
Continue your cybersecurity journey with volume four of the complete cyber security course: end point protection. Opt to take volume four as standalone, but volumes 1–3 provide the full picture.
Launch a quick, no-install security win with CanaryTokens tripwires to detect snooping across devices and accounts using Word, PDF, and email traps that alert you for fast response.
Target technically minded individuals who want to protect themselves from hackers, malware, and government or corporate tracking, and who seek online privacy and anonymous publishing.
Learn to achieve security, privacy, and anonymity by balancing breadth and depth, practicing in a test environment, taking notes, and teaching others to reinforce learning and application.
Stay ahead as security and technology evolve by following this actively updated course, which updates material as the landscape changes and invites your feedback, recommendations, and questions.
How to start a career in cyber security and ethical hacking.
Explore current and future endpoint protection technologies, from disk encryption and antivirus suites to endpoint detection and response, and master email and messenger security for defense in depth.
Protects data via disk encryption, rendering it unreadable on a disk when a device is lost or stolen. Limits protection to physical access, not traffic or coercion.
Evaluate crypto algorithm strength against brute-force and dictionary attacks, consider cascading options like aes, twofish, serpent, and recognize implementation vulnerabilities and compensating controls against unknown and quantum attacks.
Protect disk encryption by understanding physical attacks that reveal keys through memory, DMA, bootloader compromise, or evil maid scenarios; secure boot, TPM, pre-boot authentication, and device control mitigate these risks.
Compare whole disk encryption with encrypted containers, volumes, and partitions, highlighting how partial encryption enlarges the attack surface and leaves unencrypted system files, history, and temp data at risk.
The lecture surveys viable Windows disk encryption options, including TrueCrypt forks VeraCrypt and CipherShed, descriptor, BestCrypt, semantic drive encryption, and BitLocker, guiding selection by threat model.
Evaluate Windows disk encryption with BitLocker, TPM protections, and multiple authentication options. Assess benefits and privacy concerns, edition availability, and recovery key risks.
Compare windows disk encryption tools such as CipherShed, DiskCryptor, Symantec's drive encryption, and BestCrypt, highlighting twofish/serpent cascades, authentication, and boot options, with notes on containers and audits.
Enable file vault 2 on macOS by guiding entropy seeding, choosing recovery options, and using firmware password and sleep settings to harden disk encryption for endpoint protection.
Explore Linux whole disk encryption with dm-crypt and LUKS, including on-the-fly encryption during install on Debian, and flexible options like multi-key and plausible deniability.
Set up dm-crypt and LUKS on Linux during install with Debian, Kali, and Ubuntu. Use cryptsetup to create, access, and manage encrypted devices, benchmark crypto options, and manage key slots.
Encrypt the grub2 bootloader to reduce physical attack risk, and follow Debian-like steps to copy boot files, update grub, and enable crypto disk with a master password.
defense against disk decryption attacks balances usability and security, prioritizes preventing physical access, implements whole disk encryption with multifactor authentication, and disables memory dumps and hibernation.
Learn to encrypt files, archives, partitions, and disks across Windows, Linux, and BSD using PS Zip, 7-zip, and GPG, with two-factor authentication via password and key file.
Stack multiple layers of encryption and obfuscation across software and hardware to protect volumes and system partitions with distinct passwords and two-factor authentication, limiting exposure.
Explore disk-encryption case studies that reveal how memory-resident keys and boot kits, cloning, and truecrypt-era devices defeat encryption in real-world scenarios.
Explore endpoint protection on Windows, macOS, and Linux; evaluate how antivirus works and why attackers bypass it, and assess antivirus effectiveness and current best products in today’s threat landscape.
Assess how antivirus products deploy defense in depth across devices. Malware increasingly uses scripting services to create fully undetectable, encrypted code that bypasses signatures.
Evaluate endpoint protection software with features beyond antivirus and learn how independent labs test real-world protection, heuristics, and performance across vendors.
Explore how business endpoint protection (EPP) differs from home AV, with centralized management and gateway deployment, using trials and AB tests to evaluate vendors' protection strategies.
Compare top paid windows antivirus suites—Bitdefender, Kaspersky, and Norton Security—with built-in protection from Microsoft Security Essentials and Windows Defender, and explore endpoint protection and trial options.
Discover how online scanners like VirusTotal analyze files with multiple engines, show results and signatures, and how cloud second opinion tools and Hitman Pro enhance detection and removal.
Evaluate how antivirus and endpoint protection affect privacy and performance, expose data-sharing and ssl decryption risks, highlight vulnerabilities and attack surfaces, and weigh the security benefits against the downsides.
Explore how next generation antivirus and endpoint protection deliver defense in depth through prevention, detection and response and recovery technologies. Learn how these technologies synergize, avoid conflicts, and manage overhead.
Explore how application and execution controls, including ACLs, application whitelists and software restriction policies, prevent malware and unauthorized software as a layer of defense in endpoint protection.
Discover Windows user account control (uac), which runs as a standard user and prompts for admin tasks, with configurable notification levels to deter malware and attackers.
