Project Master List • Project 01 - Essential Powershell Commands for System Administration and Enumeration • Project 02 - Navigating with the Linux & Windows Command Line Interface (CLI) • Project 03 - Active Recon with NMAP • Project 04 - Packet Analysis with Tshark: Telnet vs. SSH • Project 05 - Obfuscation pt 1 - Steganography and Symmetric Encryption • Project 06 - Obfuscation pt 2: Asymmetric Encryption, Digital Signatures, ECC and Hashing • Project 07 - Web Application Attacks: XSS, SQL Injections, Directory Traversals, and File Inclusion • Project 08 - Packet Analysis pt 2: Network Traffic Monitoring with Wireshark & Tcpdump • Project 09 - Exploiting Alternate Data Streams • Project 10 - More packet analysis with Hping • Project 11 - Vulnerability Scanning w/ OpenVas • Project 12 - Exploiting Vulnerabilities w/ Metasploit (Ethical Hacking!!!) • Project 13 - Scripting for Cybersecurity Tasks • Project 14 - Threat Hunting w/ Wireshark and sguil • Project 15 - Hunting Down File Inclusions • Project 16 - Analyzing .pcap files for threats • Project 17 - Hacking An Enterprise Network • Project 18 - Detecting Port Scans w/ Wireshark • Project 19 - Brute forcing into a router with Hydra • Project 20 - Hash Cracking w/ John The Ripper and Hashcat! • Project 21 - Understanding and Configuring IP Tables in Linux • Project 22 - A Cure To The Common Code Vulnerability • Project 23 - Executing Local File Inclusion and Remote Code Execution with Burp Suite! • Project 24 - Error Based and Union Select SQL Injections! • Project 25 - Hardening Our Attack Surface • Project 26 - Automating Patch Management with Ansible and Cockpit • Project 27 - Conducting Log Analysis with Splunk • Project 28 - Recovering from a Malware Infection: Step by Step Guide • Project 29 - Enumeration with NMAP's Scripting Engine! • Project 30 - Extracting and Analyzing Malicious Traffic with T Shark • Project 31 -Configuring Suricata IDS/IPS for Cyber Defense • Project 32 - Automating Security Scans: Using Lynis Auditing Software and OpenVAS • Project 33 - Using Wireshark Filters to Detect Indicators of Compromise • Project 34 - Configuring Zeek for Network Security Analysis • Project 35 - Network Security Analysis w/ Zeek • Project 36 - Network Data Collection w/ Honeypots • Project 37 - Understanding the Security Risks of Misconfigured Sudo in Linux • Project 38 - Understanding Path Interception and Its Risks in Code Execution • Project 39 - Isolating Compromised Users and Hardening Active Directory Security • Project 40 - Searching for Persistence: Incident Response Insights • Project 41 -File Permissions and the Principle of Least Privilege in System Administration • Project 42 - Enumerating User and System Information in Linux as a Sys Admin • Project 43 - Mastering Access Control Lists for Enhanced Security • Project 44 - Understanding and Managing Special Permissions in Linux • Project 45 - Remediating Vulnerabilities Found with OpenVAS and Nessus Scanners • Project 46 - Reverse Engineering Malware using Cyber Chef and Yara Rules • Project 47 - Investigating Rogue Processes w/ Splunk • Project 48 - Configuring and Bypassing Modsecurity Web Application Firewall • Project 49 - Exploiting Broken Access Controls In A Web Application (CSRF, CORS, & JWT) • Project 50 - Padding Oracle and Server-Side Template Injection Attacks • Project 51 - Exploiting Legacy Versions of Protocols • Project 52 -Exploring OWASP ZAP Web Application Scanning Techniques • Project 53 - Burpsuite Traffic Interception 101 • Project 54 - Conducting a Man-in-the-Middle Attack w/ Burpsuite • Project 55 - Hardening A WordPress Based Web Server • Project 56 - Exploiting Server Side Web Vulnerabilities w/ Gobuster! • Project 57 - Using XSS to Hijack a Browsing Session! • Project 58 - Brute Forcing FTP Protocol and Exfiltrating Sensitive Information • Project 59 - Banner Grabbing w/ Nmap • Project 60 - Creating