
Explore the fundamentals of cybersecurity, including attack types, defense, network and application security, identity and access management, cryptography, vulnerabilities, threats, and threat actors, with hands-on hacking and penetration testing.
Engage in a hands-on class project that identifies vulnerabilities, produces a vulnerability assessment report, and optionally conducts penetration testing using scan tools on Kali Linux.
Explore the CIA triad by examining confidentiality, integrity, and availability; learn how protecting information, preventing unauthorized modification, and keeping systems up ensures cybersecurity.
Vulnerabilities are weaknesses in code that act as doors into systems, such as directory listing and CVEs. Threats occur when attackers exploit these flaws, including viruses and zero-day vulnerabilities.
Explore malware types, including virus, worm, Trojan, ransomware, spyware, botnet, and rootkit, and learn how each infects, disguises, or secretly monitors and controls systems.
Explore identity and access management: authenticate with factors such as knowledge, biometrics, or tokens; enable federation and single sign-on with OpenID Connect; apply RBAC and rule-based access control.
Study the OSI model’s seven layers, TCP and UDP roles, SSL encryption, and how firewalls and a layer-seven web application firewall protect networks by blocking ports, IPs, and malicious requests.
Understand application security and common application layer vulnerabilities like injection and SQL injection, plus defenses such as encryption, high-entropy session IDs, and web application firewalls, including the OWASP top ten.
Identify assets, scan for vulnerabilities with Nessus, OpenVAS, and Qualys, prioritize high-risk issues, and maintain a continuous patch management cycle with cross-team coordination.
Explore the 14 high-level MITRE tactics and their techniques, from reconnaissance to impact, including a brute-force example and a recommended interactive matrix at tachometer.org.
Explore common attack types like phishing, malware, DoS and DDoS, sql injection, cross-site scripting, and man-in-the-middle, driven by threat actors and reinforced by social engineering.
Explore threat actors: script kiddies, hacktivists, cybercriminals, nation-state actors, insider threats, and espionage groups, uncovering their profiles, goals, motivations, and methods through TTPs.
Explore how cryptography uses symmetric and asymmetric keys, algorithms like AES, RSA, Diffie-Hellman, ECC, and hashing for data integrity.
Study digital forensics to collect, preserve, and analyze evidence with a strong chain of custody, using tools like EnCase, Wireshark, and volatility to reconstruct timelines and report findings.
Explore how attackers use reconnaissance and scanning tools—whois, nslookup, Shodan, Maltego, recon-ng, Nmap, Nessus, OpenVAS—to enumerate, analyze vulnerabilities, and exploit with Kali Linux tools.
Explore core organizational security concepts, including least privilege, defense in depth, separation of duties, the two-person rule, fail securely, zero trust, and disaster recovery with business continuity planning.
Walk through a practical class project using two test apps—a vulnerable banking app and a shopping app—to perform vulnerability assessment with Kali Linux and Nmap, identify CVEs, and document findings.
Conclude by recognizing cybersecurity's evolving landscape and reaffirming confidentiality, integrity, and availability, with cryptography as a core concept, while encouraging continued learning and practical class project experience.
If you're fascinated by cybersecurity and curious about how hacking really works, this course is for you. It’s time to go beyond the headlines and gain a solid understanding of the digital threats and defenses shaping our world.
In this class, you'll learn the fundamentals of cybersecurity and ethical hacking by starting with core principles and expanding into practical techniques. Whether you're interested in defending systems or understanding how attackers operate, this course gives you the tools to explore both perspectives.
You'll also gain foundational knowledge helpful for entry-level cybersecurity certifications, such as CompTIA Security+.
What You'll Learn:
Cybersecurity Principles: The CIA Triad (Confidentiality, Integrity, Availability)
Common Attack Types: Man-in-the-Middle (MITM), Phishing, Denial-of-Service (DoS), Malware, Injection Attacks, Cross-site Scripting (XSS), Social Engineering
Network and Application Security: OSI Model, TCP/UDP, HTTP, Web Application Firewalls (WAF), OWASP Top 10
Organizational and Design Concepts: Defense in Depth, Least Privilege, Separation of Duties, Failing Securely
Cryptography: Symmetric and Asymmetric Encryption, Keys, Hashing
Threats and Actors: Understanding vulnerabilities, exploits, and threat actors
Identity and Access Management: SAML, OIDC, Multi-Factor Authentication (MFA)
Digital Forensics: Based on NIST SP 800-86 standards
MITRE ATT&CK Framework: Tactics and techniques used in real-world cyberattacks
Ethical Hacking: CEH Attack Methodology
Course Format:
The course includes 14 concise video lessons covering all aspects of cybersecurity—from core concepts like the CIA Triad and network security to advanced topics such as cryptography and digital forensics.
You’ll also complete a hands-on project involving a vulnerable application, where you'll identify and exploit security flaws to better understand penetration testing and ethical hacking techniques.