Enterprise Cybersecurity Academy

Become an Industry-Ready Cybersecurity Professional

Master cybersecurity through interactive concepts, guided labs, enterprise simulations, and real-world scenarios across a structured four-month learning journey.

96
Sessions
55
Core Classes
16
Hands-on Labs
30+
Industry Tools
6
Career Paths
Interactive Career Journey
From foundational concepts to enterprise-grade proficiency — follow the path that transforms beginners into industry-ready professionals.
🛡
Security Foundations
CIA triad, threat landscape, security frameworks (NIST, ISO 27001), risk fundamentals, and the role of cybersecurity in modern organizations.
Weeks 1–2 3 Classes Foundational
🌐
Networking
TCP/IP, DNS, DHCP, HTTP, network security devices, firewall configuration, packet analysis, and network topology design.
Weeks 1–2 3 Classes Wireshark
💻
Operating Systems
Linux filesystem, permissions, Bash scripting, Windows security policy, Active Directory, PowerShell automation, and system hardening.
Weeks 2–3 5 Classes Linux / Windows
🔍
SOC Operations
SIEM dashboards, log management, alert triage, EDR/XDR fundamentals, incident handling workflows, and SOC tier escalation.
Weeks 4–6 7 Classes Splunk / ELK
🎯
Threat Hunting
MITRE ATT&CK mapping, threat intelligence, anomalous behavior detection, Sysmon analysis, and proactive threat hunting methodologies.
Weeks 5–6 3 Classes MITRE ATT&CK
⚔
Ethical Hacking
Reconnaissance, OSINT, scanning, enumeration, vulnerability analysis, exploitation fundamentals, and post-exploitation techniques.
Weeks 7–8 7 Classes Kali / Metasploit
🔐
VAPT
Vulnerability assessment, penetration testing methodology (PTES), web app security (OWASP Top 10), API testing, mobile & wireless pentesting.
Weeks 9–12 11 Classes Burp Suite / Nessus
☁
Cloud Security
Cloud penetration testing, misconfiguration assessment, container security (Docker/Kubernetes), cloud-native threat modeling.
Week 12 1 Class ScoutSuite / Pacu
📋
Governance & Compliance
GRC frameworks, risk management, ISO 27001, NIST 800-53, PCI DSS, HIPAA, GDPR, security audits, BCP/DR, and vendor risk management.
Weeks 13–16 12 Classes GRC / Compliance
🏆
Enterprise Capstone & Career Ready
Full detect → exploit → report → comply simulation. End-to-end enterprise cybersecurity exercise combining SOC, VAPT, and GRC domains.
Week 16 Capstone Job Ready
Career Destinations
Each module maps to a specific industry role. Track your progression from entry-level positions to senior cybersecurity roles.
🛡
Security Fundamentals
IT Support with security awareness, foundational knowledge of threats, frameworks, and defensive principles.
CIA Triad NIST CSF Risk Basics
MITRE ATT&CK NVD/CVE
📊
Junior SOC Analyst
Monitor alerts, triage tickets, and perform initial investigation of security events in a Security Operations Center.
SIEM Alert Triage Log Analysis
Splunk Elastic Wazuh
🔍
SOC Analyst
Handle complex investigations, manage incident escalations, and perform advanced threat correlation.
Incident Response EDR/XDR Threat Intel
Splunk Sysmon CrowdStrike
🎯
Threat Hunter
Proactively hunt for threats using hypothesis-driven investigation and advanced detection techniques.
MITRE ATT&CK Behavioral Analysis Forensics
Sysmon MISP Autopsy
⚔
Ethical Hacker
Identify vulnerabilities through authorized penetration testing and security assessments.
Recon Exploitation Priv Escalation
Kali Linux Metasploit Nmap
🔐
VAPT Engineer
Lead vulnerability assessments and penetration tests across web, network, cloud, and mobile platforms.
OWASP Top 10 Web App Pentest Reporting
Burp Suite Nessus BloodHound
☁
Cloud Security Engineer
Secure cloud infrastructure, identify misconfigurations, and perform cloud-native security assessments.
Cloud Pentest Container Security IAM
ScoutSuite Pacu Docker
📋
Security Consultant
Advisory role combining technical expertise with strategic security guidance for organizations.
Security Audits Risk Assessment Advisory
ISO 27001 NIST 800-53
📝
GRC Analyst
Manage governance, risk, and compliance programs ensuring organizational security posture meets standards.
GRC Compliance Policy Writing
ISO 27001 PCI DSS Archer
4-Month Learning Roadmap
55 structured classes across 16 weeks — from foundational security concepts to enterprise-grade competency.
Month 1 · Weeks 1–4

Security Foundations & SOC Groundwork

Role: Security Fundamentals → Junior SOC Analyst → SOC Analyst (Tier 1/2)
Week 3 — System Administration
C07
Linux Administration, Logging & Scripting
ConceptLab: Bash log parser script
C08
Windows Fundamentals for Security
ConceptLab: Security policy & services
C09
Windows Administration, Active Directory & Logging
ConceptLab: Create AD users/GPOs
C10
PowerShell & Automation for Security
ConceptLab: Automate log-audit script
Week 4 — SOC Introduction
C11
Introduction to SOC Operations
ConceptLab: Tier 1–3 escalation workflow
C12
SIEM Fundamentals
ConceptLab: Build dashboard & queries
C13
Log Management & Log Analysis
ConceptLab: Correlate multi-source logs
Month 2 · Weeks 5–8

SOC Operations into Offensive Security

Role: SOC Analyst (Tier 1/2) → Ethical Hacker / Junior Penetration Tester
Week 5 — SOC Advanced Operations
C14
Alert Triage & Incident Handling
ConceptLab: Triage sample SIEM alerts
C15
EDR/XDR Fundamentals
ConceptLab: Investigate endpoint alerts
C16
Threat Intelligence & MITRE ATT&CK
ConceptLab: Map attack to ATT&CK
C17
Threat Hunting Basics
ConceptLab: Hunt anomalous processes
Week 6 — Incident Response & Forensics
C18
Incident Response Lifecycle
ConceptLab: Tabletop IR exercise
C19
Digital Forensics Fundamentals (DFIR)
ConceptLab: Disk artifact analysis
C20
SOC Tools Lab — Hands-On
LabEnd-to-end alert-to-closure
Week 7 — Ethical Hacking Foundations
C21
Introduction to Ethical Hacking
ConceptLab: Set up attacker/target VMs
C22
Ethical Hacking Methodology
ConceptLab: Draft test scope & ROE
C23
Reconnaissance & OSINT
ConceptLab: Build OSINT profile
C24
Scanning & Enumeration
ConceptLab: Scan & enumerate lab network
Week 8 — Exploitation
C25
Vulnerability Analysis
ConceptLab: Full vuln scan triage
C26
Exploitation Fundamentals
ConceptLab: Exploit a known CVE
C27
Post-Exploitation & Privilege Escalation
ConceptLab: Privilege escalation
Month 3 · Weeks 9–12

