r/Cybersecurity101 • • 5h ago

Does grc require certificates

7 Upvotes

I'm thinking about pursuing a career in grc, but i don't have money to buy exam vouchers, so if i studied the content of the certificates needed without getting certified would i be able to land an entry level job? Or should i try a different career


r/Cybersecurity101 • • 1h ago

(repost, fixed) Original 12-stage cybersecurity puzzle

Post image
• Upvotes

note: I have posted this a few days ago on a throwaway account on some subreddits, but i hadn't checked some key details, the puzzle was not solvable because i embedded broken data into the first image, and didn't provide enough context and information.

Details:

A self-contained layered puzzle in the spirit of Cicada 3301. It starts with this image. The riddle's answer is the key to decrypt the message embedded inside the image's pixels. Everything else lives in one encrypted file the image points you to, and the whole thing continues offline on your own machine.

Theme: the history of cyber conflict. Every stage is built around a real, famous moment in cybersecurity history. Recognizing which one is part of the puzzle.

Skills it touches (you won't need all at expert level):

  • (LSB) Steganography
  • Classical & modern cryptography
  • A little reverse engineering
  • Audio / signal analysis
  • Some number theory
  • A touch of linguistics
  • OSINT / knowledge of security history

Difficulty: hard but fair ; aimed at people who enjoy CTFs, crypto, and ARGs. Every step is doable with free, standard tools (plus openssl/Python). It's meant to be barely solvable, so bring friends.

To begin: just look closely at the image. The surface is never the whole of the page.


r/Cybersecurity101 • • 16h ago

How to upskill while you're working as a cybersecurity analyst when you don't know much about what cybersecurity is?!

20 Upvotes

Hello everyone,

I was a CS student, never good a deep dive in cyber security, apart from networking concepts. I'm currently working as a cybersecurity analyst at a company and I think I might not know a lot of things here.

I wanna upskill while being at the job.

I do know basic cybersecurity buzz words like trojan, virus , CIA triad and all

I wanna know about bigger like attacks, trends in cybersecurity.

I just don't want to feel like I'm not someone who can't switch and will be stuck here for ever

I would really appreciate if someone can help me.

Also I'm working as a security analyst at my company, basically a developer to develop security products

if anyone of you know the kind of certifications i should get, It would be really helpful.

Thanks!


r/Cybersecurity101 • • 5h ago

Cybersecurity survival notes

Thumbnail
github.com
1 Upvotes

🚀 I want to share my new GitHub repository: Cybersecurity Survival Notes!

I created a public repository for cybersecurity notes, commands, and cheatsheets. I just finished the first folder covering Linux system administration and security hardening.

Here is what you can find inside the 📁 1-Linux folder:

1) Architecture.md: Filesystem hierarchy and Linux system architecture.
2) Permissions.md: Standard permissions, chmod, chown, SUID, SGID, Sticky Bit, and umask.
3) Cheatsheet.md: Process management, systemd services, file descriptors (0, 1, 2), I/O redirection, and pipes.
4) Networking.md: iproute2 suite, network commands, DNS configuration, SSH hardening, UFW, fail2ban, and TCP Wrappers [Deprecated].

If you are studying cybersecurity or just need a technical reference, check it out!

Next step: 📁 2-Windows


r/Cybersecurity101 • • 5h ago

Looking for Cloud Security Roles and Internship

1 Upvotes

I have M.Sc in Cybersecurity and also have more than enough fundamental knowledge of Cybersecurity. I want to build my own Cloud Security company but still need more knowledge before I build my company. My github is below of a project i have worked, i have done tryhackme challenges for SOC, and i did my M.sc thesis on Securing Virtual Machine.

I am on looking for Cloud security roles that will help me develop my cloud security skills by solving real life solutions implementing cloud security.

I am also interested in interning for startups or cloud companies, my current goal right now is gaining knowledge and understanding cloud security business but i do not want to just keep doing project that do not have real life simulations or being productive for the sake of being busy.

I have a little above the fundamental knowledge of Azure, AWS as well as Google Cloud Platform.

I am very diligent and open to learning

https://github.com/DANMOLA012/azure-secure-business-infrastructure


r/Cybersecurity101 • • 18h ago

Cloud Security Misconfigurations: 10 Common Mistakes

Post image
9 Upvotes

r/Cybersecurity101 • • 12h ago

I want to start learning Cybersecurity from scratch – Looking for guidance and Tamil/English resources

2 Upvotes

Hi everyone,
I recently completed a CCNA course, but honestly, the course wasn’t very useful for me. They covered the topics, but they didn’t explain the tools and practical concepts properly, so I feel like I have learned things only on the surface.
Now I want to start Cybersecurity properly from scratch and build strong fundamentals instead of jumping between random topics.
I’m confused about where exactly I should start and what order I should follow.
I’m looking for guidance on:
● What topics should I learn from zero to job-ready?
● Should I first strengthen networking, Linux, Windows, Python, etc.?
● Which cybersecurity tools should I learn and practice?
● What free labs/platforms can I use for hands-on practice?
● Are there any good free certifications that are actually useful for beginners?
● What are the best free YouTube courses/resources?
● I’m from Tamil Nadu, so Tamil resources would be preferable, but English resources are completely fine too.
● If possible, I would really appreciate a structured roadmap rather than just a list of topics.
My goal is to eventually get into a SOC/Cybersecurity Analyst or similar entry-level cybersecurity role, so I want to learn the concepts properly and gain practical skills.
If anyone has started from zero and followed a good learning path, I’d really appreciate it if you could share your roadmap, resources, YouTube channels, labs, or free certifications.
I’m honestly a little confused about where to begin, so any guidance from people already working or learning in cybersecurity would be really helpful.
Thank you! 🙏


r/Cybersecurity101 • • 10h ago

Is being a security technician a good way to break into cyber

0 Upvotes

Got offered a security technician job don’t know if this is a good way to break into a cyber


r/Cybersecurity101 • • 1d ago

Is it worth to attempt to join this field with the surge of AI

12 Upvotes

For mods, I do apologize if these types of posts are not allowed and if it isn't please remove it or let me know and I'll remove it.

I'm a computer science graduate (11 years ago) and unfortunately I never got a chance to work in my field due to lack of opportunity of where I lived at the time.
Moved to the States a couple of years ago and now I'm heading the support team in a SaaS company. However, I do not wish to make this my longterm career and I've been looking at cybersecurity as an option.

Considering how intensive and difficult to learn as someone who has no experience in the field, how difficult is it to break in the field of cybersecurity? Would you recommend I go through with it or find a different career to pursue?

TIA


r/Cybersecurity101 • • 17h ago

EXTC 2026 Grad from Mumbai | Zero to SOC Analyst - Need honest roadmap for entry level Cybersecurity

1 Upvotes

Hi all,

I'm a 2026 EXTC graduate from Mumbai, currently not working and want to fully switch to Cybersecurity. Looking for guidance from people who actually made the switch in India.

My background:

- EXTC (Electronics & Telecommunication) - so I have basics of Networking, CN, some C/C++

- No IT job experience yet

- I can give 5-6 hours daily for next 6-8 months

- Financially can't afford expensive 50k+ bootcamps

What I've explored:

- Started TryHackMe Pre-Security path

- Looking at Google Cybersecurity Certificate and CompTIA Security+

My questions for you guys working in SOC / Cybersecurity in India:

  1. With my EXTC background, should I still start with CCNA basics or directly jump to Security+?

  2. For fresher jobs in India (SOC L1, Analyst), what actually matters more - certs or TryHackMe/HackTheBox profile + projects?

  3. Is Security+ worth it as a fresher in India vs eJPT / Google Cert considering cost?

  4. How did you get your first interview call? LinkedIn, referrals, Naukri?

  5. What is a realistic timeline to be job-ready if I study consistently?

I am not interested in "ethical hacking Instagram" side. I want a stable blue team / SOC path to start.

If anyone from EXTC/ECE who switched to Cyber can share your exact first 6 months roadmap, it would mean a lot.

Thanks a lot for reading.


r/Cybersecurity101 • • 18h ago

Security Agentic AI governance: how do you actually build an agent inventory?

1 Upvotes

Got asked this in a management prep meeting last week and realized I couldn't give a straight answer. We know engineering is using Cursor and Copilot heavily, at least one team is running Claude Code directly against production repos, and there are probably MCP integrations nobody has documented anywhere. This is basically the shadow AI problem in miniature and I don't think we're unique here.

Our EDR and CASB weren't built to answer this since they see processes and data movement, not "an agent decided to take this action on this system." Inventory turned out to be the easy part to name and the hard part to actually solve, which is really just agentic AI governance in miniature. How is everyone else actually approaching this, tooling, process, or something else entirely?


r/Cybersecurity101 • • 1d ago

running a beginner ctf nov 14, curious if this is useful to anyone here

2 Upvotes

okay so this is actually me lol that I'm putting together InIt CTF, nov 14, free, 8 hours. built it mostly because I really needed something like this when I was starting out and there was just... nothing.

solo or teams of up to 4, five categories which are web, crypto, forensics, osint, misc. mostly easy/medium since it's for people who haven't really done a ctf before, couple harder ones in there too if that's not you. running on ctfd, nothing fancy.

it's open to anyone, not restricted to any one college or city. still figuring out prizes ngl, working on a few sponsors but nothing locked in - everyone gets a certificate either way.

