Class Schedule
LIVECourse Introduction & Learning Roadmap THEORY
Understand course objectives, assessment, and industry expectations.
Welcome to Module 1: Cybersecurity Fundamentals & Threat Landscape. This is the foundation upon which every subsequent module is built. A solid understanding here will make advanced topics — penetration testing, incident response, forensics — significantly easier.
This course follows a progressive learning model: each module builds on the previous one. You will move from fundamentals (this module) through networking, operating systems, cryptography, offensive security, and finally defensive operations.
Practical Labs (40%) — Hands-on exercises using real tools in isolated lab environments.
Capstone Project (20%) — End-of-course penetration test report or defensive security analysis.
This course maps closely to several globally recognized certifications. Completing it positions you well for:
SY0-701Defensive: SOC Analyst, Incident Responder, Threat Hunter, DFIR Specialist
Governance: Security Auditor, GRC Analyst, Compliance Officer
Architecture: Security Engineer, Cloud Security Architect, Zero Trust Designer
What is Cybersecurity? Why It Matters THEORY
Define cybersecurity, information security, and digital transformation.
Cybersecurity is the practice of protecting systems, networks, and programs from digital attacks. These attacks typically aim to access, change, or destroy sensitive information; extort money from users; or disrupt normal business processes.
As organizations undergo digital transformation — moving operations, data, and services online — their attack surface expands dramatically. Every new cloud service, IoT device, mobile endpoint, or API integration creates a potential entry point for attackers.
Organizations must comply with various regulations that mandate security controls:
HIPAA (US) — Protects health information. Mandatory for healthcare organizations.
PCI-DSS (Global) — Security standard for organizations handling payment card data.
SOX (US) — Financial reporting integrity for public companies.
CCPA/CPRA (California) — Consumer privacy rights for California residents.
Digital Assets & CIA Triad THEORY
Identify enterprise assets and explain Confidentiality, Integrity, and Availability.
Before we can protect anything, we must understand what we are protecting. Digital assets include anything of value to an organization that exists in digital form.
| Asset Type | Examples | Classification |
|---|---|---|
| Data | Customer PII, financial records, intellectual property, trade secrets | Crown Jewels |
| Hardware | Servers, workstations, networking equipment, IoT devices | Infrastructure |
| Software | Applications, operating systems, custom code, databases | Logical |
| Services | Cloud platforms, SaaS applications, APIs, DNS | Dependencies |
| People | Employees, contractors, their credentials and access rights | Human Factor |
| Reputation | Brand trust, customer confidence, market position | Intangible |
Enforcement: Encryption (AES-256, RSA), access control lists (ACLs), role-based access control (RBAC), data classification labels, multi-factor authentication (MFA), Data Loss Prevention (DLP).
Enforcement: Cryptographic hashing (SHA-256, MD5), digital signatures, version control, checksums, database constraints, audit logs, file integrity monitoring (FIM).
Enforcement: Redundancy (RAID, failover clusters), load balancing, DDoS mitigation, disaster recovery (DR) plans, backup systems, uptime SLAs, geographic distribution.
Integrity: When you transfer $500, the system ensures exactly $500 is deducted — not $5 or $5,000. Transaction logs are tamper-proof.
Availability: The banking app must be accessible 24/7. Redundant servers and load balancers ensure no single point of failure.
Threats, Vulnerabilities, Risks & Attacks THEORY
Differentiate threat, vulnerability, exploit, risk, incident, and breach with examples.
These terms are often used interchangeably in casual conversation, but in cybersecurity they have precise, distinct meanings. Confusing them can lead to miscommunication during incident response.
| Term | Definition | Example |
|---|---|---|
| Threat | A potential cause of an unwanted incident that may harm an asset | Nation-state hacker group, hurricane, disgruntled employee |
| Vulnerability | A weakness in a system that a threat can exploit | Unpatched software, weak password policy, misconfigured firewall |
| Exploit | Code, technique, or method that takes advantage of a vulnerability | SQL injection payload, buffer overflow shellcode, phishing email |
| Risk | The potential for loss when a threat exploits a vulnerability | Risk = Likelihood × Impact |
| Incident | An observed event that compromises (or threatens) CIA | Malware detection, unauthorized access attempt, policy violation |
| Breach | A confirmed incident resulting in unauthorized data disclosure | 147M records exposed in Equifax breach |
Vulnerability: How easy is the vulnerability to exploit? (Exposure)
Impact: How bad would it be if exploited? (Consequence)
Example: A phishing email (threat) targeting employees with weak security awareness (vulnerability) that could expose customer database (high impact) = High Risk.