Deep Offensive Security & VAPT Specialization

Role: Ethical Hacker / Jr. Pentester → VAPT Analyst / Penetration Tester
Week 9 — Advanced Offensive Techniques
C28
Password Attacks & Credential Access
ConceptLab: Crack password hashes
C29
Social Engineering
ConceptLab: Phishing simulation
C30
Malware Fundamentals for Ethical Hackers
ConceptLab: Sandbox malware analysis
Week 10 — VAPT Methodology
C31
VAPT Methodology & Standards
ConceptLab: Draft VAPT test plan
C32
Vulnerability Assessment Fundamentals
ConceptLab: Score & prioritize findings
C33
Vulnerability Scanning Tools — Hands-On
LabFull-network scan & report
C34
Network Penetration Testing
ConceptLab: Pentest segmented network
Week 11 — Web & API Security
C35
Web App Pentesting — OWASP Top 10
ConceptLab: Exploit OWASP Top 10
C36
Web App Pentesting — Hands-On with Burp Suite
ConceptLab: Intercept live requests
C37
API Security Testing
ConceptLab: Test REST API auth flaws
Week 12 — Specialized Testing
C38
Mobile Application Pentesting (Intro)
ConceptLab: Analyze Android APK
C39
Wireless Penetration Testing
ConceptLab: Crack WPA2 handshake
C40
Active Directory Penetration Testing
ConceptLab: Attack vulnerable AD lab
C41
Cloud Penetration Testing Basics
ConceptLab: Assess misconfigured storage
Month 4 · Weeks 13–16

Reporting, Governance & Job Readiness

Role: VAPT Analyst → GRC Analyst / Compliance Analyst → Job Ready
Week 13 — Reporting & GRC Foundations
C42
VAPT Reporting & Remediation
ConceptLab: Write pentest report
C43
Introduction to GRC
ConceptLab: Map GRC program structure
C44
Information Security Governance
ConceptLab: Draft governance charter
Week 14 — Risk & Compliance
C45
Risk Management Fundamentals
ConceptLab: Score organizational risks
C46
Risk Assessment & Risk Register
ConceptLab: Build working risk register
C47
Security Policies, Standards & Procedures
ConceptLab: Draft acceptable-use policy
C48
Compliance Frameworks — ISO/IEC 27001
ConceptLab: Gap-assess against ISO
Week 15 — Frameworks & Auditing
C49
Compliance Frameworks — NIST
ConceptLab: Map controls to NIST 800-53
C50
Compliance — PCI DSS, HIPAA & GDPR
ConceptLab: Assess compliance gaps
C51
Security Audits & Assessments
ConceptLab: Mock internal audit
Week 16 — Capstone & Career Readiness
C52
Business Continuity & Disaster Recovery
ConceptLab: Draft BCP/DR plan
C53
Third-Party & Vendor Risk Management
ConceptLab: Score vendor risk questionnaire
C54
GRC Tools & Reporting
ConceptLab: Compliance status dashboard
C55
Enterprise Capstone — FinBank Connected Simulator ↗
Interactive LabFree Access
Learning Experience
Every concept is reinforced through a multi-layered approach — learn, build, test, and master.
💡
Interactive Concepts
Deep-dive lessons with visual diagrams, annotated code, and real-world context for every cybersecurity concept.
🔬
Hands-on Labs
Guided lab environments with step-by-step instructions, real tools, and measurable outcomes.
✅
Knowledge Checks
Validate understanding at each milestone with targeted assessments and scenario-based questions.
🏆
Challenges
Solve real-world security scenarios that push beyond the curriculum and develop critical thinking.
📊
Assessments
Comprehensive evaluations combining practical skills with theoretical knowledge at key checkpoints.
🎓
Capstone Projects
End-to-end enterprise simulations combining SOC detection, penetration testing, and GRC compliance.
100% FREE ACCESS · NO LOGIN REQUIRED
FinBank Connected Career Simulator
Experience one real, connected enterprise cybersecurity workflow across five professional roles. Every action produces verifiable evidence, computes your capability scores, and generates job-ready resume bullets.
Primary Enterprise Target

FinBank Online Banking Portal (FB-WEB-01 · 10.10.20.15)

Launch Full Simulator ↗
◆
Evidence Locker
Portfolios from real work
⌁
Capability Engine
6-dimension skill metrics
✓
Interview Arena
Evidence-backed defense
✎
Resume Toolkit
Auto-generated bullets
⚡ Progress and generated evidence are automatically stored locally in your browser.
Start Free FinBank Simulation
Virtual Enterprise
A fully simulated corporate network with interconnected departments — practice real-world security operations in a controlled environment.
🔍
SOC
Security Operations Center
📡
NOC
Network Operations Center
☁
Cloud
Cloud Infrastructure
🔑
Identity
Identity & Access Management
🏢 Enterprise Network
Interactive department simulation with real-time threat monitoring
🖥
Servers
Internal Server Fleet
💻
Endpoints
Employee Workstations
🧱
Firewall
Perimeter Defense
📧
Email
Email Gateway
🧠
Threat Intel
Threat Intelligence Platform
🚨
Incident Response
IR Team Dashboard
📋
Management
Executive Dashboard
Virtual Labs
Dedicated lab environments organized by domain — from foundational Linux to advanced cloud security assessments.
🐧
Linux Labs
12 exercises ~8 hours
Beginner
🪟
Windows Labs
10 exercises ~7 hours
Beginner
🌐 Live Simulator ↗
IP Addressing & Network Identification Lab
Module 03 · Cyber Pressure CIDR & Routing Sim
Launch Standalone ↗
🔍
SOC Labs
14 exercises ~12 hours
Intermediate
📊
Splunk Labs
10 exercises ~8 hours
Intermediate
🦈 RangeForce Cyber-OS ↗
Ports, Protocols & Wireshark Deep Packet Lab
30-Phase Interactive Engine SLA & Multi-Role Aligned
Launch Simulator ↗
🎯
Threat Hunting Labs
6 exercises ~6 hours
Intermediate
⚔
Ethical Hacking Labs
16 exercises ~14 hours
Advanced
🕸
Web Security Labs
12 exercises ~10 hours
Advanced
☁
Cloud Labs
6 exercises ~5 hours
Advanced
🔎
Digital Forensics Labs
8 exercises ~7 hours
Intermediate
📋
GRC Labs
10 exercises ~8 hours
Intermediate
Cybersecurity Tool Ecosystem
Master 30+ industry-standard tools organized by security domain — the same tools used by professional security teams worldwide.
SOC & SIEM
Splunk
SIEM & data analytics
Elastic (ELK)
Search & observability
Wazuh
Open-source SIEM
Graylog
Log management
Microsoft Sentinel
Cloud-native SIEM
Networking
Wireshark
Packet analysis
tcpdump
CLI packet capture
Packet Tracer
Network simulation
Nmap
Network scanner
Linux
Ubuntu
Linux distribution
Kali Linux
Security distribution
Bash
Shell scripting
PowerShell
Windows automation
Penetration Testing
Burp Suite
Web app testing
Metasploit
Exploitation framework
Nessus
Vulnerability scanner
OpenVAS
Open-source vuln scanner
BloodHound
AD attack path analysis
MobSF
Mobile security framework
Aircrack-ng
Wireless cracking
Cloud
Docker
Containerization
Kubernetes
Container orchestration
ScoutSuite
Cloud security auditing
Pacu
AWS exploitation framework
Digital Forensics
Autopsy
Digital forensics platform
FTK Imager
Disk imaging tool
Volatility
Memory forensics
Career Paths
A clearly defined horizontal progression from entry-level IT support to senior cybersecurity roles.
IT Support
Entry Point
Junior SOC
Month 1
SOC Analyst
Month 1–2
Threat Hunter
Month 2
Ethical Hacker
Month 2
VAPT Engineer
Month 3
Cloud Security
Month 3
Security Consultant
Month 4
GRC Analyst
Month 4
Platform Features
Everything you need to learn, practice, and track your cybersecurity career progression.
💡
Interactive Learning
Concept-driven lessons with visual diagrams and annotated code.
🏢
Virtual Enterprise
Simulated corporate network with interconnected departments.
⚡
Enterprise Simulations
End-to-end security scenarios in realistic environments.
🎯
Cyber Range
Isolated attack/defense environments for safe practice.
🔬
Real-world Labs
Guided labs using actual industry tools and real vulnerabilities.
📈
Progress Tracking
Visual dashboards tracking your learning journey milestones.
🏅
Achievements
Earn badges and certificates for completed modules and skills.
📝
Notes & Bookmarks
Save notes, bookmark resources, and download materials.
Latest Updates
Platform improvements, new labs, and upcoming modules.
New
Cloud Penetration Testing Lab
New hands-on lab for assessing misconfigured cloud storage buckets using ScoutSuite and Pacu in a safe sandbox environment.
Added to Month 3 · Week 12
New
Enterprise Capstone Simulation
Full detect → exploit → report → comply simulation combining SOC, VAPT, and GRC domains in one comprehensive exercise.
Added to Month 4 · Week 16
Updated
Splunk Lab Environment
Upgraded Splunk lab environment with fresh datasets and new dashboard templates for SIEM Fundamentals (C12) and Log Management (C13).
Updated this week
Upcoming
Active Directory Attack Labs
Deliberately vulnerable AD lab environment for practicing lateral movement, privilege escalation, and Kerberoasting techniques.
Coming to Month 3
New
Burp Suite Web Security Module
Updated web application pentesting module with hands-on Burp Suite exercises covering OWASP Top 10 exploitation techniques.
Added to Month 3 · Week 11
Updated
GRC Compliance Dashboards
New compliance status dashboard templates for ISO 27001 and NIST 800-53 gap analysis exercises in the GRC module.
Updated this month

