Cyber security · Course by Ravindra Bagale
Cyber Security Course
Cyber Security Study Guide: From Networking & Linux to Kali Linux and Ethical Hacking
A free online cyber security and ethical hacking course for beginners, with a map of the CEH exam modules. The lessons are in simple English with Marathi phrases, and Ravindra Bagale's online and offline Cyber Security classes are taught in Marathi and Hindi.
Networking, Linux on AWS EC2, Apache and Nginx, LAMP/LEMP, MySQL, domains and HTTPS, S3 and RDS and a live project first; then Kali Linux and ethical hacking in your own lab, OWASP Top 10, cloud security, SOC and defence.
50 chapters400 concepts13 parts
Course outline
Click a chapter to see its concepts. Each concept has its own page.
Part 1 Networking Foundations
Part 2 Linux on AWS EC2
5. Linux Basic Commands 9 concepts
6. Linux Advanced Commands 11 concepts
- 6.1 Searching Text: grep
- 6.2 Finding Files: find
- 6.3 Text Processing: awk and sed
- 6.4 Pipes, Redirection and Here-Documents
- 6.5 Archives and Compression: tar , gzip , zip
- 6.6 Services and Logs: service , systemctl enable , journalctl
- 6.7 Networking Commands
- 6.8 Disk and Storage Commands
- 6.9 Scheduling Tasks: cron
- 6.10 Remote Access: ssh , scp , rsync and Environment Variables
- 6.11 Basic Shell Scripting
Part 3 Web Servers
7. Apache and Nginx: Install and Understand 7 concepts
- 7.1 What a Web Server Does: Nginx vs Apache
- 7.2 Quick Reference: Packages, Services and Paths
- 7.3 Installing Nginx and Apache on Amazon Linux 2023
- 7.4 Installing Nginx and Apache on Ubuntu
- 7.5 Reading an Nginx Server Block
- 7.6 Reading an Apache Virtual Host
- 7.7 Everyday Management Commands and SELinux Basics
Part 4 Dynamic Hosting
9. PHP, LAMP and LEMP Step by Step 8 concepts
Part 5 MySQL
11. MySQL Part 2: UPDATE, ALTER, DELETE, Keys, Constraints and Users 7 concepts
- 11.1 UPDATE
- 11.2 Safe Update Mode, Error 1175 and Transactions
- 11.3 ALTER TABLE: Add, Modify, Rename and Drop Columns
- 11.4 DELETE, TRUNCATE and DROP
- 11.5 Keys: Primary, Foreign, Unique, Composite, Candidate, Super, Alternate
- 11.6 Constraints: NOT NULL, DEFAULT, CHECK, AUTO_INCREMENT
- 11.7 Users, GRANT, REVOKE and Least Privilege
Part 6 Domains, Multiple Websites and HTTPS
Part 7 AWS S3 and RDS MySQL
14. Amazon S3: Buckets, Objects, Policies and Presigned URLs 7 concepts
- 14.1 What S3 Is: Buckets, Objects and Keys
- 14.2 Creating a Bucket and Uploading Objects
- 14.3 Block Public Access and Bucket Policies
- 14.4 Hosting a Static Website on S3
- 14.5 Versioning and Lifecycle Rules
- 14.6 Presigned URLs: Temporary Private Access
- 14.7 Encryption, Logging, IAM Roles and the S3 Security Checklist
15. Amazon RDS for MySQL: Create, Connect, Back Up and Keep It Private 6 concepts
- 15.1 What RDS Is and Why Companies Use It
- 15.2 Planning the Network: Subnet Group and Security Groups
- 15.3 Creating an RDS MySQL Instance Step by Step
- 15.4 Connecting from EC2 and Creating the Application User
- 15.5 Automated Backups, Snapshots and Restore
- 15.6 Hardening RDS: Never Public, Encrypted, Monitored
Part 8 Live Project: Mitrano Reels
16. Live Project: Building a Reels App with EC2, S3 and RDS 13 concepts
- 16.1 Project Overview and Architecture
- 16.2 AWS Setup: S3 Bucket, IAM Role and RDS
- 16.3 Server Setup: LEMP, Composer and the AWS SDK for PHP
- 16.4 Database Schema
- 16.5 Configuration and Shared Code
- 16.6 Accounts: Register, Login and Logout
- 16.7 Uploading Videos and Text Posts
- 16.8 The Feed API and Likes
- 16.9 The Reel UI: HTML, CSS and JavaScript
- 16.10 Deployment: Nginx, PHP Settings and Going Live
- 16.11 Domain and HTTPS
- 16.12 Testing and Troubleshooting