Explore how Windows software restriction policies enable application control by blocking executables through path rules. AppLocker is its successor, but SRP remains usable via Local Security Policy or Group Policy.
Explore AppLocker, an advanced Windows application control tool that extends SRP through group policy, using publisher, path, and hash rules to whitelist apps and enforce controls.
Learn how Emet blocks memory exploitation on Windows using dep, aslr, and seh overwrite protection. Apply protections to apps and understand its limitations and future integration.
Explore Windows 10 device guard, a virtualization based security feature that uses a hypervisor, hardware isolation, configurable code integrity, and digital signatures to enforce trusted apps and block malware.
Explore Linux security frameworks and implement strict access controls with AppArmor, a Linux kernel security module using per-program profiles to restrict capabilities and isolate applications like Apache.
Learn how SELinux enforces mandatory access control in Linux through kernel modules and policies, enabling granular file, network, and IPC controls and Debian deployment with virtualization options.
Examine Grsecurity, a Linux kernel security framework that defends against memory corruption and other threats through advanced access control and hardening, with Debian compatibility considerations and setup challenges.
Protect macOS by warning on apps from unidentified developers or altered signatures. Clarify gatekeeper options: store only, store and identified developers, or anywhere, and its limited malware protection.
Santa for macOS uses a kernel extension, a daemon, and a gateway agent with an sqlite database to enforce whitelist and blacklist decisions.
Explore Xfence, formerly Little Flocker, a macOS kernel extension that enforces file access via the macOS mandatory access control framework, learning startup rules and prompting for new ones.
Silence, Cylance's next-generation antivirus, uses machine learning to detect zero-day malware without signatures, delivering lightweight, offline protection with a cloud-based management console.
Learn to monitor and detect active threats with host and network intrusion detection systems, file integrity monitors, system information and event management software, honeypots and other deceptions, using Linux distributions.
Assess the limits of prevention and strengthen detection, response, and recovery by deploying deception, honeypots, and other detection controls to shorten compromise to discovery times.
Discover deception through honeypots for threat detection. Distinguish research honeypots from threat detection honeypots, and learn about high quality alerts and low false positives.
Learn how intrusion detection systems work, including network and host based systems, signature and anomaly based methods, and the role of intrusion prevention systems.
Security Union is a Linux distro for intrusion detection, network security monitoring, and log management, bundling tools like snort and network miner for deployment, with a setup wizard for sensors.
Centralize logs from devices, scanners, and monitors into a siem for analysis, correlation, and real-time alerts, turning data into actionable insight that reduces risk.
Learn to detect and remove malware and active adversaries using online and offline methods, live CD forensic techniques, and hybrid cloning with a virtual machine.
Explore automated malware removal tools, including Kaspersky, Malwarebytes, and Hitman Pro, plus online and offline scanning, safe mode, and live CD methods to identify and remove malware.
Boot a live operating system from USB or CD to mount the infected system's file system and run malware-removal tools across Windows, Mac, and Linux using rescue disks.
Use process explorer to identify suspicious auto start locations and dlls. Inspect strings and memory for odd urls and endpoints, then suspend or kill processes to remove persistence.
Learn to use Windows process and service tools, compare process explorer with native command line options, export details to csv, and query the registry to track executables for malware analysis.
Learn to use auto runs to identify suspicious startup entries and malware persistence, analyze offline systems, and verify digital signatures with VirusTotal.
Learn to use Windows Process Monitor to analyze malware activity, capture and filter system events (registry, files, network, processes), and apply precise include/exclude filters to detect threats.
Identify active threats by monitoring bandwidth and network activity using tools like Wireshark and networks, which offers usage reports and a netstat-like interface across Windows, Mac, and Linux.
Explore using Sysdig on Linux to capture system events, filter results, and run scripts for malware detection and threat hunting.
Hunt Linux threats with csysdig GUI, analyzing active processes, network connections, and file activity to detect malware and hackers.
Verify system integrity with debsums by comparing md5 sums to repo hashes and reviewing config changes; use unhide to detect hidden processes and unlisted ports with six techniques.
Analyze Linux network activity with lsof to identify listening and established connections, filter by ipv4/ipv6 and tcp/udp, and validate findings with nmap and watch.
Learn how Linux servers stay secure by using rkhunter to detect rootkits and malware, update signatures, set baselines, run scans, and whitelist warnings.
Explore Linux anti-malware tools like chkrootkit, Linux malware detect, Tiger, ClamAV, and volatility to scan, identify, and mitigate Linux malware and rootkits.
Inspect Linux systems for malware persistence by examining package installation histories, dpkg status and log files, and scrutinizing startup locations like cron, services, and scheduled tasks.
Explore how Linux init systems affect malware persistence, from System V init to systemd, and manage units with systemctl, including status, enable, disable, mask, unmask, and view logs via journalctl.
Identify Linux persistence techniques by examining startup scripts, rc.d and boot directories, kernel modules, and modprobe.d; review user profiles and home directory scripts to detect malware and maintain persistence.