Module 1 — Security Foundations & SOC Groundwork

Your lesson runs here inside the academy, exactly as authored. Pick any released class below.

← Back to Roadmap
Module 1 Security Foundations & SOC Groundwork
Open standalone ↗
MODULE 01 — CLASS 01

Cybersecurity Fundamentals
& Threat Landscape

Introduction to Cybersecurity & Security Fundamentals — your first step into defending the digital world.

Duration: 90 min
9 Topics + 4 Practicals
6 Integrated Labs
\n
90-Minute Class Timeline

Class Schedule

LIVE
00:005 min

Course Introduction & Learning Roadmap THEORY

Understand course objectives, assessment, and industry expectations.

Welcome to Module 1: Cybersecurity Fundamentals & Threat Landscape. This is the foundation upon which every subsequent module is built. A solid understanding here will make advanced topics — penetration testing, incident response, forensics — significantly easier.

This course follows a progressive learning model: each module builds on the previous one. You will move from fundamentals (this module) through networking, operating systems, cryptography, offensive security, and finally defensive operations.

📋 Assessment Criteria
Theoretical Exams (40%) — End-of-module written assessments covering concepts, frameworks, and terminology.
Practical Labs (40%) — Hands-on exercises using real tools in isolated lab environments.
Capstone Project (20%) — End-of-course penetration test report or defensive security analysis.

This course maps closely to several globally recognized certifications. Completing it positions you well for:

CompTIA Security+
Entry-level. Covers broad security concepts, threats, operations, and governance. SY0-701
CEH (Certified Ethical Hacker)
Intermediate. Focuses on offensive techniques, enumeration, and exploitation methodologies.
OSCP (OffSec Certified Professional)
Advanced. Hands-on penetration testing certification with 24-hour practical exam.
CompTIA CySA+
Defensive analytics. SIEM, behavioral analytics, vulnerability management.
Career Opportunities in Cybersecurity
Offensive: Penetration Tester, Red Team Operator, Vulnerability Researcher
Defensive: SOC Analyst, Incident Responder, Threat Hunter, DFIR Specialist
Governance: Security Auditor, GRC Analyst, Compliance Officer
Architecture: Security Engineer, Cloud Security Architect, Zero Trust Designer
00:0510 min

What is Cybersecurity? Why It Matters THEORY

Define cybersecurity, information security, and digital transformation.

Cybersecurity is the practice of protecting systems, networks, and programs from digital attacks. These attacks typically aim to access, change, or destroy sensitive information; extort money from users; or disrupt normal business processes.

Cybersecurity
Protection of internet-connected systems from cyber threats. Encompasses hardware, software, data, and network defense.
Information Security (InfoSec)
Broader discipline focused on protecting information in all forms — digital, paper, verbal — regardless of medium.
Network Security
Specifically protecting computer networks from intruders, including targeted attackers or opportunistic malware.
Application Security
Protecting software from threats through design, coding practices, and runtime protection mechanisms.
⚠ The Scale of the Problem
Cybercrime is projected to cost the world $10.5 trillion annually by 2025 (Cybersecurity Ventures). If measured as a country, cybercrime would be the world's third-largest economy after the US and China. There are approximately 3.5 million unfilled cybersecurity positions globally — making it one of the most in-demand career fields.

As organizations undergo digital transformation — moving operations, data, and services online — their attack surface expands dramatically. Every new cloud service, IoT device, mobile endpoint, or API integration creates a potential entry point for attackers.

Physical Business
→
Digitization
→
Digital Transformation
→
Expanded Attack Surface
→
Security Imperative

Organizations must comply with various regulations that mandate security controls:

Key Regulatory Frameworks
GDPR (EU) — Data protection for EU citizens. Fines up to €20M or 4% of global annual revenue.
HIPAA (US) — Protects health information. Mandatory for healthcare organizations.
PCI-DSS (Global) — Security standard for organizations handling payment card data.
SOX (US) — Financial reporting integrity for public companies.
CCPA/CPRA (California) — Consumer privacy rights for California residents.
00:1510 min

Digital Assets & CIA Triad THEORY

Identify enterprise assets and explain Confidentiality, Integrity, and Availability.

Before we can protect anything, we must understand what we are protecting. Digital assets include anything of value to an organization that exists in digital form.

Asset TypeExamplesClassification
DataCustomer PII, financial records, intellectual property, trade secretsCrown Jewels
HardwareServers, workstations, networking equipment, IoT devicesInfrastructure
SoftwareApplications, operating systems, custom code, databasesLogical
ServicesCloud platforms, SaaS applications, APIs, DNSDependencies
PeopleEmployees, contractors, their credentials and access rightsHuman Factor
ReputationBrand trust, customer confidence, market positionIntangible
🔺 CIA Triad
The CIA Triad is the foundational model in information security. Every security control, policy, and mechanism exists to enforce one or more of these three principles. If any pillar is compromised, security has failed.
C — Confidentiality
Ensuring information is accessible only to authorized individuals. Preventing unauthorized disclosure.
Enforcement: Encryption (AES-256, RSA), access control lists (ACLs), role-based access control (RBAC), data classification labels, multi-factor authentication (MFA), Data Loss Prevention (DLP).
I — Integrity
Maintaining the accuracy, consistency, and trustworthiness of data throughout its lifecycle. Preventing unauthorized modification.
Enforcement: Cryptographic hashing (SHA-256, MD5), digital signatures, version control, checksums, database constraints, audit logs, file integrity monitoring (FIM).
A — Availability
Ensuring systems and data are accessible when needed by authorized users. Preventing disruption of service.
Enforcement: Redundancy (RAID, failover clusters), load balancing, DDoS mitigation, disaster recovery (DR) plans, backup systems, uptime SLAs, geographic distribution.
Real-World Scenario: Online Banking
Confidentiality: Your account balance is encrypted in transit (HTTPS/TLS) and at rest. Only you and authorized bank staff can see it.
Integrity: When you transfer $500, the system ensures exactly $500 is deducted — not $5 or $5,000. Transaction logs are tamper-proof.
Availability: The banking app must be accessible 24/7. Redundant servers and load balancers ensure no single point of failure.
⚡ Trade-Offs Exist
Increasing one pillar can sometimes decrease another. For example, extreme confidentiality (multiple encryption layers, hardware tokens) can reduce availability (users struggle to access systems). Security is about finding the right balance for your organization's risk tolerance.
00:2510 min

Threats, Vulnerabilities, Risks & Attacks THEORY

Differentiate threat, vulnerability, exploit, risk, incident, and breach with examples.

