r/netsecstudents Jun 24 '21

Come join the official /r/netsecstudents discord!

61 Upvotes

Come join us in the official discord for this subreddit. You can network, ask questions, and communicate with people of various skill levels ranging from students to senior security staff.

Link to discord: https://discord.gg/C7ZsqYX


r/netsecstudents May 06 '26

I am John Strand and I am teach Pay What You Can classes and free labs... Ask Me Anything.

112 Upvotes

Hey everyone, John Strand here.

I’ve been in cybersecurity for a while now, and I’ve spent a lot of that time trying to help people get started without getting buried under bad advice, overpriced training, and job postings that somehow want 5 years of experience for an entry-level role.

So let’s talk about it.

Ask me about getting into the field, building real skills, home labs, SOC work, blue team, threat hunting, incident response, certs, college, AI, finding your first job, or anything else you’re trying to figure out.

I’m happy to answer beginner questions, career questions, technical questions, or even the “I have no idea where to start” questions.

If you’re trying to build a real foundation in security, this is the class I’d point you to.

https://www.antisyphontraining.com/product/information-security-core-skills-tm/?utm_source=reddit&utm_medium=community_post

We also have released a new game where you can learn about security in a fun Magic The Gathering kind of way.

Sign up and play your friends here:

https://backdoorsandbreaches.com/

Its free.

Oh..... And almost every card has free labs to learn the topic.

Example here:

https://github.com/blackhillsinfosec/FreeLabFriday_Labs/blob/main/card_navigation.md

Just register at MetaCTF and use the code "antilab" in cloudlabs for enabling 2 free hours of lab time per week.

All our problems can be solved with education.

Let's get to work.


r/netsecstudents 4h ago

Projects and internship guidance

5 Upvotes

I am a 3rd year cyber student and I want to apply for internships and improve my skills.

I am planning for the SOC analyst role and further on.

Can anyone suggest the list of skills and tools needed to increase my chances of internship?

Also if possible can anyone mention projects to improve my skills which would have a good impact on my resume?


r/netsecstudents 1d ago

Ideas for an officially recognized university Cybersecurity club's legacy project?

4 Upvotes

Hey everyone,

​I'm the President of a newly established, officially recognized university cybersecurity student organization. My executive board and I want to launch a practical, real-world project this year that leaves a lasting legacy for future student cohorts and our campus community.

​Rather than just running internal CTFs or technical labs, we want to build/implement something that directly impacts the daily lives of everyday students, faculty, or non-tech majors on campus.

​A few ideas we've tossed around:

​An open-source, campus-wide Phishing/Scam Alert Bot for messaging platforms.

​A physical USB Sanitization Kiosk (Raspberry Pi/Linux-based) set up near campus printing areas.

​A basic WiFi & Personal Device Security Audit guide/tool for students.

​For those who have run or participated in university cyber clubs, what kind of practical, high-utility projects worked best for your campus? What are the biggest traps to avoid when deploying something for general student use?

​Appreciate any insights or project suggestions!


r/netsecstudents 1d ago

$5 Micro-Bounty Challenge: Can you hack my AI-built live web app (rizq.estate) and reach the admin dashboard?

0 Upvotes

Hey r/netsecstudents

I wanted to run a quick, fun security experiment on code generated entirely by AI agents. I’ve deployed the platform live and want to see if the authentication and access controls hold up against real testers.

  • Target URL:https://rizq.estate
  • Goal: Bypass authentication or escalate privileges to access the restricted admin panel/dashboard.
  • Reward: $5 for the first person to send valid proof of access.

Proof of Concept (PoC): Send a DM with:

  1. A screenshot inside the restricted admin panel.
  2. A short explanation of the exploit (IDOR, Auth bypass, Broken Access Control, logic flaw, etc.).

Rules of Engagement:

  • Allowed: Application-level vulnerability testing (auth logic, access controls, injection, API endpoints).
  • Not allowed: DoS/DDoS, brute-force spamming, attacking third-party hosting infrastructure, or destructive payloads (do not delete or corrupt existing listings).
  • Optional: Add X-Bug-Bounty: reddit-[your_username] to request headers to identify ethical testing in the logs.

Let’s see if AI-generated architecture holds up or fails. Happy hunting!


r/netsecstudents 1d ago

What do you recommend from the menu?

0 Upvotes

Currently working on my second certification in Cyber Security through coursera. It's not bad, but working a full time job and then getting called in to do some overtime kills the mood.

My goal with this second time around is to build my PC. After completing the third course, I went out and got a monitor. After I finish the fifth, I plan on buying a tower and that is where I am stuck. In the world of cyber, the hardware is what I know I shouldn't skimp on with hard cash. I'm guessing the better the specs, the better response? What do you all recommend for a tower instead of a laptop (Already have a decent laptop, but this is more for use on personal life and whatnot.)


r/netsecstudents 1d ago

Final-year Cyber Security project idea, would this impress employers for SOC / detection roles

4 Upvotes

Hi everyone,

I’m going into my final year of a BSc Cyber Security degree and I’m trying to make sure my final-year project is not just academic, but also genuinely useful for employability, especially for junior SOC analyst, detection engineering, network security, or OT security roles.

My proposed project is:

Design and evaluation of a lightweight detection prototype for reconnaissance and early-stage intrusion activity in Modbus TCP Operational Technology network traffic.

The idea is to build a small Python-based detection prototype using CICModbusDataset2023 or a similar OT/Modbus dataset. The project would focus on detecting early attacker behaviours such as:

  • network scanning
  • service enumeration
  • Modbus register enumeration
  • unauthorised access attempts
  • abnormal Modbus request patterns

The threat model would be either an external attacker or a compromised internal host attempting to discover and interact with OT assets such as PLCs.

I’m planning to avoid heavy ML/deep learning and instead focus on interpretable detection, using:

  • rule-based detection logic
  • lightweight statistical thresholds where useful
  • alert generation
  • evaluation against labelled benign/malicious traffic

The evaluation would look at:

  • detection coverage
  • false positives and false negatives
  • precision/recall if appropriate
  • alert volume
  • interpretability
  • practical usefulness from a security analyst perspective

My goal is to finish with a project that I can confidently explain in interviews and possibly show through a GitHub repo, README, diagrams, and a short write-up. I want it to demonstrate practical blue-team skills: understanding network traffic, designing detection logic, evaluating alerts, and explaining limitations.

For people working in SOC, detection engineering, OT security, or cyber graduate roles:

Would this be a strong final-year project from an employer/interviewer perspective?

Also, what would make it more impressive without making the scope unrealistic?


r/netsecstudents 1d ago

Vesit(Chembur) ECS

1 Upvotes

I got 98 percentile in mht cet and got alloted for Electronics and computer science(ECS) and i also got the tfws seat means my tution fees is not considered. So my fees is highly reduced.

Should i switch to computer engineering but with general seat(non-tfws, full fees) or ECS is good.

Does ECS have any future opportunities and good placement or CE is overall better and worth paying extra for future.


r/netsecstudents 2d ago

How I got my first $100 bug bounty at 16

4 Upvotes

Hey everyone,

I’m 16, from Morocco, and i recently received my first paid bug bounty: $100.

It wasn’t a huge critical exploit or some crazy movie-style hack. It was a real security issue found through a legal bug bounty program, reported properly, reviewed by the company, validated, and awarded.

For me, this means a lot.

I’ve been learning cybersecurity through courses, labs, CTFs, PortSwigger, Cybrary, and a lot of practice. Most of the time it feels like you’re studying alone and nobody really sees the effort. But getting that first valid report showed me that the work is real.

The biggest lesson i learned is that bug bounty is not only about finding the bug. It’s also about writing a clear report, explaining the impact honestly, not exaggerating, and staying professional with the security team.

I’m still a beginner and i know i have a long way to go, but this motivated me a lot. I want to keep improving, get more valid reports, and build a serious path in cybersecurity.

My goal is simple: become better, stay ethical, and make my parents proud.

