Resources

Where to start if you're new to cybersecurity.

Getting into cybersecurity can be a bit daunting. It’s a huge, rapidly evolving field with specializations including penetration testing, incident response, digital forensics, network engineering, malware analysis, and more.

If you’re just getting started, here’s what we recommend:

Learn Linux and/or Windows Server

Along with Bash or PowerShell, respectively. You'll use these daily.

Learn the basics of networking

Start with the OSI model. It underpins almost everything else in security.

Interact with the club, ask questions

We want to help. Come to a meeting, or ask on Discord.

Our GitHub organization

CofC Cybersecurity Club on GitHub — we keep a lot of resources and in-progress projects there. Active member? Ask and we'll add you to the org so you can contribute too.

Linux

Linux is a family of open-source operating systems. Prominent distributions (distros) exist for personal computers (Ubuntu, Fedora), mobile devices (Android), embedded devices (BusyBox), and servers (Red Hat, Ubuntu Server).

Getting started

Infosec-oriented distros

New to Linux or security? Start with Kali.

Other distros worth knowing

Virtualization

Hypervisors like VirtualBox and VMware let you run virtual machines (VMs) on your computer — multiple operating systems, each in its own sandbox. We recommend setting up Kali using Kali's own virtualization guides, or one of ours below.

Tools of the trade

Our favorites — most come prepackaged with Kali. The most important to know are nmap, netcat, and Wireshark.

Other tools

  • PEASS-ng — privilege escalation toolkit (Windows/macOS/Linux)
  • Gobuster — web server directory enumeration
  • SO-CRATES — Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Hardware hacking

  • Hak5 — pentesting/infosec gear, including the WiFi Pineapple, network implants, and hardware keyloggers
  • Raspberry Pi — cheap, versatile single-board computer

The cloud

Cloud knowledge is crucial to almost everything in computer science now, security included. Pick a platform and learn the basics — most offer free credit to get started.

YouTube channels & podcasts

Competition prep

Guides & reference sheets

Cheat sheets the Defense Team uses during practice and competitions. Print them, or keep them open on a second screen.

Competition role references

Captain

Round order of operations, triage priority, the tracking template, and the delegation quick map across every role.

Download PDF

Domain Admin

AD baselining, common attack patterns, GPO and trust checks, and the quick pattern library for domain-controller anomalies.

Download PDF

Engineer

Hardening order of operations, eviction commands, patch management, and firewall/service reference for Linux and Windows.

Download PDF

Threat Hunter

Find the user, trace the process, find the hole — cross-OS hunting workflow with a forensics deep-dive and handoff checklist.

Download PDF

SIEM Lead

Security Onion / Wazuh setup checks, hunt queries, writing detections, and alert tuning without going deaf to real hits.

Download PDF

OS hardening reference sheets

Windows Hardening Reference

Enumeration, user management, firewall, auditing, services, and threat-hunting commands for Windows hosts.

Download PDF

Linux Hardening Reference

Enumeration, users, networking, file permissions, systemd/cron, and threat-hunting commands for Linux hosts.

Download PDF

Guides written and maintained by Tyler McGuire.

Keep learning

Platforms & communities

Beyond club meetings, these are where most of us actually put in the hours.

TryHackMe

Guided, beginner-friendly rooms covering everything from Linux basics to full attack chains.

tryhackme.com

Hack The Box

Less hand-holding, more realistic boxes. A natural next step once TryHackMe starts feeling easy.

hackthebox.com

OverTheWire

Wargames like Bandit are the fastest way to actually get comfortable at a Linux command line.

overthewire.org

PortSwigger Web Security Academy

Free, and the closest thing to an industry-standard curriculum for web application security.

portswigger.net

NCL & CTFtime

The National Cyber League runs seasonal games open to students; CTFtime tracks nearly every other CTF happening.

nationalcyberleague.org

Explainshell & the man pages

Before asking the club, try man or paste the command into Explainshell. It's usually faster.

explainshell.com

Metasploitable 2

A deliberately vulnerable VM built to practice pentesting against, at your own pace and offline.

sourceforge.net

VulnHub

A whole library of vulnerable VMs beyond Metasploitable, ranging from beginner to brutal.

vulnhub.com

UnderTheWire

Like OverTheWire's Bandit, but PowerShell-focused — good practice if Windows is your weak spot.

underthewire.tech

Posh-Hunter

More advanced PowerShell practice for both blue and red team work.

posh-hunter.com

Our defense team competes in PCDC and SECCDC every year, and any member can join us for National Cyber League. See the full list on our Competitions page.