इस प्रोजेक्ट के बारे में
Awesome Cyber Security University मुफ्त शैक्षिक संसाधनों की एक क्यूरेटेड सूची है जो करके सीखने पर केंद्रित है। README में कहा गया है कि सामग्री छह भागों में व्यवस्थित है: Introduction and Pre-Security, एक Free Beginner Red Team Path, एक Free Beginner Blue Team Path, Bonus practices, Latest CVEs, और Extremely Hard rooms। कार्यों को कठिनाई में रैखिक बताया गया है, इसलिए उन्हें क्रम में पूरा करने की सलाह दी जाती है, हालांकि पाठक उन रूम्स को छोड़ सकते हैं जिनके विषय उन्हें पहले से पता हैं।
Introduction and Pre-Security अनुभाग में OpenVPN के साथ VPN कनेक्शन, TryHackMe ऑनबोर्डिंग, पेंटेस्टिंग के लिए शोध कौशल, तीन Linux Fundamentals रूम्स, पेंटेस्टिंग fundamentals, principles of security, red team engagements, एक कमजोर सर्वर के विरुद्ध walkthrough, और एक Linux command practice कोर्स शामिल है। सूचीबद्ध प्रारंभिक CTFs में Google Dorking, OSINT, और Shodan.io device enumeration शामिल हैं।
Free Beginner Red Team Path को स्तरों में विभाजित किया गया है। Level 2 (Tooling) में tmux, Nmap/Curl/Netcat, web scanning, subdomain enumeration, Metasploit, Hydra, Linux privilege escalation, red team fundamentals और reconnaissance, साथ ही Nmap ट्यूटोरियल शामिल हैं, जिसके बाद Vulnversity, Blue, Simple CTF और Bounty Hacker जैसे intro CTFs हैं। Level 3 में hash cracking और CTF अभ्यास शामिल हैं, जिनमें Agent Sudo, The Cod Caper, Ice, Lazy Admin, Basic Pentesting और bypassing UAC शामिल हैं। Level 4 (Web) में OWASP Top 10, local file inclusion, OS command injection, OWASP Juice Shop, Overpass, Year of the Rabbit, DevelPy, Jack of all trades और Bolt शामिल हैं। Level 5 (Reverse Engineering & Pwn) में Windows x64 assembly, Ghidra, Radare2, reverse engineering basics, reversing ELF files, router firmware dumping, pwntools और Pwnkit CVE-2021-4034 लैब शामिल हैं। Level 6 (PrivEsc) में sudo security bypass और buffer overflow CVEs, Windows और Linux privilege escalation arenas, Blaster, Ignite, Kenobi, Capture the Flag और Pickle Rick शामिल हैं। एक लिंक किए गए gist के माध्यम से red team completion badge प्रदान किया जाता है।
Free Beginner Blue Team Path टूल्स से शुरू होता है: digital forensics introduction, Windows fundamentals, Nessus, MITRE ATT&CK, SIEM introduction, YARA, OpenVAS, honeypots, Volatility, Redline और Autopsy। Level 2 में security operations, incident response और threat hunting शामिल हैं, जिनमें Investigating Windows, Juicy Details, Carnage, Squid Game, और Splunk Boss of the SOC volumes 1-3 तथा एक Conti ransomware hunt जैसे रूम्स हैं। Level 3 में threat intelligence, OSINT tools, picoCTF से beginner file/image/packet analysis challenges, HackTheBox से medium forensics challenges, एक threat intel challenge और Cryptohack का परिचय शामिल है। Level 4 में Sleuthkit के साथ memory और disk forensics, Windows, macOS और Linux images पर HackTheBox और CyberDefenders challenges, साथ ही Log4J detection शामिल है। Level 5 में malware history, malware introduction, basic malware reverse engineering, Windows reversing, x64 assembly, JVM reverse engineering और malicious PDF analysis शामिल है। एक blue team completion badge भी प्रदान किया जाता है।
Bonus अनुभागों में OverTheWire Bandit और Natas जैसे CTF अभ्यास, post-exploitation basics, buffer overflow preparation, Docker और Kubernetes escape scenarios, Log4j और Spring4Shell exploitation labs, और हाल के खतरे सूचीबद्ध हैं। एक Bonus Windows अनुभाग Active Directory, Retro, Blue Print, Anthem और Relevant को कवर करता है। एक Extremely Hard Rooms अनुभाग उन्नत चुनौतियों को सूचीबद्ध करता है, जिनमें Ra, CCT2019, Theseus, IronCorp, Carpe Diem 1, Borderlands, Jeff, Year of the Owl, Anonymous Playground, EnterPrize और Racetrack Bank शामिल हैं।
योगदान pull requests के माध्यम से स्वीकार किए जाते हैं, इस शर्त के साथ कि संसाधन मुफ्त होने चाहिए; wiki में एक contribution guide का संदर्भ दिया गया है। README में यह भी उल्लेख किया गया है कि red और blue team paths के लिए completion badges README के भीतर छिपे हुए हैं, और उनके HTML को writeups या profiles में कॉपी किया जा सकता है।
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.