
Engage in hands-on cyber security training with 80+ labs in docker-based environments on two virtual machines. Use real tools like Splunk, Nessus, Velociraptor, and Walgett; includes learning checks and exams.
Create a versatile, low-cost home lab using VirtualBox to host Ubuntu server with Docker and Splunk, enabling hands-on CompTIA size A+ security operations, vulnerability management, and incident response practice.
Set up a Windows 11 enterprise VM in bridged mode with 4–8 GB RAM and 100 GB disk, enable EFI, join a domain, verify internet access, and take clean-state snapshot.
Finish setting up the Windows 11 VM by installing VirtualBox guest additions, enabling bidirectional clipboard, then automate Sysmon deployment and PowerShell logging, and prepare for log ingestion in Splunk.
Master log ingestion in security operations by collecting, parsing, normalizing, and storing logs from network devices, servers, endpoints, cloud services. Enable centralized logging to support detection and response in Sims.
Learn to ingest endpoint logs into Splunk from Windows, create Sysmon and event log indexes, install Splunk forwarder, and validate real-time monitoring, threat hunting, and incident investigation.
Learn Linux log ingestion by installing and starting the syslog service on Ubuntu, then configure Splunk UDP inputs on port 1514 to ingest syslog data alongside Windows logs.
Explore operating system concepts essential for cybersecurity, including the Windows registry and system hardening. Learn about logs, file integrity monitoring, and process visibility to support detection in security operations.
Explore how operating system concepts translate into observable activity by monitoring registry changes, audit logs, and process creation in Windows and Linux with Splunk.
Explore infrastructure concepts, including serverless computing and function as a service with autoscaling and pay-per-use models. Compare virtualization and containerization, covering VMs, hypervisors, VDI, Docker, Kubernetes, and security considerations.
Engage in a hands-on infrastructure concepts lab that operationalizes virtualization and containerization using an Ubuntu server with Docker and Splunk, plus Windows 11 VM with Sysmon and PowerShell logging.
Compare on-prem, cloud, and hybrid network architectures, emphasizing segmentation, zero trust, and SASE with SDN; review TCP, IP, ARP basics and security tools like firewalls, VPNs, and NAC.
Observe mac addresses, IPs, and ARP tables on Windows 11 VM and Linux server. Demonstrate a TCP three-way handshake, docker segmentation, and zero-trust jump box with SSH for database access.
Explore identity and access management fundamentals, including authentication, authorization, accounting, and models like mac, dac, and rbac. Cover mfa, sso, federation, pam, passwordless, and casb.
Demonstrates the triple A framework: authentication, authorization, and accounting, through hands-on lab activities with Linux logins, directory permissions, and audit logs, plus a practical MFA setup.
Explore how encryption protects data at rest and in transit, and how hashing verifies integrity. Learn about PKI components: certificate authorities, CSRs, and CRLs, and TLS role in secure communications.
Demonstrates practical encryption lab techniques by hashing files to verify integrity, encrypting with OpenSSL AES-256-CBC, and generating and deploying self-signed PKI certificates for data at rest and in transit.
Explore how data loss prevention protects sensitive data at rest and in transit by integrating with security tools like proxy servers, with customizable templates for PII and CHD.
Demonstrates building a lightweight data loss prevention server with Flask to inspect posted text for Social Security numbers and credit card patterns, blocking matches while allowing benign traffic.
Detect network related indicators of compromise (IOCs) and other IOC categories to identify malicious activity, using baselining, heuristics, and behavioral analytics plus NAC and IDS/IPS.
Detect command and control beacons using Rita, an open source network analytics tool, by converting a pcap to Zeek logs and examining beacon scores for C2 activity.
Explore host based indicators of compromise, including CPU and memory anomalies, baselining, system profiling, and unauthorized software controls with EDR and security awareness training.
Explore an end-to-end security lab with bridged VMs, a Windows 11 host and Ubuntu server, where agentic AI processes alerts using PowerShell and Rundle 32 to quarantine via firewall rules.
Identify application level anomalies through baselining and continuous monitoring of services, authentication failures, unexpected output, and unusual outbound traffic to detect compromises.
Generate and detect application-level IOCs by simulating new accounts, unexpected output, and logs across Linux and Windows, using a Flask web server, Netcat listener, and audit rules.
