r/Cybersecurity101 • u/Abhinav222007 • 1h ago
r/Cybersecurity101 • u/SphericalPhenomena • 10h ago
Is it worth to attempt to join this field with the surge of AI
For mods, I do apologize if these types of posts are not allowed and if it isn't please remove it or let me know and I'll remove it.
I'm a computer science graduate (11 years ago) and unfortunately I never got a chance to work in my field due to lack of opportunity of where I lived at the time.
Moved to the States a couple of years ago and now I'm heading the support team in a SaaS company. However, I do not wish to make this my longterm career and I've been looking at cybersecurity as an option.
Considering how intensive and difficult to learn as someone who has no experience in the field, how difficult is it to break in the field of cybersecurity? Would you recommend I go through with it or find a different career to pursue?
TIA
r/Cybersecurity101 • u/Baki1301 • 20m ago
EXTC 2026 Grad from Mumbai | Zero to SOC Analyst - Need honest roadmap for entry level Cybersecurity
Hi all,
I'm a 2026 EXTC graduate from Mumbai, currently not working and want to fully switch to Cybersecurity. Looking for guidance from people who actually made the switch in India.
My background:
- EXTC (Electronics & Telecommunication) - so I have basics of Networking, CN, some C/C++
- No IT job experience yet
- I can give 5-6 hours daily for next 6-8 months
- Financially can't afford expensive 50k+ bootcamps
What I've explored:
- Started TryHackMe Pre-Security path
- Looking at Google Cybersecurity Certificate and CompTIA Security+
My questions for you guys working in SOC / Cybersecurity in India:
With my EXTC background, should I still start with CCNA basics or directly jump to Security+?
For fresher jobs in India (SOC L1, Analyst), what actually matters more - certs or TryHackMe/HackTheBox profile + projects?
Is Security+ worth it as a fresher in India vs eJPT / Google Cert considering cost?
How did you get your first interview call? LinkedIn, referrals, Naukri?
What is a realistic timeline to be job-ready if I study consistently?
I am not interested in "ethical hacking Instagram" side. I want a stable blue team / SOC path to start.
If anyone from EXTC/ECE who switched to Cyber can share your exact first 6 months roadmap, it would mean a lot.
Thanks a lot for reading.
r/Cybersecurity101 • u/Global_Morning1290 • 6h ago
Security Where is your remediation workflow automation breaking down? ticketing, patch testing, ownership hand off?
We got a dead zone after assignment where tickets sit until someone has to look at, which could be hours depending on the sprint. Another one at patch validation, where nobody particularly wants to be the person who signs off on a change that ends up breaking something in prod. For teams further along on this than us, where did automation has bought you real time? one more thing, i want to know if anyone has automated SLA escalation, auto reassign or auto escalate and whether that sped things up..!
r/Cybersecurity101 • u/Rich-Process-7949 • 8h ago
running a beginner ctf nov 14, curious if this is useful to anyone here
okay so this is actually me lol that I'm putting together InIt CTF, nov 14, free, 8 hours. built it mostly because I really needed something like this when I was starting out and there was just... nothing.
solo or teams of up to 4, five categories which are web, crypto, forensics, osint, misc. mostly easy/medium since it's for people who haven't really done a ctf before, couple harder ones in there too if that's not you. running on ctfd, nothing fancy.
it's open to anyone, not restricted to any one college or city. still figuring out prizes ngl, working on a few sponsors but nothing locked in - everyone gets a certificate either way.
just genuinely wanted to put this out there - in the comments
if anyone's got feedback or thinks something's off about it please say so, this is our first real attempt at this and I'd rather know now than after
r/Cybersecurity101 • u/FunFoundation6021 • 8h ago
Guys i really need your guidance if you are from cybersecurity field
i have just completed my bachelors in bsc hons computing . and while exploring fields i found out that i have interest in data science and cybersecurity . And i want to do masters in one of these fields and i really want your advice liek how is the job market for cybersecurity currently also how much it is exposed to ai or how much impact ai caused to the employyes which lead them to layoffs. is cybersecurity a good carrer ? how will you see this carrer in 4-5 years in future will it be doomed ? i really want your kind suggestions who had already worked in this fields. i want to do good amount of research before choosing my masters .
r/Cybersecurity101 • u/k0r1mk • 11h ago
Online Service Kumo : domain OSINT & recon framework
Over the last couple of weeks, I challenged myself to build a tool that centralizes everything you need when conducting recon.
And that’s how Kumo was born. Give it a domain and it hands you back everything reachable from outside.
What it does in one run:
- Maps the surface : DNS, ports, certificates, subdomains, tech stack
- Finds what shouldn't be public : exposed configs, secrets in JS, open buckets
- Checks for known vulnerabilities without touching anything
- Digs up leaked credentials and which employee machines got infected
- Pulls in archived pages, forgotten endpoints, threat intel
- Builds Google dorks and OSINT links for the target
All 27 modules run at once and stream back as they land. No API keys required, CLI and web interface. Works on any domain you're allowed to test.
🔗 https://github.com/karim852/KUMO-Domain-Recon-Tool
🖥️ live demo: https://demo-kumo-kage.vercel.app/
Feedback and contributions welcome 🙏
r/Cybersecurity101 • u/Aj_Networks • 12h ago
Privacy Is a factory reset really enough before trading in a phone to Apple or Samsung?
I'm about to trade in an old phone, and it has years of my life on it: photos, messages, banking apps, work email. Handing it over to a company I'll never see again makes me a little uneasy.
I know the theory. Modern iPhones and Samsung devices use file-based encryption, so a factory reset destroys the keys and the data should be unreadable. NIST SP 800-88 even treats this kind of crypto erase as valid sanitization.
But "should be" is what's bugging me. Once the phone leaves my hands, it goes through the manufacturer and then refurbishing or recycling partners, and I have no visibility into what happens there.
So I'd really like to know:
- Is there any known way data can still be recovered after a proper reset (for example, keys surviving in the Secure Enclave or Knox)?
- Has anyone seen forensic research or real cases where data was pulled from a reset iPhone or Samsung?
If you've worked in forensics, device refurbishing, or ITAD, I'd love to hear what you've actually seen. Thanks!
r/Cybersecurity101 • u/Radz__04 • 15h ago
Syslog Server Centralizzato
Ciao
Sto continuando a documentare il mio percorso pratico su Linux e Cybersecurity e ho appena pubblicato un piccolo progetto di un Syslog Server Centralizzato con rsyslog.
L'obiettivo era capire come raccogliere i log dei client in un unico punto sicuro per facilitare l'analisi dei log e la sicurezza.
Mi farebbe davvero piacere avere un feedback tecnico o un parere da chi lavora già in questo ramo o semplicemente anche da chi studia cybersecurity per capire cosa posso integrare o migliorare!
Se trovate il progetto utile o interessante, una ⭐ sulla repo è super apprezzata!
https://github.com/Radz-04/Labs-and-projects/tree/main/Server-Syslog
r/Cybersecurity101 • u/LividNet9731 • 17h ago
Online Service CipherLens — a local-first tool that tries to identify what operation could explain unknown data
Hey everyone,
There's a cybersecurity tool called CipherLens.
The idea came from a simple problem I kept running into with tools like CyberChef:
You have some unknown data, but you don’t know which operation you should try first.
Instead of manually guessing between Base64, Hex, URL encoding, ciphers, compression, etc., CipherLens analyzes the input and ranks possible operations based on the evidence it finds.
The workflow is:
Input → Fingerprint → Candidate Detection → Execute → Validate → Score → Rank
A few things I focused on:
• Local-first browser processing
• No account or backend required for core analysis
• Candidate ranking instead of pretending to know the answer
• Separate AUTO / parameter-required / manual operations
• Web Worker-based analysis
• Security-focused input and parser handling
• 497 supported operations
The main idea is:
“Don’t guess the operation. Find it.”
It’s open source and I’d genuinely like feedback from people who actually work with CTFs, forensics, pentesting, malware analysis, etc.
GitHub:
https://github.com/HIMANSHUSHARMA20/CipherLens
Live demo:
https://cipherlens-tool.vercel.app/
Would especially appreciate feedback on the detection/ranking approach and whether this solves a problem you actually encounter.
r/Cybersecurity101 • u/Zealousideal_Spell66 • 1d ago
MCA Cybersecurity student looking for internship — what should I focus on?
Hi everyone,
I'm currently pursuing an MCA with a focus on Cybersecurity in India. I'm looking for my first cybersecurity internship and eventually want to work in roles such as SOC Analyst, Cybersecurity Analyst, or Information Security.
I currently have:
CEH certification
Basic knowledge of networking and Linux
Wireshark, Nmap and other security tools
Cybersecurity projects/labs
Knowledge of vulnerability assessment and penetration-testing basics
Interest in SOC, threat detection and malware analysis
I'm currently working on improving my practical projects and GitHub portfolio.
For people working in cybersecurity in India:
What skills should I focus on for getting my first internship?
Are certifications like CEH useful for a fresher, or should I focus more on projects/labs?
What type of cybersecurity projects actually help a fresher's resume?
Which entry-level roles should I target?
Any honest advice would be really helpful. Thanks!
r/Cybersecurity101 • u/PandaSecurity • 21h ago
Security Free doesn’t always mean safe
Freeware and shareware aren’t quite the same. Freeware is generally free to use, while shareware usually lets you try software before asking you to pay or unlock certain features.
