Sunday, May 2, 2021

InfoSec101 CheatSheet

So, you’re new to InfoSec you say?  How can I help?  Below are a few resources that I just put together for one of my mentee’s.  I offer a bunch of InfoSec links over at my DFIRLinks site:  The formatting on the blog is a bit wonky, so if you want this cheatsheet as a PDF, go here:

Jason Blanchard:
-Jason is amazing.  He runs a twice-weekly job search meet-up.  Jason works for one of the leading Cyber Security firms called Black Hills InfoSec (BHIS), owned by an industry luminary, John Strand. 

Tuesday Nights: 7-9pm ET 
Friday Afternoons: 1-3pm ET 

-Jason's job meet-up group meets over Twitch, once or twice each week.  It covers job hunting tactics and techniques, resume and interview tips, and much more.  People looking to fill open positions sometimes attend, and even recruiters have been known to attend because it’s so popular with strong candidates:

-Jason has archived some of the meet-ups on the BHIS YouTube channel:, and they are also on his Twitch channel:

-Jason's online handle is @BanjoCrashLand: 
"We're doing a 5-part extended series on each one of the aspects of the job hunt. 
52+ viewers have landed new jobs so far since March 2020."
Black Hills InfoSec (BHIS): 
BHIS runs weekly Cyber Security WebCasts which they often record and post afterward.  I try to never miss them!  They also offer discounted (pay what you can) training: 

Be sure to follow them on Twitter:

They also have an active Discord server:

-Here’s an example of their “Pay what you can” training: 

Wild West Hackin’ Fest: 
Wild West Hackin’ Fest is a Cyber Security conference by the folks at BHIS: 

-Here's an example WebCast from BHIS: The Dirty Truth Behind Breaking into Cybersecurity: 

Be sure to follow them on Twitter:
They also have an active Discord server:

Active Counter Measures (ACM):
John Strand of BHIS also runs: Active Counter Measures:
-ACM often runs free Threat Hunting classes:

Be sure to follow them on Twitter:

They also have an active Discord server:

Dave Kennedy/TrustedSec/Binary Defense: 
Dave Kennedy runs two companies (Trusted Sec and Binary Defense), and he has been known to “tweet” when they are hiring (often Junior level): 
"My favorite thing this year is we are opening up our junior program. To get new folks to INFOSEC trained up and into the field. Where best to learn!? #TrustedSec We are crazy hiring over at #TrustedSec and #BinaryDefense with more jobs being posted in the next few days. Have to shape our future, and more than pumped to have new folks coming into the industry." 

Be sure to follow them on Twitter:

They also have an active Discord server:

SANS Institute: 
Great courses as well as many free offerings:

Check out their “New-to-Cyber Field Manal”: 

Train up!  CTF’s: 
I offer a bunch of links to CTF’s and training video’s:, below is a sample: 
(1) Watch Ed's CTF talk which begins about 17.5 mins in: 
(5) Smash the Stack: 
(6) picoCTF: 
(7) WarGames (Bandit is recommended): 
(8) Daily CTF, just one challenge per day: 
(17) Hack the Box (free account works fine): 
(19) Cyber Defenders: 
(20) Try Hack Me:

I can count on one hand the recruiters whom I respect, and that’s as nice as I can put it; sorry, not sorry - been burned one too many times.  That being said, I do have two fantastic recruiters whom I can highly recommend:

Katie Owston 

John Terkovich 

No comments: