// MODULE_LIBRARY

ALL MODULES

EVERY MODULE IN THE COURSE β€” CLICK ANY CARD TO OPEN IT

MODULE_02BEGINNER
πŸ”
PERMISSIONS & PRIVILEGES

Own the system by understanding who owns what. SUID, SGID, sticky bits, ACLs, sudoers β€” the gatekeeping mechanisms and how to work with them.

CHMODSUDOSUIDACL
MODULE_03INTERMEDIATE
πŸ–₯
BASH SCRIPTING COMBAT

Write scripts that execute your will. Loops, conditionals, functions, regex, and the art of piping data through a chain of commands like a pro.

BASHSCRIPTINGREGEXPIPES
MODULE_04INTERMEDIATE
🌐
NETWORK RECON

Scan, probe, and map any network. Master netstat, ss, nmap, tcpdump, and understand how data moves through the layers beneath you.

NMAPTCPDUMPSS/NETSTAT
MODULE_05INTERMEDIATE
βš™οΈ
PROCESSES & SYSTEM CONTROL

See what's running in the dark. Control, kill, and resurrect processes. Understand cron jobs, systemd, and background daemon management.

SYSTEMDCRONPS/TOP
MODULE_06ADVANCED
πŸ”
LOG ANALYSIS & FORENSICS

Leave no trace β€” or find theirs. Parse system logs, analyze auth events, use grep and awk to extract signals from terabytes of noise.

GREPAWKJOURNALCTL
// CERT_PREP β€” COMPTIA SECURITY+ (SY0-701)
SECURITY+ TRACK
A full Security+ course mapped to the exam β€” read it in depth, see it in diagrams, then practice in the inline terminal.
SEC+_01 // DOMAIN 1CERT PREP
πŸ›‘
SECURITY CONTROLS & PRINCIPLES

What security actually means β€” CIA and AAA, control categories and types, and Zero Trust β€” taught in depth, with diagrams and an inline practice terminal in every lesson.

CIACONTROLSZERO TRUST
SEC+_02 // DOMAIN 1CERT PREP
πŸ”„
CHANGE MANAGEMENT

Make change safe: approval and CAB, maintenance windows, rollback plans, technical implications, and documenting to a version-controlled baseline.

CABROLLBACKBASELINE
SEC+_03 // DOMAIN 1CERT PREP
πŸ”‘
CRYPTOGRAPHY ESSENTIALS

Symmetric vs asymmetric vs hashing, PKI and certificates, digital signatures, salting and key stretching, TLS β€” and the traps the exam loves.

AES/RSAPKIHASHING
SEC+_04 // DOMAIN 2CERT PREP
🎭
THREAT ACTORS & VECTORS

Who is attacking you, why, and through which doors β€” nation-states to script kiddies, phishing to supply chain.

ACTORSPHISHINGVECTORS
SEC+_05 // DOMAIN 2CERT PREP
πŸ”
VULNERABILITIES & INDICATORS

Identify and understand the types of vulnerabilities, malware, and indicators that signal a breach.

VULNERABILITIESMALWAREIoCs
SEC+_06 // DOMAIN 2CERT PREP
πŸ›‘οΈ
ATTACKS & MITIGATIONS

Understand the types of attacks and how to mitigate them, from network and password attacks to cryptographic vulnerabilities.

ATTACKSMITIGATIONSCRYPTOGRAPHY
SEC+_07 // DOMAIN 3CERT PREP
πŸŸ₯
SECURITY ARCHITECTURE MODELS & COMPONENTS

From cloud to on-prem, understand the layers and components that make up a secure infrastructure β€” from network zones to security appliances.

CLOUDIACMICROSERVICES
SEC+_08 // DOMAIN 3CERT PREP
πŸ”’
DATA PROTECTION & RESILIENCE

Protect your data at rest, in transit, and in use. Learn about encryption, tokenization, masking, and the importance of backups and disaster recovery.

ENCRYPTIONBACKUPSRTO/RPO
SEC+_09 // DOMAIN 4CERT PREP
πŸ”’
HARDENING & ASSET MANAGEMENT

Establish secure baselines, harden systems, and manage asset inventory from cradle to grave.

HARDENINGASSET MANAGEMENT
SEC+_10 // DOMAIN 4CERT PREP
πŸ”
VULNERABILITY MANAGEMENT & MONITORING

Manage vulnerabilities, prioritize remediation efforts, and monitor systems for threats.

VULNERABILITY MANAGEMENTMONITORING
SEC+_11 // DOMAIN 4CERT PREP
πŸ”‘
IDENTITY & ACCESS MANAGEMENT

Manage user identities, access controls, and authentication mechanisms.

