Cyber security · Course by Ravindra Bagale
Cyber Security
Cyber Security Study Guide: From Networking & Linux to Kali Linux and Ethical Hacking
Networking, Linux on AWS EC2, Apache and Nginx, LAMP/LEMP, MySQL, domains and HTTPS, S3 and RDS and a live project first; then Kali Linux and ethical hacking in your own lab, OWASP Top 10, cloud security, SOC and defence.
50 chapters400 concepts13 parts
Course outline
Click a chapter to see its concepts. Each concept has its own page.
How to Read This Book – start here
Part 1 Networking Foundations
Part 2 Linux on AWS EC2
5. Linux Basic Commands 9 concepts
6. Linux Advanced Commands 11 concepts
- 6.1 Searching Text: grep
- 6.2 Finding Files: find
- 6.3 Text Processing: awk and sed
- 6.4 Pipes, Redirection and Here-Documents
- 6.5 Archives and Compression: tar , gzip , zip
- 6.6 Services and Logs: service , systemctl enable , journalctl
- 6.7 Networking Commands
- 6.8 Disk and Storage Commands
- 6.9 Scheduling Tasks: cron
- 6.10 Remote Access: ssh , scp , rsync and Environment Variables
- 6.11 Basic Shell Scripting
Part 3 Web Servers
7. Apache and Nginx: Install and Understand 7 concepts
- 7.1 What a Web Server Does: Nginx vs Apache
- 7.2 Quick Reference: Packages, Services and Paths
- 7.3 Installing Nginx and Apache on Amazon Linux 2023
- 7.4 Installing Nginx and Apache on Ubuntu
- 7.5 Reading an Nginx Server Block
- 7.6 Reading an Apache Virtual Host
- 7.7 Everyday Management Commands and SELinux Basics
Part 4 Dynamic Hosting
9. PHP, LAMP and LEMP Step by Step 8 concepts
Part 5 MySQL
11. MySQL Part 2: UPDATE, ALTER, DELETE, Keys, Constraints and Users 7 concepts
- 11.1 UPDATE
- 11.2 Safe Update Mode, Error 1175 and Transactions
- 11.3 ALTER TABLE: Add, Modify, Rename and Drop Columns
- 11.4 DELETE, TRUNCATE and DROP
- 11.5 Keys: Primary, Foreign, Unique, Composite, Candidate, Super, Alternate
- 11.6 Constraints: NOT NULL, DEFAULT, CHECK, AUTO_INCREMENT
- 11.7 Users, GRANT, REVOKE and Least Privilege
Part 6 Domains, Multiple Websites and HTTPS
Part 7 AWS S3 and RDS MySQL
14. Amazon S3: Buckets, Objects, Policies and Presigned URLs 7 concepts
- 14.1 What S3 Is: Buckets, Objects and Keys
- 14.2 Creating a Bucket and Uploading Objects
- 14.3 Block Public Access and Bucket Policies
- 14.4 Hosting a Static Website on S3
- 14.5 Versioning and Lifecycle Rules
- 14.6 Presigned URLs: Temporary Private Access
- 14.7 Encryption, Logging, IAM Roles and the S3 Security Checklist
15. Amazon RDS for MySQL: Create, Connect, Back Up and Keep It Private 6 concepts
- 15.1 What RDS Is and Why Companies Use It
- 15.2 Planning the Network: Subnet Group and Security Groups
- 15.3 Creating an RDS MySQL Instance Step by Step
- 15.4 Connecting from EC2 and Creating the Application User
- 15.5 Automated Backups, Snapshots and Restore
- 15.6 Hardening RDS: Never Public, Encrypted, Monitored
Part 8 Live Project: Mitrano Reels
16. Live Project: Building a Reels App with EC2, S3 and RDS 13 concepts
- 16.1 Project Overview and Architecture
- 16.2 AWS Setup: S3 Bucket, IAM Role and RDS
- 16.3 Server Setup: LEMP, Composer and the AWS SDK for PHP
- 16.4 Database Schema
- 16.5 Configuration and Shared Code
- 16.6 Accounts: Register, Login and Logout
- 16.7 Uploading Videos and Text Posts
