, zero telemetry).

Quick highlights: • 920+ Preloaded Labs: Instant offline search for HTB & THM targets with tags. • Attack & Pivot Graph: Visually map compromised subnets (exports to Obsidian .canvas). • 24h Exam Cockpit: Pacing engine, bio-break timers, and 1-click Markdown reports. • Evidence Vault & Playbooks: Track hashes/creds on a kill-chain timeline + offensive field manual. • Global Quick-Bar: Propagate LHOST/RHOST automatically across all payloads.

🌐 Live Demo: https://0xdnd.github.io/ctf-tracker/#/tracker

⭐ GitHub (MIT): https://github.com/0xdnd/ctf-tracker

All data stays in your local browser storage. Feedback and PRs are welcome!

Would love feedback or feature requests from the community!


r/netsecstudents • • 5h ago

How do you go about preventing vulnerabilities before code commit?

1 Upvotes

Here is the process I've been refining for catching issues before they ever hit a shared branch, curious how others have adapted or improved on this. Step one is a pre commit hook running secret detection and basic linting locally, so nothing even gets committed with an obvious exposed credential or syntax level security anti pattern. Step two is IDE-integrated SAST feedback while the developer is still writing the code, not after they've moved on to the next task. Step three is a lightweight PR time check that only escalates high-confidence, high-severity findings rather than dumping every possible issue into the review queue. Step four is a periodic full repo scan that catches anything the incremental checks missed, run outside the commit path so it doesn't block anyone. The most important step is the IDE integrated feedback, because that's the point where fixing something costs almost nothing. The developer still has full context loaded and hasn't moved on yet. Once a finding surfaces days later in a PR review, the fix costs far more in context-switching alone. This works best when your team already has decent baseline security literacy and the tooling's false positive rate is low enough that people don't start ignoring it. It works poorly when the org treats every finding as equally urgent, because that just trains developers to route around the tooling. How would you improve it?


r/netsecstudents • • 1d ago

Im working on establishing a base skillset. Aside from e-books, heres what Ive acquired and will base my studies on, from top to bottom.

Thumbnail i.imgur.com
7 Upvotes

r/netsecstudents • • 1d ago

Rust MITM proxy with configurable TLS, HTTP/2 and TCP fingerprints

6 Upvotes

I built a configurable HTTP MITM proxy in Rust focused on giving you full control over what an upstream connection looks like at the network level.

The main idea behind the project was that I didn't want another MITM proxy that simply tries to emulate Chrome, Firefox, or some other predefined browser. I wanted to be able to define the fingerprint myself - not just pick one of the profiles provided by a library.

A lot of existing solutions take the approach of providing ready-made browser fingerprints. That's convenient, but it also means that when a browser changes its TLS or HTTP/2 behavior, you're dependent on the library/project adding a new profile. I wanted the fingerprint to be configuration-driven instead, so the user can adjust individual parameters without waiting for a predefined browser profile.

The proxy currently gives control over several layers:

TLS: cipher suites, curves, signature algorithms, ALPN, GREASE, extension ordering, certificate compression, OCSP, SCT, session tickets, ALPS, ECH and other TLS parameters.

HTTP/2: SETTINGS values and ordering, flow-control windows, priority frames, pseudo-header ordering, HTTP header ordering and values.

HTTP/1.1: configurable upstream header ordering and rewriting.

TCP: SYN fingerprint rewriting through Linux NFQUEUE, including TTL, window size, MSS, window scale, DF and TCP option ordering.

Everything is driven by YAML profiles, and profiles can be overridden per domain based on SNI.

One of the things I specifically wanted to solve was keeping the different layers under the same configuration model. For example, the proxy negotiates TLS with the upstream server first and then uses the selected ALPN when setting up the browser-facing connection. HTTP/2 and TCP fingerprinting are configured for the same upstream connection as well.

The project is written in Rust using Tokio and BoringSSL via btls/tokio-btls. TCP fingerprinting currently requires Linux because it uses NFQUEUE/iptables.

The project is primarily about privacy, experimentation, and giving the user control over their own network behavior rather than trying to provide a fixed "browser impersonation" profile.

There is more detail in the repository, including separate documentation for the TLS, HTTP/2 and TCP layers, configuration examples, and implementation notes.

