Resource Library

Resource Library

A list of resources I've personally found helpful in learning (or have on my to-do list), organized alphabetically, by category.  Nearly all of these are free resources.

Technical Topics

Access Management

Botnets

Bug Bounties

Coding

CTFs (there's a lot of overlap between this section and penetration testing, below)

Cryptography

DDoS

Email

Encryption

Frameworks

Home Lab

Mainframes

Microsegmentation

Miscellaneous

Networking

OWASP Top 10


Cross Site Scripting/XSS

CSP

CSRF

SQL Injection

Memory Allocation/Buffer Overflows


Passwords

Penetration Testing (there's a lot of overlap between this section and CTFs, above)

SASE

Threat Modeling

Career

Career Pathways

Career Advice

Interviewing

Networking

Certification Prep

General

  • Cybrary offers a number of free and paid courses, though they are very certification focused. I used their CISSP class as one of my studying resources for that exam and found it helpful. This can be helpful if you have a specific certification in mind.
  • Study Groups for Certifications

CISSP (resources ranked by usefulness)

  1. ISC2 Official Study Guide (definitely more information than you actually have to know.) 6/10
  2. Kelly Handerhan videos (solid, though they're not as in-depth as the exam can be.) 7/10
  3. 11th Hour CISSP guide  8/10
  4. IT Dojo Daily CISSP Question Videos (The guy who runs the series has a really great way of explaining complicated concepts, but I don't think the questions were reflective of the exam questions.) 6/10
  5. Made a million (probably around 1000) flashcards whenever I got a question wrong or ran into difficult concepts. Studied them. Made more (every time I ran into something I didn't know). Studied them again. 10/10
  6. Used the Shon Harris book to research specific topics I didn't understand. And  asked other people, googled the topics, read blogs, watched youtube videos, etc. 9/10
  7. Watched this video, this video, and this video on testing mindset. 10/10
  8. Took all the practice questions in the ISC2 Practice Test book (twice - same link as the study guide). The questions were good, but not necessarily reflective of what the exam questions look like. 7/10
  9. Took all the Boson practice Qs. Took them again and read all of the explanations. These were the single most useful resource. The explanations were great, though the questions were more technical than the exam was. 10/10

CISM:

  • I only leveraged the official practice questions for this exam and found it to be more than sufficient (if you've already taken the CISSP or have equivalent experience).
As seen in: