Skip to content

A thorough resource encompassing fundamental and advanced cybersecurity topics, including Web App Pen Testing concepts, interview questions and answers, network security principles, essential networking knowledge, security insights, practical tools, and threat intelligence techniques like OSINT. Free cybersecurity resources.

Notifications You must be signed in to change notification settings

IOxCyber/Ultimate-Cybersecurity-Guide_UCG

Repository files navigation

Static Badge

Ultimate-Cybersecurity-Guide (UCG)

Essential learning guide in CyberSec.

A1 Concepts:



1. Web Application Security Testing: PortSwigger Academy

Client Side Vuln: ONLY Cross Site Scripting(XSS) | Cross Site Request Forgery | Cross Origin Resource Sharing(CORS) | Clickjacking | DOM Based Vuln | Web Socket

2. All About APIs:

3. Mobile App Sec Testing:

  • Android
  • iOS


Topics-Covered:



Cheatsheet:

  1. CyberSec Tools - Resources

Imp Links to refer:

  1. OSCP — The Official Guide
  2. C|EH in Bullets

Security Tools

  1. Burp-Suite:
  • Definition: Web proxy to intercept, analyze, and modify HTTP/S traffic.
  • Best For: Web, API, Mobile (API Traffic Analysis).
  1. Metasploit:
  • Definition: Exploitation framework to identify, exploit, and validate system vulnerabilities.
  • Best For: Web, Network, API, Application, Post-Exploitation.
  1. Nessus: Vulnerability scanner
  • Definition: To detect misconfigurations and security gaps System-level (OS, services, ports, packages), CVE-based scans for known vulns
  • Best For: Network, Web, Infrastructure, Cloud Security.
  1. Nmap Network Mapper:
  • Definition: Network scanner to check open ports, services, and hosts.
  • Best For: Network Recon, Web Enumeration, API Recon, Advance NSE (NMAP Script Engine) Support
  1. Qualys Scanning Tool:
  • Definition: Cloud-based scanner for identifying vulnerabilities and ensuring compliance.
  • Best For: Web, Cloud, Network, Compliance Audits.
  1. Wireshark: Traffic Analyser
  • Intercept HTTP/S traffic between browser and server for manual and automated testing.
  • Use to analyze the traffic.
  1. Nikto: Web Server Scanner:
  • Detect misconfigurations, outdated software, and exposed files in internal networks, dev/test environments, or legacy systems.
  • Best for initial recon and hygiene checks before deeper analysis with tools like Burp or Nessus.


Youtube Resource:

NetworkChuck:

NahamSec

Null Byte

The Cyber Expert (Hindi)

HackerSploit

About

A thorough resource encompassing fundamental and advanced cybersecurity topics, including Web App Pen Testing concepts, interview questions and answers, network security principles, essential networking knowledge, security insights, practical tools, and threat intelligence techniques like OSINT. Free cybersecurity resources.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published