April 9, 2020

2789 words 14 mins read



An awesome list of FREE resources for training, conferences, speaking, labs, reading, etc that are free all the time or during COVID-19 that cybersecurity professionals with downtime can take advantage of to improve their skills and marketability to come out on the other side ready to rock.

repo name gerryguy311/CyberProfDevelopmentCovidResources
repo link https://github.com/gerryguy311/CyberProfDevelopmentCovidResources
size (curr.) 60 kB
stars (curr.) 162
created 2020-04-08

An awesome list of resources for training, conferences, speaking, labs, reading, etc that are free all the time or during COVID-19 that cybersecurity professionals with downtime can take advantage of to improve their skills and marketability to come out on the other side ready to rock.


  4. BOOKS


  • GRIMMCON April 14 - 2 tracks - top tier infosec professionals talking https://www.grimm-co.com/grimmcon

  • All the Talks (on all things DevOps, Development & Security) April 15, 2020 (for 24 hours I believe.) All The Talks is a collaborative effort of speakers, organizers and sponsors from around the world to provide a platform for the talks that have been cancelled due to the COVID-19 outbreak. Join us for 23.999 hours of talks, panels and activities while raising funds to assist select charities benefiting virus victims. https://www.allthetalks.org/

  • InfosecOasis - April 18, 2020 - (FROM CON Page) InfoSecOASIS is a free, online information security conference. We wanted to create a space to participate in the social aspects of conferences, all while respecting the guidelines for social distancing. While VR is highly recommended, it is not required to use AltspaceVR (our platform of choice). https://infosecoasis.com/

  • IsolationCon - 19TH APRIL (14:00 UTC, 10AM EST) - We are not just another infosec con; our vision is to be the online conference for information security people from all teams and different backgrounds all over the world. We actively want to encourage collaboration and participation. We want our Attendees and Speakers to be immersed in this online event, with activities and debates around the challenges we all face in our working and personal lives, and how they are adapting to the current situation we all face. https://themanyhats.club/the-many-hats-club-presents-isolationcon/

  • HITB Lockdown Livestream - April 25-26 (10:00-18:00 CET) - A free livestream featuring some of the talks and speakers from the cancelled HITBSecConf2020 - Amsterdam. https://conference.hitb.org/lockdown-livestream/

  • OWASP Virtual AppSec Days April 2020 - April 27 - The OWASP Foundation is hosting a Virtual AppSec Days on April 27-29th. They will be running a 90 minute virtual mini-conference. This is the only free part of the event. [OWASP said ability to register coming this week]

  • RedHat Summit - April 28-29 - “Our virtual event will feature the keynotes, breakout sessions, and collaboration opportunities that you’ve come to expect from Red Hat® Summit. This programming will be shared as a blend of live and recorded content designed to inspire and engage a global audience. You will have access to the experts behind the code as you learn about the latest in open hybrid cloud, automation, cloud-native development, and so, so much more. Red Hat Summit 2020 Virtual Experience is your platform to learn, network, and plot the next steps in your career as you find ways to unlock your potential.” - https://www.redhat.com/en/summit

  • DerpCon - April 30 (workshop) May 1 Conference - https://www.eventbrite.com/e/derpcon-2020-tickets-101700143868 we want to do our part to foster the information security community while simultaneously providing attendees with interesting knowledge they can use personally or professionally. We will be supporting the local Colorado community by accepting donations for the Colorado COVID-19 Relief Fund.

  • DISC – SANS ICS Virtual Conference Friday May 1 ICS Virtual Conference (10-6 pm ET) - The content is focused around being widely acceptable for both IT Security and OT/ICS audiences and the theme is focused around education especially during times when many folks are at home and working remotely. Special focuses are being given in the talks to what work and efforts can be accomplished with minimal effort during slow down periods. https://www.sans.org/webcasts/disc-ics-virtual-conference-114285

  • FWD:CLOUDSEC June 29 - a new cloud security practitioners conference which will be held online - https://fwdcloudsec.org/

  • RSAC 2020 APJ July 15 – 17 “Transforming RSA Conference 2020 Asia Pacific & Japan into a free virtual learning experience, taking place 15 – 17 July. We have many exciting and relevant sessions and keynotes planned, featuring some of the world’s leading cybersecurity experts.” https://go.rsaconference.com/rsac-apj2020/


  1. Pluralsight Free for April 2020. Massive top tier library of content including lots of cyber training www.pluralsight.com

  2. EC-Council Hacking “Per vendor: Use our Free Resource Pass to a wide range of online cybersecurity resources.” https://www.eccouncil.org/free-cybersecurity-resources/

  3. Metasploit Unleashed Most complete and in-depth Metasploit guide available, with contributions from the authors of the No Starch Press Metasploit Book. https://www.offensive-security.com/metasploit-unleashed/

  4. AWS Cloud Certified Get skills in AWS to be more marketable. Training is quality and free. https://www.youtube.com/watch?v=3hLmDS179YE Have to create an AWS account, Exam is $100.

