Teach Yourself Information Security

Inspired by Teach Yourself Computer Science, this guide intends to provide a basic (and generally, free) set of resources for getting started with learning computer security while also answering the following questions:

  • Which subjects should you learn, and why?
  • What are some recommended books/video series/CTF challenges for each subject?

Ensine-se em Segurança da Informação

Inspirado por Teach Yourself Computer Science, este guia pretende oferecer um conjunto básico (e em geral gratuito) de recursos para começar a aprender segurança de computadores, ao mesmo tempo em que responde às seguintes perguntas:

  • Quais assuntos você deve estudar e por quê?
  • Quais são alguns livros/séries em vídeo/CTFs recomendados para cada assunto?

tl;dr:

The consensus is that to build a strong foundation for infosec, you will want to start by studying networking, operating systems fundamentals (Windows & Linux), and some sort of scripting/programming language like Python or Bash. Study these first, and then dive into another subject (some of which are listed here) that piques your interest, if you want. There are many domains of infosec to explore.

Resumo rápido:

O consenso é que, para construir uma base sólida em infosec, você deve começar estudando os fundamentos de redes, sistemas operacionais (Windows e Linux) e alguma linguagem de scripting/programação como Python ou Bash. Estude estes tópicos primeiro e, se quiser, mergulhe em outro assunto (alguns estão listados aqui) que desperte seu interesse. Existem muitos domínios de infosec para explorar.

Subject Matrix

Subject Why Study? Resources Exercises/CTF
Networking Learn how computers talk to each other and how the Internet 'works'. Computer Networking: A Top-Down Approach Malware Traffic Analysis
Operating Systems This is the 'computer' in 'computer security'. Nand2Tetris & Linux Journey & Windows Internals OverTheWire: Bandit
Programming Automate tasks and write your own tools, and be able to 'get' what a program does (even if you don't know the language). Harvard CS50 &
Automate the Boring Stuff w/Python
Try making your own tools!
Open Source Intelligence Augment everything you do by being able to find all of the info you need, online. Open Source Intelligence Techniques & OSINTCurious Quiztime & SourcingGames
Cryptography This is key to confidentiality, integrity, and non-repudiation (e.g. 'no-takebacks') - i.e. the stuff vital to security. Online Cryptography Course CryptoHack
Digital Forensics & Incident Response Be able to stop bad stuff from happening and figure out what happened. 13Cubed Videos & Incident Response and Computer Forensics CyberDefenders Labs
Malware Analysis & Reverse Engineering Figure out how programs really work and make them do things they weren't designed to. Practical Malware Analysis & Pwn.college Nightmare
Pentesting Exploit vulnerabilities and navigate around an environment like an attacker, so that you can better defend. Penetration Testing, INE Penetration Testing Student TryHackMe & HackTheBox
Web App Exploitation Most of how you interact with the Internet is through web apps, so you should know how they can be broken. PortSwigger Web Security Academy

Matriz de assuntos

Assunto Por que estudar? Recursos Exercícios/CTF
Redes Entenda como os computadores se comunicam e como a Internet funciona. Computer Networking: A Top-Down Approach Malware Traffic Analysis
Sistemas Operacionais Este é o 'computador' na expressão 'segurança de computadores'. Nand2Tetris & Linux Journey & Windows Internals OverTheWire: Bandit
Programação Automatize tarefas e escreva suas próprias ferramentas, e consiga entender o que um programa faz mesmo sem dominar a linguagem. Harvard CS50 &
Automate the Boring Stuff w/Python
Tente criar suas próprias ferramentas!
Inteligência de Fonte Aberta POTENCIE tudo o que você faz sendo capaz de encontrar toda a informação necessária online. Open Source Intelligence Techniques & OSINTCurious Quiztime & SourcingGames
Criptografia É a base para confidencialidade, integridade e não repúdio (por exemplo, 'sem volta atrás') — ou seja, o que é essencial para a segurança. Online Cryptography Course CryptoHack
Forense Digital & Resposta a Incidentes Saiba impedir que coisas ruins aconteçam e descubra o que ocorreu. 13Cubed Videos & Incident Response and Computer Forensics CyberDefenders Labs
Análise de Malware & Engenharia Reversa Descubra como programas realmente funcionam e faça com que executem coisas para as quais não foram projetados. Practical Malware Analysis & Pwn.college Nightmare
Pentesting Explore vulnerabilidades e percorra um ambiente como um atacante, para poder defender melhor. Penetration Testing, INE Penetration Testing Student TryHackMe & HackTheBox
Exploração de Aplicações Web A maior parte da interação com a Internet acontece via apps web, por isso vale entender como eles podem ser quebrados. PortSwigger Web Security Academy

§ The most important skill

Being able to research effectively is the most important skill that a learner can have. No one knows everything, you will inevitably forget things, and as your knowledge/experience increases, you will inevitably need to research questions that do not have a straightforward answer.

Bottom line: If you know how to find the answer to a question, you know the answer to the question.

  • Google search operators allow you to look for data on specific sites, in specific formats (e.g. "webshell" site:github.com file:.aspx will return ASPX webshells on Github.com)
    • In particular, adding quotations (e.g. "reverse engineering malware") will search for an exact phrase, and prefixing a term with the minus sign (e.g. -worm) will exclude results with that term.
  • Typing the man or help command on Linux/Unix and Windows (respectively) before a command will give you more information on the arguments the command takes and how to use it.
  • If there is a specific domain you're interested in, Google awesome <topic> (e.g. 'awesome networking' or 'awesome osint'). This will bring up a lot of resources related to the topic you're interested in, typically in a Github repo.

If you have made a good faith effort to answer your question using available resources and still haven't found a satisfactory answer, it might be time to ask other people. This LiveOverflow Video goes over how to ask a technical question.

§ A habilidade mais importante

Ser capaz de pesquisar com eficácia é a habilidade mais importante que um aprendiz pode ter. Ninguém sabe tudo, você inevitavelmente esquece coisas e, à medida que seu conhecimento/experiência aumenta, inevitavelmente precisará pesquisar perguntas que não tenham uma resposta direta.

Resumo: Se você sabe como encontrar a resposta para uma pergunta, você sabe a resposta para a pergunta.