- 16.13 Security Checklist: The Target You Will Secure
Part 9 The Bridge: Why Learn All This Before Kali Linux
17. Why Learn All This Before Kali Linux? 7 concepts
- 17.1 You Can't Hack or Secure What You Don't Understand
- 17.2 From Networking to Nmap and Wireshark
- 17.3 From Linux and SSH to Brute Force, Privilege Escalation and Hardening
- 17.4 From HTTP and Web Servers to Burp Suite, Nikto and Misconfigurations
- 17.5 From MySQL to SQL Injection
- 17.6 From S3, RDS and IAM to Cloud Misconfigurations
- 17.7 Your Project as the Target: Roadmap for the Next Parts
Part 10 Kali Linux: Ethical Hacking Tools
18. Ethics, the Law and a Safe Kali Lab 7 concepts
19. Information Gathering and Scanning 11 concepts
- 19.1 Passive vs Active Recon
- 19.2 whois and dig
- 19.3 theHarvester and Recon-ng (Overview)
- 19.4 Maltego Introduction
- 19.5 Netdiscover: Finding Lab Hosts
- 19.6 Nmap Basics: Host Discovery, Port States and Scan Types
- 19.7 Service Versions, OS Detection and NSE Scripts
- 19.8 Timing, Output Formats and Scan Hygiene
- 19.9 Masscan: Very Fast Port Scanning
- 19.10 How Defenders Detect Scanning
- 19.11 Red vs Blue, Project and Real Incidents
20. Vulnerability Scanning and Assessment 8 concepts
- 20.1 Vulnerability, CVE, CWE and CVSS
- 20.2 Manual Lookup: searchsploit and Exploit-DB
- 20.3 Nmap Vulnerability Scripts
- 20.4 OpenVAS / Greenbone: Full Vulnerability Scanning
- 20.5 Nikto: Web Server Scanning
- 20.6 Reading Results: False Positives and Prioritising
- 20.7 Writing a Vulnerability Report
- 20.8 Red vs Blue, Project and Real Incidents
21. Web Application Testing Tools 8 concepts
- 21.1 How Web Testing Works: The Intercepting Proxy
- 21.2 Burp Suite: Proxy and Intercept
- 21.3 Burp Intruder: Automating Requests
- 21.4 OWASP ZAP: A Free Full Scanner
- 21.5 Gobuster and Dirb: Finding Hidden Content
- 21.6 sqlmap: Testing for SQL Injection
- 21.7 WPScan: Scanning WordPress
- 21.8 Red vs Blue, Project and Real Incidents
23. Exploitation with Metasploit 7 concepts
Part 11 The Ethical Hacking Course
29. OWASP Top 10 Web Vulnerabilities 8 concepts
- 29.1 What OWASP and the Top 10 Are
- 29.2 A03 Injection: SQL Injection
- 29.3 A03 Injection: Cross-Site Scripting (XSS)
- 29.4 A03 Injection: Command Injection
- 29.5 A01 Broken Access Control and IDOR
- 29.6 A07 Authentication and A02 Cryptographic Failures
- 29.7 The Rest: Design, Components, Integrity, Logging, SSRF
- 29.8 Red vs Blue, Project and Real Incidents
30. Cloud and AWS Security 7 concepts
32. Linux and Network Hardening 7 concepts
33. Cryptography Basics 7 concepts
34. Indian Cyber Law and Cyber Crime Awareness 7 concepts
- 34.1 More IT Act Sections You Should Know
- 34.2 New Criminal Laws and Electronic Evidence
- 34.3 CERT-In Directions for Organisations
- 34.4 The Digital Personal Data Protection Act, 2023
- 34.5 Common Cyber Frauds in India and How to Spot Them
- 34.6 What to Do If You Are a Victim
- 34.7 Red vs Blue, Project and Real Incidents
Part 12 Advanced Tools and CEH Modules
36. More Essential Kali Tools 7 concepts
38. Active Directory Attacks and Defence 9 concepts
- 38.1 AD Basics for Defenders
- 38.2 Safe AD Lab Setup
- 38.3 Enumeration of AD
- 38.4 Kerberos Basics: AS-REP Roasting and Kerberoasting (Defensive View)
- 38.5 NTLM Relay and Pass-the-Hash Concepts (Lab Only)
- 38.6 BloodHound Attack-Path Analysis
- 38.7 Privilege Escalation Paths and Domain Admin Risks
- 38.8 Defence Checklist – Raja-Rani Traders Style AD
- 38.9 Putting It Together – Purple Team Mindset
39. Malware Threats 9 concepts
- 39.1 What Is Malware – Types for Defenders
- 39.2 How Malware Spreads
- 39.3 Ransomware Deep Dive – Raja-Rani Traders
- 39.4 Static vs Dynamic Analysis Mindset
