Digital ကမ္ဘာမှာ ကာကွယ်ရေး — Attack နားလည်မှ Defend တတ်မယ်
Ethical Hacking · Web Security · Network Security · Kali · SOC · CySA+
⚠️ ဒီ knowledge ကို ကိုယ့် system / ခွင့်ပြုထားတဲ့ system မှာသာ သုံးရမည်
Security concepts, CIA triad, threat actors, attack surface, security mindset
Malware, Ransomware, Phishing, Social Engineering, MITM, DoS/DDoS
SQL Injection, XSS, CSRF, Broken Auth, Sensitive Data, SSRF, Insecure Design
TCP/IP, Ports, Firewalls, VPN, IDS/IPS, Packet sniffing, Wireshark basics
Symmetric/Asymmetric encryption, Hashing (MD5/SHA), SSL/TLS, Digital signatures
Nmap (port scan), Wireshark (packet analysis), Burp Suite (web), Metasploit basics
Defensive lab commands: Linux basics, network checks, nmap, tcpdump, Wireshark, logs
SIEM triage, vulnerability management, incident response, evidence, reporting
OWASP Top 10 2025, API/mobile risks, supply chain, cloud, identity, LLM app security
Safe lab design, vulnerable apps, logging, detection rules, patch priority with CISA KEV
A01: Broken Access Control
Security Misconfiguration
Supply Chain Failures
Cryptographic Failures
Injection / Input issues
22 — SSH
80 — HTTP
443 — HTTPS
3306 — MySQL
3389 — RDP
Symmetric: AES-256
Asymmetric: RSA-2048
Hashing: SHA-256
HTTPS = HTTP + TLS
Cert: Let's Encrypt
✅ HTTPS everywhere
✅ Input validation
✅ Prepared statements
✅ Strong passwords
✅ Keep software updated
HackTheBox
TryHackMe
CTFtime.org
PicoCTF
OWASP WebGoat
nmap -sV target
nikto -h target
sqlmap -u url
tcpdump -i eth0
journalctl -xe
Alert triage
Scope affected host
Collect evidence
Contain threat
Write incident report
OWASP Top 10 2025
CISA KEV catalog
MITRE ATT&CK
API & cloud identity
Supply chain risk