High Contrast Dyslexic Font

🛡️ Cybersecurity Mastery

Learn the fundamentals and practise real‑world incident response – all in one place. From the CIA Triad to ransomware investigations, this guide prepares you for interviews and on‑the‑job scenarios.


🧠 Memory Tip: Use the mnemonics and key takeaways to lock in the concepts. Expand each scenario, try to answer the questions, then reveal the solution.
6
Core Domains
20+
Key Frameworks
10
Enterprise Tools
6
Practice Scenarios

📚 Core Modules

🧩 The CIA Triad – Core Security Goals

  • Confidentiality – Only authorised people can access data. → Encryption, access controls, MFA.
  • Integrity – Data is accurate and trustworthy. → Hashing, digital signatures, version control.
  • Availability – Systems and data are accessible when needed. → Redundancy, DDoS protection, backups.
Mnemonic: Can I Ask? – Confidentiality, Integrity, Availability.

🔐 Security Controls (3 Types)

  • Administrative – Policies, training, procedures (e.g., acceptable use policy).
  • Technical – Firewalls, encryption, MFA, SIEM, EDR.
  • Physical – Locks, biometrics, CCTV, access badges.

📡 SOC & SIEM

  • SOC (Security Operations Center) – A team that monitors, detects, and responds to threats 24/7.
  • SIEM (Security Information and Event Management) – Aggregates and correlates logs to detect anomalies (e.g., Microsoft Sentinel, Splunk).
  • EDR (Endpoint Detection and Response) – Monitors endpoints for suspicious activity (e.g., Defender for Endpoint, CrowdStrike).

📜 Key Frameworks & Regulations

  • NIST CSF – Identify, Protect, Detect, Respond, Recover. (Mnemonic: I Promise Donuts Really Rock)
  • NIST 800-53 – Security and privacy controls catalogue.
  • NIST 800-61 – Incident handling guide.
  • CIS Controls – 18 prioritised actions for defence.
  • PCI DSS – Protects cardholder data.
  • GDPR – EU data protection and privacy.
  • HIPAA – Healthcare data security.

📉 Risk Management

Risk = Likelihood × Impact. Manage risk by: Accepting, Mitigating, Transferring (insurance), or Avoiding.

💡 Interview Tip: Be ready to explain how the CIA Triad applies to a ransomware attack – it hits Availability (encryption) and Integrity (data altered).

🔎 KQL (Kusto Query Language)

The query language used in Azure Data Explorer, Microsoft Sentinel, and Log Analytics. Essential for threat hunting.

📋 Key Log Sources

  • Azure Activity Logs – Control plane operations (resource creation, deletion).
  • SignIn Logs – Authentication attempts (success/failure).
  • NSG Flow Logs – Network traffic.
  • Defender for Endpoint – Process, file, network, and registry events.

🔄 Incident Response Lifecycle (SANS)

  1. Preparation – Plan, train, and equip the IR team.
  2. Detection & Analysis – Identify potential incidents via alerts and logs.
  3. Containment – Stop the spread (e.g., isolate infected systems).
  4. Eradication – Remove the threat (delete malware, patch vulnerabilities).
  5. Recovery – Restore systems from clean backups.
  6. Lessons Learned – Review and improve the IR process.
Mnemonic: Please Don't Eat Raw Carrots – Preparation, Detection, Eradication/Containment, Recovery, Lessons Learned.

🔬 Threat Hunting

Proactive search for threats that evaded existing controls. Starts with a hypothesis, uses logs, and often involves KQL.

💡 Interview Tip: Emphasise that containment is the first priority after detection – before eradication or communication.

📌 Key Concepts

  • Vulnerability – A weakness (e.g., unpatched software).
  • Zero‑Day – Unknown to the vendor, no patch.
  • CVE – Unique identifier (e.g., CVE-2024-1234).
  • CVSS – Scoring system (0–10) for severity.
  • OWASP Top 10 – The most critical web application risks.

🔄 Vulnerability Management Lifecycle

  1. Identify – Scan with Nessus, Tenable, etc.
  2. Prioritise – Based on CVSS, exploitability, and asset criticality.
  3. Remediate – Apply patches, change configurations, or use compensating controls.
  4. Verify – Rescan to confirm the fix.
  5. Report – Communicate progress and metrics.

🛠️ Remediation Techniques

  • Manual: Windows Update, software removal.
  • Programmatic: PowerShell (Windows) or BASH (Linux) scripts.
  • Risk Responses: Accept, Mitigate, Transfer, Avoid.
💡 Interview Example: Describe a time you prioritised a critical CVE over a lower‑risk one and coordinated the patch deployment.

🐍 Python Fundamentals

Variables, conditionals, loops, functions, error handling – the building blocks for automating security tasks.

🧠 Building AI Agents

  • OpenAI API – Integrate LLMs into security workflows.
  • Tool Selection – Map user requests to KQL queries.
  • Guardrails – Ensure safe, accurate outputs.
  • Agentic AI – Create an AI SOC Analyst that can interpret and act.
💡 Tip: Even without deep coding skills, understanding how AI can accelerate threat hunting is a valuable interview talking point.

