Le Duong Phi 📖 Handbook 🌐 VI

Le Duong Phi

Cyber Security Engineer

“You can't secure what you don't understand.”

Bruce Schneier

Contact

The Security Handbook

From fundamentals to real operations

Every topic answers “what is this, and what problem was it built to solve” first, then goes into the mechanics, with commands and configs you can actually run. Each chapter ends with field notes: what was misunderstood at first, and what the work itself taught.

01 Networking 02 Linux 03 Windows & AD 04 Cryptography 05 AppSec (OWASP) 06 DevSecOps 07 CI/CD & GitOps 08 SIEM & Logs 09 Observability 10 SOC & IR 11 Network Defense 12 Pentest 13 Cloud 14 Containers 15 Threat Intel 16 GRC 17 Python

Scope of work

DevSecOps & secure SDLC
SAST · SCA · secret scanning · IaC scan in CI/CD · security gates · secure coding guidelines
Monitoring & detection
SIEM · infrastructure metrics · detection engineering · alert noise reduction
Response & automation
SOAR · threat intel enrichment · runbooks · incident handling process
Infrastructure & cloud
Hardening internet-facing services · IAM least privilege · secrets management · environment separation
Training & documentation
Secure coding · threat modeling (STRIDE) · abuse cases · internal documentation

Tooling Wazuh · Shuffle · Prometheus · Grafana · Zabbix · ELK · Acunetix · pfSense · Docker · Kubernetes · AWS · OCI · GCP · Python · Bash

Projects