
Return to volume two and proceed to the goals and learning objectives. Complete volume one first for the recommended foundation, as the introduction is optional but helpful.
Meet Nathan House, CEO of Station X, a 24-year cyber security veteran who advised Vodafone, BP, Visa, and the London 2012 Olympics, guiding you through network security, privacy, and anonymity.
Stay up to date with security updates as the landscape evolves by actively updating course material and inviting your feedback, recommendations, and questions.
How to start a career in cyber security and ethical hacking.
Identify the basics of networking, the roles of network devices, and assess internal and external vulnerabilities on routers, then explore custom router firmware to expand security services.
discover how the home router serves as a security hub, connecting devices via ethernet and wifi, acting as default gateway, and moderating traffic with nat, firewall rules, and dhcp.
Learn how external vulnerability scanning reveals open ports and misconfigurations on home routers using Shodan, Nmap, and Qualys, and apply best practices like patching, disabling UPnP, and secure port forwarding.
Map your internal network to see devices and ports using nmap, zenmap, fing, and superscan. Then run vulnerability scans with mbsa, openvas, nessus, and qualys, including authenticated vs unauthenticated checks.
Discover how open source custom router firmware like OpenWrt and dd-wrt enhances security and performance, enabling VPNs, VLANs, isolated Wi-Fi, real-time monitoring, and flexible hardware support.
Compare virtual, network, and host-based firewalls to identify what they protect against and what they miss, and explore top firewall options across Windows, macOS, Linux, routers, and dedicated devices.
Explore host-based, network-based, and virtual firewalls and how access control lists govern traffic by port, protocol, address, and network address translation, including inbound and outbound filtering and deep packet inspection.
Explore Windows host-based firewall basics, default inbound deny outbound allow all, and how to lock down networks by blocking all and explicitly allowing essentials like DHCP, DNS, and VPN.
Learn to use Linux host-based firewalls with ufw, gufw, and nftables, configure default deny rules, manage IPv4/IPv6 and DHCP rules, and assess their value on untrusted networks.
Explore macOS host-based firewalls by configuring the application firewall for per-application incoming control and leveraging pf, the BSD packet filter, with anchors and PF rules to secure network traffic.
Compare macOS host-based PF frontends—pfList, IceFloor, and Murus (Lite, Basic, Pro). Murus Pro adds Vallum, drag‑and‑drop rules, inbound/outbound control, and presets; Lite has feature limits.
Discover how Little Snitch for macOS acts as a host based, application aware firewall with live traffic monitoring, per-application rules, outbound blocking, and silent mode.
Explore router based firewalls using dd-wrt and openwrt, learn iptables configuration through gui or command line, and enhance network security with filters, logging, and encryption.
Explore hardware and virtual network firewalls, from dedicated devices and APU platforms to repurposed PCs, acting as routers and firewalls with multiple network cards for network isolation.
Identify attack vectors on a network, including IoT risks and ART problems, and architect your network to mitigate those attacks and prevent propagation.
Explore why network isolation matters, separating untrusted IoT devices from trusted networks to prevent malware propagation and man-in-the-middle attacks, while balancing administrative burden.
Learn how switches use MAC addresses in their MAC table to forward traffic at the data link layer and how ARP spoofing enables man-in-the-middle attacks, injections, and DoS, with mitigations.
Explore advanced network isolation techniques, from arp protection tools like netcut and arpwatch to MACsec, 802.1X, DHCP snooping, and VLAN security, plus VPN overlays for a secure local network.
Examine Wi-Fi weaknesses such as WPS pin vulnerability, evil twin, and rogue access points, and learn mitigations like WPA2-Enterprise, certificate authentication, encryption, and VPN use.
Learn to perform wifi security testing using Kali Linux with compatible USB adapters for monitor mode and packet injection, and explore tools like Aircrack-ng, coWPAtty, Reaver, and Fern-Wifi-Cracker.
Strengthen wifi security with full network isolation, separate untrusted and semi-trusted networks, and AP isolation; use WPA2-Enterprise with EAP or strong WPA2, TLS or VPN, and keep firmware updated.
Implement rf isolation and reduction to mitigate local and remote attacks by performing a wireless signal detection survey, mapping coverage, and limiting access point power with dd-wrt and directional antennas.
Monitor your network to detect threats and attackers secretly communicating in and out of your network. Learn to find hackers and malware and stop protocol leaks.
Explain how syslog collects network device logs to a central server using RFC 5424. Show configuring facilities and severity levels, and transport options like UDP/TCP and TLS across devices.
Learn to monitor network traffic with Wireshark, tcpdump, tshark, and iptables, running on routers or devices to detect security and privacy events, analyze interfaces, DNS, and potential VPN leaks.
Learn how to capture and monitor network traffic using Wireshark, tcpdump, tshark and iptables, including remote capture over ssh, port mirroring, and live piping to Wireshark for real-time analysis.
Explore how Wireshark acts as a protocol analyzer to detect security and privacy issues, capture traffic, inspect frames across Ethernet and IP layers, and apply filters to identify suspicious traffic.
Install WinPcap on Windows and capture packets with Wireshark for remote network analysis; explore NST 22, NetworkMiner for forensics on Linux/macOS, and NetWorx for Windows to monitor usage and bandwidth.
Discover techniques ISPs, corporations, and states use to track you online and erode privacy, from cookies to supercookies, HTTP ETags and web cache. Learn how you are tracked and profiled.