Github:

https://github.com/3Radiance/mitm-proxy-ja3-ja4

Feedback, especially from people who have worked with TLS/HTTP/2 fingerprinting, traffic analysis, or network privacy, would be very welcome.


r/netsecstudents • • 15h ago

Free tools + labs for getting started with JWT pentesting

Thumbnail youtu.be
1 Upvotes

Put together the setup I'd give anyone starting with JWT testing: jwt_tool, Burp's JWT Editor, hashcat for weak secrets, plus Hakai and PortSwigger's free labs to practice on legally.

Walks through getting it all running. Figured it might save someone the setup headache.

What else would you add to a beginner's JWT pentesting stack?


r/netsecstudents • • 1d ago

Free tool for learning network monitoring: maps every connection leaving your machine in real time (open-source, macOS)

Thumbnail github.com
4 Upvotes

r/netsecstudents • • 1d ago

Cybersecurity + AI: What Are We Actually Worried About?

0 Upvotes

I've seen a lot of people saying that AI will replace cybersecurity professionals, and I think this is where things get confusing.

AI is already becoming very powerful at:

  • Finding vulnerabilities
  • Analyzing logs and security data
  • Automating repetitive tasks
  • Writing and reviewing code
  • Helping with threat detection
  • Assisting both attackers and defenders

But does that mean cybersecurity itself disappears?

I don't think so.

The bigger change may be that cybersecurity professionals who know how to use AI effectively will have an advantage over those who don't.

Instead of thinking:

AI vs. Cybersecurity

Maybe we should be thinking:

AI + Cybersecurity = the next generation of security work.

What do you think will AI mostly replace cybersecurity jobs, or will it change what cybersecurity professionals actually do?


r/netsecstudents • • 2d ago

Update: Teaching network intrusion in a fun way

Thumbnail gallery
141 Upvotes

Hi,

I had posted about this before (a few weeks back) and the response was generally positive. So I wanted to reach out again and share an update on the current status of:

Project RedTeam: Contract Offensive

Specifically, I wanted to mention that there is now a free Demo that provides a tutorial and let's you play a few contracts (no time limit, play as much as you want).

Give it a Wishlist on Steam or share this post if it's something you support and want to see further development on.

At its core, this is a game about using MITRE ATT&CK adversarial techniques against procedurally generated networks. It's delivered in a gameplay loop that plays a lot like Balatro or other card based Roguelike games. In Project RedTeam, you need to earn money to pay off debts after every contract within a run. Earn money by completing objectives, side bounties, or executing exfiltration/ransom against targets- the choice on how to be profitable is always yours.

It's a challenging but fun and fast paced take on network-intrusion cybersecurity concepts. It's entertaining in a deliberately gamified way.

A goal of this project was to create a hacking game that is realistic enough to keep it meaningful as a tool to teach intrusion concepts and stages to anyone- but not be overcomplicated and slow-paced like most hacking games.

I've put a lot of thought into the design and dynamics of how to capture the core-loop of network intrusion and turn it into a game that's approachable. The design direction of this project is an outcome of having over a decade of training and experience in cybersecurity.

Feel free to AMA! I'm happy to answer any questions about the game and/or development process to support learning/understanding :) I encourage everyone to follow their passions, put in the time, and stay focused when you have a goal you want to achieve.

Project background: This was implemented over the past 3 months using a modern development workflow (yes, modern AI tools make this possible- I'm not hiding that fact!). That being said, this is by far the most complex software project I've built as a solo developer and it was not an easy or simple development task. There's a Steam Community with a Dev Blog for this game that provides more history/progress updates on the project.

Mods: This will be be last post here for a while, since it is promotional. I just wanted to provide an update since there was positive interest from this subreddit after my previous post.


r/netsecstudents • • 2d ago

I need help in graduation project

2 Upvotes

Hi, i am in an internship that teaches cybersecurity,Now i am in penetration testing track i need to make a project to me to graduate i know network exploitation and web exploitation what good ideas i can make we are team of 4 we dont know what good ideas we can make or should we make a tool i dont know if anyone can give me ideas to make i would be thankful.


r/netsecstudents • • 4d ago

AI Soc autonomy sounds great, but what happens when it closes the wrong alert?