  • Operadores de pesquisa do Google permitem buscar dados em sites específicos e formatos específicos (por exemplo, "webshell" site:github.com file:.aspx trará webshells ASPX no Github.com)
    • Em particular, adicionar aspas (por exemplo, "reverse engineering malware") busca uma frase exata, e prefixar um termo com sinal de menos (por exemplo, -worm) exclui resultados que contenham esse termo.
  • Digitar o comando man no Linux/Unix ou o help no Windows antes de um comando traz mais informações sobre os argumentos e como usá-lo.
  • Se houver um domínio específico que você queira estudar, pesquise no Google awesome <topic> (por exemplo, 'awesome networking' ou 'awesome osint'). Isso mostra muitos recursos relacionados ao tema, normalmente hospedados em um repositório do Github.

Se você fez um esforço de boa-fé para responder à sua pergunta usando recursos disponíveis e ainda não encontrou uma resposta satisfatória, talvez seja hora de pedir ajuda a outras pessoas. Este vídeo do LiveOverflow explica como fazer uma pergunta técnica.

§ Networking

Networks facilitate communication between computers and understanding how they work is critical for nearly every other subject on this list.

Resources:

  • Computer Networking: A Top-Down Approach (Kurose, Ross) is a textbook that comes with (online/free) guided Wireshark Labs, PowerPoint slides, interactive knowledge checks/problems, and more recently, course videos. The supplementary website content can be used without the textbook.
  • Professor Messer's Network+ Videos cover a broad range of networking topics and is structured around the objectives of the Comptia Network+ exam. These videos can be helpful for a quick reference.
    • You can use certification guides as general subject study guides, without taking the exam (which costs money). A lot of IT certifications are glorified vocabulary tests that try to hit as many relevant points as possible, so they're excellent for rapidly understanding the basics.
      • A certification is an exam that tests knowledge in a specific area of IT. See the Jobs/Certifications section of the FAQ.
  • The Malware Traffic Analysis packet capture analysis exercises cover a range of different protocols, and includes solutions. Some of them are also available on the CyberDefenders CTF site.
  • Building a Homelab involves setting up and configuring an isolated environment to experiment with computing technology. You might set up an Active Directory forest to practice implementing Windows security controls, a set of sandboxes to test malware, or anything else you can think of. This is the most hands-on way to learn networking.

§ Redes

Redes facilitam a comunicação entre computadores, e entendê-las é fundamental para quase todos os outros tópicos desta lista.

Recursos:

  • Computer Networking: A Top-Down Approach (Kurose, Ross) é um livro que oferece laboratórios guiados de Wireshark (online/gratuitos), slides em PowerPoint, checagens interativas e, mais recentemente, vídeos do curso. O conteúdo suplementar do site pode ser usado sem o livro.
  • Professor Messer's Network+ Videos cobrem uma ampla gama de tópicos de redes e seguem os objetivos do exame Comptia Network+. Esses vídeos ajudam a revisar rapidamente os conceitos.
    • Você pode usar guias de certificação como estudos gerais da matéria, sem necessariamente fazer o exame (que custa dinheiro). Muitas certificações de TI são testes de vocabulário que abordam o máximo de pontos possíveis, então são excelentes para entender a base rapidamente.
      • Uma certificação é um exame que testa conhecimento em uma área específica de TI. Veja a seção Jobs/Certifications do FAQ.
  • Os exercícios de captura de pacotes do Malware Traffic Analysis cobrem vários protocolos diferentes e incluem soluções. Alguns deles também estão disponíveis no site do CyberDefenders CTF.
  • Montar um Homelab consiste em configurar um ambiente isolado para experimentar tecnologias de computação. Você pode instalar uma floresta Active Directory para praticar controles de segurança do Windows, um conjunto de sandboxes para testar malware ou qualquer outro cenário que imaginar. Esta é a forma mais prática de aprender redes.

§ Operating Systems

This is admittedly a large topic which consists of understanding the following, for both Windows and Linux operating systems:

  • System Administration - necessary in order to navigate around the operating system, understand concepts like file permissions, and potentially implement security controls.
  • Operating System fuctionality - important for understanding how programs (including malware) functions. You can probably get away with skipping learning this, but you will have a harder time grasping some concepts presented when you learn malware analysis / reverse engineering / digital forensics.

Like networking, learning how operating systems function is fundamental as the OS manages processes, memory, software, network connections, and hardware on the computer.

Resources for System Administration:

  • TryHackMe's Windows Fundamentals and Linux Fundamentals labs take students through interacting with file systems, users/groups, settings/configuration, and basic OS utilities. These labs/rooms are free, but note that you will need to make an account and need to set up OpenVPN or use TryHackMe's in-browser interface, which does have limitations.
    • For a completely in-browser (no setup needed) introduction to Linux functionality, try Linux Journey, which also has examples / exercises / built-in quizzes.
  • OverTheWire Bandit wargame teaches students to navigate and use basic functionality of a Linux system via ssh (secure shell network protocol).

Resources for OS functionality:

  • The Elements of Computing Systems (also called Nand2Tetris) takes students from building NAND logic gates to an assembler to programming a game (like Tetris) in a high-level language, giving you a pretty comprehensive understanding of how a computer works. It is project-centric, and there is also a 2-part Coursera course (free to audit) with video instruction.
  • Windows Internals - there are multiple versions and volumes of this book, which goes over how Windows and core operating system functionality works. Version 7, volume 1 is nearly 800 pages. If you want to go nuts, read/skim the entire thing, but it's most important to read the first chapter, Concepts and Tools, which outlines fundamental concepts of the Windows operating system.
    • Pavel Yusofovich, co-author of Windows Internals and a few other books on Windows has several courses covering Windows Internals on Pluralsight. Not free, but Pluralsight periodically has 'free weekend'/'free month' promotions. Worth mentioning.
    • For hands-on practice, consider Sam Bowne's Windows Internals CTF, which is periodically run in conjunction with Windows Internals workshops that Sam offers at different conferences. You can still submit and check your flags, and each set of flags is presented in a lab-style format (with instructions & screenshots).

