
Volume 1 covers threat modeling, risk assessments, and defenses against social engineering, and outlines test environments, encryption concepts, and cross‑platform patching and isolation.
How to start a career in cyber security and ethical hacking.
Explore the basics and theory of security, then progress to practical exercises and a lab using virtual machines, culminating in demonstrable security techniques and advanced topics.
Explain the differences between privacy, anonymity, and pseudonymity and how each protects content and identity. Use examples like encrypted emails, cloud storage, Tor, and VPN to show when each applies.
Explore asset selection by identifying valued assets—files, accounts, financial information, emails, identity, data, processes, and departments—and apply security controls based on risk assessments and asset classification.
Apply threat modeling and risk assessments to balance security and usability. Identify assets, vulnerabilities, threats, adversaries, and consequences to tailor risk-based controls.
Explore the interplay of security, privacy, and anonymity and how browser features can safeguard users while risking exposure. Learn how the required level of privacy dictates the needed security controls.
Implement defense in depth by layering prevention, detection, and recovery across assets, using encryption, canaries, and backups to protect, detect, and recover.
Explore why the top three safety beliefs, like antivirus and changing passwords, fall short, and learn expert-approved approaches to stay secure online.
Phishing attacks trick users into clicking malicious links or revealing credentials, a form of social engineering using spoofed domains, hidden URLs, IDN tricks, and cross-site vulnerabilities, including vishing and smishing.
Examine how spam floods emails and other channels, why it stays economically viable, and how doxing publicizes private information through public records, social media, and other sources.
Explore mass surveillance across the Five Eyes network, including the Utah data center and monitoring of calls, emails, and online activity. Consider the privacy trade-offs involved.
Explore trust, backdoors, and vulnerabilities across operating systems, applications, and hardware. Learn defense strategies such as formal methods, isolation, and deterministic, reproducible builds.
Explore how censorship operates in the west, including the right to be forgotten, search engine removals, and isp filtering shaping access.
Stay informed about the evolving threat landscape with a weekly threat intelligence report that covers security news, threats, vulnerabilities, tools, alerts, and recommended reading.
Learn how encryption turns plain text into cipher text to protect privacy, focusing on the algorithm and key, AES as the symmetric standard, and brute force or dictionary attacks.
Asymmetric encryption uses public and private keys to securely exchange keys and enable digital signatures, with algorithms like RSA, ECC, Diffie-Hellman, and hybrid systems paired with AES for efficiency.
Explore how SSL and TLS secure internet communications using symmetric and asymmetric cryptography, hashes, digital signatures, and MACs to provide confidentiality, integrity, authentication, and perfect forward secrecy.
SSL stripping exposes a man-in-the-middle attack that downgrades HTTPS to HTTP via proxies and redirects. It also covers ARP spoofing and rogue access points, mitigations like end-to-end encryption and VPN.
Explore how https secures web traffic with tls, detailing the handshake, server and optional client authentication, digital certificates, and symmetric encryption with aes, rsa, and elliptic curve diffie-hellman.
Explore how digital certificates use X.509, RSA keys, and SHA-256 signatures to authenticate websites, via certificate authorities and the chain of trust.
Explore how certificate authorities underpin https authentication, reveal the risks of misissued certificates and weak trust chains, and explain defenses like certificate pinning, reducing trusted certs, and vpn use.
End-to-end encryption encrypts data by the sender and decrypts only for the recipient, underscoring data-in-transit protection and examples like PGP, OTR, ZRTR, and Signal.
Steganography hides data inside ordinary carriers such as images, videos, or audio. It is not encryption, uses passwords, decoys, and tools like OpenPuff, and can be affected by compression.
Explore testing and learning with virtual machines using hypervisors like VirtualBox and VMware, creating host and guest environments, and loading operating systems via ISO, virtual disks, or pre-made images.
Understand how usage share shapes threat risk, with Windows dominating desktops, rising Android attacks, Linux security advantages, and Mac–Windows trade-offs, plus practical steps to reduce risk.
