All Courses
Cyber Security

Cyber Security Fundamentals

Defend real systems — and write the report that gets the holes fixed.

A defensive security course built around an isolated home lab. You learn networking, Linux and Windows hardening, cryptography, the OWASP Top 10 and incident response — then run a full authorized assessment and produce the written report employers actually hire on. Every technique is confined to lab targets you own, and the legal and ethical framework comes before any tooling.

Duration
12 Weeks
Contact Hours
60+ hours
Modules
12
Level
Beginner → Junior Security Analyst
Cyber Security Fundamentals course
Cyber Security

What You Will Be Able to Do

Outcomes, not topics covered. Each one is something you can demonstrate by the end of the course.

  1. 1Explain the CIA triad, threat actors and the attack lifecycle in the language a security team uses
  2. 2Read network traffic in Wireshark and identify when a protocol is doing something unusual
  3. 3Harden a Linux and a Windows host: users, permissions, services, patching, logging, firewall
  4. 4Apply cryptography correctly — hashing vs encryption, TLS, PKI, key management
  5. 5Find and explain the OWASP Top 10 in a vulnerable web app, and describe the fix for each
  6. 6Run an authorized vulnerability assessment end to end: scope, recon, scan, validate, report
  7. 7Respond to an incident using a standard IR lifecycle and write the timeline
  8. 8Sit the CompTIA Security+ exam with a realistic chance of passing

Full Curriculum

12 modules. Published in full — nothing behind a signup form.

  • The CIA triad: confidentiality, integrity, availability
  • Threat actors: script kiddies, criminal groups, insiders, nation states
  • Attack lifecycle: recon → weaponize → deliver → exploit → persist → exfiltrate
  • Risk = threat × vulnerability × impact
  • Nepal's Electronic Transactions Act 2063; GDPR and PCI-DSS in outline
  • Authorized testing: scope documents, rules of engagement, written permission

Hands-on: Signed code of conduct + build the isolated lab (VirtualBox, Kali, Metasploitable)

  • TCP/IP model, the three-way handshake, ports and services
  • DNS, DHCP, ARP, HTTP/HTTPS, SSH — and how each is abused
  • Subnetting and network segmentation as a defensive control
  • Firewalls, NAT, VPNs, IDS/IPS: what each actually stops

Hands-on: Lab: capture and dissect traffic in Wireshark; spot a plaintext credential

  • Filesystem, users, groups, permissions, sudo
  • Process and service management, systemd
  • Log locations and what lives in each
  • Bash scripting for repetitive security tasks
  • SSH hardening, key auth, fail2ban, ufw/iptables

Hands-on: Lab: harden a fresh Ubuntu server against a supplied checklist

  • Active Directory concepts, users, groups, group policy
  • Windows logging and Event Viewer
  • Endpoint protection, application allowlisting, BitLocker
  • Common Windows attack paths in outline

Hands-on: Lab: audit and harden a Windows workstation

  • Hashing vs encryption vs encoding — the distinction most people get wrong
  • Symmetric (AES) and asymmetric (RSA, ECC) cryptography
  • TLS handshake, certificates, certificate authorities, chain of trust
  • Password storage: bcrypt/argon2, salting, why MD5 is not a password hash
  • Key management, secrets in code, environment variables

Hands-on: Lab: issue and deploy a certificate; break a badly-hashed password list

  • Broken access control, cryptographic failures, injection
  • Insecure design, security misconfiguration, vulnerable components
  • Authentication failures, integrity failures, logging failures, SSRF
  • Burp Suite and OWASP ZAP as inspection tools
  • Secure coding patterns: parameterized queries, output encoding, CSP

Hands-on: Lab: work OWASP Juice Shop and DVWA; for each finding write cause, impact, fix

  • Scoping and written authorization — the paperwork that makes it legal
  • Passive recon (OSINT) vs active scanning
  • Nmap: host discovery, service and version detection, scripts
  • Vulnerability scanning with OpenVAS / Nessus Essentials
  • Validating findings and eliminating false positives
  • CVSS scoring and prioritization

Hands-on: Lab: full assessment of the supplied lab network

  • IR lifecycle: prepare → detect → contain → eradicate → recover → learn
  • SOC roles, tiers and escalation paths
  • SIEM concepts; log aggregation and correlation in Splunk Free
  • Building detection rules and alerts
  • Evidence handling and chain of custody basics

Hands-on: Lab: investigate a simulated breach and produce a timeline

  • Phishing, spear phishing, vishing, pretexting, business email compromise
  • Why these work: authority, urgency, reciprocity, fear
  • Building an awareness program for a Nepali office
  • Simulated phishing — run only against consenting internal participants

Hands-on: Lab: analyse real phishing samples; write the staff advisory

  • Shared responsibility model in AWS/Azure
  • IAM misconfiguration: the most common cloud breach cause
  • Storage bucket exposure, security groups, secrets management
  • Container basics and image scanning
  • CI/CD security: dependency scanning, SAST in outline
  • Security policies, standards, procedures
  • Risk register, risk treatment, residual risk
  • ISO 27001 and the NIST Cybersecurity Framework in outline
  • Business continuity and disaster recovery
  • Writing for management: the executive summary that gets budget approved
  • CompTIA Security+ (SY0-701) domain review
  • Practice exams and question strategy
  • Home lab as portfolio; documenting what you built
  • CV, LinkedIn, and the security interview
  • Nepal's security job market and remote/freelance options

Capstone Project

A complete authorized security assessment of a deliberately vulnerable environment: scope document with rules of engagement, the assessment itself, a findings register with CVSS scores and evidence, a remediation plan ranked by risk, a written report with a one-page executive summary, and a presentation defending your findings. The report is the portfolio piece — employers hire on the report, not on the exploit.

Who This Course Is For

  • IT support staff and sysadmins moving into a security role
  • Developers who keep shipping vulnerabilities and want to stop
  • Students targeting SOC analyst as a first job
  • Business owners responsible for the security of their own systems

Where This Leads

SOC Analyst (Tier 1)IT Security AdministratorVulnerability AnalystSecurity-aware Developer / DevSecOps entryIT Auditor / Compliance Analyst