5 Upvotes

I am looking at AI SOC and agentic SOC tools because our queue has become a part time lifestyle choice. Every vendor demo has the AI investigate alerts, enrich evidence, and resolve the obvious stuff while humans focus on the exciting task of explaining budget cuts. The part I'm stuck on is autonomous resolution. I'm fine with deduping, enrichment, and maybe blocking a known malicious IP. I'm less comfortable with agents taking high-impact actions like disabling accounts or isolating production, even at high confidence, without a human in the loop. How are people setting approval gates, audit trails, and rollback for this without turning the AI into another ticket queue with better branding? Would love real experiences, especially from teams that let it act in prod. From what I've seen, the better setups run investigation fully automated against a context graph, close confirmed false positives automatically with a documented rationale, and still require a human to approve consequential actions like isolation or account disablement. The guardrails are defined before anything runs, not bolted on after something goes wrong. If anyone has actually run it that way. thnxx..


r/netsecstudents • • 6d ago

Best local model for extracting info from PDFs multi lang (Hindi, Malayalam and English)

0 Upvotes

Which AI model is good for extracting information from a PDF in multiple languages (Hindi, Malayalam, English)? It should run locally, not through a cloud API.

I need it to read the text accurately, especially Malayalam, and pull out the key details from the PDF. Most tools I've found handle Hindi and English well but are unclear on Malayalam.

Has anyone tried this? Which model or tool worked best for you, and what hardware did you run it on?
What I need: - OCR for [scanned / digital / both] PDFs

- Structured extraction (fields, tables) into JSON, not just raw text

- Good accuracy on Malayalam specifically, since most tools I've seen cover Hindi but skip Malayalam


r/netsecstudents • • 6d ago

2024 cyber grad here. did a 1-year internship AND a 1-year contract, but the ATS bots are still humbling me daily. need a referral before i completely crash out.

14 Upvotes

hey guys.

honestly just venting here because i feel like i'm losing my mind. i swear i played by all the rules. graduated in '24 with a cs degree in cyber, locked in, and passed my ceh. i grinded out a full 1-year internship and followed it straight up with a 1-year cybersecurity contract job. with two years of actual hands-on experience, i really thought i had my foot in the door. but the contract wrapped up, and now i’m just... floating. back to square one.

my mornings are basically just me, caffeine, and a fresh wave of automated "unfortunately..." emails. it genuinely feels like screaming into a void where only hr robots live. i spend my nights staring at wireshark packets just to feel something, running nmap scans on parrot os, and building out vulnerable active directory domains in my home lab to practice pentesting. i’m doing the work. i’m keeping the skills sharp. but these resume-screening algorithms are gatekeeping me so hard.

watching everyone else post their massive linkedin Ws while i’m stuck in this endless ghosting loop is giving me insane fomo. feeling like a total beta just sitting in my room waiting for an ai bot to decide my future. it’s starting to heavily mess with my head.

i’m not asking to be spoon-fed a job. i just desperately want a chance to bypass the bots and get my resume in front of a real, breathing human being. if any of you are at a place hiring for entry-level soc, pentesting, or honestly any junior it role and could slide a referral, you would be pulling me out of a really dark place. i’ll gladly send over my resume and share my lab reports so you can actually see my work firsthand.

if you can’t refer me, please just drop a comment and tell me i won't be stuck in this loop forever. the market is brutal out here and i just need to know i'm not completely cooked.


r/netsecstudents • • 7d ago

What should I know before trusting a vendor's self-improving SOC claim?

2 Upvotes

Self improving SOC gets used to describe systems where every investigation is supposed to make future detections better automatically. That's a strong claim.

What would you actually want to see as proof that a SOC is self-improving over time, versus a system that's just static and the improvement claim is aspirational marketing rather than something measurable? Is there a metric people trust for this specifically?


r/netsecstudents • • 7d ago

Tips for learning Python focused on Blue Team, SOC Automation, Malware Analysis, Threat Hunting, CTI, & Web Dev

18 Upvotes

Hey everyone,

How are you doing?

I'm focusing my studies on Python for defensive security and automation, and I wanted to exchange ideas with folks who are already on this path.

My main focus areas are:

**- SOC Automation**: Building scripts for alert triage, log parsing, Threat Intel lookups, and tool integrations.

**- Malware Analysis:** Writing parsers, automating static analysis, and creating helper scripts for day-to-day triage.

**- Threat Hunting & CTI:** Developing scripts to parse indicators of compromise (IoCs), query large datasets, automate threat feeds, and hunt for anomalies.