Explore living-off-the-land attack techniques by executing hta files with mshta, certutil, and bitsadmin, and learn to log, detect, and baseline these activities using 4688 process creation and PowerShell logs.
Explore social engineering attacks and obfuscated links, including phishing and tailgating, and learn defenses such as awareness training, multi-factor authentication, and detection via baselining with behavior analytics.
Practice recognizing social engineering and phishing threats, identify tactics like authority, urgency, fear, trust, and reciprocity, and decode obfuscated URLs using encoding, URL shortening, typosquatting, and base64/hex encoding.
Identify psychological manipulation in social engineering by analyzing five tactics—authority, urgency, fear, trust, reciprocity—and recognize obfuscated links through encoding methods like base64, hex, URL encoding, typosquatting, and punycode.
Explore threat detection tools including packet capture with Wireshark and Tcpdump, log analysis with Splunk, sandboxing with Any Run, and IP reputation, DNS, and file analysis.
Learn to install strings on Ubuntu, use apt to install binutils, and download a test file with curl for string analysis in a safe lab.
analyze suspicious strings to detect stealth PowerShell usage and hidden windows, assess external IP and admin creation indicators; use VirusTotal hashes, block IP, and investigate persistence and phishing PDFs.
Develop practical automation skills for cybersecurity by building a simple API, a Python-based agent, log parsing, and YAML-driven workflows to prototype a proof-of-concept rest API.
Create an end-to-end security pipeline with two virtual machines to demonstrate agentic ai decision making, detection, automated response, and quarantining via firewall rules.
Identify and interpret anomalies across logs and emails by recognizing pattern threats, from command and control traffic and living off the land to hashing and impossible travel.
Develop hands-on email analysis to identify phishing indicators by headers and content. Triage inbound messages using SPF, DKIM, DMARC, envelope data, and social cues to determine legitimacy and document IOC.
Assess email headers and authentication results to identify phishing attempts, verify sender domains, and spot spoofing using SPF, DKIM, and DMARC, plus social engineering cues.
Learn the basics of programming and scripting languages used in cybersecurity, including JSON, XML, Python, PowerShell, and regex, and apply them to logs, malware analysis, and security operations.
Analyze structured and json log data to detect suspicious activity, brute-force patterns, and obfuscated commands using Splunk, Python snippets, PowerShell, and Linux persistence techniques, with regex for indicators of compromise.
Explore lab 14 solutions to detect brute-force and persistence techniques using json logs, Splunk, Windows event codes, PowerShell base64, and cron jobs, with threat intel and decoding techniques.
Identify threat actors and map their tactics, techniques, and procedures to defend networks, exploring APTs, hacktivists, organized crime, nation state actors, insiders, script kiddies, and supply chain risks.
Engage in a hands-on threat actors and TTP lab using Splunk to map TTPs from four incidents and classify actors, including script kiddie, cyber criminal, insider, and nation-state.
Explore confidence levels in cyber threat intelligence, detailing how timeliness, relevancy, and accuracy shape trust in data, prioritize responses, and guide decision making for SOC teams.
Score IOCs using the confidence framework, upload the results as a lookup table in Splunk, and build a dashboard to monitor high-confidence threats.
Explore threat intelligence collection methods and sources, including OSINT, closed sources, paid feeds, and internal telemetry, to validate IOCs and build a robust picture of the evolving threat landscape.
Explore how threat intelligence sharing strengthens incident response, vulnerability management, risk management, security engineering, and monitoring through shared indicators of compromise from Isacs, Cisa, and Traffic Light Protocol standards.
Collect, normalize, enrich, and share logs and threat intelligence using ISACs, CERTs, and MISP. Ingest internal logs and threat feeds into Splunk, create lookups, and demonstrate intel sharing.
Proactively hunt for evidence of compromise using indicators of compromise, logs, and threat intelligence to shift from passive to active defense. Prioritize high-value assets and ioas with honeypots.
Simulate a ransomware investigation in the core network, map threat intelligence to detections with Splunk and Sysmon, and emphasize macro delivery, PowerShell, Defender tampering, and shadow copy deletion.
Explore standardized processes that boost efficiency and accuracy in security operations, with runbooks, playbooks, and automation guiding repeatable, auditable workflows across teams.