Explore how online tracking happens through login and non-login sites, third-party widgets, ad networks, and email providers, and how ISPs, mobile networks, workplaces, and schools log visits and DNS queries.
Discover how IP addresses identify devices, distinguish local from external addresses, and how NAT protects you while exposing how tools like ping, netstat, and Wireshark reveal traffic.
Use a Burp proxy to show how visiting a site triggers connections to multiple first- and third-party domains, cookies, ad networks, and analytics like Google Analytics.
Discover how the HTTP referer header reveals your source page when loading third party content like ads, tracking scripts, and conversion or audience pixels in emails.
Explore how cookies and scripts track you across sites, including session, first-party, and third-party cookies, and the role of analytics networks like Google Analytics.
Examine super cookies, resilient tracking methods that survive deletion via techniques such as evercookie, flash cookies, HTML5 storage, and telco injected headers, enabling profiling; HTTPS helps limit exposure.
Understand how browser features like geolocation, send_pings, and WebRTC reveal location and IP, impacting privacy and advertising. Examine how phishing protection, extensions, and HTML canvas fingerprinting affect tracking.
Explore how nation-state actors use cookies, IP addresses, browser fingerprints, and presence events to create population-scale profiles for targeted surveillance, and how encryption can mitigate passive data collection.
Learn how search engines log and track your activity via cookies and analytics, how censorship and privacy risks arise, and basic mitigations like using https.
Explore Ixquick and Startpage, privacy-first meta search options that avoid IP tracking and Google monitoring, and learn how proxies and cookies affect anonymity.
DuckDuckGo is a privacy-focused meta search engine based in the United States. It does not collect or share personal information by default and uses sources like Yahoo, Bing, and Wikipedia.
Explore privacy and anonymity in online searching using private browsing, HTTPS, and privacy-conscious search engines like DuckDuckGo, Startpage, and YaCy, plus manage Google logs to improve OPSEC.
Reduce the browser attack surface and harden it for maximum security and privacy. Learn how browsers are hacked and mitigate attack vectors, with a deep dive into the Firefox browser.
Reduce your browser attack surface by disabling or removing unused internet-facing components, especially Java, Flash, Silverlight, and JavaScript. Learn practical controls for Firefox plugins, PDFs, and safe browser settings.
Explore how browsers get hacked through social engineering, cross-site scripting, and malicious scripts, then use BeEF and Metasploit in Kali Linux to gain reverse shells and remote access.
Implement browser isolation and compartmentalization to protect against hacking and tracking by using sandboxes or virtual machines, cloud browsers, and isolated profiles to reduce cross-contamination.
Explore Firefox security, privacy features, and tracking controls, including do not track, tracking protection, private windows, history settings, and safe browsing, with practical tips to balance privacy and usability.
Explore how uBlock origin uses http filtering and script blocking to block malware ads, malvertisement, phishing links, and tracking, while balancing privacy, security, and browser performance.
Compare Disconnect, Ghostery, and RequestPolicy as HTTP filters and ad blockers for privacy and security. Learn their limitations versus uBlock Origin and uMatrix.
Explore the Policeman add-on to enforce content-type rules—allow images and styles, block scripts and frames—with a mini rule language and domain controls, plus virustotal checks.
Explore how browser history, cookies, and super cookies track you, and implement privacy defenses using private browsing and non-persistent systems to prevent forensic traces.
Explore how http referer headers track navigation through links and content, and learn to control or spoof referers with RefControl, Smart Referer, Firefox about:config, and uMatrix.
Learn how browser fingerprinting uses user agents, fonts, plugins, and HTML5 canvas to uniquely identify browsers without cookies, and explore defenses like canvas blockers, plugin management, and user-agent randomization.
Become a cyber security specialist.
After this course, you will be able to discover security vulnerabilities across an entire network, by using network hacking techniques and vulnerability scanning.
You will be able to architect your network for maximum security and prevent local and remote attacks. We also cover the use of custom router firmware to provide you with better network security services.
You will understand the various types of firewalls that are available and what threats each help mitigate.
Including layer 4 firewalls like Iptables on Linux and PF on MacOS and BSD. Virtual firewalls, host-based firewalls and application based firewalls like Pfsence. We cover firewalls on all platforms including Windows, Mac OS X and Linux for all types of use scenarios.
We explore in detail wireless security, the configurations that are required for maximum security and why. How Wi-Fi is hacked and how to mitigate those attacks. Covering everything from encryption weaknesses to evil twins, RF isolation, and Wi-Fi crackers.
You will master network monitoring to discover and identify potential hackers, malware and other adversaries that might be lurking on your network. Using tools like Wireshark, Tcpdump and Syslog.
We then move away from network security and onto the details of how we are tracked online by corporations, nation-states your ISP and others. You will understand the techniques used like zombie super cookies, browser fingerprinting and how browser profiling works so third parties can establish who you are online.
We look at search engine privacy - and how to mitigate the tracking and privacy issues of search engines and their associated services.
Browser security - We cover one of the largest risks online, the browser. The doorway into your system. How to best reduce the attack surface of the browser and harden it for maximum security and privacy. A critical consideration for reducing your risk.
Finally you will fully understand how to best use methods of authentication including passwords and multi-factor authentication - soft tokens and hard tokens.
The best password managers to use and why. How passwords are cracked, and how to mitigate the cracking.
This is volume 2 of 4 of your complete guide to cyber security privacy and anonymity.