IDENTITY MANAGEMENTACCESS CONTROL
SEC+_12 // DOMAIN 4CERT PREP
πŸ›‘οΈ
ENTERPRISE SECURITY CAPABILITIES

Understanding and deploying various security tools and capabilities to protect the enterprise from threats.

IDS/IPSEDR/XDRDLP/NAC
SEC+_13 // DOMAIN 4CERT PREP
βš™οΈ
AUTOMATION, INCIDENT RESPONSE & FORENSICS

Automate security processes and manage incident response effectively. Understand the critical aspects of digital forensics.

AutomationIncident ResponseForensics
SEC+_14 // DOMAIN 5CERT PREP
πŸ”’
GOVERNANCE, RISK & COMPLIANCE

From governance documents to risk management and business continuity, this module covers the essential frameworks and practices.

GOVERNANCERISKCOMPLIANCE
SEC+_15 // DOMAIN 5CERT PREP
πŸ”—
THIRD-PARTY RISK & COMPLIANCE

Managing third-party risk and ensuring compliance with legal requirements is crucial for organizational security.

THIRD-PARTYCOMPLIANCE
PT0-003_01 // DOMAIN 1CERT PREP
πŸ“
METHODOLOGY & ENGAGEMENT

The paperwork that keeps you out of prison and the frameworks that keep you thorough β€” scope, ROE, SOW/MSA/NDA, and the methodology you test against.

SCOPINGROEPTES
PT0-003_02 // DOMAIN 1CERT PREP
βš–οΈ
LEGAL, ETHICS & COMPLIANCE

The law is part of the scope. CFAA boundaries, data-handling duties, the regulations that shape the test, and exactly what to do when you find something you were never meant to see.

CFAAHIPAA/PCIETHICS
PT0-003_03 // DOMAIN 1CERT PREP
πŸ“„
REPORTING & COMMUNICATION

The report is the product. Executive summary, risk-rated findings, evidence, remediation, and the communication triggers that can't wait for the final PDF.

REPORTCVSSREMEDIATION
PT0-003_04 // DOMAIN 2CERT PREP
πŸ•΅οΈ
PASSIVE RECON & OSINT

Map the whole attack surface without sending a single packet to the target β€” DNS, certificate logs, Shodan, dorks, and breach data.

OSINTDNSDOSSIER
PT0-003_05 // DOMAIN 2CERT PREP
πŸ“‘
ACTIVE RECON & SCANNING

Now you touch the target: host discovery, port and service scanning, and the timing knobs that trade speed for stealth.

NMAPPORTSSERVICES
PT0-003_06 // DOMAIN 2CERT PREP
πŸ”Ž
ENUMERATION

Turn open ports into names, shares, and users β€” SMB, LDAP, SNMP, DNS and web content discovery are where the target starts giving up its secrets.

SMBSNMPWEB
PT0-003_07 // DOMAIN 2CERT PREP
⌨️
SCRIPTING FOR RECON

Automate the boring parts β€” Bash and Python loops, output parsing, and reading/fixing a script you're handed. The exam tests whether you can read code, not just run tools.

BASHPYTHONPARSING
PT0-003_08 // DOMAIN 3CERT PREP
🩺
VULNERABILITY SCANNING

Point a scanner at the target without knocking it over β€” authenticated vs unauthenticated scans, the tool landscape, and safe configs that respect the ROE.

NESSUSCREDENTIALEDSAFE-SCAN
PT0-003_09 // DOMAIN 3CERT PREP
🎯
ANALYZING & VALIDATING

Kill the false positives, prove what's real, and rank by true risk β€” CVSS plus EPSS, CISA KEV, and business context turn a scanner dump into a worklist.

CVSSFALSE-POSPRIORITIZE
PT0-003_10 // DOMAIN 4CERT PREP
πŸ”Œ
NETWORK ATTACKS

Own the wire: poison name resolution, sit on-path, and relay authentication you never cracked.

MITMRELAYPOISONING
PT0-003_11 // DOMAIN 4CERT PREP
πŸ”‘
AUTH & HOST-BASED ATTACKS

Crack it, spray it, or roast it β€” passwords, hashes, Active Directory, and the climb from user to root.

HASHCATKERBEROASTPRIVESC
PT0-003_12 // DOMAIN 4CERT PREP
πŸ•ΈοΈ
WEB APPLICATION ATTACKS

Injection, client-side, and broken access control β€” the OWASP heavy-hitters, mapped to the weaknesses behind them.

SQLIXSSIDOR
PT0-003_13 // DOMAIN 4CERT PREP
πŸ“Ά
WIRELESS ATTACKS

Capture the handshake, crack the PSK, or stand up a convincing twin β€” attacking WPA2/WPA3 and the humans who connect.