AWS EC2 Key Pairs and Managing Secrets with AWS Secrets Manager • Project 61 - Creating Security Groups for AWS EC2 Instances • Project 62 - AWS IAM and S3 Security Compliance Automation • Project 63 - AWS CloudFormation Templates: Applying Changesets and Detecting Configuration Drift • Project 64 - Exploiting Client Side Vulnerabilities: Embedded Excel Macro • Project 65 - Investigating A Cyber Attack In Progress! • Project 66 - Digital Forensic Techniques 101 • Project 67 - Using Iftop to Identify and Remove Indicators of Compromise in a System • Project 68 - Protecting gathered Honeypot Logs w/ OpenSSL & KeePass • Project 69 - Detecting Malicious Activities w/ Snort • Project 70 - Using Binwalk for file inspection • Project 71 - Creating a Docker Container to Conduct Static Code Analysis of a Mobile Application! • Project 72 - Enumerating HTTP Protocol and Exploiting Vulnerabilities in an Apache Web Server • Project 73 - Compromising a MySQL Database Server • Project 74 - Brute Forcing the SSH Protocol (Capture The Flag edition) • Project 75 - Exploiting Version Specific Protocol Vulnerabilities: SMTP • Project 76 - Exploiting WebDAV pt1: Using DavTest (Capture The Flag Edition) • Project 77 - Exploiting WebDAV pt2: Using MSFvenom (Capture The Flag Edition) • Project 78 - Using Shellshock (CVE-2014-6271) To Gain Access To An Apache Web Server! • Project 79 - Web Application Vulnerability Scanning w/ WMAP • Project 80 - Exploiting the SMB Protocol w/ PsExec (Capture The Flag Edition) • Project 81 - Using Brute Forced Credentials To Log Into A Remote Server Using FreeRDP (CFT!) • Project 82 - Exploiting The WinRM Protocol w/ CrackMapExec • Project 83 - Privilege Escalation by Bypassing UAC • Project 84 - Privilege Escalation by Impersonating Access Tokens (Capture The Flag edition) • Project 85 - Exploiting the Unattended Windows Setup Utility pt. 1 (Capture The Flag Edition) • Project 86 - Exploiting the Unattended Windows Setup Utility pt. 2: (Capture The Flag Edition) • Project 87 - Exploiting CVE-2007-6377 (Badblue 2.7) and credential hash dumping w/ Mimikatz! • Project 88 - Conducting A Pass the Hash Attack To Gain Entry Into A Web Server • Project 89 - Using Hydra To Brute Force FTP (Capture the Flag Edition) • Project 90 - Using Hydra To Brute Force SSH • Project 91 - Enumerating The Details Of A Weak Password Policy w/ Enum4linux (CTF Edition) • Project 92 - Elevating User Privileges Through Misconfigured Cron Jobs (Capture The Flag Edition) • Project 93 - Linux privilege escalation - Exploiting SUID Binaries (Capture The Flag Edition) • Project 94 - Discovering A Version Specific Exploit Tool w/ Searchsploit & Cracking Password Hashes! • Project 95 - Exploiting The NetBIOS Protocol To Access Sensitive Information On Two Target Machines! • Project 96 - Enumerating SNMP To Compromise Other Protocols • Project 97 - Conducting A SMB Relay Attack • Project 98 - Importing a Nmap Scan into the Metasploit Framework • Project 99 - Encoding Payloads with MSF Venom for Enhanced Evasion • Project 100 - Spoofing An Email Client To Send Fraudulent Mail • Project 101 - Automating Metasploit Commands with Resource Scripts • Project 102 - What Is A Rejetto HTTP File Server and Why Is It A Popular Attack Vector? • Project 103 - Exploiting A Vulnerable Apache Tomcat Web Server (Capture The Flag Edition) • Project 104 - Exploiting A VSFTPD FTP Sever Vulnerability • Project 105 - Exploiting The Sambacry Vulnerability (CVE-2017-7494) • Project 106 - Exploiting The libssh Library On A SSH Server (CVE-2018-10933) • Project 107 - What Exactly Is Meterpreter and How Can It Best Be Used For Post Exploitation Activities? 