Skip to content

Enhanced project with new sections and updated resources#55

Open
morningstarxcdcode wants to merge 1 commit into
brootware:mainfrom
morningstarxcdcode:project-enhancements
Open

Enhanced project with new sections and updated resources#55
morningstarxcdcode wants to merge 1 commit into
brootware:mainfrom
morningstarxcdcode:project-enhancements

Conversation

@morningstarxcdcode
Copy link
Copy Markdown

just added several and new curated learning paths and resources to the README.md, focusing on Purple Teaming, Cloud Security, and Mobile Security. These additions provide structured, free educational materials for beginners and intermediate learners in these areas.

New learning paths and resources also with link :

Purple Team Path:

  • Introduced a two-level learning path covering foundational concepts and practical emulation/detection tools for purple teaming.

Cloud Security:

  • Added a three-level cloud security path, including fundamentals, security-specific courses for AWS/Azure/GCP, and hands-on vulnerable cloud environments.

Mobile Security:

  • Added a three-level mobile security path, covering general fundamentals, Android, and iOS security, with both educational content and intentionally vulnerable apps for practice.

Copy link
Copy Markdown
Owner

@brootware brootware left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please see my feedback for reviews

Comment thread README.md

* [Introduction to Purple Teaming](<https://tryhackme.com/room/introductiontopurpleteaming>) - Learn the fundamentals of purple teaming.
* [Threat-Informed Defense](<https://academy.attackiq.com/courses/threat-informed-defense>) - A free course on threat-informed defense from AttackIQ Academy.
* [MITRE ATT&CK for Defenders](<https://attack.mitre.org/>) - Understanding the ATT&CK framework from a defender's perspective.
Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As much as we can, we'd like to minimize this kind of "just a documentation" kind of links. While "reading the docs" is good, the main purpose of this list is for folks to have a learn by doing "lab environment" and not just passively "read".

Comment thread README.md

* [Atomic Red Team](<https://github.com/redcanaryco/atomic-red-team>) - A library of simple tests that every security team can use to test their controls.
* [Caldera](<https://github.com/mitre/caldera>) - An automated adversary emulation system.
* [Sigma](<https://github.com/SigmaHQ/sigma>) - Generic signatures for SIEM systems.
Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Similar feedback as given on these 3 links.

Comment thread README.md
### Level 3 - iOS Security

* [iOS Security for Beginners](<https://www.hacker101.com/videos/ios-basics>) - A free course from Hacker101.
* [Damn Vulnerable iOS App (DVIA)](<https://github.com/prateek147/DVIA-v2>) - A vulnerable iOS application.
Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As for this kind of DVIA links (cloudgoat,sadcloud,gcpgoat), we'd like to keep it as minimal local installation (or any kind of cloud subscriptions) needed for folks with limited spending power for self learning. Best kind of resource is something that also provides a sandbox environment/CTF style learning to give everyone an equal opportunity. Please consider these for review. Much appreicated!

Comment thread README.md

### Level 3 - Hands-On Cloud Security

* [CloudGoat](<https://github.com/RhinoSecurityLabs/cloudgoat>) - Rhino Security Labs' "Vulnerable by Design" AWS deployment tool.
Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please see the feedback below.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants