Course Module – CYBER CLAW
Cybersecurity Awareness
• Introduction to Cybersecurity
o Overview of cybersecurity and its significance
o Common cybersecurity threats and risks
o The role of individuals and organizations in cybersecurity
• Basic Security Concepts
o Password management and best practices
o Understanding encryption and its importance
o Importance of software updates and patches
o Introduction to multi-factor authentication
• Protecting Personal Information
o Safeguarding personal data and privacy
o Recognizing phishing attacks and social engineering tactics
o Safe online shopping and banking practices
o Social media safety tips
• Secure Internet Usage
o Safe web browsing habits
o Identifying and avoiding malicious websites
o Introduction to firewalls and antivirus software
o Using public Wi-Fi securely
• Email Security
o Recognizing email threats (phishing, spam, malware)
o Email best practices and secure email communication
o Attachment safety and email encryption
• Social Engineering and Human Factor
o Understanding social engineering attacks
o How to spot and respond to social engineering attempts
o Importance of employee training and awareness in organizations
• Mobile Device Security
o Securing smartphones and tablets
o App security and permissions
o Mobile device encryption and remote wipe
• Safe Online Behavior at Work
o Secure remote work practices
o Company policies and procedures
o Reporting security incidents
• Incident Response and Reporting
o Recognizing and reporting security incidents
o Steps to take in case of a security breach
o Legal and ethical considerations
• Security Culture and Continuous Learning
o Creating a culture of security awareness
o Importance of continuous learning and staying updated
o Resources for further cybersecurity education
Page | 1
Beginner To Advance Cybersecurity
• Basic Linux:
o Introduction to kali Linux
o Usages of Linux CLI
• Cryptography:
o What is Cryptography?
o Asymmetric & Symmetric Cryptography?
o RSA & some Crypto Algorithm
o Hash function Cryptography
• Steganography:
o What is Steganography ?
o Hide & Extract Information inside image
o Hide & Extract Information inside audio
o Hide & Extract Information inside video
• Open-Source Intelligence (OSINT):
o Search engine OSINT
o Email OSINT
o Phone Number OSINT
o Social Media OSINT
o GEO Location OSINT
• Networking:
o Brief Description Basic networking
o (LAN,MAN,WAN,PAN Network Topologies)
o Brief Description Classification of network
o Details Discuss OSI & TCP/IP model (Layer
o Details, Difference)
o Details Protocol, Port number
o Details IP addressing, subnetting, CIDR
o Details (Public, Private) ip address
o Details Loopback, Broadcast, Network add,
o Host Address, IPv4,IPv6
o Details ARP Protocol (How packet travel using ARP)
o Internal & External Network scanning
o Capture & Analysis the network data
• Web Android Penetration Testing:
o Reconnaissance
o Broken Authentication
o Broken Authorization
o Insecure Direct Object Reference
o Server Side Request Forgery
o Client Side Request Forgery
o Business Logic Flows
o Server Side Template Injection
o Starched Query Language Injection
o Cross Site Scripting
o XML External Entity
o File Upload Vulnerabilities
o Sensitive Information Exposure
o Security Misconfiguration
o DNS Takeover
o Account Takeover
• Android Penetration Testing:
Page | 2
o Reconnaissance
o Static Analysis
o Dynamic Analysis
o Common Vulnerabilities
• Digital Forensics:
o Introduction to digital forensics
o What is digital forensics?
o Memory Analysis with Autopsy
o Memory Analysis with Volatility Framework
o Introduction to Sandbox
• SoC Activity:
o Introduction to SOC
o Installation of Splunk
o Usage of Splunk
o Installation of Wazuh
o Usages of Wazuh
o Threat Intelligence(MISP) – Works with MITRE
o ATT&CK Framework
• IoT Security:
o Introduction to IoT Security
o IoT Penetration Testing Methodology
o IoT Protocol Analysis
• Cloud Security:
o Introduction to Cloud Computing
o Cloud Security Fundamentals
o Cloud Security Architecture
o Cloud Security Management
o Cloud Security Tools and Technologies
• Active Directory:
o Introduction to Active Directory
o External Reconnaissance
o Internal enumeration and foot printing
o Lateral movement
o Enumerating and Exploiting Trusts
o Password spraying
o LLNNR/NBT-NS Poisoning
o Gaining privileged access
o Using native tools to perform actions
o Kerberoasting
o Performing ACL Attacks
o AD hardening principles
Bug Bounty Training
• Fundamental Knowledge For Web Pentesting and Bug Hunting
o Basic Cryptography ,Basic Steganography, Basic Digital Forensic
o Basic Web Knowledge Before Pentesting and Bug Hunting
• Recon / Information Gathering
o Google Dorking , DNS Lookup , Scanning , Enumeration
o Nmap, nslookup, nikto, enum4linux, gobuster, wappalyzer, cookie editor etc
• Web Vulnerabilities Pentesting (OWASP)
o HTTP Host Header Attacks
Page | 3
o SQL Injection Attack
o Advanced SQL Injection Attack for Web Pentesting and Bug Hunting
o XSS Attack
o Advanced XSS Attack for Web Pentesting
o and Bug Hunting
o Local File Inclusion , Remote File Inclusion, RCE Using LFI
o XXE Attack
o Command Injection
o Server Side Request Forgery (SSRF)
o Business Logic Vulnerabilities For Bug Bounty
o Information Disclosures For Bug Bounty
• Code Review and Pentesting
o Flask Code Review and Pentesting
o Node Js Code Review and Pentesting
o Django Code Review and Pentesting
• API Pentesting
o What is API?
o How to pentest API for Bug Hunting and Web Pentesting ?
o API Pentesting using POSTman
o API Pentesting using Burp suite professionals
o API Vulnerabilities – Broken Object Level Authorization
o API Vulnerabilities – Broken User Authentication
o API Vulnerabilities – Excessive Data Exposure
• Attacking Common Applications
o WordPress CMS Attack for Bug Hunting
o Joomla CMS Attack for Bug Hunting
o Drupal CMS Attack for Bug Hunting
o Tomcat, Jenkins attack for Bug Hunting
• CVE and Pentesting
o What is CVE ?
o How to Pentest a Website Using CVE?
• Automation Tools for Web Pentesting and Bug Hunting
o List of Automation Tools for Web Pentesting and Bug Hunting
o Advanced use of Burp Suite Professional
• Bug Hunting Master Class with Report Writing
o What is Bug Bounty?
o Bug Bounty Methodology for Beginners
o Bug Bounty Marketplaces or Platforms for Beginners
o How to Write a Standard Report for a Bug?
CTF Bootcamp
• Cryptography:
o What is Cryptography?
o Asymmetric Symmetric Cryptography?
o RSA & some Crypto Algorithm
o Hash function Cryptography
• Steganography:
o What is Steganography ?
o Hide & Extract Information inside image
o Hide & Extract Information inside audio
o Hide & Extract Information inside video
Page | 4
• Open-Source Intelligence (OSINT):
o Search engine OSINT
o Email OSINT
o Social Media OSINT
o GEO Location OSINT
• Digital Forensics:
o Introduction to digital forensics
o What is digital forensics?
o Memory Analysis with Autopsy
o Memory Analysis with Volatility Framework
o Introduction to Sandbox
• Networking:
o Pcap File Analysis
• Web Application
o IDOR
o SSRF
o RCE
o SSTI
o SQLi
o Auth Bypass
• Fundamental Knowledge For Web Pentesting
o Basic Web Knowledge Before Pentesting
• Recon / Information Gathering
o Google Dorking , DNS Lookup , Scanning , Enumeration
o Nmap, nslookup, nikto, enum4linux, gobuster, wappalyzer, cookie editor, etc
• Web Vulnerabilities Pentesting (OWASP)
o HTTP Host Header Attacks
o SQL Injection Attack
o XSS Attack
o Local File Inclusion , Remote File
o Inclusion, RCE Using LFI
o XXE Attack
o Command Injection
o Server Side Request Forgery (SSRF)
o Business Logic Vulnerabilities
o Information Disclosures
• API Pentesting
o What is API?
o API Pentesting using POSTman
o API Pentesting using Burp suite professionals
o API Vulnerabilities – Broken Object Level
o Authorization
o API Vulnerabilities – Broken User
o Authentication
o API Vulnerabilities – Excessive Data Exposure
• CVE and Pentesting
o What is CVE ?
o How to Pentest a Website Using CVE?
• Methodology & Report Writing
o Pentesting Methodology
o How to Write a Standard Report?
Page | 5