WPA2HANDSHAKEEVIL-TWIN
PT0-003_14 // DOMAIN 4CERT PREP
☁️
CLOUD Β· CONTAINER Β· API Β· AI

The V3 frontier β€” leaked keys and metadata, container escapes, broken object-level auth, and prompt injection.

IMDSBOLAPROMPT-INJ
PT0-003_15 // DOMAIN 4CERT PREP
🎭
SOCIAL ENGINEERING & PHYSICAL

The human layer β€” phishing to pretexting to tailgating β€” done only against approved people, with evidence handled like it matters.

PHISHINGPRETEXTETHICS
PT0-003_16 // DOMAIN 5CERT PREP
🧭
POST-EXPLOITATION & LATERAL MOVEMENT

The foothold is the beginning, not the end β€” persist, pivot, move laterally to domain dominance, then leave the environment exactly as you found it.

PIVOTDCSYNCCLEANUP
PT0-003_C01 // CAPSTONECERT PREP
🏁
C01 CAPSTONE β€” FULL ENGAGEMENT

Every domain, one engagement β€” scope to shell to report. Watch the whole chain against Meridian come together, then assemble it yourself.

ALL-DOMAINSCHAINREPORT
CCNA_01 // DOMAIN 1CERT PREP
πŸ“¦
NETWORK MODELS & HOW DATA MOVES

The OSI/TCP-IP stack, encapsulation across a switched + routed path, the device→layer map, and TCP vs UDP — with a security lens on every layer.

OSI/TCP-IPENCAPSULATIONTCP-vs-UDP
CCNA_02 // DOMAIN 1CERT PREP
πŸ”’
IPv4 ADDRESSING & SUBNETTING

The one CCNA skill you must do fast and in your head: block-size math, VLSM, wildcard masks, RFC 1918, and why NAT exists.

VLSMWILDCARDRFC1918
CCNA_03 // DOMAIN 1CERT PREP
🌐
IPv6 ADDRESSING & FUNDAMENTALS

Compress addresses on sight, classify by prefix (GUA/LLA/ULA/multicast), generate EUI-64, and read the SLAAC vs DHCPv6 RA flags.

EUI-64SLAACFE80::/10
CCNA_04 // DOMAIN 2CERT PREP
πŸ”Œ
SWITCHING, VLANs & INTER-VLAN ROUTING

MAC learning, VLANs, 802.1Q trunks with a safe native VLAN, and routing between VLANs with router-on-a-stick vs SVIs β€” plus the VLAN-hopping trap.

802.1QNATIVE-VLANROAS/SVI
CCNA_05 // DOMAIN 2CERT PREP
🌳
STP, ETHERCHANNEL & DISCOVERY

Root-bridge election, port states, the edge guards (PortFast/BPDU Guard/Root Guard), LACP/PAgP bundling, and CDP vs LLDP.

RSTPETHERCHANNELROOT/BPDU-GUARD
CCNA_06 // DOMAIN 2CERT PREP
πŸ“Ά
WIRELESS LAN FUNDAMENTALS & WLC

RF/channels, autonomous vs lightweight APs, split-MAC over CAPWAP, WLAN config on the WLC, and WPA2/WPA3 vs 802.1X.

1/6/11CAPWAPWPA3-SAE
CCNA_07 // DOMAIN 3CERT PREP
🧭
ROUTING FUNDAMENTALS & STATIC ROUTING

How a router chooses a path (longest-prefix match β†’ AD β†’ metric), reading the routing table, and static/default/floating/host routes for IPv4 and IPv6.

LPMADMIN-DISTANCEFLOATING-STATIC
CCNA_08 // DOMAIN 3CERT PREP
πŸ›°οΈ
OSPFv2 SINGLE-AREA

Link-state operation, router-ID selection, neighbor states, DR/BDR election, the cost formula, and why adjacencies fail silently.

AREA-0DR/BDRRID
CCNA_09 // DOMAIN 3CERT PREP
πŸ”
FIRST-HOP REDUNDANCY (HSRP)

Remove the default-gateway single point of failure: HSRP Active/Standby, the virtual IP/MAC, preempt behavior, and how it contrasts with VRRP/GLBP.

VIRTUAL-IPPREEMPTvMAC
CCNA_10 // DOMAIN 4CERT PREP
πŸ› οΈ
IP SERVICES

The whole IP-services grab-bag: NAT/PAT, DHCP + relay, DNS, NTP, SNMP, syslog, QoS, and secure management β€” each a quick, precise exam target.

NAT/PATDHCP-RELAYSYSLOG-0-7
CCNA_11 // DOMAIN 5CERT PREP
πŸ”’
SECURITY CONCEPTS, AAA & VPNs

CIA and threat vocabulary, AAA (local vs RADIUS vs TACACS+), password hardening, and site-to-site vs remote-access VPNs (IPsec vs SSL/TLS).

AAARADIUS-vs-TACACS+IPsec/SSL
CCNA_12 // DOMAIN 5CERT PREP
πŸ›‘οΈ
DEVICE HARDENING, LAYER 2 SECURITY & ACLs

Standard/extended ACLs and placement, port security, DHCP snooping + Dynamic ARP Inspection, 802.1X, and device hardening.

ACLsPORT-SECURITYDHCP-SNOOP/DAI
CCNA_13 // DOMAIN 6CERT PREP
πŸ€–
AUTOMATION, CONTROLLERS, APIs & DATA FORMATS

Controller-based vs traditional networking, SDN planes, north/southbound APIs, REST + CRUD, JSON/XML/YAML, and Ansible/Puppet/Terraform.

SDNREST/CRUDJSON
CCNA_14 // DOMAIN 7CERT PREP
🏰
BRIDGE I β€” DEFENSE-IN-DEPTH & CISCO SECURITY ARCHITECTURE

Beyond CCNA: how ACLs/port-security/802.1X/VPN grow into the Cisco Secure portfolio (Secure Firewall/FTD, ISE, Umbrella, TrustSec/SGT) and the CCNP Security (SCOR) mindset.

ZERO-TRUSTSGTFTD/ISE
CCNA_15 // DOMAIN 7CERT PREP
πŸ•΅οΈ
BRIDGE II β€” THREAT DETECTION, TELEMETRY & SOC OPS

Beyond CCNA: telemetry (NetFlow, syslog, SPAN, EDR), SIEM correlation, MITRE ATT&CK, and the incident-response lifecycle β€” bridging to CyberOps Associate (CBROPS).

NETFLOWMITRE-ATT&CKNIST-800-61
CCNA_CAPSTONE // ALL 6 DOMAINSCERT PREP
🏁
CAPSTONE β€” DESIGN, SECURE & VERIFY A SMALL ENTERPRISE NETWORK

The finale: take Harbor Point Logistics (HQ + branch + WAN) from a blank design to a verified, hardened build threading all six domains. Human-graded on a 100-point rubric.

ALL-DOMAINSVERIFYSECURITY-FIRST
OWASP Β· FND-1CERT PREP
🌐
HTTP & THE BROWSER TRUST MODEL

Every value the server sees is attacker-controlled. Status codes, origins, cookies, sessions and JWTs β€” the mental model every web finding is built on, and how each request region maps to a Top-10 category.

HTTPSame-OriginCookiesJWT
OWASP Β· FND-2CERT PREP
🧭
METHODOLOGY, WSTG & ASVS 5.0

Turn poking-at-things into a repeatable engagement: the recon→report lifecycle, correct WSTG test IDs, valid ASVS 5.0 requirement references, CWE precision, STRIDE, and a complete finding.

LifecycleWSTGASVS 5.0STRIDE
OWASP Β· A01CERT PREP
πŸ”“
A01 BROKEN ACCESS CONTROL

The #1 category. Horizontal (IDOR/BOLA) and vertical (forced browsing, function-level) access failures, why they live server-side, and how to prove them without touching anyone else's real data.

A01IDORBOLA/BFLACWE-639
OWASP Β· A02CERT PREP
βš™οΈ
A02 SECURITY MISCONFIGURATION

The app that ships insecure by default: debug on, default creds, permissive CORS, missing security headers, directory listing, and stack traces. Cheap to find, high-signal, everywhere.

A02CORSHeadersDefaults
OWASP Β· A03CERT PREP
πŸ“¦
A03 SOFTWARE SUPPLY CHAIN FAILURES

New/expanded for 2025 (grew out of Vulnerable & Outdated Components). Risk you inherit from dependencies, registries, build pipelines and CI β€” where you didn't write the code but you own the blast radius.

A03DepsSBOMCI/CD
OWASP Β· A04CERT PREP
πŸ”
A04 CRYPTOGRAPHIC FAILURES

Sensitive data exposed because crypto is missing, weak, or misused: plaintext transport, reversible 'encryption' of passwords, MD5/SHA1 for auth, hardcoded keys. It's about protecting data, not just algorithms.

A04TLSHashingSecrets
OWASP Β· A05-ICERT PREP
πŸ’‰
A05 INJECTION I β€” SERVER-SIDE

When untrusted input crosses into an interpreter β€” SQL, a shell, an LDAP filter β€” and changes the command's structure. The classic, still-devastating class, and why parameterization (not escaping) is the fix.

