Awesome Lists

awesome-cyber-security-university

by brootware

awesome listpushed almost 2 years ago

🎓 Because Education should be free. Contributions welcome! 🕵️

AI summary

Cyber Security Training

A curated educational resource list focusing on learn-by-doing cyber security training

stars
1.8K
forks
174
watching
39
awesome lists
2
entries
143
View on GitHubbrootware.github.io/awesome-cyber-security-university

Embed the badge

Show how many awesome lists link to your project. The count updates automatically.

Awesome Lists badge
Markdown
[![Awesome Lists Badge](https://awesome.facts.dev/shield/brootware/awesome-cyber-security-university/links.svg)](https://awesome.facts.dev/awesome/brootware/awesome-cyber-security-university)
HTML
<a href="https://awesome.facts.dev/awesome/brootware/awesome-cyber-security-university"><img src="https://awesome.facts.dev/shield/brootware/awesome-cyber-security-university/links.svg" alt="Awesome Lists Badge" /></a>
Image URL
https://awesome.facts.dev/shield/brootware/awesome-cyber-security-university/links.svg

What's in the list

143 links in 15 sections, with live GitHub stats.activeno commit in 2y

Introduction and Pre-Security / Level 1 - Intro

  • OpenVPN

    Learn how to connect to a virtual private network using OpenVPN

  • Welcome

    Learn how to use a TryHackMe room to start your upskilling in cyber security

  • Intro to Researching

    A brief introduction to research skills for pentesting

  • Linux Fundamentals 1

    Embark on the journey of learning the fundamentals of Linux. Learn to run some of the first essential commands on an interactive terminal

  • Linux Fundamentals 2

    Embark on the journey of learning the fundamentals of Linux. Learn to run some of the first essential commands on an interactive terminal

  • Linux Fundamentals 3

    Embark on the journey of learning the fundamentals of Linux. Learn to run some of the first essential commands on an interactive terminal

  • Pentesting fundamentals

    Fundamentals of penetration testing

  • Principles of security

    Principles of security

  • Red Team Engagements

    Intro to red team engagements

  • Hip Flask

    An in-depth walkthrough covering pentest methodology against a vulnerable server

  • Practice Linux Commands

    A free course with 41 hands-on labs to practice and master the most commonly used Linux commands

  • Google Dorking

    Explaining how Search Engines work and leveraging them into finding hidden content!

  • Osint

    Intro to Open Source Intelligence

  • Shodan.io

    Learn about Shodan.io and how to use it for device enumeration

Free Beginner Red Team Path / Level 2 - Tooling

  • Tmux

    Learn to use tmux, one of the most powerful multi-tasking tools on linux

  • Nmap,Curl and Netcat

    Get experience with Nmap, Curl and Netcat for network communications

  • Web Scanning

    Learn the basics of automated web scanning

  • Sublist3r

    Learn how to find subdomains with Sublist3r

  • Metasploit

    An introduction to the main components of the Metasploit Framework

  • Hydra

    Learn about and use Hydra, a fast network logon cracker, to bruteforce and obtain a website's credentials

  • Linux Privesc

    Practice your Linux Privilege Escalation skills on an intentionally misconfigured Debian VM with multiple ways to get root! SSH is available

  • Red Team Fundamentals

    Learn about the basics of a red engagement, the main components and stakeholders involved, and how red teaming differs from other cyber security engagements

  • Red Team Recon

    Learn how to use DNS, advanced searching, Recon-ng, and Maltego to collect information about your target

  • Nmap Tutorials

    Learn and practice the basics of network scanning using Nmap

  • Vulnversity

    Learn about active recon, web app attacks and privilege escalation

  • Blue

    Deploy & hack into a Windows machine, leveraging common misconfigurations issues

  • Simple CTF

    Beginner level CTF

  • Bounty Hacker

    A space cowboy-themed boot to root machine

Free Beginner Red Team Path / Level 3 - Crypto & Hashes with CTF practice

  • Crack the hash

    Cracking hash challenges

  • Agent Sudo

    You found a secret server located under the deep sea. Your task is to hack inside the server and reveal the truth

  • The Cod Caper

    A guided room taking you through infiltrating and exploiting a Linux system

  • Ice

    Deploy & hack into a Windows machine, exploiting a very poorly secured media server

  • Lazy Admin

    Easy linux machine to practice your skills

  • Basic Pentesting

    This is a machine that allows you to practice web app hacking and privilege escalation

  • Bypassing UAC

    Learn common ways to bypass User Account Control (UAC) in Windows hosts

Free Beginner Red Team Path / Level 4 - Web

  • OWASP top 10

    Learn about and exploit each of the OWASP Top 10 vulnerabilities; the 10 most critical web security risks

  • Inclusion

    A beginner-level LFI challenge

  • Injection

    Walkthrough of OS Command Injection. Demonstrate OS Command Injection and explain how to prevent it on your servers