- 39.5 Indicators of Compromise (IOC)
- 39.6 Defence Stack – Practical Controls
- 39.7 Safe Malware Lab Setup
- 39.8 Incident Response for Malware + CERT-In Awareness
- 39.9 Putting It Together – Purple Team Mindset
40. DoS and DDoS – Availability Attacks 10 concepts
- 40.1 What Is DoS vs DDoS – Availability First
- 40.2 Volumetric and Flood Concepts – Defender View
- 40.3 Protocol Attacks – SYN Flood and Handshake Abuse
- 40.4 Amplification and Reflection – Closed Lab Only
- 40.5 Application-Layer DoS – Slow and Heavy Requests
- 40.6 Botnets and IoT – Mirai-Class Lesson
- 40.7 Detection and Defence Stack
- 40.8 Lab-Safe Simulation – Ethics First
- 40.9 Incident Response for Availability Attacks + CERT-In Awareness
- 40.10 Putting It Together – Purple Team Mindset
41. Session Hijacking – Tokens, Cookies and Defence 10 concepts
- 41.1 What Is a Session – Why Hijacking Matters
- 41.2 Cookie Theft and Insecure Transit
- 41.3 Session Fixation and Predictable IDs
- 41.4 XSS Path to Session Cookies – Defence First
- 41.5 Network Sniffing of Sessions – Host-Only Concepts
- 41.6 Application-Level Hijack – URL Tokens, CSRF, JWT Concepts
- 41.7 Detection – Logs, Concurrent Sessions, SIEM Signals
- 41.8 Defence Hardening Checklist
- 41.9 Lab-Safe PHP Cookie Demo + Ethics / IT Act
- 41.10 Putting It Together – Purple Team Mindset
42. Evading IDS, Firewalls and Honeypots – Detection Games 10 concepts
- 42.1 IDS vs IPS vs Firewall vs Honeypot – Why Each Exists
- 42.2 Signature vs Anomaly IDS – False Positives and False Negatives
- 42.3 Fragmentation, Encoding, Obfuscation – Concepts, Then Reassembly
- 42.4 Slow Scans, Timing, Port Knocking – Nmap vs Blue Rate Alerts
- 42.5 Firewall Types – What "Evasion" Means to Blue
- 42.6 Honeypots and Honeynets – Deception, Ethics, Alerts
- 42.7 Covering Tracks vs Log Integrity – Blue Wins
- 42.8 Lab – Suricata or firewalld Logging on OWN VM
- 42.9 Project, Ethics and IT Act
- 42.10 Putting It Together – Purple Team Mindset
43. IoT and OT Security – Cameras, Smart Devices, Plant Networks 10 concepts
- 43.1 IoT vs OT / ICS / SCADA – CIA Plus Safety
- 43.2 Attack Surface – Defaults, Telnet, HTTP, UPnP, Dashboards
- 43.3 Protocol Awareness – MQTT, CoAP, Modbus, DNP3
- 43.4 Mirai-Class Botnets – Weak IoT, Outbound C2
- 43.5 Network Segregation – IT / OT Zones, Jump Hosts, firewalld
- 43.6 Internet Exposure Awareness – Your Lab Only
- 43.7 Firmware, Updates and Supply-Chain Hygiene
- 43.8 Detection – Outbound IoT, Failed Logins, Protocol Oddities
- 43.9 Lab – Mosquitto MQTT or Fake Camera UI on OWN VM
- 43.10 Project, Ethics, IT Act and Purple Interview Lines
44. Mobile Device Security – Android, iPhone, Bluetooth and Wi-Fi 10 concepts
- 44.1 Mobile Threat Model – What Can Go Wrong
- 44.2 Android Security Model – Permissions, Play Protect, Sideloading
- 44.3 iPhone / iOS Security Model – App Store, Sandbox, Lockdown Mode
- 44.4 Signs a Phone May Be Compromised – Practical Checklist
- 44.5 Cleanup and Response – If You Believe the Phone Is Compromised
- 44.6 MDM and BYOD – SME Concepts for Sahyadri Traders
- 44.7 Bluetooth Risks – Pairing Hygiene and BlueBorne Awareness
- 44.8 Wi-Fi on Phones – Evil Twin and Captive Portal Awareness
- 44.9 Hardening Checklist and Permission-Hygiene Lab
- 44.10 Project, Ethics, IT Act and Purple Interview Lines
Part 13 Revision: Exercises, Interviews and CEH Exam Modules
45. Practice Exercises with Hints 10 concepts
- 45.1 How to Use These Exercises – Ethics First
- 45.2 Networking Foundations – Quick Fire
- 45.3 Linux on EC2 – Commands You Must Type Blind
- 45.4 Web Servers and MySQL – Build and Protect
- 45.5 Domains, S3, RDS and Project Checklist