§ Sistemas Operacionais

Este é um assunto bastante extenso, que exige entender o seguinte em ambos os sistemas Windows e Linux:

  • Administração de Sistema - necessária para navegar no sistema operacional, entender conceitos como permissões de arquivos e eventualmente implementar controles de segurança.
  • Funcionalidade do sistema operacional - importante para compreender como programas (incluindo malware) funcionam. Você pode até pular essa etapa, mas ficará com dificuldades para alguns conceitos quando estudar análise de malware/engenharia reversa/forense digital.

Assim como em redes, aprender como um sistema operacional funciona é essencial, pois ele gerencia processos, memória, software, conexões de rede e hardware.

Recursos para Administração de Sistema:

  • Os laboratórios Windows Fundamentals e Linux Fundamentals do TryHackMe guiam estudantes na interação com sistemas de arquivos, usuários/grupos, configurações e utilitários básicos. Esses labs/salas são gratuitos, mas é preciso criar uma conta e configurar o OpenVPN ou usar a interface do navegador do TryHackMe, que tem limitações.
    • Para uma introdução totalmente no navegador (sem precisar configurar nada), experimente o Linux Journey, que também traz exemplos, exercícios e quizzes embutidos.
  • O wargame Bandit do OverTheWire ensina como navegar e usar funcionalidades básicas de um sistema Linux via ssh (protocolo de shell seguro).
    • Você pode usar ssh pelo Windows Terminal, pelo Windows Subsystem for Linux (WSL) ou por uma máquina virtual.

Recursos para funcionalidade do sistema operacional:

  • The Elements of Computing Systems (também chamado de Nand2Tetris) leva estudantes a construir portas lógicas NAND, depois um montador e, por fim, programar um jogo (como Tetris) em uma linguagem de alto nível, dando uma visão completa de como um computador funciona. O curso é baseado em projetos, e há também um curso em duas partes no Coursera (gratuito para auditar) com instruções em vídeo.
  • Windows Internals - existem várias versões e volumes deste livro, que explica como o Windows e funcionalidades centrais do sistema operacional trabalham. A versão 7, volume 1 tem quase 800 páginas. Se quiser mergulhar, leia/folheie tudo, mas o mais importante é absorver o primeiro capítulo, Concepts and Tools, que descreve os conceitos fundamentais do Windows.
    • O coautor Pavel Yusofovich, além de outros livros, tem diversos cursos sobre Windows Internals no Pluralsight. Não é gratuito, mas o Pluralsight costuma oferecer fins de semana/meses grátis periodicamente.
    • Para praticar na prática, considere o Windows Internals CTF do Sam Bowne, aplicado junto a workshops do autor em conferências. Ainda é possível enviar e conferir as flags, e cada conjunto segue um formato de laboratório com instruções e capturas de tela.

§ Programming

If there is a particular language you'd like to learn, go for it! However, Python is generally viewed as the best programming language for beginners to learn, as it is:

  • high level, meaning that it is more abstracted from machine code and is more readable.
  • versatile, and used for a wide range of subjects (including infosec). Many tools and scripts relevant to infosec are written in Python.
  • widely supported - there are a ton of different online platforms that teach beginners how to Python, and abundant documentation.

In particular with programming, focus on understanding how to program with sockets, and make network connections with your scripts. Check out modules like Impacket and try using them in your scripts.

Resources:

  • Harvard's CS50 OpenCourseWare (free online course) takes students through fundamental computer science and programming concepts using multiple languages. It incorporates projects and is also available as an EdX MOOC course.
  • Automate the Boring Stuff with Python is a (free) book that focuses on practical, hands-on scripting. Of particular interest is the Web Scraping chapter.

The C/C++ programming language is also recommended for beginners after Python, and is "lower-level", and are less abstracted from machine code compared to Python. In C, programmers directly interact with low-level infrastructure like memory and buffers. This makes C more challenging to learn. An understanding of C will be helpful if you want to do disassembly / reverse engineering, or otherwise have a better grasp on reading and understanding programs and how they interact with the operating system.

§ Programação

Se houver uma linguagem específica que você queira aprender, vá em frente! No entanto, o Python costuma ser visto como o melhor ponto de partida para iniciantes, pois é:

  • de alto nível, o que significa que é mais abstrato do código de máquina e mais legível.
  • versátil, sendo usado em uma variedade de assuntos (inclusive infosec). Muitas ferramentas e scripts relevantes para segurança são escritos em Python.
  • amplamente suportado - há muitos cursos online e documentação abundante para quem começa com Python.

No âmbito da programação, foque em entender como programar usando sockets e estabelecer conexões de rede nos seus scripts. Veja módulos como Impacket e tente usá-los nos seus scripts.

Recursos:

  • Harvard's CS50 OpenCourseWare (curso online gratuito) leva estudantes por conceitos fundamentais de ciência da computação e programação usando múltiplas linguagens. Ele inclui projetos e também está disponível como um curso EdX.
  • Automate the Boring Stuff with Python é um livro gratuito focado em scripts práticos. O capítulo sobre Web Scraping merece atenção especial.

A linguagem C/C++ também é recomendada para iniciantes após o Python, pois é "mais próxima do metal" e menos abstrata em relação ao código de máquina. Em C, programadores interagem diretamente com estruturas de baixo nível, como memória e buffers. Isso torna o C mais desafiador. Entender C ajuda se você quiser fazer desmontagem/engenharia reversa ou melhorar a leitura e compreensão de programas e sua interação com o sistema operacional.

  • A série de vídeos Cherno C++ oferece um tutorial completo, mas use o recurso/plataforma de sua preferência.

§ Open Source Intelligence (OSINT)

OSINT refers to collection and analysis of publicly available information, generally available on different parts of the Internet. Within the context of infosec, OSINT is used across multiple domains: incident responders may use it to identify the type of flaw exploited in a system, malware analysts may research domains and code snippets in an effort to attribute malware, and so on. Unlike other domains, the resources for OSINT are somewhat scattered because there are so many types of OSINT, which extends beyond the scope of research specific to infosec.