🔍 • Project 108 - Taking Screenshots of A Victim's Desktop and Other Post Exploitation Shenanigans! • Project 109 - Bypassing User Account Control with Memory Injection Techniques • Project 110 - Post Exploitation: Establishing Persistence on Windows Systems • Project 111 - Enabling RDP Post Exploitation (Capture The Flag Edition) • Project 112 - Fun With Keylogging • Project 113 - Covering Our Tracks: Clearing Windows Event Logs • Project 114 - Using Autoroute & Port Forwarding To Pivot • Project 115 - Post Exploitation Enumeration Techniques Against Linux Based Targets 🔍 • Project 116 - Exploiting CVE-2014-0476: Escalating Privileges w/ Chkrootkit Post Exploitation (CTF) • Project 117 - No Hashdump? No Worries: Alternative Means To Dumping Linux Password Hashes • Project 118 - Establishing Persistence on a Compromised Linux Host (Capture The Flag Edition) • Project 119 - Port Scanning & Enumeration w/ Armitage • Project 120 - Exploiting, Dumping, & Pivoting...OH MY! Post Exploitation Fun w/ Armitage • Project 121 - Alternative Banner Grabbing Techniques • Project 122 - Vulnerability Scanning w/ NMAP Scripts • Project 123 - Configuring and Running Exploits Manually w/o The Metasploit Framework • Project 124 - Exploring Netcat: The Swiss Army Knife of Networking Tools • Project 125 - NetCat: Gaining Remote Access To A Target System Using A Bind Shell • Project 126 - NetCat: Gaining Remote Access To A Target System Using A Reverse Shell • Project 127 - Exploiting CVE-2013-10035: Vulnerable Version Of ProcessMaker (CTF Edition) • Project 128 - Exploiting CVE-2017-0144: EternalBlue • Project 129 - Defacing A Website via Microsoft IIS FTP Compromise • Project 130 - OpenSSH: 0 - Weak Password Policy: UNDEFEATED! Circumventing secure protocols! • Project 131 - Multifaceted Approaches To Compromising SMB (Manual vs Automated) • Project 132 - Gaining Access To A WordPress Admin Panel By Compromising Several Protocols • Project 133 - The Power of Banner Grabbing: Finding An Attacker's Point of Entry/Persistence • Project 134 - Exploiting CVE-2011-2523 and WebDAV To Gain Access To Linux System • Project 135 - Exploiting CVE-2012-1823 (CGI Argument Injection) To Gain Access To Target Host • Project 136 - Targeting CVE-2007-2447 To Exploit Linux Host 🎯 • Project 137 - Post Exploitation: Manually Enumerating System Details of A Windows Host (CTF) • Project 138 - Post Exploitation: Manually Enumerating User & Group Details of A Windows Host • Project 139 - Post Exploitation: Manually Enumerating Network Information of A Windows Host • Project 140 - Post Exploitation: Manually Enumerating Processes & Services of A Windows Host • Project 141 - Automating Enumeration of Exploited Windows Hosts with JAWS • Project 142- Post Exploitation: Manually Enumerating System Details of A Linux Host • Project 143 - Post Exploitation: Manually Enumerating User & Group Details of A Linux Host • Project 144 - Post Exploitation: Manually Enumerating Network Information of A Linux Host • Project 145 - Post Exploitation: Manually Enumerating Processes & Cron Jobs of A Linux Host • Project 146 - Automating Enumeration of Exploited Linux Hosts with LinEnum • Project 147 - Manually Exploiting CVE-2014-6287 (Capture The Flag Edition) • Project 148 - Upgrading Non-Interactive Shells on Compromised Linux Hosts • Project 149 - Enumerating Windows Configuration Vulnerabilities w/ PrivescCheck • Project 150 - PrivescCheck: Using Found Cleartext Credentials To Escalate Privileges (CTF Edition) • Project 151 - Exploiting Misconfigured Permissions & Passwords To Escalate Privileges (CTF Edition) • Project 152 - Gaining Root Access By Exploiting Sudo (Capture The Flag Edition) • Project 153 - Hiding A Backdoor User Account & Using RDP To Maintain Persistence • Project 154 - Exfiltrating SSH Private Keys To Maintain Persistent Access On Linux Hosts (CTF) • Project 155 - Maintaining Persistence on a Compromised Linux Host with Cron Jobs (Capture The Flag) • Project 156 - Dumping & Cracking Windows Password Hashes • Project 157 - Post Enumeration: Clearing Your Tracks On Windows • Project 158 - Post Enumeration: Clearing Your Tracks On