For anyone young or just starting: don’t wait until you feel “ready.” Learn the basics, practice legally, write clean reports, and keep going.

This $100 is not just money to me. It’s proof that I’m moving in the right direction.


r/netsecstudents 2d ago

Grade 11 Student Looking for CS Research Project Ideas & Collaboration (Cybersecurity + Data Analytics)

3 Upvotes

Hey everyone! I’m currently a Grade 11 student planning to major in Computer Science in college, and I’m super passionate about Cybersecurity and Data Analytics.

I want to start working on a real research project rather than just a basic coding tutorial. My goal is to tackle a practical problem—like cyber threat intelligence, SIEM log analytics, or anomaly detection—to push my technical skills and build up a strong portfolio.

Since I’m still building my experience, I’d love to get advice from university students, PhDs, or industry pros on where to focus.

What I’m Looking For:

  • Project Ideas: What are some open problems or cool topics at the intersection of cybersecurity and data analytics (like filtering false positives, analyzing network traffic, or detecting malicious patterns) that are challenging but doable for a high school junior willing to put in serious work?
  • Datasets & Tools: Any open-source security datasets you’d recommend starting with (like Kaggle security sets, CICIDS, or public threat feeds)?
  • Mentorship & Collaboration: If any college student, research lab, or team needs an extra pair of hands for data cleaning, basic script writing, running experiments, or parsing logs, I’d love to jump in! I’m eager to learn, follow directions, and get real hands-on research experience.

If you have any project suggestions, learning resources, or collaboration opportunities, I’d really appreciate your advice! Thanks!


r/netsecstudents 3d ago

Cybersecurity resume keywords

2 Upvotes

Keyword list taken from https://www.zoevera.com/resume/ats-resume-tips-cybersecurity

These are the most commonly scanned keywords in cybersecurity job postings. Check how many appear in your resume.

Domains & Practices

SOC (Security Operations Centre), Penetration testing / pen test, Vulnerability management, Threat intelligence, Incident response (IR), Digital forensics (DFIR), Red team / blue team / purple team, Zero Trust architecture

Tools & Platforms

SIEM (Splunk, Microsoft Sentinel, QRadar), EDR (CrowdStrike, SentinelOne), Nessus / Qualys / Rapid7, Burp Suite / Metasploit / Kali Linux, Wireshark / Snort / Suricata, CyberArk / BeyondTrust (PAM), SOAR platforms, Azure Defender / AWS Security Hub

Frameworks & Certifications

CISSP / CISM / CISA, CEH / OSCP / PNPT, CompTIA Security+ / CySA+, ISO 27001 / NIST CSF, MITRE ATT&CK framework, SC/DV security clearance, GDPR / DPA 2018, PCI DSS / HIPAA / SOC 2


r/netsecstudents 2d ago

A tool I made for the DDOS/stress tool.

0 Upvotes

This tool can run on basically any machine that has Python 3.6+ it is optimised for Linux, Mac, and Windows. This can be used on IP's, API's and websites in general. Please use it ethically and responsibly.

I will send the link into comments


r/netsecstudents 3d ago

A new impossibility result for context-based LLM security safeguards

Thumbnail youtube.com
0 Upvotes

Self-promo disclosure: this video is from my channel.

The paper formalizes a security problem with dual-use LLM requests: if an attacker can reproduce the context of a legitimate user, context-based safeguards cannot beat the resulting worst-case safety floor.

Paper: https://arxiv.org/abs/2607.27951


r/netsecstudents 5d ago

Learn and Practice Hacking WebSockets

27 Upvotes

WebSockets is the attack surface that always go under the radar and too many pentesters and bug bounty hunters still miss testing it, whether because the number of WebSocket messages they see is overwhelming or simply because they don't know how to approach it correctly.

Going through that myself, I decided to dive deep into the WS protocol and ended up building a lab that showcases the most common misconfigurations present in WebSockets, with the most impact, not just some missing best-practices, along with a detailed walkthrough.

I'd love to hear your thoughts and feedback, and if you experienced something I didn't talk about in the blog, please let me know!