Resources:

Tool Collections:

Hands-On Practice:

  • Image/geolocation OSINT: Try Quiztime challenges on Twitter, which involves answering questions about an image or video after researching the origin/context.
  • People OSINT: Try a TraceLabs Search Party CTF, where participants research missing persons cases and gather information that can be used by law enforcement. The Contestants Guide provides an overview, and includes link(s) to writeups on past CTFs. These CTFs are synchronous.
    • Tracelabs also has active cases posted to their Slack/Trello, but are undergoing some organizational changes right now and are currently unavailable. These cases are not tied to a CTF and just exist for the community to work on collectively.
  • Sourcing Games are a large set of CTFs originally created for recruiters/"sourcers." There is a good mix of challenges besides 'people'-oriented challenges.

§ Inteligência de Fonte Aberta (OSINT)

OSINT refere-se à coleta e análise de informações disponíveis publicamente, geralmente espalhadas por diferentes partes da Internet. No contexto de infosec, o OSINT é aplicado em vários domínios: respondentes de incidentes podem usá-lo para identificar o tipo de vulnerabilidade explorada em um sistema, analistas de malware pesquisam domínios e trechos de código para atribuir ameaças, e assim por diante. Ao contrário de outros domínios, os recursos de OSINT são mais dispersos porque existem muitos tipos, indo além da pesquisa típica em segurança.

Recursos:

Coleções de ferramentas:

Prática guiada:

  • OSINT de imagem/geolocalização: experimente os desafios Quiztime no Twitter, que exigem responder perguntas sobre uma imagem ou vídeo após pesquisar a origem/contexto.
  • OSINT de pessoas: participe de um TraceLabs Search Party CTF, em que competidores pesquisam casos de pessoas desaparecidas e coletam informações úteis para autoridades. O Contestants Guide oferece visão geral e links para writeups anteriores. Esses CTFs são síncronos.
    • A TraceLabs também publica casos ativos no Slack/Trello, mas atualmente passam por mudanças organizacionais e estão indisponíveis. Esses casos não fazem parte de um CTF e existem para a comunidade colaborar colectivamente.
  • Sourcing Games reúne diversos CTFs criados originalmente para recrutadores/"sourcers". Há uma boa mistura de desafios além dos focados em pessoas.

§ Cryptography

Cryptography is built around mathematical problems/concepts. If you don't have a strong foundation in math, consider reading / skimming Mathematics for Computer Science, a free MIT OpenCourseWare textbook that has an accompanying online course. Reading through the Number Theory section is recommended for Cryptography, specifically.

Resources:

  • Dan Boneh's Online Cryptography Course provides an amazing overview of cryptography and includes videos and a free textbook (which comes with proofs and homework exercises). You can also take the course on the Coursera MOOC platform.
  • CryptoHack is an online CTF platform focused around learning cryptography, focusing on "breaking bad implementations of "modern" crypto, such as AES, RSA, and Elliptic-curve" in an accessible way. Knowledge of a programming language (especially Python) is highly recommended. Some of the problems, like the 'Crypto on the Web' problems are very practical.
    • Cryptopals is less gamified than CryptoHack, and has students program their solutions for each challenge from the ground-up in any language of their choosing.

§ Criptografia

A criptografia é baseada em problemas/conceitos matemáticos. Se você não tem uma base forte em matemática, considere ler/folhear Mathematics for Computer Science, um livro gratuito do MIT OpenCourseWare que possui um curso online complementar. É recomendável ler a seção de Teoria dos Números para criptografia.

Recursos:

  • Curso Online de Criptografia do Dan Boneh oferece uma visão incrível da criptografia, com vídeos e um livro-texto gratuito (com demonstrações e exercícios). Você também pode fazer o curso no Coursera.
  • CryptoHack é uma plataforma de CTF online dedicada ao aprendizado de criptografia, focando em "quebrar implementações ruins de criptografia 'moderna', como AES, RSA e curvas elípticas" de forma acessível. Conhecer uma linguagem de programação (especialmente Python) é altamente recomendado. Alguns desafios, como os 'Crypto on the Web', são muito práticos.
    • Cryptopals é menos gamificada que o CryptoHack e exige que os estudantes programem as soluções para cada desafio do zero, em qualquer linguagem.

§ Digital Forensics & Incident Response (DFIR)

Incident response involves immediate triage and response to a security incident (e.g. 'stopping the bleeding') whereas forensics typically involves retroactively 'stepping through' data in order to develop a comprehensive picture of what happened. These two fields are intertwined (and malware analysis may also be part of this), hence we are presenting them together.

Resources:

  • 13Cubed's Windows Forensics YouTube videos cover fundamental Windows forensics artifacts and concepts (like MACB timestamps) in a way that is easy to understand, with usage of modern tools provided as examples. These videos are also up-to-date, and relevant.
    • 13Cubed (Richard Davis) also has other videos on memory forensics, and other DFIR topics. Probably the best collection of video resources on forensics.
  • Incident Response and Computer Forensics (Luttgens, Pepe, Mandia) concisely and directly explains phases of the incident response lifecycle (preparation to post-remediation), gives an overview of forensic data collection techniques, and an overview of network and host-based forensic artifacts. It also presents case studies, which provides context on why certain actions are important. While this book was published in 2014, the fundamental concepts present - particularly, how to approach each phase of an incident - are still relevant.
  • The Art of Memory Forensics (Ligh, Case, Levy, Walters) explains Windows, Linux, and MacOS memory forensics in depth, and utilizes the open-source Volatility (version 2) memory forensics framework. Labs and supplementary materials can downloaded from the book's website. Note that Volatility was completely rewritten (and is now much faster) and released as Volatility 3 in 2019.
  • File System Forensic Analysis (Carrier) walks through a wide range of different file systems and strategies for analyzing file metadata and recovering deleted files. This book was published in 2005, but a lot of the material presented is still relevant. Resources like the Forensics Wiki can be used as a reference for newer file systems like ReFS.
  • The DFIR.Training site is an excellent reference for many DFIR topics, and has a section that allows for filtering/searching different artifacts.
  • The CyberDefenders Labs site has collected a lot of forensics challenges/images onto 1 platform, which is more accessible than accessing each challenge individually.
    • Boss of the Soc (BOTS) is a team-based Splunk SIEM (Security Information and Event Management) CTF which challenges students to answer questions about realistic security incidents, and is of particular interest.

If you are doing DFIR, depending on the size of your organization, you may also be interested in Cyber Threat Intelligence (CTI). Intelligence-Drive Incident Response (Roberts, Brown) explains different CTI cycles/models and how they can be implemented into the incident response process.

