
Survey the cyber security landscape from real-world attacks and data theft to zero-days, using Cyber Kill Chain and MITRE ATT&CK Framework to understand threats and defense.
Explore the rise of sophisticated, targeted attacks, define advanced persistent threat (APT), and examine notable cases from moonlight maze to aurora, highlighting nation-state and cybercrime roles.
Explore how well-funded states breach diverse systems, highlighting Shadow Brokers and Vault 7, and define exploits and zero-days with examples like EternalBlue and DoublePulsar.
This lecture shows how theft and resale of data escalate, citing major breaches like Dropbox, Yahoo, and LinkedIn, and explains leak dating, dark web, and password managers.
Explore massive and evolving cyber threats, from SolarWinds and ProxyLogon to ransomware, data extortion, and mobile malware, highlighting big game hunting and RaaS.
Explore why detecting advanced malicious activity is increasingly difficult as attackers hide footprints, erase evidence, and use obfuscated techniques such as ICMP, DNS abuse, encrypted C2 channels, and steganography.
Explore how zero-day vulnerabilities drive a lucrative, dark market among governments, researchers, and vendors, with escalating bug bounty payouts and ethical questions around responsible disclosure.
Cyber criminals stop at nothing for profit, encrypting hospital data for ransom and selling data and live access on the dark web.
Prioritize threats from known vulnerabilities, zero-days, and malware-driven compromises, with emphasis on big game hunting and ransomware. Use threat modeling and rapid patching to reduce risk.
Explore attacker profiles—nation-state, cyber criminals, gray hats, hacktivists, and script kiddies—and their motivations, from espionage and cybercrime to financial aims, targeting technology, manufacturing, telecom, and finance.
Study six representative apt groups, including apt41, silent librarian (ta407), carbanak, lazarus, fancy bear (apt28), and equation group, to master cyber threat intelligence through this optional homework.
Master the cyber kill chain model developed by Lockheed Martin to understand how attackers progress from reconnaissance to actions on the objectives, including weaponization, delivery, exploitation, installation, and C2 channels.
Explore the MITRE ATT&CK framework as a mid-level model linking attacker tactics, techniques and procedures to defenses, with the Enterprise matrix of 14 tactics and TTP-based threat intelligence.
Compare attack lifecycles across attacker types—APTs with comprehensive preparation and erasing tracks, hacktivists with visible exfiltration, and commodity threats with rapid, automated access and data exfiltration.
Explore the diamond model for intrusion analysis as an optional perspective, alongside the cyber kill chain and MITRE ATT&CK framework, with references and learning instructions.
Study real-life attack scenarios on clients and servers, including spear-phishing, infected USB drives, browser exploits, and exposed services, plus detection, mitigation, and red team exercises.
Explore spear-phishing tactics, from passive reconnaissance to sending tailored emails with malicious documents, backdoors, and a C2 channel, mapped to the cyber kill chain.
Explore the infected usb drive scenario to trace the cyber kill chain from reconnaissance to exfiltration, and learn defense practices like user training, deactivating usb ports, whitelisting, and endpoint protection.
Explore browser exploitation from reconnaissance to exfiltration, covering waterholing, social engineering, client-side attacks, privilege escalation, installation of backdoors, and the cyber kill chain.
Examine exploitation of exposed services from reconnaissance to backdoors, via known or zero-day vulnerabilities, valid accounts, brute-force or credential stuffing, and discuss defenses like up-to-date systems and firewalls.
Explore the Epic Turla APT case, a large-scale cyber espionage operation across more than 45 countries, leveraging zero-day and other exploits, spear-phishing, waterhole attacks, and covert C2 via proxies.
Detect and mitigate attacks by building secure architectures with network segmentation, analyzing flows and systems, and deploying a SIEM with IoC and threat intelligence for automated detections and dashboards.
Conclude with real-world attack scenarios, highlighting how organizations are compromised and how defense evolves against automated commodity threats, APT groups, and costly defenses, with a chess-inspired illustration.
Discover cyber security careers across defensive security, DFIR, and offensive security, from CISO to blue, red, and purple teams, plus SOC and CERT/CSIRT roles.
Celebrate completing the comprehensive introduction to cyber security. We invite you to share your thoughts or get in touch about the course.
Through this course, we will give you a comprehensive introduction to Cyber Security.
If you already have computer prerequisites, this will undoubtedly be useful, but it is not mandatory.
Indeed, we will explain all the technical concepts, the level will therefore always be accessible to all.
In the first chapter, we first discuss the landscape and share some real-world observations.
We will highlight the rise of sophisticated and targeted attacks and we will see that well-funded states are capable of compromising any system.
It will also be noted that the theft and resale of data are also on the rise and that it is, in addition, more complex to detect malicious activity.
Next, we will discuss the about the zero-days business and what cyber criminals are currently doing for profit.
In the second chapter, we will analyze the threats.
Then we will explain who the attackers are, what their motivations are and their targets.
We will analyze how the attackers carry out their attacks against you, or your organization in the fourth chapter.
To this intend, we will introduce two important model, the first one is the “Cyber Kill Chain” and the second is the MITRE ATT&CK framework.
Through the fifth chapter, we will study real world attack scenarios, to understand how organizations are compromised by attackers.
Understanding these typical scenarios is crucial to learn how to defend your organization, or yourself as an individual, but it is also useful for testing your actual level of security and the reactions to these attacks, for evaluating the detection and response capabilities.
We will also study a real APT case, the attack campaign named "Epic Turla", in this chapter.
Then we will end this chapter by discussing detection and mitigation techniques, so that you can prevent or at least detect these attacks.
Finally, we will look back and draw conclusions on everything we have learned in this course, and we will discuss the perspectives for the future.