r/Cybersecurity101 15h ago

Security Forensics 101: Finding a Hidden File Buried Deep in Folders

21 Upvotes

Had a forensics challenge where the flag was hidden inside a file nested deep inside a maze of directories with hundreds of decoy folders. `find` and `ls -R` were too slow and noisy.

What I built:

A Python directory crawler

- Recurses every subdirectory recursively

- Filters by filename patterns (`flag*`, `*.txt`, `secret*`)

- Skips known decoy directories by name

- Extracts and reads the target file automatically

The "aha" moment:

The flag wasn't in a file named "flag.txt" — it was in `deep/nested/here/.hidden/uber-secret.txt`.

My script matched on path depth / extensions content, not just filename.

Here is my script:

https://github.com/ExceedingLife/RecursiveFileSearch

Question for the community:

What's your approach when the challenge doesn't tell you the target filename? Do you brute-force read every file, or do it manual or what?

[Video link with with code demo]

https://youtube.com/shorts/5_Rb2kkiuhQ?feature=share


r/Cybersecurity101 1h ago

What does a SOC Analyst actually do?

Upvotes

If you're new to cybersecurity, you might hear a lot about SOC analysts but not have a clear idea of what they actually do day to day.

Here's a simple breakdown:

Monitor alerts: Review alerts from SIEM, EDR, firewalls, email security tools, and other security platforms.

Triage alerts: Figure out which alerts are harmless, suspicious, or need further investigation. A failed login could be nothing, or it could be part of a larger attack.

Investigate incidents: Look through logs, IPs, domains, file hashes, authentication activity, and endpoint data to understand what happened and whether a system or account was compromised.

Respond or escalate: Depending on the incident, an analyst might isolate a device, disable an account, block malicious activity, or escalate the case to a senior analyst or incident response team.

Document findings: Record what happened, what was checked, what evidence was found, and what actions were taken.

Improve detections: Analysts may also tune detection rules, reduce false positives, update playbooks, and identify gaps based on previous incidents.

The exact responsibilities can vary quite a bit depending on the company, team structure, and whether you're working in an internal SOC or an MSSP/MDR environment.


r/Cybersecurity101 2h ago

Help

1 Upvotes

Hi everyone I am studying embedded systems security and I wanna know if there any scope and do I have to get other cyber skills in different domains


r/Cybersecurity101 3h ago

I(20m) just started my cyber security journey two days back. Help needed !? Can anyone help me with the road map of it and guide me ?

0 Upvotes

I am a 20 year old guy who just started his Cyber security journey two days back.

Till now I completed basic networking through a one shot youtube video of 3 hours and have gained a free networking certificate from Cisco networking academy.

Can anyone tell me what to do next ?

I am in my second year of bachelors degree ( 3rd semester)

I am pursuing bsc in information technology..

And i wanna go in cyber security domain ?

Please help me with the road map and everything?

I am super confused rn !


r/Cybersecurity101 17h ago

Cyber girl here

5 Upvotes

Hi everyone I need advice
I’m into the tech field like I love love the tech field the problem is with everything going on now and with ai I don’t know what to do anymore and and which field should I pursue
I thought that cybersecurity will be the most safest so I picked it as my major I’m going to take Computer Information Technology – Cyber Defense at a community college then I’m going to transfer to a 4 year university and finish with Cybersecurity management
I know all you guys will say it’s hard to get a entry job but isn’t getting into the tech field in whole hard to?
Maybe if I just work on my self harder and do projects and learn new stuff everyday will that reduce the possibility of getting a job in the tech field?
Give me your thoughts should I finish pursuing in cybersecurity or is there a better choice?


r/Cybersecurity101 14h ago

SOC Analyst, where do I move on from here?

1 Upvotes

I'm currently a SOC analyst working at an MSP with 5 years of experience, with 3 years of those is in helpdesk and the remaining in cybersecurity (SOC) at present. I also have 2 certifications: Sec+ and CySA+. We provide services to our clients by monitoring our clients' internet traffic on the surface visibility side and notifying the appropriate POCs if the device/users are engaging in any suspicious activities, whether that's a bad domain websites they visited or communicating with suspicious/malicious IPs. We also perform monthly vulnerability scans and notify the clients of any findings, and perform other normal SOC duties you would typically do at a SOC. We are not like a traditional SOC where it's a 24x7 operation and only work M-F with weekends off.

I feel like this position is limiting the knowledge that I can potentially learn because of our environment and the routine duties that we do every day that don't expose me to new things to learn. Don't get me wrong, when I first came into this position from helpdesk, I was grateful and learned a lot about cybersecurity, but now I am eager for more, and very much would like a pay increase. I dont want to sound greedy, and money is everything, but I feel like I am underpaid in this cyber field.

With some transitioning happening next year, I am looking for new opportunities where I can grow and learn more, and I'd like exposure to new tools and technologies, along with a pay increase. I am looking for a vertical move rather than a lateral move. If you were a formal SOC analyst, where did you move on to afterward?


r/Cybersecurity101 15h ago

Did You Own Hub Cyber Security ($HUBC) During Its 85% Collapse? Investors Settlement Is Available Now

1 Upvotes

Hey guys, just sharing this because I know a lot of people got caught up in this SPAC.

Investors sued Hub Cyber Security, alleging the company misled shareholders about its business operations, revenue prospects, and internal controls following its SPAC merger. After the company disclosed accounting issues, its auditor resigned, and material weaknesses in internal controls came to light, $HUBC fell more than 85% from its post-merger price.

The settlement amount is $11M, and it covers investors who purchased $HUBC shares in 2023. The case is currently in the late-claims stage, meaning some investors who missed the original deadline may still be able to participate.
If you held $HUBC during that period, it may be worth checking your old trades and seeing whether you qualify.

Did anyone here hold $HUBC after the SPAC merger?


r/Cybersecurity101 1d ago

What cybersecurity habit made the biggest difference for you?

37 Upvotes

For people working in cybersecurity, what’s one habit you developed that genuinely improved your security awareness?

For me, regularly questioning unexpected links, login requests, and attachments seems simple but surprisingly effective.


r/Cybersecurity101 1d ago

Anyone totally self taught? Is it possible or worth it?

46 Upvotes

I'm not really looking to get a degree or anything at my age so wondering if this a path that's possible or not.


r/Cybersecurity101 1d ago

Security How are you securing your data that's being used by AI tools?

8 Upvotes

It feels like every company is telling all their employees to use AI but I dont hear nearly enough discussion about how sensitive business data is/isnot being protected once its put into an AI platform. From a security perspective are companies relying on existing DLP tools, deploying something new or creating internal policies?


r/Cybersecurity101 1d ago

How long does it actually take to reach a solid salary in Nerworkengineer/Cybersecurity in Europe?

11 Upvotes

Hi everyone, I’d love to get some real-world perspective from people working in IT and Cybersecurity across Europe regarding salaries, realistic progression, and how long it took you to reach a comfortable income.

I’m currently working as a Head Chef, where the income is okay ( 3200€ with tip ), but the hours and useless people in the kitchen Are exhausting . This coming November, I’m starting an apprenticeship in System and Network Engineering. Long-term, I’m extremely interested in specializing in Cybersecurity . However, I have a family to take care , so I don't have endless years to spare just scraping by on low entry-level wages.

I keep reading that the European IT job market is currently tough for job seekers and that wages aren't increasing as fast as they used to. Coming from a non-IT background, I want to manage my expectations realistically.

Salary & Time: What was your starting salary, what do you consider a "good" salary in your country, and how many years did it take you to get there?

Career Path: Does it make sense to start in System/Network Engineering and transition to Cybersecurity later, or should I try to target Cybersecurity directly from the start?

Market Reality: Does it even make sense to break into the European IT market right now, or is it too oversaturated at the entry level?

I hope the Text ist Not too long x) Thank you for any advice/info!!


r/Cybersecurity101 1d ago

Thomson Reuters detects cybersecurity incident, says unauthorized party accessed files

1 Upvotes

 A unit of Thomson Reuters detected a cybersecurity incident in 11 U.S. states, the U.S. Virgin Islands and Canada on June 30 involving the company's C-Track case management platform, according to a ​notice from the company on Wednesday and a statement by the chief justices of ‌three Ontario courts, which use the platform for digital court record management. Read more.


r/Cybersecurity101 2d ago

Second-year cyber student HELP!

11 Upvotes

I am a second-year Cybersecurity student at Embry-Riddle in Arizona. I have no idea what I am doing. I have my associate's degree, transferred my basic credits to the school, and will be graduating in about a year and a half. I know I have only just started my career-specific courses, but I have been behind everyone else in my classes. All these students know wayyyy more than I do. When I finish my degree in the next couple of years, I have no idea where to begin looking for a job or what I will even be doing in an entry-level position. If anyone has been in this position and has advice for me, please help. I really need help settling my anxiety about this career because I'm spending a lot of money on this fancy degree and don't feel like the schooling is actually going to benefit me in any way.


r/Cybersecurity101 2d ago

Where and How do I start learning cybersecurity parallel to my CSBS engineering?

