These cybersecurity projects give you an unfair advantage

Sdílet
Vložit
  • čas přidán 20. 08. 2024

Komentáře • 103

  • @SupportSquirrel
    @SupportSquirrel Před 7 měsíci +126

    Something I did back when I was starting:
    Make a Virtual Machine with a bridged network connection (or a 2nd clean Windows install machine) - this gives you 2 machines on the same network. Install Wireshark on your clean machine. Start a packet capture and then try an attack or a network scan against that machine. Then analyze that packet capture. You know exactly what you did - now you can see exactly what it looks like! If you're doing some sort of metasploit-based attack you can even install things like Sysmon to capture specific logs, perform your attack and then look at the logs on your clean machine to see what the defender would see.

    • @SupportSquirrel
      @SupportSquirrel Před 7 měsíci

      Also I should say that Regex (Regular Expressions) are the bane of my existence...but are endlessly useful. If you can wrap your head around them and learn them effectively then do so! If you can learn them well enough to use the free tools online - that's perfectly fine! But 100% expose yourself to them.

    • @nicoleenesse
      @nicoleenesse  Před 7 měsíci +10

      Yes!!

    • @Bw2788
      @Bw2788 Před 7 měsíci

      This is a great idea I never thought of using Wireshark to replay my work to see it in that form

    • @treyb2885
      @treyb2885 Před 6 měsíci

      Smart and you can start 2 machines up in qemu

    • @treyb2885
      @treyb2885 Před 6 měsíci

      Vmware

  • @crowbar9566
    @crowbar9566 Před 7 měsíci +18

    Thanks Nicole. I just passed the Security + exam the week before Christmas so this is is very much needed to build practical experience. Thank you 🙏

  • @TheBoyNamedR
    @TheBoyNamedR Před 7 měsíci +9

    Thank you so much!
    I don't do well with just reading and memorizing. War rooming is where it's at!

  • @colinlarson9656
    @colinlarson9656 Před 6 měsíci +3

    Thank you! I am getting tired of memorizing protocols and not getting my hands dirty. Have a great day.

  • @Aacadian-xe8kq
    @Aacadian-xe8kq Před 7 měsíci +6

    you are a Queen, thank you so much for all this heavy lifting. I appreciate all your efforts on your superb channel. Happy New Year 👍👍👍

  • @EricWAtchesVideos
    @EricWAtchesVideos Před 7 měsíci +5

    With all of the corporate attention on automation, I wonder how long it will take a cybersecurity software developer to make a package that is more appealing than having a team and it's all put on one person. I believe that the only way to have reasonably secure data is to keep what doesn't need to have an internet connection, doesn't get an internet connection and what does only exposes a very secure API.

  • @kevinkasp
    @kevinkasp Před 7 měsíci +27

    Thank you. My son is on the verge of graduating from Western Governor’s University’s bachelor’s in cyber security and it’s time to do projects. He needs to be able to demonstrate that he’s familiar and has mastery with the tools that are used everyday in the real world.

    • @beasttowers392
      @beasttowers392 Před 7 měsíci +3

      😂

    • @kevinhartsstuntdouble1382
      @kevinhartsstuntdouble1382 Před 7 měsíci

      Are you laughing at WGU?​@@beasttowers392

    • @Lucky9_9
      @Lucky9_9 Před 7 měsíci +6

      Let me give you some unsolicited advice. The longer you parent him, the longer it will take him to mature. Let HIM worry about the work. Stop giving him tasks and homework. Helicopter parenting harms people because it prevents them from learning how to develop the capacity to discover their own insights. THIS is the skill your son needs in the real world, NOT for you to tell him what to do.

