An exhaustive, production-grade cybersecurity master notes compendium comprising 12 Volumes, 34 Master Modules, and comprehensive compendia (>150,000 words).
Engineered for security researchers, penetration testers, blue team defense engineers, and application security auditors, this repository bridges foundational computer science with enterprise-grade offensive and defensive security operations.
- Executive Overview
- Curriculum Architecture & Master Notes
- Volume 01: Computer & Programming Foundations
- Volume 02: Linux, Networking & Security Foundations
- Volume 03: Reconnaissance, OSINT & Enumeration
- Volume 04: Core Ethical Hacking
- Volume 05: Web Security Foundations
- Volume 06: Web Application VAPT
- Volume 07: Network Penetration Testing
- Volume 08: API Security
- Volume 09: Mobile & Android Security
- Volume 10: Advanced Security Disciplines
- Volume 11: Reporting Methodology & Professional Practice
- Volume 12: Career Roadmap, Checklists & Reference Material
- The 20-Point Topic Schema Mandate
- Frameworks & Standards Compliance
- Operational Security & Responsible Testing
- License
This curriculum is structured around an analytical, defensive-engineering discipline:
- Evidence-Based Auditing: Replaces guesswork and indiscriminate scanning with systematic enumeration, hypothesis formulation, benign boundary verification, and verifiable proof-of-concept synthesis.
- First-Principles Mastery: Begins from absolute zero (bits, bytes, hardware, OS boot, and postal networking) up to advanced enterprise Active Directory attacks, binary exploitation, and cloud testing.
- Methodical Technical Architecture: Every module features deep architectural diagrams, protocol state machines, step-by-step verification methodologies, and defensive code remediations.
- Defense-in-Depth Remediation: Every vulnerability classification pairs root-cause data-flow analysis with production-ready code fixes, framework-specific defenses, and system hardening benchmarks.
The master notes library spans 12 structured volumes covering every operational phase of offensive and defensive security engineering:
- Special Primer: Computer Science & Systems Foundations from Absolute Zero — First-principles guide for absolute beginners: bits, bytes, binary/hex, CPU/RAM/SSD hardware anatomy, OS boot lifecycle, terminal survival guide, magic bytes, postal networking model, and core security definitions.
- Windows & Linux OS Foundations, Directory Structures & Command Mastery — Comprehensive comparative OS lineage (Unix/Linux & DOS/Windows NT), monolithic vs hybrid kernel architectures, FHS and Windows directory hierarchies, Top 50 Linux commands, Top 50 Windows commands (CMD & PowerShell), and dual-platform Rosetta Stone.
- Special Primer: Web Application & HTTP Protocols from Absolute Zero — First-principles guide for beginners: web anatomy, HTTP/1.1 vs HTTP/2 vs HTTP/3, request/response cycles, status codes, headers, cookies/sessions, browser rendering engine, and modern web architecture.
- Module 01: Computer Hardware, OS Architecture & Productivity Systems — CPU microarchitectures, memory hierarchy, system calls, OS kernel/user-space mechanics, stack layout, 6-stage buffer overflow, and malicious document macro structures.
- Module 02: Advanced Programming, Fullstack Architecture & Secure SDLC — Multi-tier software architecture, secure SDLC integration, STRIDE threat modeling, SAST taint-flow analysis, CI/CD pipeline security, Poisoned Pipeline Execution (PPE), GitHub Actions
pull_request_targetRCE, dependency confusion, and SLSA/SBOM provenance.
- Module 04: Operating System Installation & Virtual Lab Architecture — Hypervisors (Type-1/Type-2), isolated virtual network topologies, multi-NIC pivot architectures, and Kali Linux tuning.
- Module 05: Linux Architecture, System Administration & Privilege Isolation — Linux directory hierarchy, systemd, process namespaces, SUID/SGID auditing, and shell automation.
- Computer Networking Foundations, IP Addressing & Subnetting Master Guide — Comprehensive guide to network topologies (Bus, Star, Ring, Mesh), hardware devices (Hubs, Switches, Routers, collision vs. broadcast domains), transmission media, IPv4/IPv6 address types, classful addressing, master CIDR prefix table (/0 to /32), step-by-step subnetting math, VLSM, TCP vs. UDP, and routing hierarchies.