A05SQLiOS cmdASVS V2
OWASP Β· A05-IICERT PREP
πŸ–₯️
A05 INJECTION II β€” XSS & SSTI

Injection into a rendering context. Reflected, stored and DOM-based XSS; server-side template injection; and why the fix is context-aware output encoding plus a strict CSP β€” never the deprecated X-XSS-Protection.

XSSSSTIDOMCSP
OWASP Β· A06CERT PREP
πŸ“
A06 INSECURE DESIGN

Bugs you can't patch away because the flaw is in the design: a missing control, an unbounded flow, a trust assumption. Threat modeling, abuse cases, and secure-by-design thinking β€” distinct from implementation bugs.

A06Threat modelBusiness logicASVS V1
OWASP Β· A07CERT PREP
πŸ”‘
A07 AUTHENTICATION FAILURES

Proving identity, and keeping it proven. Credential stuffing and brute force, weak recovery, session fixation/handling, and JWT pitfalls β€” the difference between authentication and session management.

A07SessionJWTASVS V6/V7
OWASP Β· A08CERT PREP
🧬
A08 INTEGRITY FAILURES

Trusting code or data whose integrity you never verified: insecure deserialization, unsigned/auto-updates, tampered CI artifacts. Overlaps supply chain (A03) but centers on the verify-before-you-trust gap.

A08DeserializationSigningWSTG-BUSL
OWASP Β· A09CERT PREP
πŸ“Š
A09 LOGGING & ALERTING FAILURES

Renamed for 2025 to stress alerting. You can't respond to what you never saw: missing auth/authz logs, no alerting on abuse, and the opposite failure β€” logging secrets. Detection is a security control.

A09AlertingPII in logsASVS V16
OWASP Β· A10CERT PREP
🧯
A10 MISHANDLING EXCEPTIONAL CONDITIONS

New for 2025 (24 CWEs). How apps behave when something goes wrong: fail-open logic, unhandled exceptions, verbose error leakage, and edge cases that bypass controls. The behavior at the boundary is the vulnerability.

A10Fail-openError handlingEdge cases
OWASP Β· BEYOND-1CERT PREP
πŸ›°οΈ
SSRF, XXE & API SECURITY

The classes that lost a standalone Top-10 slot but not their teeth. SSRF and cloud metadata, XXE, and the separate OWASP API Security Top 10 (2023): BOLA, BFLA, BOPLA and API-side SSRF.

SSRFXXEAPI Top 10BOLA
OWASP Β· BEYOND-2CERT PREP
πŸ”—
CHAINING, METHODOLOGY & REPORTING

How single findings combine into critical impact, a repeatable bug-bounty workflow, CVSS that matches its vector, and a report a developer can act on. This module feeds the C01 capstone.

ChainingCVSSReportingScope
OWASP Β· CAPSTONECERT PREP
πŸŽ“
C01 CAPSTONE: MERIDIANSHOP

The graded finale: a full assessment of the MeridianShop app that threads all ten 2025 categories into one engagement, scored on a 100-point rubric (β‰₯80 to pass). Find, chain, and report β€” correctly labeled.

CapstoneAll 10RubricReport
CEH_01 // 1CERT PREP
🎯
INTRODUCTION TO ETHICAL HACKING

The mental model: the CIA triad, threat taxonomy, the Cyber Kill Chain vs MITRE ATT&CK, the five phases, AI on both sides, and why written authorization is non-negotiable.

5 PHASESFRAMEWORKSLAW & ETHICS
CEH_02 // 1CERT PREP
πŸ”Ž
FOOTPRINTING & RECONNAISSANCE

Phase 1: passive OSINT (WHOIS, DNS, CT logs, job posts), the tools used correctly (theHarvester, Amass, Shodan), zone transfers, and the countermeasures that shrink a public footprint.

PASSIVE OSINTDNS & CT LOGSCOUNTERMEASURES
CEH_03 // 1CERT PREP
πŸ“‘
SCANNING NETWORKS

Phase 2: host discovery, the TCP handshake and the scans that abuse it (-sS/-sT/-sU/-sA), port states, -sV/-O, banner grabbing, and scan-time evasion.

HOST DISCOVERYNMAP SCANSEVASION
CEH_04 // 2CERT PREP
πŸ—ƒοΈ
ENUMERATION

Service-by-service extraction of users, shares, and config — SMB null sessions, SNMP strings, LDAP anon binds, DNS/SMTP/NFS/RPC — each with its tool and countermeasure.

SMB Β· SNMP Β· LDAPDNS Β· SMTP Β· NFSSCOPE DISCIPLINE
CEH_05 // 2CERT PREP
πŸ”
VULNERABILITY ANALYSIS

Read a scanner like a professional: vuln types, the assessment lifecycle, CVSS v3.1 scoring, NVD/CISA-KEV/EPSS prioritization, authenticated vs unauthenticated scans, and verification before you report.

