🏠 Home / Hub
🔐

Cyber Security

Digital ကမ္ဘာမှာ ကာကွယ်ရေး — Attack နားလည်မှ Defend တတ်မယ်
Ethical Hacking · Web Security · Network Security · Kali · SOC · CySA+

⚠️ ဒီ knowledge ကို ကိုယ့် system / ခွင့်ပြုထားတဲ့ system မှာသာ သုံးရမည်

⚖️ Ethical Hacking Rule: ဒီ lesson တွေ ကိုယ်ကာကွယ်ဖို့ (Defensive Security) အတွက် သင်တာ။ သူတစ်ပါး system ကို ခွင့်မတောင်းဘဲ တိုက်ခိုက်တာ = ဥပဒေဆိုင်ရာ အရေးယူခံရနိုင်တယ်။ Bug Bounty / CTF competition တွေမှာ legal ဖြစ်တဲ့ environment မှာ practice လုပ်ပါ။
🔐 Cyber Security ဆိုတာ: Computer systems, networks, data တွေကို unauthorized access, damage, attack ကနေ ကာကွယ်တာ
🎯 CIA Triad: Confidentiality (လျှို့ဝှက်မှု) · Integrity (တိကျမှု) · Availability (အသုံးပြုနိုင်မှု)
💼 Career Paths: SOC Analyst · CySA+ Analyst · Security Engineer · Penetration Tester · Cloud Security
Part 1 — Fundamentals
01
🛡️

Intro & CIA Triad

Security concepts, CIA triad, threat actors, attack surface, security mindset

CIAThreatRiskAttack Surface
02
☠️

Threats & Attacks

Malware, Ransomware, Phishing, Social Engineering, MITM, DoS/DDoS

MalwarePhishingDoSMITM
Part 2 — Web & Network Security
03
🌐

Web Security — OWASP Top 10

SQL Injection, XSS, CSRF, Broken Auth, Sensitive Data, SSRF, Insecure Design

OWASPXSSSQLiCSRF
04
🔌

Network Security

TCP/IP, Ports, Firewalls, VPN, IDS/IPS, Packet sniffing, Wireshark basics

FirewallVPNPortsWireshark
Part 3 — Crypto & Tools
05
🔑

Cryptography

Symmetric/Asymmetric encryption, Hashing (MD5/SHA), SSL/TLS, Digital signatures

AESRSASHA-256TLS
06
🔧

Security Tools

Nmap (port scan), Wireshark (packet analysis), Burp Suite (web), Metasploit basics

NmapBurp SuiteKali Linux
Part 4 — Kali, SOC & Current Trends
07
💻

Kali Linux Commands

Defensive lab commands: Linux basics, network checks, nmap, tcpdump, Wireshark, logs

Kalinmaptcpdumplogs
08
🎧

CySA+ & SOC Analyst

SIEM triage, vulnerability management, incident response, evidence, reporting

CySA+SIEMIRReport
09
📈

Modern Security Trends

OWASP Top 10 2025, API/mobile risks, supply chain, cloud, identity, LLM app security

OWASPAPICloudLLM
10
🧪

Blue Team Home Lab

Safe lab design, vulnerable apps, logging, detection rules, patch priority with CISA KEV

LabDetectionKEVHardening

📋 Security Quick Reference

OWASP Top 10 2025

A01: Broken Access Control
Security Misconfiguration
Supply Chain Failures
Cryptographic Failures
Injection / Input issues

Common Ports

22 — SSH
80 — HTTP
443 — HTTPS
3306 — MySQL
3389 — RDP

Encryption

Symmetric: AES-256
Asymmetric: RSA-2048
Hashing: SHA-256
HTTPS = HTTP + TLS
Cert: Let's Encrypt

Defense Checklist

✅ HTTPS everywhere
✅ Input validation
✅ Prepared statements
✅ Strong passwords
✅ Keep software updated

Practice Platforms

HackTheBox
TryHackMe
CTFtime.org
PicoCTF
OWASP WebGoat

Kali Tools

nmap -sV target
nikto -h target
sqlmap -u url
tcpdump -i eth0
journalctl -xe

SOC Flow

Alert triage
Scope affected host
Collect evidence
Contain threat
Write incident report

Trend Watch

OWASP Top 10 2025
CISA KEV catalog
MITRE ATT&CK
API & cloud identity
Supply chain risk

📌 Study Checklist