- Windows & Linux Enterprise Networking, Administration & VAPT Master Guide — Exhaustive operational manual: Linux (
netfilter,iproute2, network namespaces,nftables, kernel network hardening) and Windows (NDIS,WFP,tcpip.sys, Winsock, Defender Firewall), dual-platform command Rosetta Stone, enterprise protocol dissection (SMBv1–v3, MSRPC, Kerberos vs NTLMv2), network VAPT methodology (stealth SYN/UDP scanning, Layer 2 ARP/LLMNR/NBT-NS verification), enterprise pivoting (SSH, Chisel, Ligolo-ng TUN), and packet forensics (BPF syntax, nativenetsh trace). - VMware Virtualization, Enterprise vSphere Networking & Security Master Guide — Bare-metal Type-1 (ESXi) vs Hosted Type-2 (Workstation Pro) hypervisors, Standard vs Distributed Virtual Switches (VSS & vDS), 802.1Q VLAN modes (EST, VST, VGT), layer-2 security policies (Promiscuous, MAC changes, Forged transmits), storage virtualization (VMFS6, vSAN, VMDK anatomy), CLI automation (
esxcli,vim-cmd, PowerCLI), vSphere attack surface & critical CVEs (CVE-2021-21972, CVE-2021-22005, CVE-2023-34048), and CIS ESXi/vCenter hardening. - Module 08: Networking Protocols, Traffic Analysis & Boundary Defense — OSI and TCP/IP protocol stacks, IPv4/IPv6 headers, TCP three-way handshake state machines, Wireshark packet dissection, and stateful firewalls.
- Module 24: Applied Cryptography, PKI Infrastructure & Secret Management — Symmetric/asymmetric ciphers (AES-GCM, RSA, ECC), secure hashing algorithms, X.509 certificate chains, TLS 1.3 handshakes, and PKI validation.
- Module 06: Information Gathering, Passive Reconnaissance & OSINT — Open-source intelligence (OSINT), DNS zone transfers, WHOIS auditing, Certificate Transparency (CT) log mining, and Shodan queries.
- Module 07: Enumeration Methodology & Active Service Auditing — Active port scanning, banner grabbing, SMB dialect negotiation, RPC endpoint mapping, and SNMP MIB walking.
- Module 28: Web Surface Mapping, Asset Discovery & Endpoint Extraction — Web application fingerprinting, DOM parsing, client-side JavaScript asset extraction, and hidden API route mining.
- Cyber Threat Frameworks: Cyber Kill Chain® & MITRE ATT&CK® Master Guide — Behavioral threat modeling reference: David Bianco's Pyramid of Pain, Lockheed Martin's 7-phase Cyber Kill Chain, MITRE ATT&CK Matrix across all 14 Enterprise tactics, technique/sub-technique taxonomy, ATT&CK Navigator heat maps, and D3FEND countermeasures.
- Vulnerability Research, CVE Lifecycle & Exploit-DB Mastery — Vulnerability discovery lifecycles, patch diffing, CVE tracking, SearchSploit CLI, Exploit-DB filtering, payload adaptation, and responsible disclosure workflows.
- Module 03: Introduction to Ethical Hacking, Legal Boundaries & RoE — Legal frameworks (CFAA, IT Act, GDPR), Rules of Engagement (RoE), CIDR scope guardrails, and vulnerability triage.
- Module 09: Anonymity, Privacy Engineering & Operational Security (OpSec) — Tor onion routing mechanics, multi-hop VPN chains, DNS/WebRTC leak auditing, and operational identity isolation.
- Module 10: Password Security, Cryptographic Hashes & Credential Auditing — Key derivation functions (PBKDF2, bcrypt, scrypt, Argon2), password entropy, rainbow tables, Hashcat rule synthesis, and passkey architecture.
- Module 11: Layer 2 Attacks, Packet Sniffing & Switch Security Defense — ARP cache poisoning, MAC table flooding, Dynamic ARP Inspection (DAI), DHCP snooping, and switch port security.
- Module 12: Social Engineering, Psychological Lures & Human Risk Assessment — Psychological influence vectors (Cialdini heuristics), pretext formulation, authorization verification, and security awareness programs.
- Module 21: Web Application Architecture, Protocols & Browser Security — HTTP/1.1, HTTP/2, HTTP/3, Same-Origin Policy (SOP), Cross-Origin Resource Sharing (CORS), secure cookie attributes, and DOM contexts.
- Module 29: Web Application Security Testing Tools & Interception Proxies — Interception proxy architecture (Burp Suite Pro, OWASP ZAP, Caido), parameter fuzzing engines (ffuf), upstream proxy chaining, and custom matchers.
- Module 30: OWASP Top 10 Vulnerabilities, Root Causes & Remediation — Broken Access Control, SQLi, SSRF, XSS, Insecure Deserialization, SSTI, Web Cache Poisoning, Web Cache Deception, and OAuth 2.0/OIDC flaws.
- Advanced Web Attacks: OAuth 2.0, JWT, GraphQL & Request Smuggling — Exhaustive exploitation methodology for OAuth redirect URI abuse, CSRF on state, JWT algorithm confusion (RS256 to HS256), none alg bypass, GraphQL batching/circular DoS, HTTP/1.1 request smuggling (CL.TE/TE.CL), and web cache poisoning.
- Module 31: Web VAPT Reporting, Proof-of-Concept & Defect Documentation — Vulnerability scoring (CVSS v3.1 and v4.0), CWE mapping, reproduction step formulation, and executive/technical report generation.
- Module 26: Penetration Testing Methodologies & Standards — PTES, NIST SP 800-115, OSSTMM execution lifecycles, and black-box, gray-box, and white-box test postures.
- Module 27: Hands-On Network Penetration Testing Lab Architecture — Multi-tier virtualized test networks, DMZ segmentation, vulnerable target enclaves, and strict isolation controls.
- Module 32: Network Penetration Testing Execution & Host Auditing — Active Directory architecture, Kerberos authentication dance, the "Big 6" AD attacks, BloodHound graph analysis, ADCS (ESC1–ESC8) & Shadow Credentials, Linux/Windows privilege escalation frameworks, Kubernetes cluster pentesting, and container breakout vectors.
- Active Directory & Enterprise Kerberos Attacks Master Playbook — Complete operational methodology for AD DS, Kerberos authentication dance, BloodHound CE Cypher queries, AS-REP Roasting, Kerberoasting, Unconstrained/Constrained/RBCD delegation, ADCS ESC1–ESC8 abuse with Certipy, PetitPotam coercion, and DCSync.
- Container & Kubernetes (K8s) Penetration Testing Guide — Container isolation internals (namespaces, cgroups, seccomp), Docker socket breakout, capability abuse (SYS_ADMIN), hostPath escapes, Kubernetes Service Account token harvesting, K8s RBAC privilege escalation, Kubelet unauthenticated API (:10250), and insecure etcd exploitation.
- Cloud Security Foundations: AWS, Azure & GCP — Multi-cloud architecture, shared responsibility models, IAM privilege escalation, S3/Blob misconfigurations, metadata service abuse (IMDSv1 vs IMDSv2), and serverless security.
- API Architectures, Protocols & Types Master Guide — Comprehensive architectural analysis of System APIs vs Web APIs, REST, SOAP (WSDL/XXE), GraphQL (Introspection/DoS), gRPC (Protobuf/mTLS), WebSockets (CSWSH), Webhooks (HMAC verification), RPC (JSON-RPC/XML-RPC), and master 10-dimension comparison matrix.
- Module 33: API Security Testing, Microservices & Modern Web Architectures — REST, GraphQL, gRPC, OAuth2/OIDC, BOLA, Mass Assignment, JWT algorithm manipulation, and AI & LLM Application Security (OWASP Top 10 for LLMs 2025, Prompt Injection, RAG Poisoning, and Agentic Tool Security).
- AI & Large Language Model (LLM) Security Assessment Playbook — Practical security assessment methodology for AI systems: OWASP Top 10 for LLMs 2025, Direct & Indirect Prompt Injection, RAG vector database poisoning, Model Context Protocol (MCP) tool security, system prompt extraction, and defense-in-depth guardrail architectures.
