Advanced Search
Search Results
40 total results found
XSS - Merry XSSMas
Day 11 Learn about types of XSS vulnerabilities and how to prevent them.
SOC Alert Triaging - Tinsel Triage
Day 10 Investigate and triage alerts through Microsoft Sentinel.
YARA Rules - YARA mean one!
Day 13 Learn how YARA rules can be used to detect anomalies.
Phishing - Phishmas Greetings
Day 12 Learn how to spot phishing emails from Malhare's Eggsploit Bunnies sent to TBFC users.
Containers - DoorDasher's Demise
Day 14 Continue your Advent of Cyber journey and learn about container security.
ICS/Modbus - Claus for Concern
Day 19 Learn to identify and exploit weaknesses in ICS systems.
Obfuscation - The Egg Shell File
Day 18 McSkidy keeps her focus on a particular alert that caught her interest: an email posing as northpole-hr.
CyberChef - Hoperation Save McSkidy
Day 17 The story continues, and the elves mount a rescue and will try to breach the Quantum Fortress's defenses and free McSkidy.
Forensics - Registry Furensics
Day 16 Learn what the Windows Registry is and how to investigate it.
Web Attack Forensics - Drone Alone
Day 15 Explore web attack forensics using Splunk.
Race Conditions - Toy to The World
Day 20 Learn how to exploit a race condition attack to oversell the limited-edition SleighToy.
Malware Analysis - Malhare.exe
Day 21 Learn about malware analysis and forensics.
C2 Detection - Command & Carol
Day 22 Explore how to analyze a large PCAP and extract valuable information.
AWS Security - S3cret Santa
Day 23 Learn the basics of AWS enumeration.
Exploitation with cURL - Hoperation Eggsploit
Day 24 The evil Easter bunnies operate a web control panel that holds the wormhole open. Using cURL, identify the endpoints, send the required requests, and shut the wormhole once and for all.
Side Quests
Introduction to WebHacking
Get hands-on, learn about and exploit some of the most popular web application vulnerabilities seen in the industry today.
BurpSuite
Burp Suite is the industry standard tool for web application hacking, and is essential in any web penetration test.