- 16.8 The Feed API and Likes
- 16.9 The Reel UI: HTML, CSS and JavaScript
- 16.10 Deployment: Nginx, PHP Settings and Going Live
- 16.11 Domain and HTTPS
- 16.12 Testing and Troubleshooting
- 16.13 Security Checklist: The Target You Will Secure
Part 9 The Bridge: Why Learn All This Before Kali Linux
17. Why Learn All This Before Kali Linux? 7 concepts
- 17.1 You Can't Hack or Secure What You Don't Understand
- 17.2 From Networking to Nmap and Wireshark
- 17.3 From Linux and SSH to Brute Force, Privilege Escalation and Hardening
- 17.4 From HTTP and Web Servers to Burp Suite, Nikto and Misconfigurations
- 17.5 From MySQL to SQL Injection
- 17.6 From S3, RDS and IAM to Cloud Misconfigurations
- 17.7 Your Project as the Target: Roadmap for the Next Parts
Part 10 Kali Linux: Ethical Hacking Tools
18. Ethics, the Law and a Safe Kali Lab 7 concepts
19. Information Gathering and Scanning 11 concepts
- 19.1 Passive vs Active Recon
- 19.2 whois and dig
- 19.3 theHarvester and Recon-ng (Overview)
- 19.4 Maltego Introduction
- 19.5 Netdiscover: Finding Lab Hosts
- 19.6 Nmap Basics: Host Discovery, Port States and Scan Types
- 19.7 Service Versions, OS Detection and NSE Scripts
- 19.8 Timing, Output Formats and Scan Hygiene
- 19.9 Masscan: Very Fast Port Scanning
- 19.10 How Defenders Detect Scanning
- 19.11 Red vs Blue, Project and Real Incidents
20. Vulnerability Scanning and Assessment 8 concepts
- 20.1 Vulnerability, CVE, CWE and CVSS
- 20.2 Manual Lookup: searchsploit and Exploit-DB
- 20.3 Nmap Vulnerability Scripts
- 20.4 OpenVAS / Greenbone: Full Vulnerability Scanning
- 20.5 Nikto: Web Server Scanning
- 20.6 Reading Results: False Positives and Prioritising
- 20.7 Writing a Vulnerability Report
- 20.8 Red vs Blue, Project and Real Incidents
21. Web Application Testing Tools 8 concepts
- 21.1 How Web Testing Works: The Intercepting Proxy
- 21.2 Burp Suite: Proxy and Intercept
- 21.3 Burp Intruder: Automating Requests
- 21.4 OWASP ZAP: A Free Full Scanner
- 21.5 Gobuster and Dirb: Finding Hidden Content
- 21.6 sqlmap: Testing for SQL Injection
- 21.7 WPScan: Scanning WordPress
- 21.8 Red vs Blue, Project and Real Incidents
23. Exploitation with Metasploit 7 concepts
Part 11 The Ethical Hacking Course
29. OWASP Top 10 Web Vulnerabilities 8 concepts
- 29.1 What OWASP and the Top 10 Are
- 29.2 A03 Injection: SQL Injection
- 29.3 A03 Injection: Cross-Site Scripting (XSS)
- 29.4 A03 Injection: Command Injection
- 29.5 A01 Broken Access Control and IDOR
- 29.6 A07 Authentication and A02 Cryptographic Failures
- 29.7 The Rest: Design, Components, Integrity, Logging, SSRF
- 29.8 Red vs Blue, Project and Real Incidents
30. Cloud and AWS Security 7 concepts
32. Linux and Network Hardening 7 concepts
33. Cryptography Basics 7 concepts
34. Indian Cyber Law and Cyber Crime Awareness 7 concepts
- 34.1 More IT Act Sections You Should Know
- 34.2 New Criminal Laws and Electronic Evidence
- 34.3 CERT-In Directions for Organisations
- 34.4 The Digital Personal Data Protection Act, 2023
- 34.5 Common Cyber Frauds in India and How to Spot Them
- 34.6 What to Do If You Are a Victim
- 34.7 Red vs Blue, Project and Real Incidents
Part 12 Advanced Tools and CEH Modules
36. More Essential Kali Tools 7 concepts