Learn practical scripting and automation for cybersecurity by building a simple API, a lightweight agent, log parsing, and YAML-driven workflows for repeatable REST API interactions and JSON handling.
Streamline operations in security operations centers by automating repeatable tasks and orchestrating cross-tool workflows to reduce alert overload, enrich alerts with threat intelligence, and accelerate incident response.
Integrate security tools through APIs, webhooks, and plugins to create a unified, automated workflow that speeds detections and reduces analyst workload.
Demonstrate an end-to-end security pipeline with two virtual machines, ingesting alerts, applying an agentic ai decision to monitor or quarantine, and displaying results in a lightweight dashboard.
Unify security data into a single pane of glass to reduce tool sprawl and accelerate detection, investigation, and response across endpoints, networks, and cloud services.
Ingest logs into Splunk, create SPG_internal_logs index, surface failed logins; add panels for outbound CTI hits, top users by alerts, and high confidence alerts on a single pane of glass.
Install Openvas in a docker container on Ubuntu, mounting data and configuring health checks. Access the web GUI via port 9443 to support vulnerability management.
Install Nessus in a docker lab, register Nessus Essentials, and run a network-wide vulnerability scan on Ubuntu, then compare Nessus findings with OpenVAS and snapshot the setup.
Identify all assets through map scans and device fingerprinting to create a baseline inventory, prioritize remediation, and support vulnerability assessments with tools like Nessus and OpenVAS.
Map the network to identify active hosts and fingerprint devices to determine operating systems and services, distinguishing discovery from fingerprinting and showing how asset inventory underpins vulnerability management.
discover all network hosts with openvas lab, create a new target for an IP range, run a scan, review the hosts report, and compare automated results with nmap.
Schedule vulnerability scans with business impact in mind, align with change management and operations, balance performance and sensitivity, and apply segmentation and regulatory requirements.
Learn how Nessus scans vary by device, balancing CPU impact, availability, and data sensitivity; use safe checks and off hours scans to protect critical systems.
Compare internal and external vulnerability scanning to reveal insider threats and exposed attack surfaces. Learn how scope, frequency, and credentialed methods strengthen a proactive vulnerability management program.
Explore internal versus external scanning in the CySA+ hands-on course, using Nessus credentialed scans within a 192.168.0.0/24 lab and attempting an external scan across a pfSense firewall.
Compare agent-based and agentless vulnerability scanning, examining depth versus breadth, offline capabilities, and hybrid strategies to maximize coverage while minimizing overhead.
Compare credentialed and non credentialed vulnerability scans, detailing what each reveals about external view, patch levels, and internal configurations; using both approaches yields a complete picture of vulnerabilities.
Compare non credentialed and credentialed scanning with Nessus on a Windows VM to reveal deeper visibility and the high vulnerability detected only in credentialed scans.
Demonstrate active and passive scanning techniques with nmap and tcpdump on a Windows VM in VirtualBox, revealing open services, OS detection, and log-forwarding traffic patterns.
Explore static versus dynamic testing in vulnerability management, including SAST and live application testing with BurpSuite and OWASP ZAP, their benefits, limits, and how they complement each other.
This lab demonstrates the difference between static and continuous scanning by running a one-time credentialed Windows scan and then converting it into a weekly scheduled scan.
Balance vulnerability management for infrastructure by prioritizing passive monitoring, vendor-approved tools, segmentation, and lab testing to protect OT, ICS, and SCADA, aligning with NERC CIP, IEC 62 443, and HIPAA.
Run a vulnerability scan with Nessus on a critical hvac control system, mitigate identified flaws, and configure a Splunk dashboard to detect and monitor suspicious activity for Steel Mountain facility.
Compare a system's state to security baselines like CIS benchmark, DISA STIGs, and Microsoft security baseline, verifying password complexity, firewall rules, network access, and logging to reduce risk.
Create a security baseline with the Waza tool to apply CIS benchmarks. Deploy via Docker, generate TLS certificates, install a Windows agent, and export a CSV report.
Explore how industry frameworks guide vulnerability scanning with PCI DSS, CIS benchmarks, OWASP, and ISO 27001, ensuring regular scans, reporting, and continuous monitoring and risk assessment.