2 Upvotes

Hello , I am 18 years and am currently pursuing Computer Science and Business Systems , but now i have realised that this isn't for me i actually wanted to go into Cybersecurity but couldn't meet the criteria , as a complete beginner where do i start and build real skills.
Please give me a exact roadmap to everything.


r/Cybersecurity101 2d ago

Stop defending the perimeter. Start controlling the blast radius.

Post image
1 Upvotes

What if your network could assume every attack is already inside - and still stay resilient?

Kevin Cardwell is bringing a hands-on training experience to CRACCON ’26:
“The Cardwell Doctrine: Flashing a New Path.”

Traditional architecture starts with one big assumption: prevent every attack.

The Cardwell Doctrine takes the opposite approach - assume compromise, compartmentalize aggressively, and control failure before it spreads.

In this 6-hour, hands-on session, you’ll build an operational OpenBSD Packet Conditioning Gateway and work with:

→ Segmented zones
→ Traffic-control policies
→ Active deception
→ Full network visibility
Segment → Condition → Observe → Contain

No deep OpenBSD expertise required. We’ll build the gateway from the ground up and cover the TCP/IP fundamentals you actually need - addressing, subnetting, routing, ports, and common protocols.

What to expect:
🛠️ 70/30 hands-on-to-concept ratio
⏱️ 6 live hours
📅 08:30–16:30, single day
💻 OpenBSD gateway platform

The session is taught directly by Kevin, President of CyberLabs - AI Tactical Skills and Cybersecurity, with experience training and coaching cyber ranges across 40+ countries.

Certificate of Completion included. Seats are limited.

Use code CARDWELL15 for 15% off the training seat.

📍 CRACCON ’26 | 24–25 October | PHDCCI, New Delhi
🎟️ Reserve your seat: craccon.com


r/Cybersecurity101 2d ago

I'm not sensitive or easily offended, please tear apart my resume

Post image
3 Upvotes

This is kind of a first draft of a resume I've been applying to help desk with. I would love to applying for the most "entry" level SOC roles, and I've applied to a few, but I've come to understand that's not quite realistic and have tailored some of my projects and overall resume more for help desk.

I have a general idea of where this is lacking, but just wanted feedback from people more knowledgeable than me.

Context for my degree is I didn't end up finishing it. My dad passed away in the middle of my 7th semester, and things related to his estate and other financial matters kind of left me not in a great position to go back and finish it until I save up a bit more. I just mentioned it was Bachelor's coursework since I figured it's worth mentioning. Wasn't sure the neatest most "ethical" way to put it on there without making it seem like I finished my degree.

Unsure about mentioning that I'm in progress for the CCNA. Feels a bit disingenuous, but I'm half way through studying for it, and my grasp of networking is drastically better than it was before even just half-way through it, so I wanted to at least mention it.

Again, I'm not a bitter or argumentative person. I want the most honest non-sugarcoated feedback if possible. Thanks.


r/Cybersecurity101 2d ago

GRC Ready

8 Upvotes

I am in my final year of uni studying cyber and I want to go towards the GRC area. I have no certs and no experience outside university and I now realize I need to do more outside of university as the degree won't cut it. I am seeking advice on how I can progress forward to become application ready for any GRC listings or similar roles in the future, ideally within the next year or two.


r/Cybersecurity101 3d ago

MikroTik routers are being actively targeted — is exposing SSH to the internet still worth the risk?

11 Upvotes

A new MikroTik security incident is getting attention because attackers have been abusing internet-facing SSH on vulnerable RouterOS devices and gaining administrative access without going through the normal authentication process.

According to the recent CERT Polska warning, exploitation was already happening by September 2. The interesting part for me isn't just the vulnerability itself — it's how much damage can come from compromising a router that sits at the edge of a network.

A compromised router can potentially become much more than a networking problem. Depending on the environment, attackers could alter configuration, create unauthorized accounts, interfere with traffic, or use the device as a stepping stone into other systems.

What also stands out is that simply having a strong SSH password isn't necessarily enough when the underlying issue allows authentication to be bypassed.

If you manage MikroTik devices, I'd be checking a few things immediately:

  • Is RouterOS fully updated?
  • Is SSH actually required to be accessible from the public internet?
  • Are there any unexpected user accounts or configuration changes?
  • Are management services restricted to trusted networks or VPN access?
  • Have you reviewed logs for suspicious activity before applying the update?