38. Active Directory Attacks and Defence 9 concepts
- 38.1 AD Basics for Defenders
- 38.2 Safe AD Lab Setup
- 38.3 Enumeration of AD
- 38.4 Kerberos Basics: AS-REP Roasting and Kerberoasting (Defensive View)
- 38.5 NTLM Relay and Pass-the-Hash Concepts (Lab Only)
- 38.6 BloodHound Attack-Path Analysis
- 38.7 Privilege Escalation Paths and Domain Admin Risks
- 38.8 Defence Checklist – Raja-Rani Traders Style AD
- 38.9 Putting It Together – Purple Team Mindset
39. Malware Threats 9 concepts
- 39.1 What Is Malware – Types for Defenders
- 39.2 How Malware Spreads
- 39.3 Ransomware Deep Dive – Raja-Rani Traders
- 39.4 Static vs Dynamic Analysis Mindset
- 39.5 Indicators of Compromise (IOC)
- 39.6 Defence Stack – Practical Controls
- 39.7 Safe Malware Lab Setup
- 39.8 Incident Response for Malware + CERT-In Awareness
- 39.9 Putting It Together – Purple Team Mindset
40. DoS and DDoS – Availability Attacks 10 concepts
- 40.1 What Is DoS vs DDoS – Availability First
- 40.2 Volumetric and Flood Concepts – Defender View
- 40.3 Protocol Attacks – SYN Flood and Handshake Abuse
- 40.4 Amplification and Reflection – Closed Lab Only
- 40.5 Application-Layer DoS – Slow and Heavy Requests
- 40.6 Botnets and IoT – Mirai-Class Lesson
- 40.7 Detection and Defence Stack
- 40.8 Lab-Safe Simulation – Ethics First
- 40.9 Incident Response for Availability Attacks + CERT-In Awareness
- 40.10 Putting It Together – Purple Team Mindset
41. Session Hijacking – Tokens, Cookies and Defence 10 concepts
- 41.1 What Is a Session – Why Hijacking Matters
- 41.2 Cookie Theft and Insecure Transit
- 41.3 Session Fixation and Predictable IDs
- 41.4 XSS Path to Session Cookies – Defence First
- 41.5 Network Sniffing of Sessions – Host-Only Concepts
- 41.6 Application-Level Hijack – URL Tokens, CSRF, JWT Concepts
- 41.7 Detection – Logs, Concurrent Sessions, SIEM Signals
- 41.8 Defence Hardening Checklist
- 41.9 Lab-Safe PHP Cookie Demo + Ethics / IT Act
- 41.10 Putting It Together – Purple Team Mindset
42. Evading IDS, Firewalls and Honeypots – Detection Games 10 concepts
- 42.1 IDS vs IPS vs Firewall vs Honeypot – Why Each Exists
- 42.2 Signature vs Anomaly IDS – False Positives and False Negatives
- 42.3 Fragmentation, Encoding, Obfuscation – Concepts, Then Reassembly
- 42.4 Slow Scans, Timing, Port Knocking – Nmap vs Blue Rate Alerts
- 42.5 Firewall Types – What "Evasion" Means to Blue
- 42.6 Honeypots and Honeynets – Deception, Ethics, Alerts
- 42.7 Covering Tracks vs Log Integrity – Blue Wins
- 42.8 Lab – Suricata or firewalld Logging on OWN VM
- 42.9 Project, Ethics and IT Act
- 42.10 Putting It Together – Purple Team Mindset
43. IoT and OT Security – Cameras, Smart Devices, Plant Networks 10 concepts
- 43.1 IoT vs OT / ICS / SCADA – CIA Plus Safety
- 43.2 Attack Surface – Defaults, Telnet, HTTP, UPnP, Dashboards
- 43.3 Protocol Awareness – MQTT, CoAP, Modbus, DNP3
- 43.4 Mirai-Class Botnets – Weak IoT, Outbound C2
- 43.5 Network Segregation – IT / OT Zones, Jump Hosts, firewalld
- 43.6 Internet Exposure Awareness – Your Lab Only
- 43.7 Firmware, Updates and Supply-Chain Hygiene
- 43.8 Detection – Outbound IoT, Failed Logins, Protocol Oddities
- 43.9 Lab – Mosquitto MQTT or Fake Camera UI on OWN VM
- 43.10 Project, Ethics, IT Act and Purple Interview Lines