These terms are often used interchangeably in casual conversation, but in cybersecurity they have precise, distinct meanings. Confusing them can lead to miscommunication during incident response.

TermDefinitionExample
ThreatA potential cause of an unwanted incident that may harm an assetNation-state hacker group, hurricane, disgruntled employee
VulnerabilityA weakness in a system that a threat can exploitUnpatched software, weak password policy, misconfigured firewall
ExploitCode, technique, or method that takes advantage of a vulnerabilitySQL injection payload, buffer overflow shellcode, phishing email
RiskThe potential for loss when a threat exploits a vulnerabilityRisk = Likelihood × Impact
IncidentAn observed event that compromises (or threatens) CIAMalware detection, unauthorized access attempt, policy violation
BreachA confirmed incident resulting in unauthorized data disclosure147M records exposed in Equifax breach
📐 Risk = Threat × Vulnerability × Impact
Threat: How likely is the threat to exploit the vulnerability? (Probability)
Vulnerability: How easy is the vulnerability to exploit? (Exposure)
Impact: How bad would it be if exploited? (Consequence)

Example: A phishing email (threat) targeting employees with weak security awareness (vulnerability) that could expose customer database (high impact) = High Risk.
Threat Event
→
Vulnerability Exploited
→
Security Incident
→
Data Breach (if data exfiltrated)
Key Distinction
All breaches are incidents, but not all incidents are breaches.

Incident (not a breach): Employee clicks phishing link but IT detects and quarantines the endpoint before any data is accessed.

Breach: Attacker exploits SQL injection to extract 50,000 customer records. Confirmed unauthorized disclosure has occurred.
Nation-State (APT)
Government-sponsored groups with massive resources. Target: espionage, sabotage. Examples: APT28, APT29, Lazarus Group.
Cybercriminal
Financially motivated. Ransomware, fraud, data theft. Often organized like businesses (RaaS, affiliate models).
Hacktivist
Ideologically motivated. Defacement, data leaks for political/social causes. Examples: Anonymous, LulzSec.
Insider
Current/former employees or contractors. Malicious (theft, sabotage) or negligent (accidental exposure).
00:3515 min

Modern Threat Landscape INTERACTIVE

Explore malware, phishing, ransomware, insider threats, APTs, cloud & supply-chain attacks.

The threat landscape is constantly evolving. Attackers refine their techniques, automate exploitation, and monetize access through increasingly sophisticated models. Understanding the current landscape is essential for effective defense.

TypeBehaviorSelf-Replicating?
VirusAttaches to legitimate files; executes when host file runsYes (requires host)
WormSpreads independently across networks without human interactionYes (autonomous)
TrojanDisguised as legitimate software; creates backdoorsNo
RootkitHides deep in OS kernel; maintains persistent, hidden accessNo
SpywareCovertly collects user information and keystrokesNo
RansomwareEncrypts files; demands payment for decryption keySometimes
Fileless MalwareOperates entirely in memory; leaves no disk artifactsNo

Phishing has evolved far beyond mass-sent spam emails:

Spear Phishing
Highly targeted at specific individuals using personalized information gathered through reconnaissance.
Whaling
Spear phishing targeting C-suite executives (CEO, CFO) with high-value lures.
Vishing
Voice phishing — phone calls impersonating IT support, banks, or government agencies.
Smishing
SMS phishing — malicious links sent via text messages. Increasingly common with mobile-first users.
🔒 The RaaS Business Model
Modern ransomware operates like a SaaS business. Developers create the malware and lease it to affiliates who carry out attacks. The developers take 20-30% of the ransom; affiliates keep the rest.

Notable RaaS groups: LockBit, BlackCat/ALPHV, Cl0p, Royal, Play
Average ransom demand (2024): $1.54 million (Sophos)
Average recovery cost: $2.73 million (including downtime)

APTs are long-term, targeted campaigns typically sponsored by nation-states. They are characterized by:

  • Extended dwell time — Months or years inside a network before detection
  • Multi-stage attacks — Initial access → reconnaissance → lateral movement → data exfiltration
  • Custom tooling — Purpose-built malware that evades commercial antivirus
  • Specific objectives — Intellectual property theft, espionage, pre-positioning for future conflict
Emerging Attack Vectors
Cloud Misconfigurations: Exposed S3 buckets, overly permissive IAM roles, unencrypted databases. 82% of breaches involve cloud-stored data (IBM 2023).

Supply Chain Compromise: Attackers target trusted vendors/software to reach multiple victims simultaneously. SolarWinds (2020), Kaseya (2021), 3CX (2023).

API Attacks: As organizations expose more APIs, broken authentication, injection, and excessive data exposure become prime targets (OWASP API Security Top 10).
00:5015 min

Real Breach Case Study CASE STUDY

Analyze a major breach and map it to the CIA Triad and business impact.

Understanding real-world breaches provides critical context for defensive strategy. We will analyze the Equifax breach (2017) in depth, examining the attack chain, CIA violations, and business consequences.

🚨 At a Glance
Records Compromised: 147 million individuals
Vulnerability: Apache Struts (CVE-2017-5638) — unpatched
Dwell Time: 76 days undetected
Total Cost: $1.4+ billion (settlements, fines, remediation)
Vulnerability Identified
→
Patch Available (Mar 7)
→
Equifax Fails to Patch
→
Exploitation (May 13)
→
Lateral Movement (76 days)
→
Data Exfiltration
→
Discovery (Jul 29)
PrincipleViolationImpact
Confidentiality147M SSNs, birth dates, addresses, driver's licenses exposedMass identity theft, credit fraud, lifelong financial impact for victims
IntegrityUnpatched system persisted for months despite known vulnerabilitySecurity infrastructure integrity was fundamentally compromised
AvailabilityCredit services disrupted; dispute portals overwhelmedBusiness continuity severely impacted post-disclosure
  • Patch management is critical: The patch was available 2 months before exploitation. Implement automated patching with maximum SLA windows.
  • Network segmentation: Once inside the web application, attackers moved freely to internal databases. Proper segmentation would have limited lateral movement.
  • Certificate management: Expired SSL certificates on internal inspection tools meant encrypted traffic was not being monitored.
  • Incident detection: 76-day dwell time indicates insufficient monitoring and alerting. Invest in SIEM, IDS/IPS, and threat hunting.
Class Discussion Prompt
If you were Equifax's CISO, what three immediate actions would you have taken to prevent this breach? Consider patch management, network architecture, and monitoring capabilities.
01:0510 min

MITRE ATT&CK Navigator DEMO

Introduction to ATT&CK, tactics, techniques, and mapping attacker behavior.

The MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It is used as a foundation for threat modeling and behavioral detection.

🏗️ Three-Layer Model
Tactics (The "Why") — High-level goals the attacker is trying to achieve. Think of these as phases of an attack. (14 Enterprise tactics)

Techniques (The "How") — Specific methods used to achieve a tactic. (200+ techniques documented)

Procedures (The "Specific Implementation") — Actual observed implementations of techniques by specific threat groups (e.g., APT29 uses T1059.001 — PowerShell — for execution).
Recon
→
Initial Access
→
Execution
→
Persistence
→
Priv Esc
→
Defense Evasion
→
Lateral Move
→
Exfiltration
→
Impact
  • Common language: Security teams, threat intelligence, and blue teams can communicate using standardized terminology
  • Detection engineering: Map detection rules to specific techniques to identify coverage gaps
  • Threat intelligence: Profile threat groups by their known techniques (e.g., APT29 → T1566.001, T1059.001, T1053.005)
  • Red team planning: Structure engagements around the full attack chain
Mapping Equifax to ATT&CK
TA0001 — Initial Access: T1190 (Exploit Public-Facing Application — Apache Struts)
TA0002 — Execution: T1059 (Command and Scripting Interpreter)
TA0003 — Persistence: T1053 (Scheduled Task/Job)
TA0008 — Lateral Movement: T1021 (Remote Services)
TA0010 — Exfiltration: T1048 (Exfiltration Over Alternative Protocol)
01:1510 min

CVE, CVSS & NVD DEMO

Understand vulnerability disclosure, severity scoring, and databases.

Understanding how vulnerabilities are discovered, disclosed, cataloged, and scored is essential for prioritizing remediation efforts.

🔖 CVE Identifier Format
CVE-YYYY-NNNNN
CVE = Prefix
YYYY = Year of assignment
NNNNN = Sequential number

Example: CVE-2017-5638 = Assigned in 2017, the 5,638th entry.

CVE Program: Maintained by MITRE Corporation. When a vulnerability is discovered, a CVE is requested and assigned a unique identifier. This does NOT include severity scoring — only identification.

CVSS v3.1 provides a standardized way to rate the severity of vulnerabilities. It produces a score from 0.0 to 10.0.

Score RangeSeverityColorAction Required
9.0 – 10.0Critical●Patch immediately (24-48 hours)
7.0 – 8.9High●Patch within 7 days
4.0 – 6.9Medium●Patch within 30 days
0.1 – 3.9Low●Patch within 90 days
Reading a CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AV:N — Attack Vector: Network (remotely exploitable)
AC:L — Attack Complexity: Low (no special conditions)
PR:N — Privileges Required: None (no authentication needed)
UI:N — User Interaction: None (no social engineering)
S:C — Scope: Changed (can impact other components)
C:H/I:H/A:H — Full CIA impact (High across the board)

This is the worst-case scenario: remotely exploitable, no authentication, full impact. Score: 10.0 CRITICAL.

The NVD (nvd.nist.gov) is the U.S. government's authoritative source for vulnerability information. It provides:

  • CVE analysis with enhanced data beyond the base CVE description
  • CVSS score calculations with all vector details
  • Known Exploited Vulnerabilities (KEV) catalog — which CVEs are actively being exploited in the wild
  • CPE (Common Platform Enumeration) — which specific products are affected
  • References — patches, advisories, and exploit links
01:255 min

Recap, Quiz & Q&A ASSESSMENT

Reinforce key concepts and assess understanding.

1. CIA Triad is Foundational
Every security control exists to protect Confidentiality, Integrity, or Availability. Apply this lens to every scenario.
2. Precise Terminology Matters
Threats, vulnerabilities, exploits, risks, incidents, and breaches are distinct concepts. Use them correctly.
3. The Threat Landscape is Evolving
RaaS, APTs, supply chain attacks, and cloud-native threats require continuous learning and adaptation.
4. Frameworks Enable Structure
ATT&CK maps attacker behavior. CVE/CVSS systematizes vulnerability management. Use them.
5. Learn from Real Breaches
Equifax, Target, SolarWinds — every major breach teaches us something about defense. Study the past to protect the future.
📖 Coming Up in Class 2
We will dive into Networking Fundamentals — TCP/IP, the OSI model, DNS, HTTP/S, and how understanding network protocols is essential for both attack and defense.
Core Framework

The CIA Triad

FOUNDATIONAL

Click a pillar — or its card below — to see it applied to a real GFS scenario.

CConfidentiality
IIntegrity
AAvailability
🛡️
Confidentiality

Data accessible only to authorized parties. Enforced via encryption, access controls, classification.

✅
Integrity

Accuracy and consistency of data throughout its lifecycle. Enforced via hashing, signatures, version control.

⚡
Availability

Systems and data accessible when needed. Enforced via redundancy, load balancing, DR plans.

Select Confidentiality, Integrity, or Availability above to see it applied to a GFS online-banking scenario.

Modern Threat Landscape

Threat Categories

7 TYPES

Click any threat category for a real example and its primary defense.

🦠
Malware

Viruses, worms, trojans, rootkits, spyware.

CRITICAL
🎣
Phishing

Social engineering via deceptive emails & sites.

HIGH
🔒
Ransomware

Encrypts data, demands payment. RaaS lowers barrier.

CRITICAL
👤
Insider Threats

Malicious/negligent employees with access.

HIGH
🎯
APTs

Long-term targeted campaigns by well-funded actors.

CRITICAL
☁️
Cloud Attacks

Misconfigs, API exploits, identity attacks.

HIGH
🔗
Supply Chain

Compromising vendors to infiltrate targets.

CRITICAL

Click a category above to see a real breach example and how to defend against it.

Real Breach Case Study

Breach Analysis

Equifax Data Breach

147M records · July 2017

Confidentiality

SSNs, DOBs, addresses, driver's licenses of 147M exposed.

Integrity

Unpatched Apache Struts (CVE-2017-5638) for months.

Availability

Credit services disrupted; dispute portals overwhelmed.

Attack Vector: Unpatched Apache Struts. Patch was available 2 months before exploitation. 76-day dwell time. Total cost: $1.4B+.

Target Data Breach

40M cards + 70M records · Dec 2013

Confidentiality

Payment card data stolen from POS across 1,800+ stores.

Integrity

RAM-scraping malware (Kaptoxa) injected into POS systems.

Availability

$100M+ invested in chip-and-PIN post-breach.

Attack Vector: Third-party HVAC vendor credentials phished via email. Kaptoxa RAM-scraping malware deployed on POS. Total cost: $292M.

SolarWinds Supply Chain

18,000+ orgs · Dec 2020

Confidentiality

Email & data of US agencies and Fortune 500 exfiltrated.

Integrity

Build pipeline compromised — trojanized Orion updates.

Availability

Emergency patching; agencies disconnected Orion entirely.

Attack Vector: APT29 compromised the build pipeline. SUNBURST → TEARDROP → BEACON. 14-month dwell time. Most sophisticated supply chain attack in history.
MITRE ATT&CK Navigator

MITRE ATT&CK — Enterprise Matrix

FRAMEWORK

The ATT&CK framework catalogs Tactics (goals), Techniques (how), and Procedures (specific implementations).

TA0043
Reconnaissance
Gather target info
TA0042
Resource Dev
Establish infra
TA0001
Initial Access
Gain foothold
TA0002
Execution
Run malicious code
TA0003
Persistence
Maintain access
TA0004
Priv Escalation
Higher privileges
TA0005
Defense Evasion
Avoid detection
TA0006
Cred Access
Steal creds
TA0007
Discovery
Explore env
TA0008
Lateral Move
Move through net
TA0009
Collection
Gather data
TA0011
C2
Command & Control
TA0010
Exfiltration
Steal data out
TA0040
Impact
Disrupt ops

Click any tactic above for its definition, an example technique, and whether it appeared in the Equifax breach.

Equifax Breach — ATT&CK Mapping
Initial Access
Execution
Persistence
Lateral Move
Collection
CVE, CVSS & NVD

Vulnerability Lookup

NVD DEMO

Search a CVE to view its CVSS severity. The NVD is the U.S. government's authoritative vulnerability source.

CVE-2017-5638
10.0 CRITICAL
Integrated Practical Activities

Hands-On Labs

Click any activity to jump straight to it.

CIA Triad Exercise

Identify which CIA principle is compromised in real-world scenarios.

5 min

Breach Analysis

Map a real cyberattack to the CIA Triad and classify impacts.

10 min

MITRE ATT&CK Demo

Identify attacker tactics used in the case study breach.

5 min

NVD / CVE Demo

Search a CVE and interpret its CVSS score.

5 min
Hands-On Labs
LAB 01

Phishing Identification

Not started

Review the email below and select every indicator that marks it as a phishing attempt.

From: IT-Helpdesk <it-helpdesk@gfs-support.co>
To: j.mercer@gfs.com
Subject: URGENT: Your mailbox will be deactivated in 2 hours
Dear User,
Our records show your password expires today. Failure to re-validate within 2 hours will permanently disable your account.

Re-validate here: http://gfs-secure-login.verify-portal.ru/auth

Regards,
IT Helpdesk
Sender domain gfs-support.co does not match the corporate domain
Artificial urgency — "2 hours" deadline
The email contains a subject line
Link points to an unrelated foreign TLD .ru
Generic salutation "Dear User" instead of the recipient name
Email is addressed to an internal employee
LAB 02

Password Strength Analyzer

Not started

Type a candidate passphrase. Reach a Strong rating to complete the lab.

No input0 bits
■ 12+ characters
■ Uppercase letter
■ Lowercase letter
■ Number
■ Symbol
■ Not a common password
LAB 03

CIA Triad Matching

Not started

Select a scenario on the left, then select the CIA pillar it violates. Match all four.

Scenario
Customer database dumped on a leak forum
Attacker alters payroll bank account numbers
Ransomware encrypts the ERP file server
Log files silently modified to erase attacker activity
CIA Pillar
Confidentiality
Integrity — financial data tampering
Availability
Integrity — audit trail tampering
LAB 04

SOC Alert Prioritisation

Not started

Four alerts land in the queue at the same minute. Which one does an L1 analyst escalate first?

17 failed logons for a service account over 4 hours
Domain Controller — successful logon from an unrecognised country followed by lsass.exe memory access
Antivirus quarantined an EICAR test file on a lab workstation
Expired TLS certificate on an internal wiki
LAB 05

Risk Assessment

Not started

An internet-facing server runs an unpatched CVSS 10.0 RCE. Exploit code is public. The server holds regulated customer data. Classify the risk.

Low
Medium
High
Critical
LAB 06

Attack Surface Identification

Not started

Select every GFS asset that forms part of the external attack surface.

Public web application www.gfs.com
VPN concentrator exposed on TCP/443
Air-gapped OT historian in Plant 2
SaaS tenant with federated SSO
Offline backup tapes in the vault
Third-party vendor with an API integration
Interactive Simulations

Explore 16 interactive visual simulations covering every core cybersecurity concept from the CIA Triad to the SOC Pipeline.

Sections
⚡
CIA Triad
Core concept
🔗
Asset → Risk Chain
Concept
🌐
Attack Surface
Security
🔑
Auth vs Authz
Access Control
📱
MFA
Security
🛡
Firewall
Network
🔀
Segmentation
Network
📋
Logging
Monitoring
🏢
SOC Pipeline
Monitoring
🚨
Incident Response
Response
🧱
Defense in Depth
Response
🔍
Threat Detection
Detection
🔎
Investigation
Detection
📊
Risk Matrix
Risk
⚠
Vuln Prioritization
Risk
⚔
Attack → Defense
Integrated

The CIA Triad

Confidentiality, Integrity, and Availability are the three pillars of information security. Watch each principle break in real time.

Enterprise Data Flow Simulation
Click a simulation button to watch the attack visually unfold.

Asset → Threat → Vulnerability → Risk

Every risk connects an asset, a vulnerability, and a threat. Build the chain step by step.

Attack Chain Visualization
Click "Advance Step" to reveal each element.

Attack Surface

Every exposed entry point increases attack surface. Click each one to inspect.

Company Network Topology
Click any entry point to inspect its exposure level.

Authentication vs Authorization

Authentication proves who you are. Authorization determines what you can access.

Identity Flow Simulation
Choose a user to watch the identity flow.

Multi-Factor Authentication

Toggle MFA on and off. Simulate a stolen password attack to see the difference.

MFA Protection Simulation
MFA: ENABLED
Toggle MFA, then run the stolen password attack.

Firewall Rules

A firewall evaluates every packet against rules. Watch packets get allowed or blocked.

Packet Flow Simulation
Send packets and watch the firewall evaluate rules.

Network Segmentation

Segmentation isolates zones. Watch packets traverse or get blocked.

Network Segmentation Topology
Send traffic between zones.

Security Logging

Every action generates a log event. Watch them flow into the SIEM.

Live Event Generator
ACTIONS
SIEM LOG STREAM
Click actions to generate log events.

SOC Alert Pipeline

Events flow through collection, normalization, correlation, and alert stages.

SOC Pipeline
Generate events and watch them flow through the pipeline.

Incident Response Lifecycle

Step through a real incident from detection to lessons learned.

Incident Timeline: WORKSTATION-101
CURRENT PHASE
Click "Advance" to begin.

Defense in Depth

Multiple layers protect data. Watch an attack attempt traverse each layer.

Layered Defense Simulation
Choose an attack level.

Threat Detection

Compare normal baseline against anomalous behavior.

Traffic Analysis
NORMAL BASELINE
LIVE TRAFFIC
Generate traffic and compare.

Security Investigation

Click events. Watch the topology and evidence panel update.

Investigation Dashboard
TOPOLOGY
EVIDENCE
Click an event below.
EVENT TIMELINE

Risk Matrix

Place scenarios on the matrix. The system calculates risk level.

Interactive Risk Assessment
RISK MATRIX
SCENARIOS
Select a scenario, then click a cell.

Vulnerability Prioritization

Drag vulnerabilities into priority buckets.

Prioritize Vulnerabilities
Drag each vulnerability into the appropriate bucket.

Attack Lifecycle → Defense Telemetry

Watch an attack unfold and see which controls detect it.

Attack & Defense Timeline
ATTACKER
DEFENSE
Click "Advance Attack" to progress.
Knowledge Check

Recap Quiz

10 QUESTIONS · 5 LEVELS

Each level reflects a stage of the SOC career path, from fresher to business-impact judgment. Answer both questions in a level, then check it.

Overall score0 / 10
MODULE 01 — CLASS 02

Networking Fundamentals
for Security

How data actually moves across a network — OSI/TCP-IP, addressing, ports and protocols — and why every attack starts here.

Duration: 90 min
9 Topics + 4 Practicals
6 Integrated Labs
Tools: Wireshark · Packet Tracer
\n
90-Minute Class Timeline

Class Schedule

LIVE
00:005 min

Recap & Why Networking Matters for Security THEORY

Bridge Class 1's threat landscape into how attacks actually travel.

In Class 1 you learned what threats, vulnerabilities, and risk are. Every one of those threats — malware, phishing, ransomware, APTs — has to travel across a network to reach its target, and every SOC alert you'll ever triage is, at its core, a record of network traffic. You cannot defend what you don't understand, so this class builds the networking foundation everything else in this course sits on.

A SOC analyst who doesn't understand TCP/IP can't read a firewall log, can't tell a normal DNS query from data exfiltration, and can't explain why blocking a port stops an attack. Networking is the language every security tool — SIEM, IDS/IPS, firewall, EDR — is written in.

📋 What This Class Covers
The OSI & TCP/IP models (how data is layered), IP addressing & subnetting (how hosts are identified and grouped), MAC addresses, ARP & switching (how devices find each other locally), routing & NAT (how traffic leaves the LAN), ports, protocols & services (how applications talk), and the network-based attacks that abuse all of the above.
Security Fundamentals
→
Networking (you are here)
→
OS Security
→
Cryptography
→
Offensive / Defensive Ops
00:0515 min

The OSI Model & TCP/IP Stack THEORY

Seven layers of abstraction that every network conversation passes through.

The OSI (Open Systems Interconnection) Model is a conceptual framework that splits network communication into seven layers. Real-world networking runs on the leaner TCP/IP model (four layers), but OSI remains the shared vocabulary the entire industry — and every certification exam — uses to describe where a problem or an attack is happening.

Each layer only talks to the layers directly above and below it. This means a web developer never has to think about electrical signaling, and a network engineer never has to think about HTML — each layer encapsulates the one above it and hands off to the one below, adding its own header as data descends the stack.

🧠 Memory Aid
Top to bottom — "All People Seem To Need Data Processing" — Application, Presentation, Session, Transport, Network, Data Link, Physical. Bottom to top for troubleshooting — start at Physical (is it plugged in?) and work up.

Explore the interactive stack below — click any layer for its job, its protocols, and a matching attack technique.

00:2015 min

IP Addressing & Subnetting Basics THEORY

IPv4 structure, classes, private ranges, CIDR notation and subnet masks.

An IPv4 address is a 32-bit number, written as four decimal octets (e.g. 192.168.1.10), that uniquely identifies a device on a network. A subnet mask (or its shorthand, CIDR notation like /24) splits that address into a network portion and a host portion.

Public IP
Globally unique, routable on the internet. Assigned by ISPs / regional registries (ARIN, RIPE).
Private IP (RFC 1918)
Reserved ranges reused inside every LAN: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16.
Loopback
127.0.0.0/8 — always refers back to the local host itself.
APIPA
169.254.0.0/16 — auto-assigned when a device can't reach a DHCP server. Sign of a networking problem.
CIDRSubnet MaskUsable HostsTypical Use
/24255.255.255.0254Standard office LAN
/25255.255.255.128126Split floor into two segments
/30255.255.255.2522Point-to-point router link
/16255.255.0.065,534Large corporate site
⚠ Why Analysts Care About Subnetting
Subnetting is how organizations enforce network segmentation — keeping guest Wi-Fi, finance workstations, and production servers on separate subnets so a compromise in one doesn't automatically reach the others. Try the live Subnet Calculator later in this class.
00:3510 min

MAC Addresses, ARP & Switching THEORY

How devices on the same LAN actually find one another.

Every network interface has a MAC (Media Access Control) address — a 48-bit identifier burned into the hardware, e.g. 00:1A:2B:3C:4D:5E. While IP addresses route traffic between networks, MAC addresses deliver traffic to the correct device within a single local segment.

ARP (Address Resolution Protocol) is how a device discovers which MAC address owns a given IP address on the local subnet. A device broadcasts "Who has 192.168.1.1?" and the owner replies with its MAC — the requester caches this mapping in its ARP table.

Hub
Legacy device. Repeats every frame to every port — no intelligence, high collision risk. Rare today.
Switch
Learns MAC addresses per port and forwards frames only to the intended destination — far more efficient and secure than a hub.
Router
Operates at Layer 3. Forwards packets between different networks based on IP address.
Access Point
Bridges wireless clients (802.11) onto the wired switch fabric.
🔓 Security Weakness: ARP Has No Authentication
ARP trusts whatever reply arrives first — it has no built-in verification. This is exactly what ARP spoofing / poisoning abuses (covered in the Threats section below) to redirect traffic through an attacker's machine.
00:4510 min

Routing & NAT THEORY

How traffic leaves the LAN and reaches the internet — and back again.

Routing is the process of forwarding packets between different networks based on their destination IP address, using a routing table. A router examines the destination network, matches it against known routes, and forwards accordingly — hop by hop — until the packet reaches its destination network.

Every host is configured with a default gateway — the router it sends traffic to whenever the destination isn't on its local subnet. Get this wrong and a device can talk to local machines but never reach the internet.

Why NAT Exists
IPv4 has roughly 4.3 billion addresses — nowhere near enough for every device on Earth. NAT lets an entire private network share one public IP by rewriting source addresses as traffic exits the router. This is also why an internal attacker's real IP is hidden from the outside — and why logging the NAT translation table matters during incident response.
Internal host 192.168.1.10
→
NAT rewrites source to public IP
→
Internet
00:5510 min

Ports, Protocols & Services THEORY

TCP vs UDP, the three-way handshake, and the ports every analyst must know.

A port is a 16-bit number (0–65535) that identifies which application on a host should receive incoming traffic. An IP address gets a packet to the right device; a port gets it to the right service on that device.

PropertyTCPUDP
ConnectionConnection-oriented (handshake)Connectionless
ReliabilityGuaranteed delivery, orderedBest-effort, no guarantee
SpeedSlower (overhead)Faster (minimal overhead)
Use CaseHTTP/S, SSH, email, file transferDNS queries, video/voice streaming, DHCP
🤝 The TCP Three-Way Handshake
SYN (client requests connection) → SYN-ACK (server acknowledges & responds) → ACK (client confirms). This is also what a SYN flood DDoS abuses — flooding a server with SYNs and never completing the handshake to exhaust its connection table.

Explore the most important well-known ports in the interactive reference later in this class — every one of them shows up repeatedly in SOC alerts.

01:0515 min

Network-Based Attacks INTERACTIVE

ARP spoofing, MITM, DNS spoofing, port scanning, DDoS and more.

Nearly every attack you studied in Class 1 has a network-layer component. Understanding how these attacks manipulate protocols is what separates an analyst who can only follow a runbook from one who can reason about a novel alert.

Before exploitation, attackers map the network: port scanning (Nmap) identifies open ports and running services; network sniffing (Wireshark, tcpdump) captures unencrypted traffic; banner grabbing reveals software versions to target with known exploits.

Explore the full interactive attack-category grid below — click any card for a real example and its primary defense.