Linux • Project 159 - Gone Phishing w/ Gophish • Project 160 - Using Curl and Burpsuite To Enumerate Allowed HTTP Methods • Project 161 - Exploring Site Mapping Techniques: Passive Crawling vs Active Spidering 🕷️ • Project 162 - Restricting Port Access on an AWS EC2 for Enhanced Security • Project 163 - Building A Virtual Machine & Restricting Port Access In Microsoft Azure • Project 164 - Building A Virtual Machine & Restricting Port Access In Google Cloud Platform • Project 165 - Enumerating Web Application Details And Vulnerabilities w/ Nikto • Project 166 - Custom File & Directory Brute-Forcing w/ Gobuster • Project 167 - Enumerating WordPress Vulnerabilities /w WPScan • Project 168 - Capture The Flag Edition: Finding and Exploiting A Vulnerable WordPress Plug-in • Project 169 - IP Address Monitoring w/ Custom Suricata Rules • Project 170 - Using ADFind for Active Directory Enumeration • Project 171 - Incident Detection and Alerting with Wazuh • Project 172 - Conducting A Malware Investigation w/ Splunk and VirusTotal • Project 173 - Identifying Indicators of Compromise w/ MISP • Project 174 - Investigating Digital Forensics w/ Autopsy • Project 175 - Memory Forensics w/ Volatility • Project 176 - File and Artifact Carving w/ Foremost • Project 177 - On-boarding A New User To Active Directory • Project 178 - Monitoring and Preventing Data Exfiltration Attempts • Project 179 - Sabotaging Windows Systems and Causing Service Disruptions • Project 180 - Post-Exploitation: Creating and Mitigating Persistence Mechanism • Project 181 - Configuring Wazuh For Log Collection and Management • Project 182 - Detecting Reconnaissance & Unauthorized Access Attempts w/ Wazuh • Project 183 - Implementing Least Privilege Access Controls in Windows • Project 184 - PowerShell Threat Detection and Response w/ Wazuh • Project 185 - Analyzing LockerGoga Ransomware Sample • Project 186 - Automated Malware Analysis w/ Hybrid Analysis • Project 187 - Memory Forensics and Malicious Application Analysis w/Volatility • Project 188 - Static Malware Analysis with PE Studio • Project 189 - Detection and Initial Analysis of a Phishing Attack • Project 190 - Analyzing Malicious Attachments and Links in Phishing Emails • Project 191 - Spear Phishing Campaign: Spoofing A Messaging App • Project 192 - Using Hashcat to Crack session token (Capture The Flag edition) • Project 193 - Detecting Packet Flood Attacks w/ Wireshark • Project 194 - Automating DDoS Defense w/ Fail2ban • Project 195 - Preventing a DHCP Attack w/ Suricata & Wazuh • Project 196 - Network Traffic Monitoring and Analysis w/ Ntopng • Project 197 - Remediating A DDoS Attack w/ IPTables • Project 198 - File Type Identification w/ PeStudio • Project 199 - Eradicating Malware w/ RKill & Malwarebytes • Project 200 - Ransomware Containment • Project 201 - Ransomware Eradication and Recovery w/ No More Ransom.org • Project 202 - Performing Email Header Analysis w/ That'sThem • Project 203 - Hunting for a Pass the Hash Attack w/ Splunk • Project 204 - Finding Vulnerabilities in An AI Chatbot Through Manual Analysis • Project 205 - Conducting AI Model Log Analysis w/ Kibana Dashboard • Project 206 - Auditing The Security Of A Chatbot's Vector Database • Project 207 - Prompt Injecting Lakera Gandalf • Project 208 - Prompt Injection: Testing and Bypassing An AI Chatbot’s Guardrails • Project 209 - Prompt Injection: Accessing The System Prompt & Sensitive Data From An AI Chatbot • Project 210 - Document Based Prompt Injection • Project 211 - Poisoning An AI’s RAG Pipeline • Project 212 - Testing The Effectiveness Of A Chatbot’s Guardrails and Filters • Project 213 - Securely Coding AI: Remediating Broken Guardrails • Project 214 – Applying Human In The Loop Approval Gates • Project 215 – AI Security: Hardening RAG Sources • Project 216 – Exploiting An Agent Chain To Exfiltrate System Prompt and Chatbot User Prompt History