- Special Primer: Android & Mobile Application Foundations from Absolute Zero — First-principles guide for absolute beginners: smartphone hardware & SoC architecture, Android vs Linux (Bionic/SurfaceFlinger), APK ZIP anatomy, Dalvik/ART compilation, the 4 core components (Activity, Service, Receiver, Provider), Intent communication, UID sandboxing, runtime permissions, Top 20 ADB commands, and initial VAPT inspection.
- Module 17: Mobile Application Security Foundations & Architecture — Android & iOS platform architectures, Linux kernel/Darwin XNU sandboxing, Secure Enclave (SEP) vs. ARM TrustZone, iOS Keychain, App Transport Security (ATS), and mobile attack surfaces.
- Module 34: Mobile Application VAPT (Android & iOS), Reverse Engineering & Dynamic Hooks — APK/IPA anatomy, Smali bytecode analysis, JADX deobfuscation, iOS FairPlay DRM decryption, Mach-O binary analysis, ATS auditing, and dynamic instrumentation using Frida and Objection.
- Module 13: Wireless Security, 802.11 Protocols & Enterprise Defense — 802.11 frame structures, WPA2/WPA3 4-way handshakes, PMKID analysis, rogue AP detection, and 802.11w Protected Management Frames.
- Module 14: System Security, Operating System Hardening & Host Defense — Windows & Linux internal security models, CWE-428 unquoted service paths, Registry Run keys, Sysmon telemetry, and EDR mechanics.
- Module 15: Phishing Infrastructure Analysis, Authentication & Defense — Email delivery mechanisms, SPF, DKIM, DMARC, ARC protocols, and Adversary-in-the-Middle (AiTM) reverse proxies.
- Module 16: Malware Analysis Foundations & Reverse Engineering — PE and ELF file formats, section entropy analysis, static import hashing (
imphash), dynamic sandboxing, and YARA signature compilation. - Module 18: Defensive Technologies, SIEM Architecture & Detection Engineering — NIDS/NIPS (Snort, Suricata), SIEM pipeline architecture, Sigma detection rule compilation, and Risk-Based Alerting (RBA).
- Module 19: Email Security Protocols & Header Forensics — Chronological
Received:header hop forensics, forged gateway boundaries, SPF/DKIM verification, and forensic artifact extraction. - Module 20: Denial of Service, Distributed DoS & Mitigation Architectures — L4 amplification mechanisms (DNS, NTP), SYN flood mitigation (RFC 4987 SYN cookies), ReDoS algorithmic complexity, and Token Bucket rate limiting.
- Module 22: Internet of Things (IoT) & Embedded Device Security — IoT hardware interfaces (UART, JTAG, SPI), firmware unpacking with Binwalk, SquashFS extraction, and hardcoded credential discovery.
- Module 23: Steganography & Digital Media Forensics — Spatial domain LSB steganography in BMP/PNG, transform domain techniques, Chi-Square statistical detection, and file carving.
- Module 25: Cyber Laws, Incident Response Compliance & Evidence Handling — Computer fraud statutes, GDPR/HIPAA compliance, digital evidence preservation, and cryptographic chain-of-custody ledgers.
- Enterprise VAPT Execution Workflow — End-to-end commercial engagement lifecycle: pre-engagement scoping, testing execution, vulnerability triage, and remediation retesting.
- Bug Bounty Hunting Methodology — Program reconnaissance, asset surface expansion, high-signal reporting, and triager communication guidelines.
- Career Roadmap & Technical Interview Mastery — Comprehensive Top 50 Technical Interview Questions & Model Answers across 7 domains, candidate recovery playbooks, and career progression pathways.
- Certifications Roadmap: CEH, OSCP, CRTP & Beyond — Progressive cybersecurity certification pathways, domains, costs, passing thresholds, lab preparation strategies, and timeline planning.
- Windows & Linux Privilege Escalation Master Playbook — Exhaustive local elevation guide covering Sudo LD_PRELOAD, SUID GTFOBins, Linux capabilities, cron wildcard injection, Windows token manipulation (SeImpersonate, PrintSpoofer, GodPotato), unquoted service paths, and AlwaysInstallElevated.