- 45.6 Kali Recon, Scan and Enum – Host-Only Only
- 45.7 OWASP Top 10 – Fix What You Break (DVWA / Juice)
- 45.8 Cloud, SOC, Hardening and Crypto – Mixed Drill
- 45.9 Advanced Defensive Drills – AD to Mobile
- 45.10 Capstone – Project Build-Hack-Fix (Sahyadri or Raja-Rani)
46. General Interview Q and A 11 concepts
- 46.1 How to Answer Cyber / SOC / Cloud Security Interviews
- 46.2 Networking Interview Questions
- 46.3 Linux on EC2 Interview Questions
- 46.4 Web Servers and MySQL Interview Questions
- 46.5 Domains, S3, RDS and Live-Project Security Questions
- 46.6 AWS Cloud Security Interview Questions
- 46.7 Ethical Hacking, OWASP and Kali Lab Questions
- 46.8 SOC, IR, Hardening and Cryptography Questions
- 46.9 AD, Malware, Session, IoT and Mobile — Defensive Talking Points
- 46.10 Scenario Round — Sahyadri / Raja-Rani
- 46.11 Red vs Blue, Project and Real Incidents
47. Interview Questions Asked in MNC Interviews 10 concepts
- 47.1 How to Use This Chapter – Sources and Ethics
- 47.2 Networking and Protocols (MNC rounds)
- 47.3 Linux, Logs and Windows Event IDs
- 47.4 SOC Analyst Round – SIEM, Triage, MITRE
- 47.5 Identity Attacks Awareness (Kerberos / PTH – defensive talking points only)
- 47.6 Cloud and AWS Security MNC Themes
- 47.7 OWASP / Web / Email Auth (SPF DKIM DMARC)
- 47.8 Scenario and HR + Technical Mix
- 47.9 Source Appendix (URLs actually read)
- 47.10 Red vs Blue, Project and Real Incidents
48. CEH v13 Exam Modules Map and Practice Questions 9 concepts
- 48.1 How to Use This Map – Ethics and Exam Mindset
- 48.2 Modules 01–05 Map (Intro through Vulnerability Analysis)
- 48.3 Modules 06–10 Map (System Hacking through DoS)
- 48.4 Modules 11–15 Map (Session Hijacking through SQL Injection)
- 48.5 Modules 16–20 Map (Wireless through Cryptography)
- 48.6 CEH-Style Practice Questions – Set A (Modules 01–10)
- 48.7 CEH-Style Practice Questions – Set B (Modules 11–20)
- 48.8 Quick Revision Table – Module → Book Chapter → Blue Control
- 48.9 Red vs Blue, Project and Real Incidents
Frequently asked questions
Is this Cyber Security course free?
Yes. All 50 chapters and 400 concept pages are free to read online, and you do not need an account.
Is the Cyber Security course in Marathi?
The lessons on this website are written in simple English with some Marathi phrases in the trainer's voice. In his online and offline classes, Ravindra Bagale teaches in Marathi, with some Hindi.
What does the cyber security course cover?
Networking, Linux on AWS EC2, Apache and Nginx, LAMP/LEMP, MySQL, domains and HTTPS, S3 and RDS and a live project first; then Kali Linux and ethical hacking in your own lab, OWASP Top 10, cloud security, SOC and defence.
Does the course follow the CEH exam modules?
48. CEH v13 Exam Modules Map and Practice Questions maps the course to the CEH v13 exam modules, with practice questions.
Do I need networking and Linux before ethical hacking?
The course teaches networking, Linux on AWS EC2, web servers, MySQL and AWS first, then Kali Linux. 17. Why Learn All This Before Kali Linux? explains why.
Is it legal to practise these ethical hacking techniques?
Every attack technique in this course is for learning in your own practice lab or on systems you have written permission to test. Unauthorised access is a crime. See 18. Ethics, the Law and a Safe Kali Lab.
How do I join online or offline cyber security classes?
Send an enquiry on the enquiry page, or call / WhatsApp 7690071001. Ravindra Bagale runs online and offline batches for Cyber Security.
Join an online / offline batch — Enquire now
Ravindra Bagale runs online and offline batches for AWS Cloud, DevOps, Power BI, Excel, Data Analytics, Data Science and Cyber Security.