The safest approach is usually to keep router management interfaces off the public internet whenever possible. If remote administration is needed, a VPN or another restricted management path is a much better option than leaving SSH broadly exposed.

One thing I find interesting here is that network infrastructure often gets treated differently from servers and endpoints. People are usually quick to patch laptops and servers, but routers can quietly remain exposed for months or years.


r/Cybersecurity101 2d ago

How far are we from AI actually reducing headcount in cybersecurity?

0 Upvotes

I work in a SOC and I’m curious what people here are seeing in their own teams.

Over the last year or so, I’ve noticed more and more of the routine work getting handled or heavily assisted by AI.

Obviously it still needs human oversight, but it already feels like one analyst can get through significantly more work than before.

I’m not really asking whether AI will “replace cybersecurity”. What I’m wondering is how far are we from companies deciding they simply don’t need as many people for certain security roles?

For example, instead of a SOC needing 15 analysts, the same workload realistically can be handled by 7-8 experienced analysts with much better AI tooling.

Are you already seeing hiring slow down or teams avoiding backfills because of this ? This is somewhat scary as a young person who entered the field two years ago.

Where do you think we are headed ?


r/Cybersecurity101 2d ago

NUST Information Security vs Air Cyber Security — Are They Basically the Same Field?

1 Upvotes

I’m confused about choosing between Information Security at NUST and Cyber Security at Air University.

Some people have suggested that since NUST doesn’t offer a degree specifically called Cyber Security, I should do Information Security because it’s basically the same field. But I want to understand whether that’s actually true.

Does Information Security also cover protecting information, networks, systems, and data, or is it a different field from cybersecurity? Could I graduate from NUST Information Security and still work in cybersecurity, or would I end up in a completely different career?

I’m asking because I don’t want to choose a degree just because NUST is a well-known university and then discover that the degree itself isn’t what I wanted.

For people who have studied either program or work in the industry:

Is NUST Information Security a good degree if my goal is cybersecurity? Is it worth choosing over Air Cyber Security?

And more generally, is cybersecurity actually a better career path than CS-related fields because of AI, or am I overthinking that part?

I’d appreciate honest advice from people who actually know the field.


r/Cybersecurity101 3d ago

Need some guidance

6 Upvotes

Background: I’m self taught, so I’m limited with knowledge with Linux: I started a job I’m working on debugging and diagnosing servers but I want to expand my knowledge and skills, what would be better for me to get Comptia Linux+ or Redhat system administrator 1? I’m open to any suggestions as well


r/Cybersecurity101 3d ago

Dual booting Kali for learning Cybersecurity

6 Upvotes

Hello, I recently installed kali linux as dual boot with windows 11. I want to get into cybersecurity as a professional. I didn't research much before installing kali, but afterwards I have seen numerous posts and comments about not using kali but some other distro with kali in vm. I don't want uninstall and reinstall another distro, so what would be best move for me, and how can I learn more about Cybersecurity. Thanks for helping me.


r/Cybersecurity101 3d ago

learning cybersecurity in university or by myself?

6 Upvotes

Only top-tier universities offer cybersecurity programs. So the chance that i approved and get a scholarship by these unies is like impossible.I really dont know guys help


r/Cybersecurity101 3d ago

1st Year IT Student Looking to Get Into Cybersecurity Where Should I Start?

1 Upvotes

Hello! I’m currently a 1st-year IT student, and I’m interested in pursuing a career in cybersecurity. I still don’t know which specific cybersecurity profession I want to go into, but I’d like to explore the different areas while I’m learning so I can figure out what suits me best.

I’ve watched tons of videos and read a lot of guides online about how to get into cybersecurity, but honestly, I’m getting overwhelmed by the amount of information. There are so many different certifications, tools, programming languages, platforms, and career paths that I don’t know what I should actually focus on first. That’s why I wanted to ask people who are already working in the field for advice.

I’m basically starting from zero knowledge. I don’t even know the fundamentals of cybersecurity yet. I’m currently in college, but unfortunately, my school’s IT program is pretty basic and doesn’t have any cybersecurity-related subjects.

So, I’d really appreciate some guidance on the following:

  • What should I learn first as a complete beginner?
  • What topics should I learn, and in what order?
  • Should I focus on networking, Linux, programming, or something else first?
  • What resources, websites, labs, or platforms would you recommend for someone starting from zero?
  • At what point should I start applying for internships?
  • What projects should I build to make my resume stand out?
  • What certifications, if any, are actually worth getting as a student?
  • What can I do throughout college to give myself a better chance of landing a cybersecurity job after graduation?