Incident (not a breach): Employee clicks phishing link but IT detects and quarantines the endpoint before any data is accessed.
Breach: Attacker exploits SQL injection to extract 50,000 customer records. Confirmed unauthorized disclosure has occurred.
Modern Threat Landscape INTERACTIVE
Explore malware, phishing, ransomware, insider threats, APTs, cloud & supply-chain attacks.
The threat landscape is constantly evolving. Attackers refine their techniques, automate exploitation, and monetize access through increasingly sophisticated models. Understanding the current landscape is essential for effective defense.
| Type | Behavior | Self-Replicating? |
|---|---|---|
| Virus | Attaches to legitimate files; executes when host file runs | Yes (requires host) |
| Worm | Spreads independently across networks without human interaction | Yes (autonomous) |
| Trojan | Disguised as legitimate software; creates backdoors | No |
| Rootkit | Hides deep in OS kernel; maintains persistent, hidden access | No |
| Spyware | Covertly collects user information and keystrokes | No |
| Ransomware | Encrypts files; demands payment for decryption key | Sometimes |
| Fileless Malware | Operates entirely in memory; leaves no disk artifacts | No |
Phishing has evolved far beyond mass-sent spam emails:
Notable RaaS groups: LockBit, BlackCat/ALPHV, Cl0p, Royal, Play
Average ransom demand (2024): $1.54 million (Sophos)
Average recovery cost: $2.73 million (including downtime)
APTs are long-term, targeted campaigns typically sponsored by nation-states. They are characterized by:
- Extended dwell time — Months or years inside a network before detection
- Multi-stage attacks — Initial access → reconnaissance → lateral movement → data exfiltration
- Custom tooling — Purpose-built malware that evades commercial antivirus
- Specific objectives — Intellectual property theft, espionage, pre-positioning for future conflict
Supply Chain Compromise: Attackers target trusted vendors/software to reach multiple victims simultaneously. SolarWinds (2020), Kaseya (2021), 3CX (2023).
API Attacks: As organizations expose more APIs, broken authentication, injection, and excessive data exposure become prime targets (OWASP API Security Top 10).
Real Breach Case Study CASE STUDY
Analyze a major breach and map it to the CIA Triad and business impact.
Understanding real-world breaches provides critical context for defensive strategy. We will analyze the Equifax breach (2017) in depth, examining the attack chain, CIA violations, and business consequences.
Vulnerability: Apache Struts (CVE-2017-5638) — unpatched
Dwell Time: 76 days undetected
Total Cost: $1.4+ billion (settlements, fines, remediation)
| Principle | Violation | Impact |
|---|---|---|
| Confidentiality | 147M SSNs, birth dates, addresses, driver's licenses exposed | Mass identity theft, credit fraud, lifelong financial impact for victims |
| Integrity | Unpatched system persisted for months despite known vulnerability | Security infrastructure integrity was fundamentally compromised |
| Availability | Credit services disrupted; dispute portals overwhelmed | Business continuity severely impacted post-disclosure |
- Patch management is critical: The patch was available 2 months before exploitation. Implement automated patching with maximum SLA windows.
- Network segmentation: Once inside the web application, attackers moved freely to internal databases. Proper segmentation would have limited lateral movement.
- Certificate management: Expired SSL certificates on internal inspection tools meant encrypted traffic was not being monitored.
- Incident detection: 76-day dwell time indicates insufficient monitoring and alerting. Invest in SIEM, IDS/IPS, and threat hunting.
MITRE ATT&CK Navigator DEMO
Introduction to ATT&CK, tactics, techniques, and mapping attacker behavior.
The MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It is used as a foundation for threat modeling and behavioral detection.
