Security Handbook
A security handbook I've put together while learning and working. The core is foundational knowledge and technical mechanisms, organized for reference; each chapter ends with personal notes drawn from practice. I explain mechanisms in depth with real examples β to revise for myself, and hopefully to help others who are studying.
Each chapter follows the same flow: concept β how it works β practical example β security notes, favoring understanding why over rote memorization. If you spot anything inaccurate, feedback is very welcome.
How to use this handbook
Written for both newcomers and practitioners who need a quick reference β read it as you need; there's no need to read everything at once:
- The "Overview" at the top of each chapter: read it quickly to get the big picture (what it is, why it matters).
- The numbered sections (1.1, 1.2β¦): the in-depth reference, down to bit/byte/config level β no need to memorize it all now, come back when you need it.
- New to the field? Follow the suggested learning paths below; for unfamiliar terms, check the Glossary & Abbreviations appendix.
Contents
Part A β Fundamentals
| # | Chapter | Key topics |
|---|---|---|
| 01 | Computer Networking (TCP/IP, OSI) | Byte-by-byte encapsulation, Ethernet/IPv4/IPv6/TCP/UDP header layouts, ARP, subnetting, TCP handshake & state machine, NAT, DNS, TLS |
| 02 | Linux Operating System | Permissions & SUID/ACL, passwd/shadow, processes/namespaces, systemd, logging, bash + grep/awk/sed, hardening (iptables/nftables), performance & resource diagnostics |
| 03 | Windows & Active Directory | Security event IDs, Sysmon, Kerberos vs NTLM, AD attacks (PtH, Kerberoasting, golden ticket) + detection |
| 04 | Cryptography & Security Foundations | AES/RSA/ECC/DH, hashing & password storage, HMAC, digital signatures, PKI/X.509, CIA/AAA, CVE/CVSS/CWE |
Part B β Application Security & DevSecOps
| # | Chapter | Key topics |
|---|---|---|
| 05 | Web Application Security (OWASP Top 10) | OWASP Top 10 2025 edition, SQLi/XSS/CSRF/SSRF/IDOR (payload + fix), prompt injection, race conditions, JWT/OAuth2/OIDC, STRIDE, Zero Trust |
| 06 | DevSecOps & Source Code Scanning | SAST/DAST/SCA/secret/IaC, Semgrep (AST, rule writing, taint), Gitleaks/Trivy, supply chain (SLSA/SBOM), governing AI-generated code |
| 07 | CI/CD & GitOps | GitLab CI, GitHub Actions, Jenkins, Argo CD/GitOps, git submodule β real examples per tool |
Part C β Monitoring, Detection & Response
| # | Chapter | Key topics |
|---|---|---|
| 08 | SIEM & Log Management | SIEM architecture, Wazuh (decoder/rule, FIM, active response), detection engineering, a real investigation workflow, SOAR |
| 09 | Observability & Infrastructure Monitoring | Elasticsearch/Logstash/Kibana/Beats, Zabbix, Prometheus/PromQL/Alertmanager, Grafana; when to use which |
| 10 | SOC Operations & Incident Response | SOC tiers, triage, IR lifecycle (NIST/SANS), playbooks, threat hunting |
Part D β Network Defense & Testing
| # | Chapter | Key topics |
|---|---|---|
| 11 | Network Defense (IDS/IPS, WAF, Firewall, VPN) | Snort/Suricata (rules + examples), ModSecurity + CRS, pfSense, VPN (IPsec/OpenVPN/WireGuard), hardening nginx as a reverse proxy, Zeek |
| 12 | Penetration Testing & Vulnerability Assessment | Burp Suite, Acunetix, Nmap (scan types + packets, NSE) |
Part E β Infrastructure, Virtualization & Cloud
| # | Chapter | Key topics |
|---|---|---|
| 13 | Cloud Security | IAM, VPC, SG vs NACL, S3, KMS, CloudTrail/GuardDuty, IMDSv2/SSRF, cloud attacks; AWS β OCI β GCP side by side |
| 14 | Virtualization & Containers | Docker internals, container escape, Kubernetes + security (RBAC/NetworkPolicy/PSS) |
Part F β Offense, Compliance & Automation
| # | Chapter | Key topics |
|---|---|---|
| 15 | Threat Intelligence & Attack Frameworks | 14 tactics + techniques, Kill Chain, Diamond Model, IOC vs IOA, malware analysis |
| 16 | Compliance & Governance (GRC) | Risk management, NIST CSF/800-53/61/207, ISO 27001 & SOC 2, Vietnam regulations (PDP Law 91/2025) |
| 17 | Programming & Automation for Security | socket/requests/scapy/boto3, port scanner, log parser, API calls, secure coding |
Suggested learning paths
- Beginner: 01 β 02 β 04 β 05. Networking + Linux + crypto + web vulnerabilities are the foundation of everything.
- Blue Team / SOC: 01, 02, 03 β 08, 09, 10 β 15. Focus on monitoring, investigation, and understanding attacker behavior.
- AppSec / DevSecOps: 04, 05 β 06, 07 β 14, 17. Security from source code to pipeline to container.
- Cloud / Infrastructure: 01, 02 β 13, 14 β 07. Securing systems and operating environments.
- GRC / Compliance: 04 β 16 β 10. Risk management, standards frameworks, and regulations.
How to study effectively: read β explain it back in your own words β retype the examples (commands/config/rules/code) in a real lab. Security knowledge only sticks when you do it hands-on.
About
This handbook is written and shared by Fee, free for learning purposes. If you find it useful, feel free to use it for your own revision or share it onward.
This is educational content. Any offensive techniques shown here are meant to help you understand how to defend β use them responsibly and legally, only on systems you are authorized to test.