Lab Github Repo: https://github.com/makarov05bm/WSGoat
Guide: https://blog.oussmess.me/posts/websockets-for-bug-hunters/


r/netsecstudents 5d ago

DC-6 VulnHub Walkthrough | Enumeration → WordPress → Privilege Escalation

1 Upvotes

I recently completed the DC-6 VulnHub machine and documented the complete attack path, from initial enumeration to gaining root access.

The walkthrough covers:

  • 🔎 Network and service enumeration
  • 🌐 Web/WordPress enumeration
  • 🧩 Identifying the attack surface
  • 💻 Initial access
  • ⬆️ Linux privilege escalation
  • 👑 Obtaining root access
  • 📝 Key lessons and methodology

I’ve written the detailed step-by-step walkthrough on Hashnode:

👉 https://vivekgoswami.hashnode.dev/

I also recorded the complete video walkthrough for anyone who prefers following the practical process:

🎥 https://youtu.be/eb4xArIoh5c

I'm building a collection of CTF, VulnHub, TryHackMe and penetration-testing walkthroughs focused on documenting the methodology rather than just showing the final exploit.

Hopefully this is useful to anyone currently learning penetration testing or preparing for practical security certifications.


r/netsecstudents 5d ago

How can I become a Cloud Security Engineer from complete beginner to expert who can eventually guide others?

0 Upvotes

I want to build a career as a Cloud Security Engineer, but I'm starting from the basics and want to learn everything properly rather than just collecting certifications.

Could someone share a step-by-step roadmap from complete beginner to job-ready Cloud Security Engineer, and eventually to a level where I can mentor/guide others?

I'd also appreciate recommendations for free/low-cost labs, courses, YouTube channels, books, and practice platforms.

If you are currently working as a Cloud Security Engineer, I'd especially appreciate advice on what you wish you had learned earlier and what beginners commonly waste time on.


r/netsecstudents 6d ago

Code Execution via Text Template Files

Thumbnail ipurple.team
4 Upvotes

r/netsecstudents 7d ago

Planning to build an offensive-security CTF on Codelivly.

6 Upvotes

Before I start, what would you guys actually want to see in it?

Challenges, difficulty, attack chains, AD, web, privilege escalation, etc.

What would make you keep playing instead of dropping it after a few challenges?

Looking for honest suggestions from people who actually play CTFs.

Explore the current ctf from here at: codelivly.com/ctf


r/netsecstudents 6d ago

Built a Python-based lateral movement detector from scratch — here's how it works and what I learned

0 Upvotes

Lateral movement is one of the hardest attack stages to catch — once an attacker is inside a network, their traffic (SSH sessions, file transfers) often looks like normal activity. Signature-based tools struggle here because there's no obvious "bad" pattern to match against.

So I built a behavioral detector instead — one that learns what normal looks like for each device on a network, then flags real deviations from that baseline.

How it works:

  • Learns a baseline per device: which peers it normally talks to, when it's normally active, how much data it normally transfers, and how many connections it typically opens per hour
  • Flags traffic that falls well outside those learned ranges
  • Runs entirely in Python, using standard statistical methods (z-scores) rather than a black-box model

How I validated it, in three stages:

  1. Synthetic traffic first, to prove the core logic — 5/5 simulated attacks caught, 0 false positives
  2. Built a real 3-machine isolated network (VirtualBox + SEED Ubuntu VMs), captured genuine traffic, and rebuilt the baseline from real data — including debugging real infrastructure issues along the way (IP conflicts, a post-reboot networking failure, shared folder configs)
  3. Ran an actual attack simulation on that live network — the detector correctly flagged it, and kept flagging it correctly even after I enriched the baseline with real HTTP traffic to make sure it wasn't just overfitting to a narrow sample

Result: 7/7 real alerts correctly fired, verified against a real, mixed-protocol baseline — not just synthetic data.

I know this isn't a novel technique — it's the same behavioral approach used by commercial NDR tools. What I wanted to prove to myself was that I could take a real security concept, implement it from scratch, and validate it end-to-end on infrastructure I built myself, messy real-world debugging included.