    • @kevinkasp
      @kevinkasp Před 7 měsíci

      @@Lucky9_9 I appreciate the concern but my son isn’t some marshmallow, snowflake helicopter parented kid. He spent his senior year in high school working nearly full time while attending school with nearly all AP classes, where he was without a car and on his own to get to work regardless of the weather. He scored the highest in the state chemistry proficiency exam. But despite being gifted academically he didn’t go straight to college.
      Instead after graduation he spent a year as a marine construction helper. Working outdoors, full time, while he taught himself welding he attended college full time at night and on weekends. During that year he lived at a distant relative’s house where he had to sleep on a couch and store all his belongings in the trunk of his car.
      Huntington Ingalls is the exclusive designer and builder of the Navy’s aircraft carriers and nuclear submarines. My son was part of the 12% of applicants accepted by Huntington Ingalls for their trades four-year apprenticeship program. He completed the most rigorous welding program in the world. Rigorous in both the sense of the skill level required as well as the physical challenge of being in a literal steel capsule where the walls, ceiling and floors are made of steel so the compartment reaches temperatures well over a hundred degrees. There are thousand of welders there and HI has been the exclusive builder for the Navy for more than a hundred years. During his apprenticeship he set several company welding records for both production and quality - despite being just an apprentice, and those records encompass literally hundreds of thousand of welders over more than a hundred years of company history.
      After I showed him Time Value of Money equations and how incredible compounding in investing becomes over the decades he changed his spending habits on the spot. Since then he’s disciplined himself to save and invest nearly $30,000/ year for going on six years. He has no debt, he owns his own house. He was selected by the company to be a linchpin in the biggest data analytics project in company history because in addition to welding he knows advanced math, electronics, and computer programming.
      Obviously as a dad I’m proud of him but the point of me listing all these details here isn’t to brag, but merely to point out he’s far from a coddled helicopter parented child. He’s a young man who’s capable in multiple fields. If you want to have an in-depth conversation about classical Greek literature or or go blow by blow on the merits and demerits of individual Roman Emperors, or maybe compare and contrast them to Napoleon or others, or ask him to teach you multivarable calculus or differential equations, or the subtleties of growing certain rare plants from islands east of Africa, or play a violin sonata for you he can do it.
      And he attained all these skills and knowledge without me. I live on the other side of the country from him. We just happen to be best friends in addition to father and son. I’ve advised him about academics, and navigating the internal machinations and politics of a Fortune 500 corporation, but he’s had to do it all on his own.
      He switched out of a mechanical engineering program to cyber security because he’s rational and not emotional. He knows he will plateau at $100K as a mechanical engineer or welder, and his older brother makes $260K as a cyber security engineer at Amazon (And that’s an entirely different story of a self-made young man that’s even more spectacular than the son I’ve been describing). He looks at it like opportunities when automobiles were in their major growing period in history, or when electricity and electrification of cities was in its infancy, or being a programmer in the ‘90s during the birth years of the internet. Right now is cyber security’s time to shine.

    • @michaelwood7021
      @michaelwood7021 Před 7 měsíci +12

      @@Lucky9_9let me give you some unsolicited advice, as children mature and find new interests as they approach adulthood, parents like to stay connected by learning about their interests so that common ground is available for discussion and bonding. To assume helicopter parenting by the OPs comment is a reach at best, take a step back and try to see more dimensions than the 1 you currently view life through

  • @user-og4nr2ym9i
    @user-og4nr2ym9i Před 5 měsíci

    This list is so cool! Certainly a much needed guide to projects for many who are confused on where to start regarding projects

  • @Dimlutube
    @Dimlutube Před 7 měsíci +5

    This was a good video with a good list of resources and I'd like to pump the YT algo with a comment. GOAD (Game of Active Directory) is another good one to add to your list (but it's a bit larger, so maybe it doesn't fit in with the theme of quick to stand up projects). Hm.. you know how we all get together around black friday and have a github repo for CyberSec black friday deals? Someone should do that, but with CyberSec projects. Just one big ole repo of up to date links to projects and what-have-you.... but I digress. This video was very good.

  • @DBX79
    @DBX79 Před 5 dny

    Super great video! Thanks for the resources!

  • @shrutishovandas5883
    @shrutishovandas5883 Před 7 měsíci +3

    This list is so cool! Certainly a much needed guide to projects for many who are confused on where to start regarding projects ✅

  • @Liftheavy85
    @Liftheavy85 Před 2 měsíci

    Something I've been doing is doing projects then adding them to my github and calling one of my buddies who is not tech savy and explained the entire thing to him so I get a better understanding of what I've been doing

  • @gilfernando7623
    @gilfernando7623 Před 3 měsíci

    the root cause of poor training in Cybersecurity = College/university , bunch of theories and memorizing, ComPTIA Security + , bunch of theories, and memorizing nothing really, really practical and both cost lots of money. This is why employers want experience and Not degrees and Certs.

  • @squid13579
    @squid13579 Před 7 měsíci +8

    You can add wazuh or suricata or other xdr/edr in SOC project and also SOAR as well.
    nice video 👍

  • @swiswach3130
    @swiswach3130 Před 7 měsíci +1

    Great video about cyber security projects. I tell my students the same thing: do independent projects.

  • @IamJohnKelly
    @IamJohnKelly Před 4 měsíci

    I beg you please make a video on what project to become a security engineer and how to add them to your resume

  • @StephenLee529
    @StephenLee529 Před 7 měsíci

    Thank you for providing such great content…I needed this..I’m a hands on guy…the labs are ok but it does little to help info to stick.

  • @urdynamix
    @urdynamix Před 6 měsíci +1

    Cyber Security is so hyped up as an on-demand skills, but jobs are elusive in the market.
    Don't Believe the Hype.

  • @Angelcee492
    @Angelcee492 Před 4 měsíci

    Thank you so much for all the great content!

  • @mistersaints4482
    @mistersaints4482 Před 7 měsíci +1

    I just started the Cybersecurity program in WGU. I'm learning the basics. But I'm not sure which field I would like to get into. I just want job security and if possible not be on call 24-7.

    • @drgnhuman2006
      @drgnhuman2006 Před 6 měsíci

      cisa.gov
      biden made a branch of cybercops.
      threat actors in or out of country get a number and if you id the person you can ask the da to charge them.
      most of what thier doing now is cleaning up all the coding languages so they cant be used to crack your way up the infrastructure layer.

  • @adamstones6187
    @adamstones6187 Před 4 měsíci

    What a video thank you, I've been struggling to retain the info. I think this might just help a fair bit

  • @HandsomeGenius
    @HandsomeGenius Před 7 měsíci

    Most beneficial imo: play ctfs and after you've got some experience try to make your own ctf challenges

  • @its_basheer_here
    @its_basheer_here Před 7 měsíci

    ❤ thanks for making these videos
    It was quite insightful, loved it

  • @drgnhuman2006
    @drgnhuman2006 Před 6 měsíci

    totally gonna make you explain this stuff to my av theater grad gf now that she got her palo alto network cert. watching her get from hardware to software was so hard for me. explaning what shell actualy do at work is hard. i dont want to leave install and implementation projects behind but she wants the desk noc work.

  • @r-test3668
    @r-test3668 Před 7 měsíci

    that lady in waf did not look happy

  • @johnczech7074
    @johnczech7074 Před 7 měsíci

    Thanks Nicole! Great content!!

  • @Sean-dg2uw
    @Sean-dg2uw Před 7 měsíci +2

    This video came at a great time. I’m struggling to get a job in cybersecurity. I have some certs and help desk experience. Thanks for this. Do you also have mentorship courses like 1 on 1?

  • @rembautimes8808
    @rembautimes8808 Před 7 měsíci

    This is an excellent video and learnt quite a lot. Joined as a sub, btw I’m in tech risk management in a financial institution.

  • @amjads8971
    @amjads8971 Před 7 měsíci

    Security in IT sadly is way over rated but very important area . Sadly filled up with mostly scam and unskilled CISOs

  • @ruslanbedoev9264
    @ruslanbedoev9264 Před 6 měsíci

    Thank you very much you are the best

  • @bayou__
    @bayou__ Před 7 měsíci

    thanks nicole

  • @AngelMaldonado2
    @AngelMaldonado2 Před 7 měsíci +7

    Nicole, most of the times during interviews they told me "and what about -real- projects in a company? have you done anything?" And i was like... :/ Well, no really... gg

    • @PolicyMaker456
      @PolicyMaker456 Před 6 měsíci +1

      This!!! ☝️☝️☝️☝️☝️☝️

  • @nordicvolkan
    @nordicvolkan Před 5 dny

    🙏🏻

  • @1angrykoala
    @1angrykoala Před 6 měsíci

    This is really good stuff. What skill/experience level would you recommend to be at before starting these projects?

  • @ysr1622
    @ysr1622 Před 7 měsíci

    this video is quite helpful. thank you!

  • @Theinsomniac826
    @Theinsomniac826 Před 7 měsíci +3

    Nicole, as a woman, have you ever been treated like an administrative assistant or secretary in a cybersecurity role?
    I work at a consulting company that begins with A as a "Security Delivery Analyst". But I keep getting projects where I use zero cybersecurity skills and the managers keep giving me secretary tasks such as take notes, schedule Team calls, monitor the managers calendar to find time for the managers next Teams call. I am treated like some sort of personal assistant/administrative assistant.
    Have you seen this in cybersecurity? I'm not sure what to do. On this current project I repeatedly highlighted my cybersecurity skills but the manager put me down as "Support" and is treating me like her own personal assistant and she is talking to me very disrespectfully.

    • @nicoleenesse
      @nicoleenesse  Před 7 měsíci +5

      Yes I have. Usually only from woman bosses though. Not sure why haha

    • @nicoleenesse
      @nicoleenesse  Před 7 měsíci +2

      I would talk to her about it as she may not know you want to do more technical tasks

  • @nickcarnevalino7462
    @nickcarnevalino7462 Před 7 měsíci +1

    im getting the not found also -> Page not found
    Either this page doesn't exist or you don't have permission to access it.

  • @christophers8849
    @christophers8849 Před 7 měsíci

    Do you think cybersecurity professionals will be replaced by AI?

  • @natalieriquelmy2504
    @natalieriquelmy2504 Před 7 měsíci

    Thank you so much for creating this video! So very helpful. Unfortunately, the link for your project list leads to a "Page not Found" error. Is there another way to access it?

    • @nicoleenesse
      @nicoleenesse  Před 7 měsíci +2

      Updated nicoleenesse.notion.site/Open-Source-Cybersecurity-Projects-04419423bb6d43b8a93c8d9b9c19d5d4?pvs=4

    • @natalieriquelmy2504
      @natalieriquelmy2504 Před 7 měsíci

      @@nicoleenesse Thank you so much!!

  • @Pokefitdad
    @Pokefitdad Před 7 měsíci

    Changing careers and using the Vet Tech program to get my journey going. Are there any programs that help vets get a laptop for education and career change. Also if looking for a laptop what specs are adequate for all these programs to run properly? Since I do have my phone on me what applications can I download to help us on our journey to learn IT since it is a whole lot to learn and take in? Hope you are doing well. Have a wonderful year.

  • @EugeneRadcliff2
    @EugeneRadcliff2 Před 7 měsíci

    Do you think its better to learn either Azure or AWS first? Does it matter?

  • @tonekb47
    @tonekb47 Před 6 měsíci

    Thank you so much beautiful, all I here from you is facts. Lfg

  • @SICKSHIT247
    @SICKSHIT247 Před 7 měsíci

    I gave up was too hard 😢

  • @Ou8y2k2
    @Ou8y2k2 Před 7 měsíci +1

    If you're going to mention 4525 projects, either create time stamps or links to all the projects in the video description. Thanks.

  • @StudiofrogPl
    @StudiofrogPl Před 7 měsíci

    Notion - Page not found
    Either this page doesn't exist or you don't have permission to access it.

    • @nicoleenesse
      @nicoleenesse  Před 7 měsíci

      Oh thanks. It should be good now nicoleenesse.notion.site/Open-Source-Cybersecurity-Projects-04419423bb6d43b8a93c8d9b9c19d5d4?pvs=4

  • @lllllllllll11111lllllllll
    @lllllllllll11111lllllllll Před 7 měsíci

    All you need is countless hours on capture the flag

  • @felixcalderon7258
    @felixcalderon7258 Před 7 měsíci

    Thanks so much! your the best! :v

  • @tuurblaffe
    @tuurblaffe Před měsícem

    no thanks i dont want to sponsor the cockrocket bald one or the labgrown meat cricket hoarder, i'd rather use realistic consumer hardware because simulations do not represent reality!

  • @myname-mz3lo
    @myname-mz3lo Před 7 měsíci +2

    i wish blue team people would say soc or blue team in their titles so that youtube stops recomending their stuff to red team people like me just because it says cybersecurity .

    • @aarontheone7193
      @aarontheone7193 Před 7 měsíci +4

      The whole point of cybersecurity is to be the best attacker and defender you can. More versatile and educated employees make for better responses

    • @myname-mz3lo
      @myname-mz3lo Před 7 měsíci

      @@aarontheone7193 cybersecurity is not a job. It is a sector. You do not need to know how to do every job just to do one. I am a pentester and I know the basics of every job in IT but it doesn't mean I need to be expert in them all to do my job. Blue team protects and red team destroys and when people do videos on cybersecurity it would help everyone's recomended algorithm if creators specified what field they are talking about instead of just saying cybersecurity. It makes it harder for people to find the learning content they are looking for and makes people learn less ultimately

    • @myname-mz3lo
      @myname-mz3lo Před 7 měsíci

      @@aarontheone7193 tell that to programmers writing code with more bugs than Australia not to pentesters haha

    • @jo4370
      @jo4370 Před 7 měsíci +6

      This comment gives 10 year old with kali vibes

    • @ProBallerJordan3
      @ProBallerJordan3 Před 7 měsíci +4

      How old are you? Sound immature

  • @blackdonte24
    @blackdonte24 Před 6 měsíci

    So you did nothing your whole career? Sounds like bs to me. And it doesn’t matter how many indy projects you’ve done, some companies demand those certificates, especially in the govtech space.

    • @nicoleenesse
      @nicoleenesse  Před 6 měsíci +4

      GOVTech prefers military

    • @Dee-zy2xv
      @Dee-zy2xv Před 4 měsíci +1

      That's how you shut down arrogant rude people Nicole...😂​@@nicoleenesse

  • @user-lt3nx7yb4z
    @user-lt3nx7yb4z Před 7 měsíci

    if one is kinda noob, then which of the resources one has to follow for building cybersec. projects ?