§ Forense Digital e Resposta a Incidentes (DFIR)

A resposta a incidentes envolve o próprio triagem e resposta imediata a um incidente de segurança (por exemplo, 'estancar o sangramento'), enquanto a forense geralmente envolve 'percorrer' dados retroativamente para montar uma visão completa do que ocorreu. Esses dois campos estão entrelaçados (e a análise de malware pode fazer parte disso), por isso os apresentamos juntos.

Recursos:

  • Vídeos do 13Cubed sobre Forense no Windows abordam artefatos e conceitos fundamentais de forense no Windows (como timestamps MACB) de maneira didática, mostrando ferramentas modernas como exemplo. Os vídeos também estão atualizados.
  • Incident Response and Computer Forensics (Luttgens, Pepe, Mandia) explica de forma direta as fases do ciclo de vida da resposta a incidentes (preparação até pós-remediação), fornece visão geral de técnicas de coleta forense e artefatos de rede/hosts. Também apresenta estudos de caso, o que ajuda a entender por que certas ações são importantes. Apesar de ter sido publicado em 2014, os conceitos fundamentais — especialmente como abordar cada fase — continuam relevantes.
  • The Art of Memory Forensics (Ligh, Case, Levy, Walters) explica com profundidade a forense de memória no Windows, Linux e MacOS, utilizando o framework Volatility (versão 2). Laboratórios e materiais complementares podem ser baixados do site do livro. Note que o Volatility foi reescrito (agora bem mais rápido) e lançado como Volatility 3 em 2019.
  • File System Forensic Analysis (Carrier) percorre diversos sistemas de arquivos e estratégias para analisar metadados e recuperar arquivos excluídos. Embora o livro tenha sido publicado em 2005, muito do conteúdo continua relevante. Recursos como o Forensics Wiki servem de referência para sistemas mais recentes, como o ReFS.
  • O site DFIR.Training é uma excelente referência para muitos tópicos de DFIR e possui uma seção para filtrar/pesquisar diferentes artefatos.
  • O site CyberDefenders Labs reuniu diversos desafios/imagens de forense em uma única plataforma, facilitando o acesso.
    • Boss of the Soc (BOTS) é um CTF em equipe baseado em Splunk SIEM (Security Information and Event Management) que desafia estudantes a responder perguntas sobre incidentes reais e merece atenção.

Se você trabalha com DFIR, dependendo do porte da organização, pode se interessar também por Inteligência sobre Ameaças (CTI). Intelligence-Driven Incident Response (Roberts, Brown) explica diferentes ciclos/modelos de CTI e como integrá-los ao processo de resposta a incidentes.

§ Malware Analysis & Reverse Engineering (RE)

A prerequisite for malware analysis and RE is setting up an environment where you can safely detonate and analyze malware, and reset the environment back to 'normal' once you're done. This is generally done through the use of virtual machines (VMs), which are essentially emulated computers that you can run from your own machine (host OS) or the cloud (You can also use Docker containers). FireEye's FLARE VM is a Windows 10 environment that comes with a ton of preinstalled tools for both dynamic and static analysis. Note that you will need a Windows 10 ISO for it. REMnux is a Linux-based toolkit for malware analysis, and is especially helpful for analyzing malicious documents (maldocs).

When disassembling a sample, the disassembler will display machine language in Assembly language format, hence it will also be helpful to learn Assembly language (like x86), particularly for RE / binary exploitation. UoV's x86 Assembly Guide offers a straightforward overview.

Resources:

  • Practical Malware Analysis is a book that takes students through the basics of static and dynamic analysis, basic disassembly, and malware functionality. Each chapter has a set of labs which are downloadable via the book website.
    • The amazing Sam Bowne periodically hosts an online PMA course (using the textbook and going through the projects) which he graciously allows any student to audit online for free. Check his website to see if he's teaching it soon, or use the videos/lecture notes from a previous iteration.
    • Malware Analysis and Detection Engineering (Mohanta, Saldanha) provides a more gradual introduction to malware analysis (including chapters on Windows Internals, for instance) and has newer examples, but it is less widely available compared to PMA.
  • Pwn.college is an online course that takes students through program functionality, Assembly, debugging and reverse engineering. Each module has videos and practice problems.
  • Nightmare is an online course focused around CTF challenges to teach different RE concepts. Each challenge has a writeup and can be 'solved' using open-source (free) tools. Some of the writeups are high-level and help explain what is happening.

Resources for Researching Malware:

  • Malpedia is pretty invaluable for tracking malware and associated threat actor groups. The site acts as an aggregator for information on different groups and malware families, providing easy access to high quality information on a specific type of malware you're trying to research.
  • ThreatFox IoC Database is constantly being updated with indicators of compromise (e.g. hashes, domain names, IP addresses, etc) for malware samples. Search by IoC, tag, or malware family. Also helpful for triaging incidents from a DFIR perspective.

For a more detailed discussion of resources for RE & malware analysis (including specific recommendations for learning about different types of malware techniques), see Hasherezade's How to start guide.

§ Análise de Malware e Engenharia Reversa (RE)

Um pré-requisito para análise de malware e RE é montar um ambiente onde você possa detonar e analisar malware com segurança, e depois voltar ao estado 'normal'. Isso geralmente é feito com máquinas virtuais (VMs), que emulam computadores que podem ser executados no seu host ou na nuvem (também é possível usar containers Docker). FireEye's FLARE VM é um ambiente Windows 10 com várias ferramentas pré-instaladas para análise dinâmica e estática. Você precisará de uma ISO do Windows 10. REMnux é um conjunto baseado em Linux para análise de malware, especialmente útil para documentos maliciosos (maldocs).

Ao desmontar uma amostra, o disassembler mostrará linguagem de máquina em formato Assembly, então também vale aprender Assembly (como x86), especialmente para RE/binary exploitation. O Guia de Assembly x86 da UoV apresenta uma visão direta.