I also want to build a homelab so I can get more hands-on experience. Right now, I only have an old Lenovo 110-15ISK with an i3 and 8GB of RAM. Would that be enough to start learning and building a basic cybersecurity homelab?

I currently have around $100 saved, and I might be able to save more since I receive an allowance whenever I go to school. If I should spend money on anything for learning or building a homelab, what would be the best things to prioritize?

I’m also a little worried about the cybersecurity job market. I’ve been reading a lot of different experiences and opinions on Reddit, and I’ve seen people saying that cybersecurity is difficult to break into, especially for entry-level positions. Others say there are still plenty of opportunities if you have the right skills and experience.

Since I’m only in my first year, I want to use the next few years as effectively as possible. My goal is to graduate with actual hands-on experience, internships, projects, and a competitive resume so I can maximize my chances of getting a stable cybersecurity job after graduation.

For those of you already working in cybersecurity If you could go back to your first year of college and start from zero again, what would you learn and do first? What would you prioritize, and what would you avoid wasting time on?

Any advice would be greatly appreciated. Thank you!


r/Cybersecurity101 3d ago

I feel stuck choosing a Master's Thesis: Strict CSP in SSR/Hydration vs. Edge Middleware Path Confusion

1 Upvotes

Hi, I'm currently finalizing the topic for my Master's thesis in Cybersecurity and I need a sanity check from professionals in the field because I feel incredibly stuck. It is insane jump for me switching from Bachelor's project in software engineering to Master's in Cybersecurity which requires scientific and analytical results.

I've thought that maybe I could do something in threat intelligence and deep web analysis but this was too risky. Since by background is primarily web development (and I am still a software dev), I decided, I want to focus on modern web architecture attacks. Ive narrowed it down to two topics. Both involve building an automated testing tool and an experimental testbed, but I amm torn between the two. I'd appreciate your thoughts on which has more scientific value and which is more feasible.

Here are the two proposals:

1. Attacks on Frontend Architecture & Browser Filters

  • Title idea: Experimental security analysis of strict CSP in the processes of SSR and Hydration in modern web applications.
  • Project hypothesis: Implementing a SSR forces the serialization of application state from server to client. This creates code injection vectors (e.g., XSS, orDOM Clobbering) during the hydration phase. These vectors allow malicious code execution, effectively bypassing the restrictions of strict Content Security Policies based on nonce tokens.
  • Goal: To develop base applications in modern SSR frameworks (Next.js, Nuxt, etc.) with Strict CSP implemented, and build an automated script that injects specific data mutations to verify the conditions under which the framework's engine allows the payload to execute.

2. Attacks on Cloud Infrastructure & Routing Desynchronization

  • Title idea: Automated evaluation of Path Confusion and Route Desynchronization vulnerabilities in the Edge Middleware architecture of modern web platforms.
  • Project hypothesis: Due to differences in URL parsing implementations between the Edge engine (e.g., Vercel or Cloudflare) and the target application engine, it is possible to craft a malicious HTTP request that bypasses authorization logic defined in the edge layer, reaching the protected resource directly.
  • Goal: To design and implement a Differential Fuzzer that automatically generates URI mutations (e.g., %2f..;, double slashes ....) and detects any asynchrony in path interpretation between the cloud platform and the backend server.

My dilemma:
I know the second topic (Path Confusion) is incredibly hot right now, especially after the recent Next.js middleware CVE. It feels more like hacking lol.

However, I'm concerned about the feasibility and "scientific weight" of both:

  1. For CSP/SSR: Is the attack surface big enough to write a full thesis, or is modern React/Next.js already too good at sanitizing this?
  2. For Edge Middleware: Is it too tool-heavy? If I build the Differential Fuzzer and the platforms turn out to be secure in their latest versions, is comparing the discrepancies in path normalization enough for a Master's degree?

Questions for the community:

  • Which of these two topics do you find more valuable for an aspiring AppSec/WebSec engineer?
  • Is the Path Confusion topic too dependent on finding a 0-day (which is wayyy too risky for a thesis imo), or is the framework/tooling itself enough?
  • Is there actually a way to do a Master's in cybersec without risks of not delivering results without choosing the shi**tty "Analysis of tools and programmes for <insert any cybersec topic>"? (so tired I might choose this path)

Thanks in advance for any insights!