Apply industry frameworks such as NIST CSF, CIS controls, and ISO 27001 to asset discovery and vulnerability assessments, mapping findings to a framework alignment report.
Explore vulnerability assessment tools from network scanners to web application scanners, learn how to interpret outputs, validate findings, and translate results into a prioritized, evidence-based vulnerability management plan.
Explore Nessus Essentials in a docker-based tools lab, register for a free activation code, run scans against your network, compare results with OpenVAS, and review vulnerability findings.
Interpret Cvss scores to prioritize vulnerability remediation by analyzing attack vector, attack complexity, privileges required, user interaction, scope, and impacts on confidentiality, integrity, and availability.
Compute cvss base scores for vulnerabilities using the first cvss calculator, scoring attack vector, complexity, privileges, user interaction, scope, and CIA triad to prioritize fixes.
Distinguish true positives, false positives, true negatives, and false negatives to validate detections and prioritize responses. Tune detection rules and thresholds to reduce noise while improving overall security accuracy.
Learn to validate alerts in Splunk by classifying events as true/false positives and negatives, and quantify detection with precision, recall, and F1 for data-driven incident response.
Apply context awareness to vulnerability management by evaluating internal, external, and isolated contexts and interpreting alerts from vulnerability scanners, intrusion detection systems, and SIEMs to assess exploitability as actionable risk.
Learn to classify vulnerabilities by context awareness, internal, external, or isolated, and weigh exploitability and exposure to prioritize remediation and guide action plans.
Explore exploitability and weaponization, mapping how vulnerabilities become attacks through attack vectors and proof-of-concepts, and how attackers package, deliver, and operate exploits in the wild.
Analyze vulnerability scenarios to assess exploitability and weaponization risk, then recommend detection, containment, and remediation actions through a walkthrough lab with real-world scenarios.
Identify asset value to prioritize vulnerabilities and guide risk scoring, remediation, and incident response, balancing tangible costs, data sensitivity, regulatory impact, and reputational risk.
This asset value lab teaches a structured method to rank assets using an asset register and weights in Excel, scoring business criticality, uptime tier, and regulatory compliance for prioritized defense.
Explore zero day vulnerabilities at the intersection of discovery and exploitation, and learn urgent, layered defense strategies, indicators of exploit, rapid response, and risk prioritization until patches arrive.
Identify zero-day exploits by analyzing behavioral indicators in logs, perform triage and endpoint correlation, assess likelihood, implement rapid mitigations, and develop detections and clear communications.
In this course, your learning experience isn't limited to theory. We take you far beyond the lectures and slides. This is a hands on, lab driven program built to help you truly understand cybersecurity analysis, detection, and response techniques the way real SOC analysts do. Throughout the course, you'll work through over eighty hands on labs.
Nearly every lecture has a corresponding lab giving you the opportunity to immediately apply the concepts you just learned. These labs reinforce the theory, boost retention, and build real operational skills. To support these labs, every module includes step by step walk through documents. These walk throughs mirror the video lectures exactly. So whether you prefer to read, follow along visually, or reference material later, you'll always have a clear guide.
The combination of lecture plus walk through plus hands on ensures you understand not just what to do, but why you're doing it. The best part is that you don't need a high end laptop or a powerful workstation. Thanks to Docker based lab architecture, the entire practical environment runs in just two virtual machines, One Ubuntu server running Docker containers and one Windows eleven VM for endpoint activities. This lightweight setup lets you run enterprise grade tools without enterprise grade hardware. And, yes, these are real tools used in real security operations.
You will gain direct experience with technologies like Splunk, Wazet, Nessus, Velociraptor, and more. To make it fun and interesting, we've developed scenarios and attacks based on the TV show, Mr. Robot.
To help check your understanding, every lecture ends with a learning check. These are short quizzes designed to reinforce the concepts before you move on. And when you're ready to test your skills at the exam level, you'll have access to over six hundred test questions and two full length practice exam simulations. But you're not doing this alone. Enrollment in this course gives you access to our discord community where you can connect with instructors and fellow students, ask questions, share insights, and build relationships that support your learning journey.
In total, this course includes over forty hours of instructional video content. To make sure this course is a good fit for you, try the lab set up in the first size of plus objective lecture in labs for free.