Recursos:

  • Practical Malware Analysis acompanha estudantes pelos fundamentos de análise estática/dinâmica, disassembly básico e funcionalidade de malware. Cada capítulo tem labs que podem ser baixados via o site do livro.
    • O incrível Sam Bowne ministra periodicamente um curso online de PMA (com o livro e os projetos), que ele permite auditar gratuitamente. Veja se haverá uma nova turma ou use os vídeos/anotações de uma edição anterior.
    • Malware Analysis and Detection Engineering (Mohanta, Saldanha) oferece uma introdução mais gradual à análise de malware (incluindo capítulos sobre Windows Internals) e tem exemplos mais recentes, mas é menos difundido que o PMA.
  • Pwn.college é um curso online que aborda funcionalidade de programas, Assembly, debugging e engenharia reversa. Cada módulo conta com vídeos e exercícios práticos.
  • Nightmare é um curso online baseado em desafios de CTF que ensina conceitos de RE. Cada desafio tem um writeup e pode ser 'resolvido' com ferramentas open-source. Alguns writeups são de alto nível e ajudam a entender o que está acontecendo.

Recursos para pesquisar malware:

  • Malpedia é valiosa para rastrear malware e grupos associados. O site agrega informações sobre famílias e grupos, facilitando o acesso a dados de alta qualidade sobre o tipo de malware que você está pesquisando.
  • ThreatFox IoC Database é constantemente atualizado com indicadores de comprometimento (hashes, domínios, IPs, etc.) para amostras de malware. Busque por IoC, tag ou família de malware. Também é útil para triagem de incidentes sob a ótica do DFIR.

Para uma discussão mais detalhada sobre recursos de RE e análise de malware (incluindo recomendações específicas para aprender diferentes técnicas), veja o guia How to start da Hasherezade.

§ Pentesting

Penetration testing involves finding and exploiting vulnerabilities across an organization's computer infrastructure, which includes networks, operating systems, identity infrastructure like Active Directory, and applications/services. Emulating the different steps that an attacker can take as they move through a system is helpful for understanding how to defend against malicious activity.

Resources:

  • Penetration Testing (Weidman) walks students through setting up their exploitation environment and different phases of the attack lifecycle, including exploit development. Weidman has a YouTube Playlist with walkthrough videos to complement chapters of the book. While this book was published in 2014, the underlying concepts presented are still relevant.
    • Note: Weidman is currently working on an updated version of this book per information posted to their Twitter account.
  • INE/ELearnSecurity's Penetration Testing Student course takes student through prerequisite knowledge - including networking and programming fundamentals - before discussing different exploitation techniques. If you are looking to get started with exploitation right away, this is a good resource.
    • Note: The course can be taken for free with the INE Starter Pass, though you will only have access to the course content (and not the labs). This course is used to prepare for the eJPT, which you can skip.
  • HackTricks is an extensive collection of techniques across multiple areas of exploitation, and is a great reference for CTFs.

To practice penetration testing techniques, try exploiting some hosts on a CTF platform like TryHackMe or HackTheBox.

§ Pentesting

Testes de invasão envolvem identificar e explorar vulnerabilidades na infraestrutura de uma organização, incluindo redes, sistemas operacionais, infraestrutura de identidade como Active Directory e aplicações/serviços. Emular as etapas que um atacante pode seguir ajuda a entender como defender melhor contra ameaças.

Recursos:

  • Penetration Testing (Weidman) guia estudantes na configuração do ambiente e nas fases do ciclo de ataque, incluindo desenvolvimento de exploits. O Weidman mantém uma playlist no YouTube com vídeos complementares aos capítulos. Embora tenha sido publicado em 2014, os conceitos continuam atuais.
    • Nota: o autor está trabalhando em uma versão atualizada do livro, conforme divulgado no Twitter.
  • O curso Penetration Testing Student da INE/ELearnSecurity leva os estudantes pelos conhecimentos pré-requisitos - incluindo redes e programação - antes de cobrir técnicas de exploração avançadas. Se você quer começar a explorar logo, é um bom recurso.
    • Nota: o curso pode ser feito gratuitamente com o INE Starter Pass, mas você só terá acesso ao conteúdo (sem os labs). O curso prepara para o eJPT, que pode ser ignorado.
  • HackTricks é uma coleção extensa de técnicas em diferentes áreas de exploração e um ótimo material de referência para CTFs.

Para praticar técnicas de pentest, experimente explorar hosts em plataformas de CTF como TryHackMe ou HackTheBox.

§ Web App Exploitation

Web apps represent a major part of how people interact with computers and the Internet on a day-to-day basis. Exploitation of them involves understanding different types of flaws in authentication/authorization and the way data is stored.

  • Penetration testing encompasses this, but we are including it as a distinct section because many newcomers are specifically interested in studying web app exploitation so that they can pursue bug bounties.

Resources:

  • The OWASP Top 10 represents the most widespread / common web application vulnerabilities and is a standard for web application security. Click the hamburger menu (≡) > Top 10:2021 List to navigate to different pages explaining each vulnerability.
  • PortSwigger Web Security Academy is a free self-guided set of labs/guides that explains web application vulnerabilies, providing hands-on labs for exploitation using the Burp Suite Framework. PortSwigger Academy was developed by the group behind the Web Application Hacker's Handbook and is updated as a living reference. Note that for some labs, using the Burp Suite Professional (not free) is advised - you can skip these labs or complete (some of) them with Burp Suite Community (free) Edition (which is admittedly a bit harder).

§ Exploração de Aplicações Web

Aplicações web representam a maior parte da interação das pessoas com computadores e a Internet no dia a dia. Explorá-las exige entender diferentes tipos de falhas em autenticação/autorização e no modo como dados são armazenados.

  • Testes de invasão cobrem esse domínio, mas o incluímos separadamente porque muitos iniciantes buscam estudar exploração web com foco em bug bounties.

Recursos:

  • O OWASP Top 10 representa as vulnerabilidades mais comuns em aplicações web e é um padrão de segurança. Clique no menu (≡) > Top 10:2021 List para navegar pelas páginas de cada vulnerabilidade.
  • PortSwigger Web Security Academy oferece laboratórios/guias gratuitos guiados que explicam vulnerabilidades em aplicações web, com labs práticos usando a suíte Burp. A Academy foi criada pelo mesmo grupo do Web Application Hacker's Handbook e é atualizada constantemente. Note que alguns labs recomendam o Burp Suite Professional (pago); você pode pular esses labs ou concluí-los parcialmente com o Burp Suite Community (gratuito), que é um pouco mais difícil.