- CVE, CVSS & OWASP Scoring Quick Reference — Quick reference for CVE lifecycle, CVSS v3.1 & v4.0 calculator breakdowns, EPSS exploit likelihood models, OWASP Web/API/Mobile Top 10, CWE Top 25, and triage prioritization frameworks.
- Top 100 Security Tools Cheat Sheet — Definitive Kali Linux reference cheat sheet covering 100 essential offensive and defensive security tools with exact command syntaxes and operational flags.
- Master VAPT Checklists — Comprehensive assessment checklists covering Web, API, Network, Active Directory, and Mobile scopes.
- Authoritative References Library — Master bibliography spanning IETF RFCs, NIST Special Publications, OWASP methodologies, and academic security literature.
To maintain consistent depth across the entire curriculum, every primary module adheres strictly to an authoritative 20-point analytical structure:
- Learning Objectives: Concrete, measurable skills acquired.
- Prerequisites: Conceptual and technical foundation required before study.
- What Is It?: Clear, conceptual explanation accessible to newcomers.
- Technical Explanation: Deep architectural mechanics, memory layout, system calls, or protocol design.
- How It Works: Step-by-step state machines, ASCII/Mermaid protocol sequences, data flows.
- Security Perspective: Attack surface analysis, trust boundaries, threat actors, and abuse cases.
- Auditing Methodology: Professional verification workflow: Recon → Enumeration → Mapping → Hypothesis → Benign Testing → Evidence Collection → Impact Assessment → Remediation.
- Tooling Deep-Dive: In-depth inspection of key diagnostic utilities (CLI syntax, flag mechanics, safe lab usage).
- Practical Lab Setup: Reproducible, isolated lab configurations using Docker or virtualized networks.
- Evidence & Verification: Eliminating false positives, validating boundary reactions, establishing deterministic proof.
- Telemetry & Detection: Log analysis, SIEM signatures, Suricata/Snort/Sigma rules, host artifacts.
- Mitigation: Production-ready code patches, robust configuration snippets, defense-in-depth measures.
- Hardening: System and protocol hardening guides aligned with CIS Benchmarks and NIST SP 800-53.
- Documented Case Studies: Analysis of historical, documented vulnerabilities, root-cause mechanisms, and lessons learned.
- Common Mistakes & Anti-Patterns: Pitfalls made by novice practitioners and defensive architects.
- Professional vs. Naive Methodology: Contrast between automated scanner reliance and manual security verification.
- Knowledge Check & Interview Questions: Graded questions (Beginner, Intermediate, Advanced, Scenario).
- Progressive Practice Exercises: Hands-on challenges designed for skill reinforcement.
- Key Takeaways: High-density summary of core tenets.
- Authoritative References: Primary literature, RFCs, NIST SP, OWASP documents, vendor specifications.
The analytical methodologies, technical architectures, and checklists across this repository directly align with industry standards:
- NIST Special Publications: NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment), NIST SP 800-53 Rev. 5, NIST SP 800-30.
- OWASP Foundations: OWASP Web Security Testing Guide (WSTG v4.2), Application Security Verification Standard (ASVS v4.0.3), Mobile Application Security Verification Standard (MASVS), and API Security Top 10.
- Penetration Testing Execution Standard (PTES): Full phase coverage from Pre-engagement Interactions to Post-exploitation and Reporting.
- MITRE ATT&CK Framework: Enterprise and Cloud tactics, techniques, and procedures (TTPs).
- IETF RFC Standards: Core internet protocols (RFC 791 IPv4, RFC 793 TCP, RFC 9110 HTTP, RFC 5246/8446 TLS, RFC 5321/5322 Email).
- Secret Masking & Redaction: In accordance with operational security standards, all sample tokens, API keys, and session hashes are redacted to their first 4 characters followed by masking (e.g.,
sk_live_1234****REDACTED). - Benign Boundary Verification: All test probes in the curriculum use non-destructive indicators (e.g., mathematical evaluation proofs, loopback listeners, console log triggers) rather than intrusive payloads.
- Strict Scoping: Testing must strictly remain within authorized target environments, virtualized isolated networks, and designated systems.
This project is licensed under the terms of the MIT License.
Authored by Tejas (@tejassroot).