Techniques (The "How") — Specific methods used to achieve a tactic. (200+ techniques documented)
Procedures (The "Specific Implementation") — Actual observed implementations of techniques by specific threat groups (e.g., APT29 uses T1059.001 — PowerShell — for execution).
- Common language: Security teams, threat intelligence, and blue teams can communicate using standardized terminology
- Detection engineering: Map detection rules to specific techniques to identify coverage gaps
- Threat intelligence: Profile threat groups by their known techniques (e.g., APT29 → T1566.001, T1059.001, T1053.005)
- Red team planning: Structure engagements around the full attack chain
TA0002 — Execution: T1059 (Command and Scripting Interpreter)
TA0003 — Persistence: T1053 (Scheduled Task/Job)
TA0008 — Lateral Movement: T1021 (Remote Services)
TA0010 — Exfiltration: T1048 (Exfiltration Over Alternative Protocol)
CVE, CVSS & NVD DEMO
Understand vulnerability disclosure, severity scoring, and databases.
Understanding how vulnerabilities are discovered, disclosed, cataloged, and scored is essential for prioritizing remediation efforts.
CVE = Prefix
YYYY = Year of assignment
NNNNN = Sequential number
Example:
CVE-2017-5638 = Assigned in 2017, the 5,638th entry.
CVE Program: Maintained by MITRE Corporation. When a vulnerability is discovered, a CVE is requested and assigned a unique identifier. This does NOT include severity scoring — only identification.
CVSS v3.1 provides a standardized way to rate the severity of vulnerabilities. It produces a score from 0.0 to 10.0.
| Score Range | Severity | Color | Action Required |
|---|---|---|---|
| 9.0 – 10.0 | Critical | ● | Patch immediately (24-48 hours) |
| 7.0 – 8.9 | High | ● | Patch within 7 days |
| 4.0 – 6.9 | Medium | ● | Patch within 30 days |
| 0.1 – 3.9 | Low | ● | Patch within 90 days |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAV:N — Attack Vector: Network (remotely exploitable)
AC:L — Attack Complexity: Low (no special conditions)
PR:N — Privileges Required: None (no authentication needed)
UI:N — User Interaction: None (no social engineering)
S:C — Scope: Changed (can impact other components)
C:H/I:H/A:H — Full CIA impact (High across the board)
This is the worst-case scenario: remotely exploitable, no authentication, full impact. Score: 10.0 CRITICAL.
The NVD (nvd.nist.gov) is the U.S. government's authoritative source for vulnerability information. It provides:
- CVE analysis with enhanced data beyond the base CVE description
- CVSS score calculations with all vector details
- Known Exploited Vulnerabilities (KEV) catalog — which CVEs are actively being exploited in the wild
- CPE (Common Platform Enumeration) — which specific products are affected
- References — patches, advisories, and exploit links
Recap, Quiz & Q&A ASSESSMENT
Reinforce key concepts and assess understanding.
The CIA Triad
FOUNDATIONALClick a pillar — or its card below — to see it applied to a real GFS scenario.
Confidentiality
Data accessible only to authorized parties. Enforced via encryption, access controls, classification.
Integrity
Accuracy and consistency of data throughout its lifecycle. Enforced via hashing, signatures, version control.
Availability
Systems and data accessible when needed. Enforced via redundancy, load balancing, DR plans.
Select Confidentiality, Integrity, or Availability above to see it applied to a GFS online-banking scenario.
Threat Categories
7 TYPESClick any threat category for a real example and its primary defense.
Malware
Viruses, worms, trojans, rootkits, spyware.
CRITICALPhishing
Social engineering via deceptive emails & sites.
HIGHRansomware
Encrypts data, demands payment. RaaS lowers barrier.
CRITICALInsider Threats
Malicious/negligent employees with access.
HIGHAPTs
Long-term targeted campaigns by well-funded actors.
CRITICALCloud Attacks
Misconfigs, API exploits, identity attacks.
HIGHSupply Chain
Compromising vendors to infiltrate targets.
CRITICALClick a category above to see a real breach example and how to defend against it.
Breach Analysis
Equifax Data Breach
147M records · July 2017
Confidentiality
SSNs, DOBs, addresses, driver's licenses of 147M exposed.
Integrity
Unpatched Apache Struts (CVE-2017-5638) for months.