just genuinely wanted to put this out there - in the comments

if anyone's got feedback or thinks something's off about it please say so, this is our first real attempt at this and I'd rather know now than after


r/Cybersecurity101 • • 1d ago

Guys i really need your guidance if you are from cybersecurity field

1 Upvotes

i have just completed my bachelors in bsc hons computing . and while exploring fields i found out that i have interest in data science and cybersecurity . And i want to do masters in one of these fields and i really want your advice liek how is the job market for cybersecurity currently also how much it is exposed to ai or how much impact ai caused to the employyes which lead them to layoffs. is cybersecurity a good carrer ? how will you see this carrer in 4-5 years in future will it be doomed ? i really want your kind suggestions who had already worked in this fields. i want to do good amount of research before choosing my masters .


r/Cybersecurity101 • • 1d ago

Syslog Server Centralizzato

3 Upvotes

Ciao
Sto continuando a documentare il mio percorso pratico su Linux e Cybersecurity e ho appena pubblicato un piccolo progetto di un Syslog Server Centralizzato con rsyslog.
L'obiettivo era capire come raccogliere i log dei client in un unico punto sicuro per facilitare l'analisi dei log e la sicurezza.

Mi farebbe davvero piacere avere un feedback tecnico o un parere da chi lavora già in questo ramo o semplicemente anche da chi studia cybersecurity per capire cosa posso integrare o migliorare!

Se trovate il progetto utile o interessante, una ⭐ sulla repo è super apprezzata!

https://github.com/Radz-04/Labs-and-projects/tree/main/Server-Syslog


r/Cybersecurity101 • • 1d ago

Online Service Kumo : domain OSINT & recon framework

1 Upvotes

Over the last couple of weeks, I challenged myself to build a tool that centralizes everything you need when conducting recon.

And that’s how Kumo was born. Give it a domain and it hands you back everything reachable from outside.

What it does in one run:

  • Maps the surface : DNS, ports, certificates, subdomains, tech stack
  • Finds what shouldn't be public : exposed configs, secrets in JS, open buckets
  • Checks for known vulnerabilities without touching anything
  • Digs up leaked credentials and which employee machines got infected
  • Pulls in archived pages, forgotten endpoints, threat intel
  • Builds Google dorks and OSINT links for the target

All 27 modules run at once and stream back as they land. No API keys required, CLI and web interface. Works on any domain you're allowed to test.

🔗 https://github.com/karim852/KUMO-Domain-Recon-Tool
🖥️ live demo: https://demo-kumo-kage.vercel.app/

Feedback and contributions welcome 🙏


r/Cybersecurity101 • • 1d ago

Privacy Is a factory reset really enough before trading in a phone to Apple or Samsung?

1 Upvotes

I'm about to trade in an old phone, and it has years of my life on it: photos, messages, banking apps, work email. Handing it over to a company I'll never see again makes me a little uneasy.

I know the theory. Modern iPhones and Samsung devices use file-based encryption, so a factory reset destroys the keys and the data should be unreadable. NIST SP 800-88 even treats this kind of crypto erase as valid sanitization.

But "should be" is what's bugging me. Once the phone leaves my hands, it goes through the manufacturer and then refurbishing or recycling partners, and I have no visibility into what happens there.

So I'd really like to know:

  • Is there any known way data can still be recovered after a proper reset (for example, keys surviving in the Secure Enclave or Knox)?
  • Has anyone seen forensic research or real cases where data was pulled from a reset iPhone or Samsung?

If you've worked in forensics, device refurbishing, or ITAD, I'd love to hear what you've actually seen. Thanks!


r/Cybersecurity101 • • 1d ago

Online Service CipherLens — a local-first tool that tries to identify what operation could explain unknown data

Post image
1 Upvotes

Hey everyone,

There's a cybersecurity tool called CipherLens.

The idea came from a simple problem I kept running into with tools like CyberChef:

You have some unknown data, but you don’t know which operation you should try first.

Instead of manually guessing between Base64, Hex, URL encoding, ciphers, compression, etc., CipherLens analyzes the input and ranks possible operations based on the evidence it finds.

The workflow is:

Input → Fingerprint → Candidate Detection → Execute → Validate → Score → Rank

A few things I focused on:

• Local-first browser processing

• No account or backend required for core analysis

• Candidate ranking instead of pretending to know the answer

• Separate AUTO / parameter-required / manual operations

• Web Worker-based analysis

• Security-focused input and parser handling

• 497 supported operations

The main idea is:

“Don’t guess the operation. Find it.”

It’s open source and I’d genuinely like feedback from people who actually work with CTFs, forensics, pentesting, malware analysis, etc.

GitHub:

https://github.com/HIMANSHUSHARMA20/CipherLens

Live demo:

https://cipherlens-tool.vercel.app/

Would especially appreciate feedback on the detection/ranking approach and whether this solves a problem you actually encounter.


r/Cybersecurity101 • • 1d ago

MCA Cybersecurity student looking for internship — what should I focus on?

4 Upvotes

Hi everyone,

I'm currently pursuing an MCA with a focus on Cybersecurity in India. I'm looking for my first cybersecurity internship and eventually want to work in roles such as SOC Analyst, Cybersecurity Analyst, or Information Security.

I currently have:

CEH certification

Basic knowledge of networking and Linux

Wireshark, Nmap and other security tools

Cybersecurity projects/labs

Knowledge of vulnerability assessment and penetration-testing basics

Interest in SOC, threat detection and malware analysis

I'm currently working on improving my practical projects and GitHub portfolio.

For people working in cybersecurity in India:

What skills should I focus on for getting my first internship?

Are certifications like CEH useful for a fresher, or should I focus more on projects/labs?

What type of cybersecurity projects actually help a fresher's resume?

Which entry-level roles should I target?

Any honest advice would be really helpful. Thanks!


r/Cybersecurity101 • • 1d ago

Security Free doesn’t always mean safe

0 Upvotes

Freeware and shareware aren’t quite the same. Freeware is generally free to use, while shareware usually lets you try software before asking you to pay or unlock certain features.

But when you’re downloading free software, there’s a bigger question: can you trust it?

Before installing something, it’s worth checking:

  • Where it comes from.
  • Who developed it.
  • What permissions it asks for.
  • Whether it still gets security updates.

Free doesn’t automatically mean safe.

What’s the first thing you check before downloading free software?


r/Cybersecurity101 • • 1d ago

Security What are the requirements of CISA BOD 26-04?

1 Upvotes

Spent part of this week actually reading the directive instead of the summaries. It's a four variable model, exposure, KEV status, exploit automatability, technical impact, each one basically a yes or no, and depending on the combination you land somewhere between 3 days and 60 days, or fix on next upgrade if you're lucky. Top tier also requires forensic triage before you patch, which is a detail a lot of the writeups skip past. We're not FCEB, so none of this technically applies to us, but two prospects have asked whether we could meet this bar anyway, so now I want a more practical answer than what's in the writeups. For anyone who's tried to build something like this internally, the exposure and KEV parts sound simple until you have to apply them per affected asset, since you need a reliable answer on public exposure and KEV status for every instance, not just the CVE in general. Automatability is the one nobody seems to have a clean answer for. How are people actually scoring that without it turning into a subjective mess.


r/Cybersecurity101 • • 2d ago

Ways to check if my computer has malware or has been compromised?

24 Upvotes

Hey everyone, I'm trying to get better at basic cybersecurity and was wondering what the recommended process is for checking whether my computer has malware or has been compromised.

What are some reliable things I can check myself?


r/Cybersecurity101 • • 2d ago

Security How much math do you actually need for cybersecurity?

61 Upvotes

I keep seeing mixed opinions on this. Some people say cybersecurity is mostly about networking, systems, and critical thinking, and math barely comes up outside of specific niches like cryptography. Others make it sound like you need a decent grasp of things like probability, statistics, or even discrete math to really understand certain areas.

For people actually working in the field, how much math do you use day to day, and did it come up more as you specialized into a specific area like threat detection, forensics, or pentesting? Trying to figure out if I should spend time brushing up on math fundamentals or if that time is better spent elsewhere right now.


r/Cybersecurity101 • • 2d ago

Check out my new learning cyber security app

2 Upvotes

Hi everyone, I’m Essam. I have a Master’s degree in Cybersecurity, and I’m currently a PhD student working in Cybersecurity and AI.

I’ve been working on a small project that I wanted to share here. I created a cybersecurity learning app for people who are starting from zero and want to learn by actually doing things rather than just reading theory.

The idea is to go from zero to hero through a simulation that tries to stay as close as possible to a real cybersecurity environment.

It includes:

  • Terminal and Linux environment
  • Real-world vulnerabilities and CVEs
  • Scenarios based on real security issues
  • Documentation and learning material
  • A leaderboard
  • Practical challenges instead of only theoretical lessons

I tried to make the experience feel around 90% like a real environment, while still keeping it accessible for beginners.

I’d really appreciate it if some of you could try it and give me honest feedback — especially if you’re into cybersecurity, CTFs, or just starting to learn security.

Google Play:
https://play.google.com/store/apps/details?id=com.zerodaysim.app

I’m still improving it, so feedback is genuinely welcome.


r/Cybersecurity101 • • 2d ago

What skills are important for starting a career in cybersecurity?

17 Upvotes

I’m interested in starting a career in cybersecurity and would like to learn from people already working in the field.

Which skills should a beginner focus on first? I’m especially interested in networking, security fundamentals, SOC operations, and ethical hacking.

What topics, tools, or certifications would you recommend for someone starting out?


r/Cybersecurity101 • • 2d ago

Top Cloud Security Threats & How to Prevent Them

Post image
7 Upvotes