  • Juiceshop

    This room uses the OWASP juice shop vulnerable web application to learn how to identify and exploit common web application vulnerabilities

  • Overpass

    What happens when some broke CompSci students make a password manager

  • Year of the Rabbit

    Can you hack into the Year of the Rabbit box without falling down a hole

  • DevelPy

    Boot2root machine for FIT and bsides Guatemala CTF

  • Jack of all trades

    Boot-to-root originally designed for Securi-Tay 2020

  • Bolt

    Bolt themed machine to root into

Free Beginner Red Team Path / Level 5 - Reverse Engineering & Pwn

Free Beginner Red Team Path / Level 6 - PrivEsc

  • Sudo Security Bypass

    A tutorial room exploring CVE-2019-14287 in the Unix Sudo Program. Room One in the SudoVulns Series

  • Sudo Buffer Overflow

    A tutorial room exploring CVE-2019-18634 in the Unix Sudo Program. Room Two in the SudoVulns Series

  • Windows Privesc Arena

    Students will learn how to escalate privileges using a very vulnerable Windows 7 VM

  • Linux Privesc Arena

    Students will learn how to escalate privileges using a very vulnerable Linux VM

  • Windows Privesc

    Students will learn how to escalate privileges using a very vulnerable Windows 7 VM

  • Blaster

    Metasploit Framework to get a foothold

  • Ignite

    A new start-up has a few security issues with its web server

  • Kenobi

    Walkthrough on exploiting a Linux machine. Enumerate Samba for shares, manipulate a vulnerable version of proftpd and escalate your privileges with path variable manipulation

  • Capture the flag

    Another beginner-level CTF challenge

  • Pickle Rick

    Rick and Morty themed LFI challenge

Free Beginner Blue Team Path / Level 1 - Tools

Free Beginner Blue Team Path / Level 2 - Security Operations, Incident Response & Threat Hunting

Free Beginner Blue Team Path / Level 3 - Beginner Forensics, Threat Intel & Cryptography

Free Beginner Blue Team Path / Level 4 - Memory & Disk Forensics

Free Beginner Blue Team Path / Level 5 - Malware and Reverse Engineering

Bonus CTF practice and Latest CVEs

  • Bandit

    Aimed at absolute beginners and teaches the basics of remote server access

  • Natas

    Teaches the basics of serverside web-security

  • Post Exploitation Basics

    Learn the basics of post-exploitation and maintaining access with mimikatz, bloodhound, powerview and msfvenom

  • Smag Grotto

    An obsecure boot to root machine

  • Dogcat

    I made a website where you can look at pictures of dogs and/or cats! Exploit a PHP application via LFI and break out of a docker container

  • Buffer Overflow Prep

    Practice stack-based buffer overflows

  • Break out the cage

    Help Cage bring back his acting career and investigate the nefarious going on of his agent

  • Lian Yu

    A beginner-level security challenge

  • Insecure Kubernetes

    Exploiting Kubernetes by leveraging a Grafana LFI vulnerability

  • The Great Escape (docker)

    Escaping docker container

  • Solr Exploiting Log4j

    Explore CVE-2021-44228, a vulnerability in log4j affecting almost all software under the sun

  • Spring4Shell

    Interactive lab for exploiting Spring4Shell (CVE-2022-22965) in the Java Spring Framework

  • Most Recent threats

    Learn about the latest industry threats. Get hands-on experience identifying, exploiting, and mitigating critical vulnerabilities

Bonus Windows

  • Attacktive Directory

    Learn about 99% of Corporate networks that run off of AD

  • Retro

    Breaking out of the retro-themed box

  • Blue Print

    Hack into this Windows machine and escalate your privileges to Administrator

  • Anthem

    Exploit a Windows machine in this beginner-level challenge

  • Relevant

    Penetration Testing Challenge

Extremely Hard Rooms to do

  • Ra

    You have found WindCorp's internal network and their Domain Controller. Pwn the network

  • CCT2019

    Legacy challenges from the US Navy Cyber Competition Team 2019 Assessment sponsored by US TENTH Fleet

  • Theseus

    The first installment of the SuitGuy series of very hard challenges

  • IronCorp

    Get access to Iron Corp's system

  • Carpe Diem 1

    Recover your client's encrypted files before the ransomware timer runs out

  • Borderlands

    Compromise a perimeter host and pivot through this network

  • Jeff

    Hack into Jeff's web server

  • Year of the Owl

    Owl-themed boot to root machine

  • Anonymous Playground

    Want to become part of Anonymous? They have a challenge for you

  • EnterPrize

    Enterprise-themed network to hack into

  • Racetrack Bank

    It's time for another heist

  • Python Playground

    Use python to pwn this room

Footnotes / Contributors & stargazers ✨

Add a GitHub project

Missing a project or an awesome list? Paste its GitHub URL and we fetch it right away.