01:205 min

Building & Inspecting a LAN PRACTICAL

Practical lab context: a small office LAN in Cisco Packet Tracer.

Today's hands-on lab uses Cisco Packet Tracer to build a small GFS branch-office LAN: a switch, a router, three workstations, and a server — then verify connectivity and inspect how addressing and segmentation decisions play out in practice.

  • Place a switch, router, and end devices onto the topology canvas
  • Assign static IPs from the correct subnet to each workstation
  • Configure the router's default gateway interface
  • Use ping and tracert in simulation mode to verify end-to-end reachability
  • Segment guest devices onto a separate VLAN and confirm they can't reach internal servers
Why This Matters
Building the topology yourself is the fastest way to internalize how IP addressing, default gateways, and switching interact — concepts that stay abstract until you've had to troubleshoot a device that "can't reach the internet."
01:255 min

Tool Preview: Wireshark & Packet Tracer PRACTICAL

What each tool is for, and where you'll use them across this course.

Wireshark
A packet capture and protocol analyzer. Lets you see every byte crossing an interface — headers, payloads, handshakes. The primary tool for network forensics and traffic analysis.
Cisco Packet Tracer
A network simulation environment for designing, configuring, and testing topologies — switches, routers, VLANs — without physical hardware.
🔭 Looking Ahead
We will dive into deeper protocol analysis — DNS, HTTP/S request/response structure, and full packet-capture walkthroughs — as this module continues, building directly on today's addressing and protocol foundation.
Core Framework

The OSI Model & TCP/IP Stack

FOUNDATIONAL

Click any layer to see its job, its protocols, and a matching attack technique.

L7Application
HTTP, DNS, FTP, SMTP
TCP/IP: Application
L6Presentation
Encryption, encoding, TLS/SSL
TCP/IP: Application
L5Session
Session establishment, auth
TCP/IP: Application
L4Transport
TCP, UDP — ports, handshake
TCP/IP: Transport
L3Network
IP, ICMP, routing
TCP/IP: Internet
L2Data Link
MAC addresses, ARP, switches
TCP/IP: Network Access
L1Physical
Cables, radio, voltages, NICs
TCP/IP: Network Access

Select a layer on the left to see its purpose, key protocols, and a real attack technique that targets it.

Modern Threat Landscape

Network Attack Categories

7 TYPES

Click any attack category for a real example and its primary defense.

🕸️
ARP Spoofing

Forged ARP replies redirect local traffic through the attacker.

HIGH
🎭
Man-in-the-Middle

Attacker secretly intercepts traffic between two parties.

CRITICAL
🧭
DNS Spoofing

Poisoned DNS responses redirect users to malicious sites.

HIGH
🔍
Port Scanning

Reconnaissance to map open ports and running services.

HIGH
🌊
DoS / DDoS

Floods a target's bandwidth or resources to deny service.

CRITICAL
📶
MAC Flooding

Overflows a switch's MAC table, forcing hub-like broadcast.

HIGH
🛰️
Rogue DHCP

Unauthorized DHCP server hands out malicious gateway/DNS.

CRITICAL

Click a category above to see a real example and how to defend against it.

Real Breach Case Study

Breach Analysis

Mirai Botnet DDoS

Dyn DNS, 1.2Tbps peak · Oct 2016

Vulnerability

IoT devices (cameras, routers) with unchanged default telnet credentials.

Attack Method

Compromised devices formed a botnet flooding Dyn's DNS infrastructure.

Impact & Scale

Twitter, Netflix, Reddit, PayPal unreachable across the US East Coast.

Attack Vector: Mirai malware scanned the internet for IoT devices with default telnet logins, recruiting them into a botnet that generated a record 1.2 Tbps flood against a single DNS provider — a single point of failure for huge swaths of the internet.

GitHub Memcached DDoS

1.35Tbps peak · Feb 2018

Vulnerability

Publicly exposed Memcached servers with UDP support enabled.

Attack Method

Spoofed source IP requests triggered a 51,000x amplification factor.

Impact & Scale

GitHub offline for roughly 10 minutes at the then-largest DDoS on record.

Attack Vector: Attackers spoofed GitHub's IP as the source of small requests to open Memcached servers, which replied with massively amplified responses directly at GitHub — a textbook UDP amplification attack.

Kaminsky DNS Cache-Poisoning Flaw

Global DNS infrastructure · Jul 2008

Vulnerability

Predictable DNS transaction IDs allowed forged responses to be accepted.

Attack Method

Attacker floods a resolver with guesses to poison its cache before the real answer arrives.

Impact & Scale

Coordinated, simultaneous multi-vendor patch release — a first for the internet.

Attack Vector: Researcher Dan Kaminsky discovered that a resolver could be tricked into caching a forged DNS record, silently redirecting every user of that resolver to an attacker-controlled server — affecting almost every DNS implementation in existence.
Ports & Protocols Reference

Well-Known Ports

REFERENCE

Every SOC alert names a port. Click any tile for its protocol, transport type, and a security note.

TCP/21
FTP
File transfer
TCP/22
SSH
Secure shell
TCP/23
Telnet
Remote login
TCP/25
SMTP
Send email
UDP/53
DNS
Name resolution
UDP/67
DHCP
IP assignment
TCP/80
HTTP
Web traffic
TCP/443
HTTPS
Encrypted web
TCP/445
SMB
File sharing
TCP/3306
MySQL
Database
TCP/3389
RDP
Remote desktop
TCP/8080
HTTP-Alt
Proxy / web-alt

Click any port above for its protocol details and a real-world security note.

Ports Scanned in the Mirai Botnet Reconnaissance Sweep
Telnet (23)
SSH (22)
HTTP (80)
HTTPS (443)
DNS (53)
Subnet Calculator

IPv4 Subnet Calculator

LIVE TOOL

Enter an IP address with CIDR notation (e.g. 192.168.1.10/24) to see the network breakdown.

Enter a valid IPv4 address with a /0–/32 CIDR suffix.
Integrated Practical Activities

Hands-On Labs

Click any activity to jump straight to it.

OSI Layer Matching

Match protocols and devices to the correct OSI layer.

5 min

Breach Analysis

Examine a real network attack and classify the vulnerability exploited.

10 min

Ports Reference Demo

Identify which ports were scanned in the Mirai reconnaissance sweep.

5 min

Subnet Calculator

Calculate a network address, broadcast, and usable host range.

5 min
Hands-On Labs
Phase 1
Foundation
HTTP GET Request flow (Client to Server)
Phase 2
Core Protocols
ARP Broadcast & DNS Resolution
Phase 3
Perimeter
Firewall NAT & Port Forwarding
Phase 4
Security Arena
SYN Flood Attack Simulation
Phase 5
Investigator
Data Exfiltration Incident Response

Phase 1: Foundation (Client → Server)

LIVE TOPOLOGY

Watch an HTTP request travel hop by hop, with the OSI layer, protocol, and device updating live.

Current Device
—
Protocol
—
OSI Layer
—
TCP/IP Layer
—

Device Inspector

Click any device on the canvas to inspect its configuration.

Packet Timeline

No simulation run yet. Press "Run Simulation".

Packet Inspector

PACKET DATA

Layer matching the current step is highlighted.

Knowledge Check

Recap Quiz

10 QUESTIONS · 5 LEVELS

Each level reflects a stage of the SOC career path, from fresher to business-impact judgment. Answer both networking questions in a level, then check it.

Overall score0 / 10
Saved automatically on this device.