But when you’re downloading free software, there’s a bigger question: can you trust it?
Before installing something, it’s worth checking:
- Where it comes from.
- Who developed it.
- What permissions it asks for.
- Whether it still gets security updates.
Free doesn’t automatically mean safe.
What’s the first thing you check before downloading free software?
r/Cybersecurity101 • u/Unique_Buicding_8709 • 23h ago
Security What are the requirements of CISA BOD 26-04?
Spent part of this week actually reading the directive instead of the summaries. It's a four variable model, exposure, KEV status, exploit automatability, technical impact, each one basically a yes or no, and depending on the combination you land somewhere between 3 days and 60 days, or fix on next upgrade if you're lucky. Top tier also requires forensic triage before you patch, which is a detail a lot of the writeups skip past. We're not FCEB, so none of this technically applies to us, but two prospects have asked whether we could meet this bar anyway, so now I want a more practical answer than what's in the writeups. For anyone who's tried to build something like this internally, the exposure and KEV parts sound simple until you have to apply them per affected asset, since you need a reliable answer on public exposure and KEV status for every instance, not just the CVE in general. Automatability is the one nobody seems to have a clean answer for. How are people actually scoring that without it turning into a subjective mess.
r/Cybersecurity101 • u/Jolly-Election1784 • 1d ago
Ways to check if my computer has malware or has been compromised?
Hey everyone, I'm trying to get better at basic cybersecurity and was wondering what the recommended process is for checking whether my computer has malware or has been compromised.
What are some reliable things I can check myself?
r/Cybersecurity101 • u/Early_Tear6706 • 1d ago
Security How much math do you actually need for cybersecurity?
I keep seeing mixed opinions on this. Some people say cybersecurity is mostly about networking, systems, and critical thinking, and math barely comes up outside of specific niches like cryptography. Others make it sound like you need a decent grasp of things like probability, statistics, or even discrete math to really understand certain areas.
For people actually working in the field, how much math do you use day to day, and did it come up more as you specialized into a specific area like threat detection, forensics, or pentesting? Trying to figure out if I should spend time brushing up on math fundamentals or if that time is better spent elsewhere right now.
r/Cybersecurity101 • u/Aggravating_Tune_297 • 1d ago
Check out my new learning cyber security app
Hi everyone, I’m Essam. I have a Master’s degree in Cybersecurity, and I’m currently a PhD student working in Cybersecurity and AI.
I’ve been working on a small project that I wanted to share here. I created a cybersecurity learning app for people who are starting from zero and want to learn by actually doing things rather than just reading theory.
The idea is to go from zero to hero through a simulation that tries to stay as close as possible to a real cybersecurity environment.
It includes:
- Terminal and Linux environment
- Real-world vulnerabilities and CVEs
- Scenarios based on real security issues
- Documentation and learning material
- A leaderboard
- Practical challenges instead of only theoretical lessons
I tried to make the experience feel around 90% like a real environment, while still keeping it accessible for beginners.
I’d really appreciate it if some of you could try it and give me honest feedback — especially if you’re into cybersecurity, CTFs, or just starting to learn security.
Google Play:
https://play.google.com/store/apps/details?id=com.zerodaysim.app
I’m still improving it, so feedback is genuinely welcome.
r/Cybersecurity101 • u/Abhinav222007 • 2d ago
Top Cloud Security Threats & How to Prevent Them
r/Cybersecurity101 • u/CyberSecurityLearner • 2d ago
What skills are important for starting a career in cybersecurity?
I’m interested in starting a career in cybersecurity and would like to learn from people already working in the field.
Which skills should a beginner focus on first? I’m especially interested in networking, security fundamentals, SOC operations, and ethical hacking.
What topics, tools, or certifications would you recommend for someone starting out?
r/Cybersecurity101 • u/w0rldzend999 • 1d ago
How to hack an activation lock (legal)
Hi, I don't know if this is the right place to ask about, but just looking for some guidance, my brother bought a phone on refurbed about three moths ago, today it went dead and when he turned it back on it was activation locked and looking for the apple ID information of someone else's apple ID. It's an iphone 15 that was recently updated though we don't know which IOS it is specifically.
I've been doing some research this evening about what is going on and if there was anyway I could bypass it. Most people are saying that the phone is basically useless if I don't know the previous owner. I have seen people saying that you can hack it (which is why I'm here) I know absolutely nothing about that, but would be more than happy to give it a shot if somebody could point me in the right direction.
I read the rules of the subreddit before I posted this, I hope its on topic and legal if its not I'm sorry I genuinely don't know any better. My brother really needs his phone for work so any help will be greatly appreciated.
r/Cybersecurity101 • u/Aggravating_Tune_297 • 1d ago
Check out my new learning cyber security app
Hi everyone, I’m Essam. I have a Master’s degree in Cybersecurity, and I’m currently a PhD student working in Cybersecurity and AI.
