Security Notes
Start here

Knowledge Self-Assessment Matrix

Rate each topic: 0 = never seen · 1 = aware · 2 = can explain · 3 = can teach/apply under pressure

12 min read 17 sections

Update the Status column as you study. Use the Notes column for specific gaps.


How to Use

  1. Go through each row and honestly rate yourself 0–3.
  2. Highlight rows where score < 2 — these are your priority study areas.
  3. Re-assess every 1–2 weeks.
  4. Before an interview: all rows should be ≥ 2. Rows critical for the role should be 3.

Networking & Protocols

TopicScore (0–3)StatusNotes / Gaps
OSI Model (all 7 layers, what lives where)
TCP three-way handshake + state machine
TCP vs UDP — when/why each
TLS handshake (1.2 vs 1.3 differences)
DNS resolution chain (recursive, authoritative)
DNS record types (A, AAAA, MX, NS, PTR, CNAME, SOA)
DNS exfiltration detection
ARP + ARP spoofing
DHCP flow (DORA)
BGP basics + hijacking
HTTP/S request-response headers
HTTP status codes (1xx-5xx)
ICMP + traceroute mechanics
VPN vs Tor vs Proxy
SSL/TLS attacks: POODLE, BEAST, HEARTBLEED
PKI + certificate chains + trust stores
CAM table overflow
tcpdump + Wireshark usage

Web Application Security

TopicScore (0–3)StatusNotes / Gaps
Same-Origin Policy + CORS
XSS — reflected, stored, DOM-based
CSRF — mechanism + mitigations
SQL injection — blind, union, time-based
SSRF — exploitation + mitigations
Directory traversal
HSTS + HPKP
Cookie flags (HttpOnly, Secure, SameSite)
OAuth 2.0 flow + bearer token abuse
JWT — structure, none-alg attack, signing
Local/remote file inclusion
Insecure deserialization
OWASP Web Top 10 (all 10)
Content Security Policy (CSP)
Burp Suite usage

Cryptography

TopicScore (0–3)StatusNotes / Gaps
Encryption vs Encoding vs Hashing vs Signing
Symmetric encryption: AES-GCM
Asymmetric encryption: RSA, ECC
Diffie-Hellman key exchange
Forward secrecy (ephemeral keys)
HMAC — construction and use cases
Hash functions: MD5, SHA-1, SHA-256, BLAKE3
Block vs stream ciphers
Padding oracle attacks
Timing attacks + constant-time comparison
Entropy + PRNG
PKI — CA hierarchy, cert revocation (CRL, OCSP)
Envelope encryption

Authentication & Identity

TopicScore (0–3)StatusNotes / Gaps
Password hashing: bcrypt, Argon2, scrypt
MFA methods — TOTP, FIDO2, SMS
OAuth 2.0 + OIDC flow
SAML 2.0
Kerberos — ticket lifecycle, golden/silver ticket
Pass-the-hash + Pass-the-ticket
Service accounts vs user accounts
Federated identity
JWT attacks (alg:none, weak secret)
Session management + fixation

Linux & Operating Systems

TopicScore (0–3)StatusNotes / Gaps
Linux kernel architecture (ring 0 vs ring 3)
SUID/SGID binary abuse
Sudo misconfigurations + GTFOBins
DirtyCOW (CVE-2016-5195)
DirtyPipe (CVE-2022-0847)
PwnKit / Polkit (CVE-2021-4034)
eBPF verifier bugs (CVE-2021-3490)
Looney Tunables (CVE-2023-4911)
OverlayFS privesc (CVE-2023-0386)
Cron job abuse
NFS no_root_squash
Kernel mitigations: ASLR, SMEP, SMAP, stack canary
Capabilities (CAP_SYS_ADMIN, CAP_NET_ADMIN, etc.)
Namespaces (pid, net, user, mnt)
/proc, /tmp, /shadow — attacker relevance
linpeas / linux-exploit-suggester
Active Directory: Kerberos, BloodHound, DCSync
Windows: SMB, NTLM, Pass-the-hash

macOS Security

TopicScore (0–3)StatusNotes / Gaps
SIP — what it protects, known bypasses
TCC — architecture, tccd, database schema
TCC service types (FDA, Screen Recording, etc.)
TCC bypass via entitlement-privileged process
App Sandbox + data containers (~/Library/Containers)
com.apple.macl xattr — drag-and-drop grant, irrevocable
Archive Utility — privileges, preference-driven behavior
CVE-2026-28910 — full 3-weakness chain + app hijacking
AUHelperService XPC design flaw (FDA entitlement, no caller check)
Gatekeeper + quarantine xattr + notarisation
FileVault 2 — AES-XTS-256, Secure Enclave
Secure Boot levels (Full / Reduced / No Security)
XProtect + MRT + XProtect Remediator
AMFI — code signing enforcement in kernel
macOS persistence: LaunchAgents, LaunchDaemons, login items
macOS pf firewall rules
Application Firewall + stealth mode
codesign — verify app bundle integrity
macOS BSM audit framework
T2 / Secure Enclave — what it protects