  5. SANS Faculty Free Tools List of OSS developed by SANS staff. https://www.sans.org/media/free/free-faculty-tools.pdf?msc=sans-free-lp

  6. “Using ATT&CK for Cyber Threat Intelligence Training” - 4 hour training The goal of this training is for students to understand the following: at: https://attack.mitre.org/resources/training/cti/

    • What ATT&CK is and why it’s useful for cyber threat intelligence (CTI)
    • How to map to ATT&CK from both finished reporting and raw data
    • Why it’s challenging to store ATT&CK-mapped data and what you should consider when doing that
    • How to perform CTI analysis using ATT&CK-mapped data
    • How to make defensive recommendations based on CTI analysis
  7. Coursera -“Coursera Together: Free online learning during COVID-19” Lots of different types of free training. https://blog.coursera.org/coursera-together-free-online-learning-during-covid-19/

  8. Fortinet Security Appliance Training Free access to the FortiGate Essentials Training Course and Network Security Expert courses 1 and 2 https://www.fortinet.com/training/cybersecurity-professionals.html

  9. Chief Information Security Officer (CISO) Workshop Training - The Chief Information Security Office (CISO) workshop contains a collection of security learnings, principles, and recommendations for modernizing security in your organization. This training workshop is a combination of experiences from Microsoft security teams and learnings from customers. - https://docs.microsoft.com/en-us/security/ciso-workshop/ciso-workshop

  10. CLARK Center Plan C - Free cybersecurity curriculum that is primarily video-based or provide online assignments that can be easily integrated into a virtual learning environments https://clark.center/home

  11. Hack.me is a FREE, community based project powered by eLearnSecurity. The community can build, host and share vulnerable web application code for educational and research purposes. It aims to be the largest collection of “runnable” vulnerable web applications, code samples and CMS’s online. The platform is available without any restriction to any party interested in Web Application Security. https://hack.me/

  12. Hacker101 - Free classes for web security - https://www.hacker101.com/

  13. ElasticStack - Free on-demand Elastic Stack, observability, and security courses. https://training.elastic.co/learn-from-home

  14. Hoppers Roppers - Community built around a series of free courses that provide training to beginners in the security field. https://www.hoppersroppers.org/training.html

  15. IBM Security Learning Academy Free technical training for IBM Security products. https://www.securitylearningacademy.com/

  16. M.E. Kabay Free industry courses and course materials for students, teachers and others are welcome to use for free courses and lectures. http://www.mekabay.com/courses/index.htm

  17. Open P-TECH Free digital learning on the tech skills of tomorrow. https://www.ptech.org/open-p-tech/

  18. Autopsy Digital Forensics - FREE ($495 value) Autopsy is a Windows-based desktop digital forensics tool that is free, open source, and has all of the features that you’d normally find in commercial digital forensics tools. It is extensible and comes with features that include keyword search, hash matching, registry analysis, web analytics, and more. https://www.autopsy.com/support/training/covid-19-free-autopsy-training/

  19. Udemy - Online learning course platform “collection from the free courses in our learning marketplace” https://www.udemy.com/courses/free/

20. Security+ Training CompTIA Security+ (SY0-501) Complete Video Course is an engaging self-paced video training solution that provides learners with more than 19 hours of personal training from security expert Sari Greene. https://pearsonadvance.com/courses/comptia-security-sy0-501/ #now $250 4/13/2020

  1. Linux Fundamentals Linux Fundamentals LiveLessons has more than 10 hours of comprehensive video training for you to have everything you need to build a strong understanding of working with Linux. https://pearsonadvance.com/courses/linux-fundamentals/

  2. AWS Certified Cloud Practitioner Seven hours of video instruction covering the fundamentals of cloud computing; AWS core services such as Amazon EC2, Amazon RDS, and Amazon S3; security; architecture design principles; best practices; and cost management.AWS Certified Cloud Practitioner Complete Video Course is a video product designed to help viewers understand Amazon Web Services at a high level, introduce cloud computing concepts, and key AWS services, and prepare them for the exam according to the certification exam guide published by Amazon Web Services. https://pearsonadvance.com/courses/aws-certified-cloud-practitioner/

  3. Enroll Now Free: PCAP Programming Essentials in Python https://www.netacad.com/courses/programming/pcap-programming-essentials-python Python is the very versatile, object-oriented programming language used by startups and tech giants, Google, Facebook, Dropbox and IBM. Python is also recommended for aspiring young developers who are interested in pursuing careers in Security, Networking and Internet-of-Things. Once you complete this course, you are ready to take the PCAP – Certified Associate in Python programming. No prior knowledge of programming is required.