CVSS v3.1KEV Β· EPSSVERIFY FIRST
CEH_06 // 3CERT PREP
πŸ”‘
SYSTEM HACKING

Phases 3–5: crack or pass credentials, escalate on Windows/Linux, persist, hide data, and cover tracks β€” mapped to the correct hash modes and ATT&CK IDs.

GAIN ACCESSPRIVESC & PERSISTCOVER TRACKS
CEH_07 // 3CERT PREP
🦠
MALWARE THREATS

Taxonomy by behavior, APT/living-off-the-land, trojan/C2, static β†’ dynamic β†’ memory analysis, distribution vectors, IoCs, and defense-in-depth.

TAXONOMYANALYSISDEFENSE
CEH_08 // 3CERT PREP
πŸ“‘
SNIFFING

Passive vs active sniffing, the switched-network attacks (MAC flood, ARP spoof, rogue DHCP, DNS spoof, LLMNR poison), cleartext exposure, and Layer-2 defenses.

PASSIVE vs ACTIVEMITM ATTACKSL2 DEFENSE
CEH_09 // 4CERT PREP
🎣
SOCIAL ENGINEERING & DENIAL-OF-SERVICE

Human/computer/mobile SE and Cialdini's principles; SET & GoPhish; the three DoS families (volumetric, protocol, app-layer), botnets, and layer-matched defenses.

SOCIAL ENGINEERINGDoS / DDoSDEFEND BY LAYER
CEH_10 // 4CERT PREP
🎭
SESSION HIJACKING & EVADING IDS, FIREWALLS & HONEYPOTS

App- and network-level session hijacking (theft/fixation/RST), cookie-flag fixes, IDS/firewall evasion (fragmentation, encoding, tunneling), and honeypot types + detection.

SESSION HIJACKINGIDS / FW EVASIONHONEYPOTS
CEH_11 // 4CERT PREP
🌐
HACKING WEB SERVERS & WEB APPLICATIONS

Web-server recon and flaws (version disclosure, CVE-2021-41773 path traversal, WebDAV/HTTP methods) and the app methodology across the OWASP Top 10 at CEH depth with Burp/ZAP/ffuf.

WEB-SERVER ATTACKSOWASP TOP 10BURP / ZAP / FFUF
CEH_12 // 5CERT PREP
πŸ’‰
SQL INJECTION

How untrusted input alters a query, the SQLi types (UNION, boolean vs time-based blind, OOB), information_schema enumeration, sqlmap, and the fix β€” parameterized queries.

TYPES & DETECTIONENUM & sqlmapPARAM QUERIES
CEH_13 // 5CERT PREP
πŸ“‘
HACKING WIRELESS NETWORKS

802.11 basics, the WEP→WPA→WPA2→WPA3/SAE progression, the 4-way handshake + PMKID capture, offline cracking (hashcat 22000), evil-twin/WPS, and enterprise 802.1X attacks.

802.11 & HANDSHAKECAPTURE & CRACKROGUE AP & 802.1X
CEH_14 // 5CERT PREP
πŸ“±
HACKING MOBILE PLATFORMS, IoT & OT

Android/iOS attack surface + OWASP Mobile Top 10 (2024), IoT protocols & OWASP IoT Top 10 (2018), firmware analysis, and OT/ICS (Modbus/502, Purdue model) where a wrong write causes physical harm.

MOBILE & OWASPIoT & FIRMWAREOT / ICS
CEH_15 // 6CERT PREP
☁️
CLOUD & CONTAINER HACKING

The misconfiguration playbook — public S3, over-permissive IAM, SSRF→IMDS credential theft, docker.sock escape, exposed K8s — and the AWS defenses. CEH Domain 8.

MISCONFIG FIRSTSSRF→IMDSCONTAINER ESCAPE
CEH_16 // 6CERT PREP
πŸ”
CRYPTOGRAPHY

Tell encryption/hashing/encoding apart, know what's broken (MD5/SHA-1/ECB/TLS 1.0), match each attack to its defense, and the hashcat modes. CEH Domain 9.

OPS APARTWHAT'S BROKENATTACK→DEFENSE
CEH_17 // 6CERT PREP
🏁
CAPSTONE β€” 5-PHASE ENGAGEMENT

A signed, 5-phase engagement threading all 16 modules — 20 flags, pass 14/20 — CEH Practical-style, end to end with discipline.

5 PHASES20 FLAGSFULL CHAIN
KLCP_01 // 1CERT PREP
πŸ‰
ABOUT KALI & GETTING STARTED

What Kali is (Debian-testing, rolling, OffSec), how to verify an image two ways, the run modes, and the non-root kali+sudo model.

WHAT IS KALIVERIFY & BOOTNON-ROOT
KLCP_02 // 1CERT PREP
🐧
LINUX FUNDAMENTALS FOR KALI

The daily operator skills: bash + sudo, the FHS layout, files, rwx/SUID permissions, systemd services, and pipes.

SHELL & FHSPERMISSIONSPIPES & SYSTEMD
KLCP_03 // 1CERT PREP
πŸ’Ώ
INSTALLING KALI LINUX

Installer types, guided vs manual partitioning, LVM for flexibility, and LUKS encrypted LVM for data at rest.

INSTALLER TYPESLVM & PARTITIONSLUKS FDE
KLCP_04 // 2CERT PREP
βš™οΈ
CONFIGURING KALI LINUX

The desktop networking default (NetworkManager), NM-managed DNS, the ssh unit, non-root users with visudo, and the single official kali-rolling APT line.

NETWORKMANAGERSYSTEMD & SSHUSERS & APT
KLCP_05 // 2CERT PREP
🧭
GETTING HELP & THE KALI COMMUNITY

The self-sufficiency loop: man sections, --help/info, finding packages (apt-cache/dpkg/apt policy), reading journalctl, and filing a reproducible report at the right tracker.

MAN & --HELPLOGS & PACKAGESBUG REPORTS
KLCP_06 // 3CERT PREP
πŸ”’
SECURING & MONITORING KALI

The operator security stack: scoped sudo, SSH hardening, ufw/nftables firewall, fail2ban, patching, log monitoring, AIDE/auditd, and LUKS at rest.

ACCOUNTS & SSHFIREWALL & FAIL2BANMONITOR & LUKS
KLCP_07 // 3CERT PREP
πŸ“¦
DEBIAN PACKAGE MANAGEMENT

The two layers β€” dpkg (single .deb, no deps) and apt (resolves deps) β€” plus sources, keyring-signed repos, pinning, holds, and recovery.

DPKG vs APTSOURCES & KEYRINGHOLD & PIN
KLCP_08 // 3CERT PREP
🧰
METAPACKAGES, TOOLS & KALI-TWEAKS

Metapackages carry no binaries β€” only deps. The kali-linux-*/kali-tools-* sets, dependency inspection, the kali-tweaks ncurses menu, and Kali Undercover.

METAPACKAGESROLE PACKSTWEAKS & UNDERCOVER
KLCP_09 // 4CERT PREP
πŸ’Ώ
LIVE-BUILD, ISO & PERSISTENCE

Build a custom Kali ISO with live-build, add plain and LUKS-encrypted persistence, and arm the cryptsetup-nuke-password self-destruct.

LIVE-BUILDPERSISTENCELUKS NUKE
KLCP_10 // 4CERT PREP
🏒
KALI IN THE ENTERPRISE

Provision fleets with PXE/preseed, enforce config with SaltStack, and govern packages with a signed reprepro repo — repeatable, controlled, auditable.

PXE + PRESEEDSALTSTACKSIGNED REPO
KLCP_11 // 4CERT PREP
πŸ”§
EXTENDING KALI

Rebuild Debian packages from source, build one from scratch, host a signed local repo, and compile a custom kernel — standard Debian packaging.

APT SOURCEBUILD & SIGNKERNEL
KLCP_12 // 4CERT PREP
🌐
KALI VARIANTS & PLATFORMS

Match the mission to the variant: NetHunter editions, Kali Purple, WSL + Win-KeX, Docker, cloud, and ARM — each with its real constraints.

NETHUNTERPURPLE / WSLDOCKER / ARM
KLCP_13 // 4CERT PREP
🏁
CAPSTONE β€” DEPLOY, CUSTOMIZE & SECURE

The final challenge: five phases from a verified, encrypted install to a hardened, packaged, persistence-enabled, fleet-deployed environment — capture all 16 flags.

5 PHASES16 FLAGSALL AREAS A–D
CISSP_01 // 1CERT PREP
πŸ›‘οΈ
SECURITY & RISK MANAGEMENT: FOUNDATIONAL CONCEPTS

The CIA triad and its extensions, governance vs management, security roles, due care/due diligence, and the ISC2 Code of Ethics β€” the foundation every other domain builds on.

CIA + GOVERNANCEDUE CAREETHICS
CISSP_02 // 1CERT PREP
βš–οΈ
RISK MANAGEMENT

The risk lifecycle, quantitative math (SLE = AVΓ—EF; ALE = SLEΓ—ARO), inherent vs residual risk, appetite vs tolerance, the four risk responses, and control cost-justification.