Availability
Credit services disrupted; dispute portals overwhelmed.
Target Data Breach
40M cards + 70M records · Dec 2013
Confidentiality
Payment card data stolen from POS across 1,800+ stores.
Integrity
RAM-scraping malware (Kaptoxa) injected into POS systems.
Availability
$100M+ invested in chip-and-PIN post-breach.
SolarWinds Supply Chain
18,000+ orgs · Dec 2020
Confidentiality
Email & data of US agencies and Fortune 500 exfiltrated.
Integrity
Build pipeline compromised — trojanized Orion updates.
Availability
Emergency patching; agencies disconnected Orion entirely.
MITRE ATT&CK — Enterprise Matrix
FRAMEWORKThe ATT&CK framework catalogs Tactics (goals), Techniques (how), and Procedures (specific implementations).
Click any tactic above for its definition, an example technique, and whether it appeared in the Equifax breach.
Equifax Breach — ATT&CK Mapping
Vulnerability Lookup
NVD DEMOSearch a CVE to view its CVSS severity. The NVD is the U.S. government's authoritative vulnerability source.
Hands-On Labs
Click any activity to jump straight to it.
CIA Triad Exercise
Identify which CIA principle is compromised in real-world scenarios.
Breach Analysis
Map a real cyberattack to the CIA Triad and classify impacts.
MITRE ATT&CK Demo
Identify attacker tactics used in the case study breach.
NVD / CVE Demo
Search a CVE and interpret its CVSS score.
Phishing Identification
Not startedReview the email below and select every indicator that marks it as a phishing attempt.
Our records show your password expires today. Failure to re-validate within 2 hours will permanently disable your account.
Re-validate here:
http://gfs-secure-login.verify-portal.ru/authRegards,
IT Helpdesk
gfs-support.co does not match the corporate domain.ruPassword Strength Analyzer
Not startedType a candidate passphrase. Reach a Strong rating to complete the lab.
CIA Triad Matching
Not startedSelect a scenario on the left, then select the CIA pillar it violates. Match all four.
Scenario
CIA Pillar
SOC Alert Prioritisation
Not startedFour alerts land in the queue at the same minute. Which one does an L1 analyst escalate first?
lsass.exe memory accessRisk Assessment
Not startedAn internet-facing server runs an unpatched CVSS 10.0 RCE. Exploit code is public. The server holds regulated customer data. Classify the risk.
Attack Surface Identification
Not startedSelect every GFS asset that forms part of the external attack surface.
www.gfs.comExplore 16 interactive visual simulations covering every core cybersecurity concept from the CIA Triad to the SOC Pipeline.
The CIA Triad
Confidentiality, Integrity, and Availability are the three pillars of information security. Watch each principle break in real time.
Asset → Threat → Vulnerability → Risk
Every risk connects an asset, a vulnerability, and a threat. Build the chain step by step.
Attack Surface
Every exposed entry point increases attack surface. Click each one to inspect.
Authentication vs Authorization
Authentication proves who you are. Authorization determines what you can access.
Multi-Factor Authentication
Toggle MFA on and off. Simulate a stolen password attack to see the difference.
Firewall Rules
A firewall evaluates every packet against rules. Watch packets get allowed or blocked.
Network Segmentation
Segmentation isolates zones. Watch packets traverse or get blocked.
Security Logging
Every action generates a log event. Watch them flow into the SIEM.
SOC Alert Pipeline
Events flow through collection, normalization, correlation, and alert stages.
Incident Response Lifecycle
Step through a real incident from detection to lessons learned.
Defense in Depth
Multiple layers protect data. Watch an attack attempt traverse each layer.
Threat Detection
Compare normal baseline against anomalous behavior.
Security Investigation
Click events. Watch the topology and evidence panel update.
Risk Matrix
Place scenarios on the matrix. The system calculates risk level.
Vulnerability Prioritization
Drag vulnerabilities into priority buckets.
Attack Lifecycle → Defense Telemetry
Watch an attack unfold and see which controls detect it.
Recap Quiz
10 QUESTIONS · 5 LEVELSEach level reflects a stage of the SOC career path, from fresher to business-impact judgment. Answer both questions in a level, then check it.