CI/CD & Supply Chain Security

TopicScore (0–3)StatusNotes / Gaps
CICD-SEC-1: Insufficient flow controls
CICD-SEC-2: IAM in pipelines
CICD-SEC-3: Dependency chain abuse
CICD-SEC-4: Poisoned Pipeline Execution (PPE)
CICD-SEC-5: Pipeline-Based Access Controls (PBAC)
CICD-SEC-6: Credential hygiene
CICD-SEC-7: Insecure system config
CICD-SEC-8: 3rd party services
CICD-SEC-9: Artifact integrity (Sigstore/SLSA)
CICD-SEC-10: Logging + visibility
GitHub Actions: pull_request vs pull_request_target
OIDC in CI (replacing long-lived credentials)
Dependency confusion attack
Typosquatting
SLSA levels 1–4
Sigstore / cosign
Secrets scanning (truffleHog, gitleaks)
Branch protection + CODEOWNERS

Kubernetes

TopicScore (0–3)StatusNotes / Gaps
Control plane components (API server, etcd, scheduler)
Pod lifecycle + workload types
Service types (ClusterIP, NodePort, LoadBalancer)
RBAC — Role vs ClusterRole vs Binding
Dangerous RBAC permissions
Pod Security Standards (privileged/baseline/restricted)
Network Policies — default deny + allow patterns
Admission controllers (OPA, Kyverno)
Secrets management (native vs Vault vs ESO)
etcd encryption at rest
Container escape techniques (privileged, docker.sock, CAP_SYS_ADMIN)
Falco runtime security
Workload Identity (GKE)
Binary Authorization
K8s audit logging setup
IR: quarantine pod via NetworkPolicy
IR: SA token compromise response

AWS Security

TopicScore (0–3)StatusNotes / Gaps
IAM policy evaluation order
IAM privilege escalation paths
SCPs + permission boundaries
Security Groups vs NACLs
VPC Flow Logs
IMDSv1 vs IMDSv2 (SSRF mitigation)
CloudTrail — setup, data events, log validation
GuardDuty — key findings, integration
Security Hub
AWS Config + conformance packs
KMS — CMK, envelope encryption, key policy
S3 security (block public access, bucket policy)
Secrets Manager vs SSM Parameter Store
Inspector (EC2 + ECR scanning)
Macie (data classification)
IAM Access Analyzer
Lambda security (execution role, resource policy)
IR: compromised IAM key (contain + investigate)
IR: EC2 isolation + snapshot

GCP Security

TopicScore (0–3)StatusNotes / Gaps
GCP resource hierarchy (Org → Folder → Project)
IAM principals (user, SA, allUsers, allAuthenticatedUsers)
Role types (primitive vs predefined vs custom)
Dangerous GCP IAM permissions
Org Policy constraints
VPC Service Controls (perimeters, access levels)
Security Command Center (SCC) feature set
Cloud Audit Logs (3 types)
Workload Identity for GKE
Service account key risks + key-less alternatives
Cloud Armor (WAF + DDoS)
Secret Manager
Binary Authorization
Chronicle SIEM + YARA-L
GCPloit / SA impersonation attacks
Metadata server SSRF (GCE)
IR: compromised SA key
IR: crypto mining on GCE

AI / LLM Security (OWASP 2025)

TopicScore (0–3)StatusNotes / Gaps
LLM01: Prompt injection (direct + indirect)
LLM02: Sensitive information disclosure
LLM03: Supply chain (model/plugin/package)
LLM04: Data and model poisoning
LLM05: Improper output handling (XSS, SQLi, RCE)
LLM06: Excessive agency
LLM07: System prompt leakage
LLM08: Vector/embedding weaknesses
LLM09: Misinformation / hallucination risk
LLM10: Unbounded consumption / DoS
RAG architecture + indirect injection via retrieval
LLM agent privilege design (least privilege)

Detection & Forensics

TopicScore (0–3)StatusNotes / Gaps
SIEM concepts + Splunk/Chronicle queries
IOC types (IP, hash, domain, behaviour)
YARA rule writing
Snort/Suricata signatures
Honeypots + canary tokens
Anomaly vs signature-based detection
VPC/network flow log analysis
Memory forensics (Volatility)
Disk forensics (FTK, The Sleuth Kit)
Chain of custody
Anti-forensics techniques
Malware analysis: static vs dynamic
Cyber kill chain stages
MITRE ATT&CK framework (navigation)

Incident Management

TopicScore (0–3)StatusNotes / Gaps
PICERL phases + what happens in each
Google IMAG model
Communication in an incident (who, when, how)
Triage vs investigation vs containment distinction
Legal/privacy notification obligations
Playbook structure
Post-mortem format + blameless culture
Tabletop exercise facilitation

Python / Coding

TopicScore (0–3)StatusNotes / Gaps
String manipulation (reverse, anagram, palindrome)
List operations (two-sum, merge sorted, rotate)
Dict patterns (counting, grouping)
Recursion (fibonacci, factorial, permutations)
Sliding window / two-pointer
Sorting with custom key
OOP: classes, inheritance, dunders
Context managers
Regex in Python
Big O — time and space
Log parser in Python
Port scanner in Python
Rate limiter implementation
HMAC / crypto primitives in Python
Python security anti-patterns (eval, pickle, shell=True)

Threat Modelling

TopicScore (0–3)StatusNotes / Gaps
STRIDE framework (all 6)
DREAD risk scoring
Data Flow Diagrams + trust boundaries
MITRE ATT&CK for threat hunting
Attack trees
PASTA methodology
Secure design principles

Scoring Summary

Copy your scores here after each session for trend tracking.

DateNetworkingWeb AppCryptoAuthLinuxCI/CDK8sAWSGCPAI/LLMDetectionCoding

Target before interviewaverage ≥ 2.5 across all domains; no domain below 2.