RISK LIFECYCLESLE / ALEAPPETITE
CISSP_03 // 1CERT PREP
πŸ“œ
GOVERNANCE, COMPLIANCE, LAW & BCP

Legal systems and regulations (GDPR, HIPAA, PCI), intellectual property, governance frameworks, and business continuity β€” the BIA, MTD, and RTO vs RPO.

LAW & COMPLIANCEBCP / BIARTO vs RPO
CISSP_04 // 2CERT PREP
πŸ—ƒοΈ
ASSET SECURITY

Data classification, the owner/custodian/processor roles, the data lifecycle, retention and remanence, and protecting data at rest, in transit, and in use.

CLASSIFICATIONDATA ROLESRETENTION
CISSP_05 // 3CERT PREP
πŸ›οΈ
SECURITY ARCHITECTURE & MODELS

Security models done precisely β€” Bell-LaPadula (no read up / no write down), Biba, Clark-Wilson, Brewer-Nash β€” plus evaluation criteria and secure design principles.

SECURITY MODELSREAD/WRITE RULESEVALUATION
CISSP_06 // 3CERT PREP
πŸ”
CRYPTOGRAPHY

Symmetric vs asymmetric, hashing and digital signatures, PKI and key management, TLS 1.3 forward secrecy, and matching the mechanism to confidentiality / integrity / authenticity / non-repudiation.

SYMMETRIC/ASYMPKI & SIGNATURESKEY MGMT
CISSP_07 // 3CERT PREP
🏒
PHYSICAL & ENVIRONMENTAL SECURITY

CPTED and layered defense, fire suppression (clean agents are safe for occupied spaces; CO2 is the hazard), power anomalies, HVAC, and media handling.

CPTEDFIRE / POWERLAYERED DEFENSE
CISSP_08 // 4CERT PREP
🌐
COMMUNICATION & NETWORK SECURITY

Where controls live in the OSI/TCP-IP stack, secure protocols (TLS 1.3, IPsec AH vs ESP), segmentation and zero trust, firewalls and VPNs, and wireless (WPA3/SAE).

OSI PLACEMENTIPsec / TLSZERO TRUST
CISSP_09 // 5CERT PREP
πŸ”‘
IDENTITY & ACCESS MANAGEMENT

The AAA chain, true MFA (different factor types), biometric accuracy (CER is the FAR=FRR crossover), access-control models, SSO/federation, and the JML lifecycle.

AAA + MFAACCESS MODELSJML / PAM
CISSP_10 // 6CERT PREP
πŸ”Ž
SECURITY ASSESSMENT & TESTING

Assessment vs audit vs test, vulnerability assessment vs penetration test, SOC 1/2/3 and Type I vs II, code testing (SAST/DAST), and security process metrics (KPI/KRI/KGI).

VA vs PENTESTSOC REPORTSKPI / KRI
CISSP_11 // 7CERT PREP
βš™οΈ
SECURITY OPERATIONS

Operational principles (least privilege, SoD, dual control), logging/SIEM/UEBA, change and patch management, backups and the 3-2-1 rule, RTO vs RPO, RAID, and recovery sites.

SoD / DUAL CTRL3-2-1 BACKUPRECOVERY SITES
CISSP_12 // 7CERT PREP
🚨
INCIDENT MANAGEMENT & INVESTIGATIONS

The (ISC)2 7-step incident lifecycle (Detection -> Response -> Mitigation -> Reporting -> Recovery -> Remediation -> Lessons Learned), digital forensics (order of volatility, chain of custody), and evidence admissibility.

IR LIFECYCLEFORENSICSEVIDENCE
CISSP_13 // 8CERT PREP
πŸ’»
SOFTWARE DEVELOPMENT SECURITY

The secure SDLC and shift-left, maturity models (CMMI vs OWASP SAMM vs BSIMM), secure coding and the OWASP Top 10 (2021), CI/CD and SBOM, database security, and API/third-party risk.

SECURE SDLCOWASP / SAMMSBOM / API
CISSP // CAPSTONECERT PREP
πŸŽ“
CAPSTONE: INTEGRATED 8-DOMAIN GRC SCENARIO

One healthcare-tech company run through 15 governance decision points across all eight domains and a live cross-domain breach β€” where life-safety is literal and every domain is exercised.

ALL 8 DOMAINSDECISION POINTSLIVE INCIDENT
πŸ’€
MODULE TITLE
β–ͺ BEGINNER Β· 4 LESSONS Β· 0% COMPLETE
β–Ά

SELECT A LESSON TO BEGIN

πŸ—‚
LAB TITLE
LAB_01 Β· BEGINNER Β· ~20 MIN
πŸ†
LAB COMPLETE β€” ALL OBJECTIVES CLEARED

Well executed. Review your commands above or proceed to the next lab.

LAB_01 // ACTIVE
root@lab:~$