Course
Cybersecurity for Beginners
A 12-week hands-on introduction to cybersecurity for people starting from zero. You will learn what attackers actually do and why, how computers and networks work well enough to defend them, and how to read the evidence a system leaves behind. From Week 8 you build and run your own Wazuh SIEM in a home lab — deploying the server, enrolling Linux and Windows agents, watching real attacks light up the dashboard, and monitoring file changes and vulnerabilities. You finish by securing and monitoring a small network end to end, then defending your work in a presentation. No prior IT experience required; expect 10–15 hours per week of lessons, labs, and a weekly project. You need a laptop with 16 GB of RAM to run the lab.
Module 1 — Week 1 — What Security Actually Is: Threats, Attackers & the CIA Triad
- ✓What security actually means30mFree preview
- ✓Who attacks, and why it decides what you defend30mFree preview
- ✓The CIA triad: the three questions you ask about anything25mFree preview
- ✓Your home lab: what you are building and why25mFree preview
- ✓Lab: build your two-machine lab75mPracticalFree preview
- ✓Lab: what an attack looks like from the defender's side60mPracticalFree preview
- ✓Weekly project: threat-model something you own150mProjectFree preview
Module 2 — Week 2 — How Computers Work: The Attack Surface
- ✓What a computer is actually doing30m🔒
- ✓Users, permissions and least privilege30m🔒
- ✓Attack surface: every door is a door25m🔒
- ✓Defence in depth, and why one control is never enough25m🔒
- ✓Lab: inventory your own attack surface75mPractical🔒
- ✓Lab: break permissions, then fix them60mPractical🔒
- ✓Weekly project: asset and attack-surface inventory150mProject🔒
Module 3 — Week 3 — Networking Fundamentals for Defenders
- ✓How data actually moves30m🔒
- ✓Addresses, ports and protocols30m🔒
- ✓DNS and HTTP: the two protocols attackers love25m🔒
- ✓Firewalls, segmentation and where to put the wall25m🔒
- ✓Lab: capture and read your own traffic75mPractical🔒
- ✓Lab: build a firewall and prove it works60mPractical🔒
- ✓Weekly project: map and defend your lab network150mProject🔒
Module 4 — Week 4 — Linux Essentials for Security
- ✓The Linux filesystem: where everything lives30m🔒
- ✓The investigator's toolkit30m🔒
- ✓Where Linux writes things down25m🔒
- ✓Hardening: making a host boring to attack25m🔒
- ✓Lab: investigate a machine you do not know75mPractical🔒
- ✓Lab: harden your Ubuntu server60mPractical🔒
- ✓Weekly project: a Linux baseline and hardening report150mProject🔒
Module 5 — Week 5 — Windows Essentials & Where the Logs Live
- ✓How Windows differs, and why it matters30m🔒
- ✓Accounts, groups and the privilege attackers want30m🔒
- ✓Event Viewer and the IDs that carry the signal25m🔒
- ✓Hardening Windows25m🔒
- ✓Lab: read the story in Windows security logs75mPractical🔒
- ✓Lab: baseline and harden Windows60mPractical🔒
- ✓Weekly project: Windows baseline and event-ID reference150mProject🔒
Module 6 — Week 6 — Malware & the Anatomy of an Attack
- ✓Malware: what it is and what it wants30m🔒
- ✓The attack chain, and where you get to intervene30m🔒
- ✓Persistence: how attackers stay, and where to look25m🔒
- ✓Ransomware, and what actually stops it25m🔒
- ✓Lab: watch a harmless test file behave like malware75mPractical🔒
- ✓Lab: plant persistence, then hunt it60mPractical🔒
- ✓Weekly project: anatomy of a real breach150mProject🔒
Module 7 — Week 7 — Cryptography, Passwords & Authentication
- ✓Cryptography without the mathematics30m🔒
- ✓Hashing: the one-way street30m🔒
- ✓How passwords are stored, and how they are cracked25m🔒
- ✓Authentication and the control that beats the rest25m🔒
- ✓Lab: crack weak passwords and watch salting defeat it75mPractical🔒
- ✓Lab: assess and redesign real authentication60mPractical🔒
- ✓Weekly project: an authentication security review150mProject🔒
Module 8 — Week 8 — Logs, SIEM Concepts & Your First Wazuh Deployment
- ✓Why a SIEM, and what one actually is30m🔒
- ✓What Wazuh is, and how its parts fit30m🔒
- ✓Decoders, rules and how an event becomes an alert25m🔒
- ✓What to expect when you deploy25m🔒
- ✓Lab: deploy the Wazuh stack75mPractical🔒
- ✓Lab: connect your first agent and see real data60mPractical🔒
- ✓Weekly project: deploy, document and reflect150mProject🔒
Module 9 — Week 9 — Wazuh Agents & File Integrity Monitoring
- ✓Agents, and watching more than one machine30m🔒
- ✓File Integrity Monitoring: watching for change30m🔒
- ✓FIM, rootcheck and configuration assessment together25m🔒
- ✓Turning noise into signal25m🔒
- ✓Lab: add Windows and compare the two75mPractical🔒
- ✓Lab: configure FIM, trigger it, and tune it60mPractical🔒
- ✓Weekly project: a tuned monitoring policy150mProject🔒
Module 10 — Week 10 — Vulnerability Management & Hardening
- ✓Vulnerabilities, CVEs and the patch problem30m🔒
- ✓Vulnerability management as a process30m🔒
- ✓What Wazuh detects, and writing your own rules25m🔒
- ✓Active response: when detection acts25m🔒
- ✓Lab: find and prioritise your vulnerabilities60mPractical🔒
- ✓Lab: write a rule and an automated response60mPractical🔒
- ✓Weekly project: a vulnerability management plan150mProject🔒
Module 11 — Week 11 — Phishing, Social Engineering & Security Awareness
- ✓Social engineering: hacking the person30m🔒
- ✓Reading a phishing email like an analyst30m🔒
- ✓Business Email Compromise and real awareness25m🔒
- ✓Detecting phishing with your SIEM25m🔒
- ✓Lab: dissect real phishing60mPractical🔒
- ✓Lab: investigate a phishing incident end to end60mPractical🔒
- ✓Weekly project: a human-layer defence plan150mProject🔒
Module 12 — Week 12 — Capstone: Secure and Monitor a Small Network
- ✓Putting it all together30m🔒
- ✓The capstone brief30m🔒
- ✓Planning your defence25m🔒
- ✓Presenting and defending your work25m🔒
- ✓Lab: build Zenith Craft's defence75mPractical🔒
- ✓Lab: attack your own network and catch it75mPractical🔒
- ✓Capstone: present and defend your work165mProject🔒
Already enrolled? Sign in with your enrollment email to unlock all lessons.