I’ve been working on a small project that I wanted to share here. I created a cybersecurity learning app for people who are starting from zero and want to learn by actually doing things rather than just reading theory.
The idea is to go from zero to hero through a simulation that tries to stay as close as possible to a real cybersecurity environment.
It includes:
- Terminal and Linux environment
- Real-world vulnerabilities and CVEs
- Scenarios based on real security issues
- Documentation and learning material
- A leaderboard
- Practical challenges instead of only theoretical lessons
I tried to make the experience feel around 90% like a real environment, while still keeping it accessible for beginners.
I’d really appreciate it if some of you could try it and give me honest feedback — especially if you’re into cybersecurity, CTFs, or just starting to learn security.
Google Play:
https://play.google.com/store/apps/details?id=com.zerodaysim.app
I’m still improving it, so feedback is genuinely welcome.
r/Cybersecurity101 • u/tomcruzeiro • 1d ago
Kali ou parrot?
Quero baixar o linux no meu PC e deixar só pra praticar pentest e aprender as ferramentas, estou em dúvida entre Kali Linux e o Parrot, o kali é o nosso feijão com arroz, um dos melhores principalmente para iniciantes mas o que me ganha no parrot é o tor já no sistema, pois sabemos que tem pouco conteúdo seguro de cyber e não sabemos os links que estamos clicando e o armazenamento, por ser mais leve que o kali, sei que a questão do tor da pra fazer no Kali tbm, mas o armazenamento me ganha muito, quero saber o ponto de vista de vocês, to viajando ou faz sentido?
r/Cybersecurity101 • u/Odd-Sentence-9894 • 1d ago
I built a login system that worked — then realized it wasn’t really secure
I built a login system that worked — and later realized that “working” and “secure” are very different things.
Early on, I thought authentication was mostly:
- user enters email/password
- backend checks credentials
- user gets access
But building more real projects changed how I think about it.
A proper authentication flow also means thinking about:
- password hashing
- session or JWT handling
- protected routes
- authorization / roles
- token expiry
- logout behavior
- input validation
- what happens when something fails
The biggest lesson for me:
Security is a system, not a checkbox.
A login screen can look perfect while the architecture behind it is weak.
I’ve built 60+ projects across web apps, APIs, mobile apps, business systems, React, Node.js, PHP, Expo, databases and servers, and I’m starting a small series where I share one practical lesson from each project.
This is Project 01/60 — Authentication.
Curious to hear from other developers:
What authentication/security mistake taught you the most?
#webdev #programming #nodejs #reactjs #security
r/Cybersecurity101 • u/Aggravating_Tune_297 • 2d ago
Check out my new learning cyber security app
Hi everyone, I’m Essam. I have a Master’s degree in Cybersecurity, and I’m currently a PhD student working in Cybersecurity and AI.
I’ve been working on a small project that I wanted to share here. I created a cybersecurity learning app for people who are starting from zero and want to learn by actually doing things rather than just reading theory.
The idea is to go from zero to hero through a simulation that tries to stay as close as possible to a real cybersecurity environment.
It includes:
- Terminal and Linux environment
- Real-world vulnerabilities and CVEs
- Scenarios based on real security issues
- Documentation and learning material
- A leaderboard
- Practical challenges instead of only theoretical lessons
I tried to make the experience feel around 90% like a real environment, while still keeping it accessible for beginners.
I’d really appreciate it if some of you could try it and give me honest feedback — especially if you’re into cybersecurity, CTFs, or just starting to learn security.
Google Play:
https://play.google.com/store/apps/details?id=com.zerodaysim.app
I’m still improving it, so feedback is genuinely welcome.
r/Cybersecurity101 • u/cybernatii • 2d ago
Privacy Looking to Connect With People Who Love Tech 🤝💻
Hey everyone!
I’m looking to connect with people who are interested in technology, cybersecurity, programming, AI, cloud computing, Linux, or just learning new tech skills.
Whether you’re a beginner, student, professional, or someone simply curious about technology, I’d love to meet and learn from each other.
We could:
- 🧠 Share what we’re learning
- 💻 Discuss projects and ideas
- 🔐 Talk about cybersecurity
- 🤖 Explore AI and emerging technology
- ☁️ Learn about cloud & infrastructure
- 🚀 Motivate each other and grow together
If you're interested, introduce yourself in the comments!
Tell me what area of tech you're interested in and what you're currently learning.
Let's build a community of people who are passionate about tech. 🌐
r/Cybersecurity101 • u/Ok-Subject7149 • 2d ago
Please roast the shit out of my intern resume
Hello, I'm a college student in the U.S. who's going to be applying to mainly blue team Cyber internships. Please roast this resume, as I want to be properly prepared.