Use Task Explorer to visually inspect Mac running processes, signatures, dynamic libraries, open files, and network connections. Verify items with VirusTotal and unsigned indicators to detect threats.
Use Knock Knock to reveal mac persistence by scanning extensions, kernel extensions, launch items, and other locations. Verify with VirusTotal and explore Block Block alerts for unsigned or unknown items.
Discover OSQuery, an open-source enterprise tool that exposes operating system information via SQL across Mac, Linux, and Windows, enabling detection, IOC searches, and SIEM integration with syslog.
Explore what firmware is and how firmware rootkits compromise devices from BIOS to hard drives, surviving OS reinstallations and patching, with supply chain and IoT implications.
Discover firmware protections for motherboards, including BIOS/EFI and secure boot, with updates and UEFI password practices. Learn to analyze firmware using open tools and VirusTotal for detection.
Develop a robust end-point protection recovery and remediation strategy that contains threats and avoids slow manual removal. Use cloning and snapshots to quickly restore systems to known good states.
Protect data with on-premise backups that include redundancy such as raid and local storage. Evaluate encrypted cloud storage and self-hosted options with client-side encryption to keep offsite backups private.
Explore hardening standards and benchmarks from the Center for Internet Security, including baselines for Windows, macOS, Linux, and iOS, plus STIGs and XML formats.
Learn how SCAP, a standard for machine-readable security documents, powers OpenSCAP tools for auditing, hardening, and remediating Linux systems with SCAP-compliant policies.
Audit your system baseline with vulnerability scanners to reveal configuration gaps and harden defenses. Authenticated scans simulate administrator checks, uncover kernel updates, password weaknesses, and file integrity status.
Explore Windows hardening sources such as open scrap baselines, Defense Information System Agency templates, and security templates, with scripts to automate Windows seven to ten and guidance on UAC.
Explore how Windows security baselines and the security compliance manager streamline hardening, auditing, and customizing policies via group policy, local group policy, and GPO exports.
This lecture covers linux hardening across distributions, kernel redesign, and the Google kernel self protection project, stressing integration of geo security, pax, SELinux and app armor into the kernel.
Learn how to detect and prevent security drift by monitoring changes that move systems away from the hardened baseline, using Osquery file integrity tools, custom scripts, and automated restoration.
Delete data and metadata across Windows, Mac, and Linux to be unrecoverable by forensics and anti forensics, remove EXIF and metadata from files, apps, and operating systems.
Explain why secure deletion on solid state drives differs from mechanical drives due to trim command, wear leveling, and spare area, and emphasize encryption as the only reliable unrecoverable guarantee.
Understand anti-forensics and how to minimize evidence by avoiding data creation and enabling encryption. Learn layered defenses, from whole disk encryption to encrypted removable media and secure containers.
Discover how virtual memory and swap can leave data on disk and how encryption mitigates this risk. Learn to clear paging and disable swap across Windows, Mac, and Linux.
Discover how to scrub metadata and exif data from documents, images, and audio, including author, dates, and geo coordinates. Understand privacy risks and how removal prevents disclosure when sharing online.
Search and remove metadata across Windows, Mac, and Linux using tools like exiftool, batch purifier light, and batch purify to understand and manage exif data in files.
Disable geotagging across iPhone, Android, and cameras. Avoid uploading files unless necessary; scrub metadata with document inspectors, watch for tracked edits, and separate aliases and environments to improve anonymization.
Camera fingerprinting uses sensor noise to uniquely identify a camera and link photos or videos to it, threatening anonymity; it notes Google's patent and countermeasures like aliases and privacy tools.
Learn a
practical skill-set in securing laptops, desktops and mobile devices from all types
of threats, including, advanced hackers, trackers, exploit kits, thieves and much more.
On this course we cover end-point-protection,
which is an extremely important and hot topic in cyber security right now!
Become a cyber security specialist - Go from a beginner to advanced in this easy to follow expert course.
Covering all the major platforms Windows, MacOS, Linux, iOS and Android.
Master the selection and implementation of solid disk encryption technology to protect devices from disk decryption attacks.
Understand the current and next generation anti-virus solutions, how they work, how to select the best products and how to implement them successfully.
Covering traditional end-point-protection technologies through to next generation and future technology; application control, execution prevention, machine learning and Artificial Intelligence.
Learn how we can detect and monitor for threats such as malware and hackers through the use of security through deception and detection technologies.
We have fun learning how to seek and destroy system resident malware and hackers. Get up to speed on your hacker hunting!
Learn how to perform operating system hardening to decrease the attacker surfaces of your devices to make them safer.
Explore the best techniques in anti-forensics to securely delete data and meta-data so that it is unrecoverable by even computer forensics experts.
Plus there is more. We end by looking the extremely important topic of email and messenger security. Email has natively poor security, but in this course, I teach you how to overcome those weaknesses and fully secure your communication.
This is volume 4 of 4 of your complete guide to cybersecurity, privacy, and anonymity.