§ FAQ

§ What computer / operating system / tools do I need to get started?

Use what you have. You don't need any specific hardware or operating system to learn. This includes Kali or Parrot Linux, two penetration testing-focused Linux distributions.

It will be helpful to have some sort of Linux command line interface from which you can install and run tools.

  • If you are on MacOS or a Linux distribution, awesome! Use your installation manager of choice and plonk away.
  • If you are on Windows, you may consider installing a virtual machine, or using Windows Subsystem for Linux (WSL).

§ What if I want something that will give me a bit of everything?

  • SANS Cyber Aces goes over just the fundamentals. There are several hours of content here.
  • Professor Messer's Security+ course videos are structured around objectives for the Security+ certification exam, so referring to the videos provides a good way to hit a lot of different points. Warning: there are ~21 hours worth of video content.
  • SOC Core Skills with John Strand is a 16-hour (4 days x 4 hours) live/synchronous course with hands-on labs offered periodically through Black Hills Information Security Antisyphon. It is pay what you can and seems to be offered every 4-5 months.
  • TryHackMe's Learning Paths offer a more structured exploration of infosec topics through CTF 'rooms', which contain instruction and hands-on exercises. Note that some of the rooms require a subscription, but most are free. You can also choose rooms individually to explore via the search tab.
    • HackTheBox Academy also provides an instruction & exercise-based introduction on the HackTheBox CTF platform, with some of the introductory 'modules' being free, and others that need to be unlocked based on 'cubes' earned from completion of exercises or purchased as part of the subscription model or 1-time payment.

§ How do I get a job in infosec? What certifications do I get?

Ultimately, when you apply for a job, you are selling a story of what you did, who you are, and what you bring. In IT, employers care about many things, but these components can generally be broken down into 3 parts:

  • Experience - the most important, this not only includes job/internship experience, but also personal projects like your homelab, or that blog post explaining some malware you analyzed, or the bot you wrote. It also includes volunteer experience, participation in CTFs, as well as community involvement.
  • Education - for some orgs, this is a hard requirement. Studying Computer Science is one good option, as the curriculum is relevant to most areas of IT and you will develop strong foundations for how computers work. You can also do a cybersecurity program, but be sure to scrutinize the curriculum to ensure that you will be exposed to low-level (e.g. technical) concepts that are more hands-on than abstracted, or theoretical.
    • That said, not having a CS (or STEM) degree is still very valuable - you just need to identify how and fold that into your story. For example, studying philosophy may mean that you are very good at dissecting and analyzing problems. Figure out how what you have studied makes you awesome, and be able to talk about it.
  • Certifications - certs show that you passed a test, and can augment your experience as physical proof that you have knowledge in an area. Certs are valuable depending on your desired position and local job market, so do research using job boards to see which certs are in demand.
    • Paul Jerimy's interactive Security Certification Roadmap groups security certifications by area of focus, with more advanced certifications towards the top. Hover over a cert name for more information (including costs).
    • Some certifications are exorbitantly expensive, because they're priced for employers, not for individuals.

While having all 3 of these points is ideal, you can get a job with just 2, or 1 (but it will be more difficult). If you identify that you can't do 1 of the 3 points, supplement by doing more of what is feasible for you.

Recommended Resources:

  • /r/ITCareerQuestions Wiki is not specific to security, but answers a lot of common questions regarding IT jobs and generally gives good advice for getting into IT.
  • Black Hills Infosec's 5 Year Plan into Infosec provides an outline on how to establish and progress your learning over 5 years of your career.
  • Daniel Miessler's Build a Successful Infosec Career explains how to get yourself into the field, what to study, what certs you can get, and how to progress long-term.

§ How do I stay up-to-date on infosec topics?

If you generally want to stay informed, here are a few options:

  • Join local (or remote) meetup or interest groups. Some popular groups which may have chapters near you include: 2600, DEFCON, OWASP, ISACA.
  • Twitter - follow different tags and groups of users and then use Tweetdeck to get a good view of things happening day-to-day.
  • Email aggregation feeds/lists - Personal suggestions: I'm subscribed to the following email newsletters: SANS NewsBites (semiweekly summary of infosec news articles, with commentary from different subject matter experts) and Daniel Miessler's Unsupervised Learning newsletter which also has a podcast.
  • Set up some sort of feed, be it an RSS feed using Feedly or a Discord server with a feed produced via the SocialFeeds bot.
    • YCombinator's Hacker News aggregates news articles and blog posts relevant more generally to technology and computer science. HNRSS provides several RSS feeds for it.

§ What is a CTF?

Per the Trail of Bits CTF Field Guide, Capture the Flag competitions "distill major disciplines of professional computer security work into short, objectively measurable exercises. The focus areas that CTF competitions tend to measure are vulnerability discovery, exploit creation, toolkit creation, and operational tradecraft."

CTFs are generally grouped into 2 categories:

  • jeopardy style, consisting of individual challenges focused on different domains of infosec, such as forensics, binary exploitation, OSINT, IoT, etc.
  • attack/defense, where each team has vulnerable services/computers that they need to configure/defend, while also attacking other teams' resources.

Here are some good asynchronous CTFs for starting out:

  • OverTheWire Wargames are SSH/shell-based, have cute themes, and cover topics from the absolute basics of using Linux utilities to web security to exploitation techniques.
  • PicoCTF is a beginner 'jeopardy-style' CTF that assumes no knowledge. If you are in middle or high school in the US, you can also win prizes. Available as a synchronous (e.g. time-limited) CTF and retroactively for play.
  • TryHackMe is platform for learning security with 'rooms', which are either challenge-oriented (where you need to obtain flags with almost no instruction) or tutorial-oriented (instruction-heavy).
    • HackTheBox is similar, but almost entirely focused around exploiting virtual machine 'boxes', and is less tutorial-oriented.
  • The CyberDefenders CTF platform collects multiple blue team-oriented CTFs (e.g. OSINT, log/pcap analysis, maldoc analysis, memory/forensic analysis) in one place. You can search for a 'writeup' if you get stuck.

If you want to do a live / synchronous CTF that is more time-restricted, check out CTF Time.