📁 Portfolio & GitHub

Showcase projects like vulnerability management reports, threat hunting dashboards, and incident response playbooks.

📄 Resume & Job Search

  • Highlight hands‑on tools: Tenable, Sentinel, Defender, Azure, KQL, Python.
  • Emphasise any practical experience, even from lab environments.

🎤 Interview Practice

  • Technical: "How would you handle a ransomware outbreak?" – Containment, eradication, recovery.
  • Behavioural: "Tell me about a time you communicated a vulnerability to a non‑technical audience." – Use an analogy.
  • Scenario: "You receive an alert that a user clicked a phishing link. What do you do?" – Isolate, investigate, reset credentials.
🔑 Key to success: Always link your answers to business impact – show you understand that cybersecurity protects the organisation's mission.

🚨 Practice Scenarios

Expand each scenario, read the brief, try to answer the investigation questions, then reveal the solution to check your understanding.

Incident Brief

Date: 14 September 2025

A routine support request left behind a trail of anomalies. What was framed as troubleshooting was actually an audit – probing, cataloging, and preparing to linger. A fake explanation was planted to justify the activity.

Investigation Questions
  • Initial access method?
  • Compromised accounts?
  • Data accessed or stolen?
  • Persistence mechanisms?
  • Exfiltration method?
Starting KQL
DeviceProcessEvents
| where DeviceName contains "flare"
| where Timestamp between (datetime(2025-09-14) .. datetime(2025-09-15))
| project Timestamp, AccountName, FileName, ProcessCommandLine
| sort by Timestamp asc

Incident Brief

A competitor undercut our 6‑year contract by 3%. Supplier contracts and pricing data appeared on underground forums. Compromised system: AZUKI-SL (IT admin workstation).

Investigation Questions
  • Initial access method?
  • Compromised accounts?
  • Data stolen?
  • Exfiltration method?
  • Persistent access left?
Starting KQL
DeviceProcessEvents
| where DeviceName == "azuki-sl"
| where Timestamp between (datetime(2025-11-19) .. datetime(2025-11-20))
| project Timestamp, AccountName, FileName, ProcessCommandLine
| sort by Timestamp asc

Incident Brief

After initial access, the attacker returned ~72 hours later. Suspicious lateral movement and large data transfers on the file server were detected.

Investigation Questions
  • Which systems were accessed?
  • Credentials used?
  • Tools deployed?
  • Data accessed on file server?
Starting KQL
DeviceLogonEvents
| where DeviceName contains "azuki"
| where Timestamp between (datetime(2025-11-22) .. datetime(2025-11-23))
| project Timestamp, AccountName, DeviceName, LogonType, IPAddress
| sort by Timestamp asc

Incident Brief

Five days after file server breach, attacker pivoted to the CEO's PC, deploying persistent backdoors and exfiltrating sensitive data.

Investigation Questions
  • How did they move from file server to CEO's PC?
  • Persistence mechanisms on CEO's PC?
  • Sensitive data accessed?
  • Privilege escalation tools?
Starting KQL
DeviceLogonEvents
| where DeviceName contains "azuki"
| where Timestamp between (datetime(2025-11-24) .. datetime(2025-11-25))
| project Timestamp, AccountName, DeviceName, LogonType, IPAddress
| sort by Timestamp asc

Incident Brief

November 27, 2025 – ransom notes across all systems. Attackers destroyed backups and encrypted critical servers.

Investigation Questions
  • How did they reach backups?
  • What was destroyed?
  • How did ransomware spread so fast?
  • Can we recover?
Starting KQL
DeviceProcessEvents
| where DeviceName contains "azuki"
| where Timestamp between (datetime(2025-11-27) .. datetime(2025-11-28))
| project Timestamp, AccountName, DeviceName, FileName, ProcessCommandLine
| sort by Timestamp asc

Incident Brief

An operational account with local admin privileges was used interactively during year‑end reviews. Irregular access patterns led to unauthorised script execution, data staging, and exfiltration.

Investigation Questions
  • Which accounts were involved?
  • What scripts were executed?
  • What sensitive data was accessed?
  • How was data exfiltrated?
  • What persistence was found?
Starting KQL
DeviceProcessEvents
| where Timestamp between (datetime(2025-12-01) .. datetime(2025-12-10))
| where FileName in ("powershell.exe", "cmd.exe", "wscript.exe")
| where ProcessCommandLine contains "bonus" or ProcessCommandLine contains "performance"
| project Timestamp, AccountName, DeviceName, FileName, ProcessCommandLine
| sort by Timestamp asc

📊 Quick Reference – Incident Response Lifecycle

1. Preparation
Plan, train, acquire tools
2. Detection & Analysis
Identify incidents, gather evidence
3. Containment
Stop the spread – isolate systems
4. Eradication
Remove threat, patch, delete malware
5. Recovery
Restore from clean backups
6. Lessons Learned
Post‑incident review, improve processes
Mnemonic: Please Don't Eat Raw Carrots

🚀 Ready to apply these skills?

Explore the full curriculum with hands‑on labs and live coaching.

🔗 Access the Full Course