44. Mobile Device Security – Android, iPhone, Bluetooth and Wi-Fi 10 concepts
- 44.1 Mobile Threat Model – What Can Go Wrong
- 44.2 Android Security Model – Permissions, Play Protect, Sideloading
- 44.3 iPhone / iOS Security Model – App Store, Sandbox, Lockdown Mode
- 44.4 Signs a Phone May Be Compromised – Practical Checklist
- 44.5 Cleanup and Response – If You Believe the Phone Is Compromised
- 44.6 MDM and BYOD – SME Concepts for Sahyadri Traders
- 44.7 Bluetooth Risks – Pairing Hygiene and BlueBorne Awareness
- 44.8 Wi-Fi on Phones – Evil Twin and Captive Portal Awareness
- 44.9 Hardening Checklist and Permission-Hygiene Lab
- 44.10 Project, Ethics, IT Act and Purple Interview Lines
Part 13 Revision: Exercises, Interviews and CEH Exam Modules
45. Practice Exercises with Hints 10 concepts
- 45.1 How to Use These Exercises – Ethics First
- 45.2 Networking Foundations – Quick Fire
- 45.3 Linux on EC2 – Commands You Must Type Blind
- 45.4 Web Servers and MySQL – Build and Protect
- 45.5 Domains, S3, RDS and Project Checklist
- 45.6 Kali Recon, Scan and Enum – Host-Only Only
- 45.7 OWASP Top 10 – Fix What You Break (DVWA / Juice)
- 45.8 Cloud, SOC, Hardening and Crypto – Mixed Drill
- 45.9 Advanced Defensive Drills – AD to Mobile
- 45.10 Capstone – Project Build-Hack-Fix (Sahyadri or Raja-Rani)
46. General Interview Q and A 11 concepts
- 46.1 How to Answer Cyber / SOC / Cloud Security Interviews
- 46.2 Networking Interview Questions
- 46.3 Linux on EC2 Interview Questions
- 46.4 Web Servers and MySQL Interview Questions
- 46.5 Domains, S3, RDS and Live-Project Security Questions
- 46.6 AWS Cloud Security Interview Questions
- 46.7 Ethical Hacking, OWASP and Kali Lab Questions
- 46.8 SOC, IR, Hardening and Cryptography Questions
- 46.9 AD, Malware, Session, IoT and Mobile — Defensive Talking Points
- 46.10 Scenario Round — Sahyadri / Raja-Rani
- 46.11 Red vs Blue, Project and Real Incidents
47. Interview Questions Asked in MNC Interviews 10 concepts
- 47.1 How to Use This Chapter – Sources and Ethics
- 47.2 Networking and Protocols (MNC rounds)
- 47.3 Linux, Logs and Windows Event IDs
- 47.4 SOC Analyst Round – SIEM, Triage, MITRE
- 47.5 Identity Attacks Awareness (Kerberos / PTH – defensive talking points only)
- 47.6 Cloud and AWS Security MNC Themes
- 47.7 OWASP / Web / Email Auth (SPF DKIM DMARC)
- 47.8 Scenario and HR + Technical Mix
- 47.9 Source Appendix (URLs actually read)
- 47.10 Red vs Blue, Project and Real Incidents
48. CEH v13 Exam Modules Map and Practice Questions 9 concepts
- 48.1 How to Use This Map – Ethics and Exam Mindset
- 48.2 Modules 01–05 Map (Intro through Vulnerability Analysis)
- 48.3 Modules 06–10 Map (System Hacking through DoS)
- 48.4 Modules 11–15 Map (Session Hijacking through SQL Injection)
- 48.5 Modules 16–20 Map (Wireless through Cryptography)
- 48.6 CEH-Style Practice Questions – Set A (Modules 01–10)
- 48.7 CEH-Style Practice Questions – Set B (Modules 11–20)
- 48.8 Quick Revision Table – Module → Book Chapter → Blue Control
- 48.9 Red vs Blue, Project and Real Incidents
Join an online / offline batch — Enquire now
Ravindra Bagale runs online and offline batches for AWS Cloud, DevOps, Power BI, Excel, Data Analytics, Data Science and Cyber Security.