§ FAQ

§ Qual computador / sistema operacional / ferramentas eu preciso para começar?

Use o que você tem. Você não precisa de hardware ou sistema operacional específicos para aprender. Isso inclui Kali ou Parrot Linux, duas distribuições focadas em pentesting.

É útil ter algum terminal Linux para instalar e rodar ferramentas.

  • Se você usa MacOS ou Linux, ótimo! Use seu gerenciador de pacotes favorito e mãos à obra.
  • Se você usa Windows, considere instalar uma máquina virtual ou usar o Windows Subsystem for Linux (WSL).

§ E se eu quiser algo que aborde um pouco de tudo?

  • SANS Cyber Aces cobre apenas o básico. Há várias horas de conteúdo.
  • Vídeos do Security+ do Professor Messer são estruturados em torno das metas do exame Security+, portanto são uma boa forma de revisar diversos tópicos. Aviso: são ~21 horas de conteúdo.
  • SOC Core Skills com John Strand é um curso ao vivo/síncrono de 16 horas (4 dias x 4 horas) com labs práticos oferecido periodicamente pela Black Hills Information Security Antisyphon. É pague quanto puder e costuma acontecer a cada 4-5 meses.
  • Learning Paths do TryHackMe oferecem uma exploração estruturada de tópicos de infosec por meio de 'rooms' de CTF, com instrução e exercícios práticos. Note que alguns rooms exigem assinatura, mas a maioria é gratuita. É possível explorar salas individualmente pela aba de busca.
    • HackTheBox Academy também traz uma introdução com instrução/exercício na plataforma HackTheBox, com alguns módulos introdutórios gratuitos e outros desbloqueados via 'cubos' ganhos em exercícios ou adquiridos na assinatura ou compra única.

§ Como eu arrumo um emprego em infosec? Quais certificações eu faço?

Ao disputar uma vaga, você está vendendo uma história sobre o que fez, quem é e o que entrega. No TI, empregadores valorizam várias coisas, mas elas podem ser divididas em três partes:

  • Experiência - a mais importante. Inclui empregos/estágios, projetos pessoais como homelab, posts explicando malwares analisados ou bots que você escreveu. Também engloba voluntariado, participação em CTFs e envolvimento em comunidades.
  • Educação - para algumas organizações, é exigência. Estudar Ciência da Computação é uma boa opção, pois o currículo cobre muitas áreas de TI e desenvolve bases sólidas de como computadores funcionam. Você também pode cursar algo em cibersegurança, mas confira o conteúdo para garantir exposição a conceitos técnicos e de baixo nível, mais práticos que teóricos.
    • A ausência de um diploma em CS (ou STEM) não desvaloriza você — basta identificar como isso contribui para sua história. Por exemplo, estudar filosofia pode significar que você é excelente em dissecar e analisar problemas. Mostre como sua formação te torna ótimo e saiba falar sobre isso.
  • Certificações - mostram que você passou em um exame e aumentam a credibilidade da sua experiência. Valem de acordo com o cargo desejado e o mercado local, então pesquise vagas para saber quais certificações estão em alta.
    • O Security Certification Roadmap interativo do Paul Jerimy agrupa certificações por foco, com as mais avançadas no topo. Passe o cursor sobre um nome para ver mais informações (inclusive custos).
    • Algumas certificações são caríssimas porque são precificadas para empresas, não para indivíduos.

Idealmente você teria os três pontos, mas você pode conseguir uma vaga com apenas 2 ou até 1 (embora fique mais difícil). Se não conseguir cobrir um dos três, complemente fortalecendo o que for possível.

Recursos recomendados:

§ Como me mantenho atualizado sobre infosec?

Se você quer se manter informado, aqui vão algumas opções:

  • Participe de meetups ou grupos locais/remotos. Alguns populares com capítulos espalhados são: 2600, DEFCON, OWASP, ISACA.
  • Twitter - siga hashtags e grupos de usuários, e use o Tweetdeck para visualizar o que acontece diariamente.
  • Listas/feeds de e-mail - sugestões pessoais: eu assino o SANS NewsBites (resumo semanário de notícias com comentários de especialistas) e o newsletter Unsupervised Learning do Daniel Miessler, que também tem um podcast.
  • Configure um feed, como RSS usando o Feedly, ou um servidor Discord com um feed via o bot SocialFeeds.
    • O Hacker News, da YCombinator, agrega artigos e posts sobre tecnologia e ciência da computação. O HNRSS oferece vários feeds RSS.

§ O que é um CTF?

Segundo o Trail of Bits CTF Field Guide, Capture the Flag "destila grandes disciplinas do trabalho profissional em segurança em exercícios curtos e objetivamente mensuráveis. Os focos medidos por CTFs incluem descoberta de vulnerabilidades, criação de exploits, construção de ferramentas e tradecraft operacional."

CTFs geralmente se dividem em duas categorias:

  • estilo jeopardy, composto por desafios individuais de domínios como forense, exploração binária, OSINT, IoT, etc.
  • ataque/defesa, em que cada equipe tem serviços/computadores vulneráveis para configurar/defender enquanto ataca os recursos dos outros times.

Boas CTFs assíncronas para começar:

  • OverTheWire Wargames são baseados em SSH/shell, têm temas divertidos e cobrem dos conceitos mais básicos de utilitários Linux até segurança web e técnicas de exploração.
  • PicoCTF é um CTF 'jeopardy-style' para iniciantes que assume nenhum conhecimento prévio. Se você estiver no ensino fundamental/médio nos EUA, pode ganhar prêmios. Disponível como CTF síncrono (com tempo limitado) e também retroativamente.
  • TryHackMe é uma plataforma para aprender segurança com 'rooms', que podem ser orientados a desafios (onde é preciso obter flags sem muita instrução) ou tutoriais (com muita explicação).
    • HackTheBox é similar, mas focado quase exclusivamente em explorar máquinas virtuais 'boxes' e é menos tutorial.
  • A plataforma CyberDefenders CTF reúne múltiplos CTFs orientados a blue team (por exemplo, OSINT, análise de logs/pcap, análise de maldocs, forense de memória) em um só lugar. É possível buscar writeups caso fique preso.

Se quiser fazer um CTF ao vivo/síncrono e com tempo limitado, visite CTF Time.