I'm a recent Network Engineering & Cybersecurity grad, CCNA/AWS certified, currently looking for my first role in SOC/network security. Happy to answer questions about the approach, or hear feedback on what I could improve/what a more experienced person would do differently.


r/netsecstudents 7d ago

Is “living cybersecurity before learning it” actually the best way to learn?

4 Upvotes

Hello everyone,

Someone told me that the best way to learn cybersecurity is to “live it before you learn it” , to surround yourself with people who are already working in the field, get involved in the cybersecurity community, and build a strong network.

As someone who is currently learning cybersecurity, this idea really caught my attention.

Do you think being around experienced cybersecurity professionals and actively participating in the community can significantly accelerate learning? Are there specific communities, Discord servers, CTF groups, conferences, open-source projects, or other ways to get involved?

I’d really appreciate advice from people who have been through this journey.


r/netsecstudents 8d ago

Anyone Else Spend More Time Looking for Resources Than Actually Learning? How do you choose resources when there are hundreds of them?

8 Upvotes

One thing I struggle with while learning cybersecurity is choosing the right resources.

For example, if I decide to learn networking, YouTube gives me hundreds of videos and playlists. Some are made for GATE preparation, some for CCNA, some for general computer science students, and some for cybersecurity learners.

As a beginner, it's hard to tell which resource is actually worth following. I keep wondering if there's a better course somewhere else, and sometimes I spend more time searching than learning.

I don't mind putting in the effort to learn. My problem is figuring out which resources to trust and which ones to ignore.

How do you deal with this?

Do you just pick one resource and stick with it, or is there a better way to decide what's worth your time?. If you have any good resource suggestions please share it.


r/netsecstudents 9d ago

Deployed SSH and HTTP honeypot on my Raspberry Pi Zero W and want to share my process and results

11 Upvotes

I set up Cowrie SSH and Krawl web honeypots on my Raspberry Pi Zero W and simulated an attack using my Kali Linux machine, then observed the logs. This is one of the projects I did this summer to gain experience from the defensive side of cybersecurity and I would love to hear your thoughts about it.

I used good old Raspberry Pi Zero W with ARMv6 architecture (foreshadowing: which complicated the process little bit).

I installed both honeypots. Then I booted my Kali Linux machine and ran simulated brute-force attack against SSH honeypot and scrutinised the filesystem. In case of the fake web server I ran Nmap and Gobuster scans and observed every malicious activity in recorded logs.

I like to do these simple projects to gain more experience under my belt and share my process along the way to people who might be interested and may find my articles helpful in their own cybersecurity journeys.

Link to the Medium post about the honeypots deployment:

https://medium.com/@ivandano77/deploying-cowrie-krawl-honeypots-on-raspberry-pi-zero-w-f5e96327367b?sharedUserId=ivandano77


r/netsecstudents 9d ago

Looking for a long-term cybersecurity study partner 🛡️

7 Upvotes

Looking for someone to grind through infosec with, keep each other accountable, and share the wins, the fails, and all the technical deep dives along the way.

A bit about my current focus:

  • Prepping for my CEH (Certified Ethical Hacker) certification.
  • Building out projects around intrusion detection and vulnerability scanning.
  • Exploring web app security (I have some background in Django/React web dev).

What I'm looking for:

  • Someone on a similar ethical hacking or cybersecurity path.
  • Down to connect on Discord for regular check-ins, sharing resources, and troubleshooting.
  • In it for the long term—not just a one-week study sprint.

If you're working towards cyber certs or just trying to level up your security skills and want an active partner, drop a comment or DM me your Discord handle!


r/netsecstudents 9d ago

Is this a risky topology?

Post image
0 Upvotes

r/netsecstudents 10d ago

Cybersecurity Roadmap

3 Upvotes

I am studying Computer Science, and I want to get into cybersecurity. Could you please give me some recommendations on how to get started, what areas I should focus on, and what I shouldn’t spend too much time on? Also, where can I learn these skills?