  4. Packt Web Development Course Web Development Get to grips with the fundamentals of the modern web Unlock one year of free online access. https://courses.packtpub.com/pages/free?fbclid=IwAR1FtKQcYK8ycCmBMXaBGvW_7SgPVDMKMaRVwXYcSbiwvMfp75gazxRZlzY

  5. Learn Empire Powershell This Tutorial contains installation of Kali Linux and Windows VM, Installation of Empire PowerShell 3.1,Exploiting Windows 10 machines by various attacks including Empire,Running Mimikatz, Privelege Escalation & Using Hashcat to crack the various password hashes https://pentestskills.teachable.com/p/empire-powershell

  6. Stanford University Webinar - Hacked! Security Lessons from Big Name Breaches 50 minute cyber lecture from Stanford.You Will Learn: – The root cause of key breaches and how to prevent them; How to measure your organization’s external security posture; How the attacker lifecycle should influence the way you allocate resources https://www.youtube.com/watch?v=V9agUAz0DwI

  7. Stanford University Webinar - Hash, Hack, Code: Emerging Trends in Cyber Security Join Professor Dan Boneh as he shares new approaches to these emerging trends and dives deeper into how you can protect networks and prevent harmful viruses and threats. 50 minute cyber lecture from Stanford. https://www.youtube.com/watch?v=544rhbcDtc8

  8. Kill Chain: The Cyber War on America’s Elections (Documentary) (Referenced at GRIMMCON), In advance of the 2020 Presidential Election, Kill Chain: The Cyber War on America’s Elections takes a deep dive into the weaknesses of today’s election technology, an issue that is little understood by the public or even lawmakers. https://www.hbo.com/documentaries/kill-chain-the-cyber-war-on-americas-elections

  9. Intro to Cybersecurity Course (15 hours) Learn how to protect your personal data and privacy online and in social media, and why more and more IT jobs require cybersecurity awareness and understanding. Receive a certificate of completion. https://www.netacad.com/portal/web/self-enroll/c/course-1003729

  10. Cybersecurity Essentials (30 hours) Foundational knowledge and essential skills for all cybersecurity domains, including info security, systems sec, network sec, ethics and laws, and defense and mitigation techniques used in protecting businesses. https://www.netacad.com/portal/web/self-enroll/c/course-1003733

Instructor Led Webinar/ Labs / Workshops



  • Cyber Threat Hunting Training – May Session (4-Hours) - Blackhills Information Security - Tuesday, May 12th, 12pm – 4pm EST – In this free, one-day course, we will cover how to leverage network data to perform a cyber threat hunt. The course includes hands-on labs using packet captures of various command and control channels. The labs will enable you to apply what you’ve learned using various open-source tools. https://register.gotowebinar.com/register/5841228496128209677

  • SANS @MIC Talk - Prioritizing OT Security Efforts: The Five Tactical Things to Accomplish While Leadership Defines a Security Program (Don Weber Talk) May 27 8:30PM EDT - This talk will cover the five tactical things an OT/IT team can do while leadership defines the direction of a security program for the OT environment. It will discuss quick wins that can be accomplished with equipment typically already deployed. These steps will also provide the leadership team with valuable information that will help prioritize future efforts and quickly improve vendor / integrator / MSP requirements for near-term greenfield and upcoming brownfield maintenance projects. https://www.sans.org/webcasts/atmic-talk-prioritizing-ot-security-efforts-tactical-things-accomplish-leadership-defines-security-program-113985

  • Responding to Incidents in Industrial Control Systems (ICS): Identifying Threats, Reactions and Developing the IR Process Friday May 29 1:00 PM - How can effective and proven incident response processes identify, mitigate and remediate threats in the ICS environment? In this new webcast with SANS instructor Don C. Weber and representatives Eric Knapp and Matt Wiseman from Honeywell, we will identify ICS threats, look at how incidents can be managed, and provide recommendation for setting up an effective IR program to reduce risk exposure. Attendees will learn how to best apply proven IR programs and techniques.https://www.sans.org/webcasts/responding-incidents-industrial-control-systems-ics-identifying-threats-reactions-developing-ir-process-114525



  • Risky Business Published weekly, the Risky Business podcast features news and in-depth commentary from security industry luminaries. Hosted by award-winning journalist Patrick Gray, Risky Business has become a must-listen digest for information security professionals. https://risky.biz/

  • Pauls Security Weekly This show features interviews with folks in the security community; technical segments, which are just that, very technical; and security news, which is an open discussion forum for the hosts to express their opinions about the latest security headlines, breaches, new exploits and vulnerabilities, “not” politics, “cyber” policies and more. https://securityweekly.com/category-shows/paul-security-weekly/

  • Security Now - Steve Gibson, the man who coined the term spyware and created the first anti-spyware program, creator of Spinrite and ShieldsUP, discusses the hot topics in security today with Leo Laporte. https://twit.tv/shows/security-now

  • Daily Information Security Podcast (“StormCast”) Stormcasts are daily 5-10 minute information security threat updates. The podcast is produced each work day, and typically released late in the day to be ready for your morning commute. https://isc.sans.edu/podcast.html

comments powered by Disqus