Explore Windows 10 privacy settings, compare express and custom installs, and manage Microsoft versus local accounts while understanding how Cortana affects search and privacy across updates.
Explore Windows 10 Wi-Fi Sense, its preview status and decline, its crowdsourced open hotspot connections, and how to disable it in favor of a guest network.
Explains how Windows 7, 8 and 8.1 collect telemetry via the CEIP and how to disable it across Windows Media Player, Office, and Windows Live Messenger, while avoiding optional updates.
Explore Debian, Arch Linux, and OpenBSD as general-use, security- and privacy-focused operating systems, highlighting free and open-source software, reproducible builds, security audits, and hardware compatibility challenges.
Explore anonymity focused operating systems like Tails and Whonix, with live USB/DVD setup, Tor-based privacy, and isolation-driven security; Tails resists local forensic examination, Whonix emphasizes isolation.
Explore mobile operating systems through a security, privacy, and anonymity lens, comparing iOS and Android and examining open source options like LineageOS, Sailfish OS, Replicant, OmniROM, MicroG, FLOSS, and PureOS.
Learn to install and troubleshoot VirtualBox guest additions on Debian 8 Jessie, using live CDs or ISO installs, editing sources, and installing gcc, dkms, xserver and xorg.
Update all software and apply security patches promptly to stay safe online, prioritizing browsers, extensions, email apps, and the operating system, with automatic updates or download-and-evaluate patches.
Configure Windows 10 update settings to control automatic updates and ensure Internet Explorer, Edge, and Office apps stay current; view installed updates and look up KB numbers.
Automate security patches across Windows systems using Secunia Personal Software Inspector, enabling automatic or selective updates, detailed scanning, and ongoing monitoring to keep defenses up to date.
Configure Firefox to automatically update the browser, extensions, and plugins, check for updates, review update history, and enable automatic add-on updates to stay secure.
Learn how Chrome automatically updates the browser and extensions, including those with a manifest auto-update URL, and how to force updates via Help and About Google Chrome and developer mode.
Remove admin privileges from a Windows 7 account, switch it to a standard user, and create a separate administrator account for tasks needing admin rights.
In Windows 10, learn to remove admin privileges by creating a separate administrator account, switching your account to standard, and disabling or deleting unused accounts.
Explore how to limit personal information exposure on social media through identity strategies—avoidance, compartmentalization, content and audience controls, privacy settings, and decentralized alternatives.
Apply technical security controls to thwart phishing, vishing, smishing, scams, cons, doxing, and spam by choosing email providers with strong filtering and enabling login and activity alerts.
Explore virtual and physical security domains to reduce the attack surface and interfaces between assets, and learn how security domains limit the impact and spread of attacks.
Learn a practical skill-set in defeating all online threats, including - advanced hackers, trackers, malware, zero days, exploit kits, cybercriminals and more.
Become a Cyber Security Specialist - Go from a beginner to advanced in this easy to follow expert course.
Covering all major platforms - Windows 7, Windows 8, Windows 10, MacOS and Linux.
This course covers the fundamental building blocks of your required skill set - You will understand the threat and vulnerability landscape through threat modeling and risk assessments.
We explore the Darknet and mindset of the cyber criminal. Covering malware, exploit kits, phishing, zero-day vulnerabilities and much more.
You will learn about the global tracking and hacking infrastructures that nation states run. Covering the NSA, FBI, CIA, GCHQ, China’s MSS and other intelligence agencies capabilities.
You will understand the foundations of operating system security and privacy functionality. A close look at the new Windows 10 privacy issues and how to best mitigate them.
There is a complete easy to follow crash course on encryption, how encryption can be bypassed and what you can do to mitigate the risks.
Master defenses against phishing, SMShing, vishing, identity theft, scam, cons and other social engineering threats.
Finally we cover the extremely important, but underused security control of isolation and compartmentalization. Covering sandboxes, application isolation, virtual machines, Whonix and Qubes OS.
This is volume 1 of 4 of your complete guide to cyber security privacy and anonymity.