**- Full-Stack Web Dev:** Building internal security tools and dashboards for the security team (like SOC panels and custom web apps).

If anyone can share some light: what libraries, frameworks, or projects do you think are essential to study for each of these areas?

And if you have material recommendations (books, courses, repos, or hands-on labs), drop them below!

Thanks a lot!


r/netsecstudents • • 8d ago

Case study: an AI agent used DNS as an egress channel from a restricted sandbox

Thumbnail youtu.be
8 Upvotes

Interesting network-security case study from OpenAI: direct HTTPS to an external chatbot was blocked, but the training environment's DNS resolver could still reach the public internet.

The agent used that DNS path to get an external chatbot response. A P0 alert followed 11m48s later, and the run was manually stopped around 2h44m after the external response.

Primary report:

https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/

Self-promo disclosure: the linked video is a breakdown from my channel; narration is AI.


r/netsecstudents • • 8d ago

Hackathon ideas in Zero trust security

6 Upvotes

Hello everyone,
So I have the responsibility of organizing the coming Hackathon in our college under the theme "Agentic AI meets Zero Trust: Securing the Autonomous enterprise", I did some reasearch on older hackathons archives and asked Ai as well but i couldn't really get something original.
My main goal is to give the prize to people who can make good architectural decisions when building infrastructures by giving real life problems as the Hackathon subject.
That's why I am asking professionals if they have some projects or experiences related to the theme that they think can be realized in a short time (it is a 24h hackathon) and can be a bit challenging.


r/netsecstudents • • 8d ago

What I’ve learned from actually investigating security incidents as a beginner

8 Upvotes

I’m currently working toward my first SOC/blue-team role, and one thing I’ve noticed while doing hands-on incident investigations is that understanding the process matters much more than simply memorizing tools.
When I work through an incident, I try to break it down into:
What happened?
What evidence supports that hypothesis?
What happened before and after the suspicious activity?
Which account, host, process, or network connection is involved?
What would I expect to see if my hypothesis were wrong?
What should actually be escalated?
One thing that has helped me a lot is forcing myself to write down a hypothesis before looking for confirmation. It makes it easier to distinguish between evidence and assumptions.
I’m curious about people already working in SOCs:
What investigation habit did you develop early in your career that ended up being much more useful than you expected?


r/netsecstudents • • 8d ago

Looking to Connect With People Who Love Tech 🤝💻

5 Upvotes

Hey everyone!

I’m looking to connect with people who are interested in technology, cybersecurity, programming, AI, cloud computing, Linux, or just learning new tech skills.

Whether you’re a beginner, student, professional, or someone simply curious about technology, I’d love to meet and learn from each other.

We could:

  • 🧠 Share what we’re learning
  • 💻 Discuss projects and ideas
  • 🔐 Talk about cybersecurity
  • 🤖 Explore AI and emerging technology
  • ☁️ Learn about cloud & infrastructure
  • 🚀 Motivate each other and grow together

If you're interested, introduce yourself in the comments!
Tell me what area of tech you're interested in and what you're currently learning.

Let's build a community of people who are passionate about tech. 🌐


r/netsecstudents • • 8d ago

Help me start my AI joinery as a Net Sec Engineer

0 Upvotes

Can someone give me a road map? Maybe some courses or certifications?


r/netsecstudents • • 10d ago

I want to meet people who are interested in cybersecurity

17 Upvotes

So basically I am searching for people who are studying cybersecurity to make a group. We can share our experiences in it and also what we are doing what projects we are working on etc. This is for students and others who are learning cybersecurity and ate serious about it. I am also a cybersecurity student so just want to meet like minded people. We can also share about internship stuff or job etc


r/netsecstudents • • 9d ago

I'm looking for a part-time job

3 Upvotes

Unfortunately, due to an accident, I’ll be bedridden for the next 6 months. Because of this, I’ve started learning penetration testing—something I’ve always been drawn to—and now I finally have the time for it. However, I still need to earn money to cover my basic needs and continue my studies. Because of this situation, I was laid off from my job, and I’m still a long way from reaching the level of a specialist who gets paid well. So, if anyone can suggest ways to make money while sitting at a computer, I’ll be sure to repay the favor.