
LevelUp Cyber · 2024-10-15 · 32 min
Key moments - from our scoring
Substance score
55 / 100
Five dimensions, 20 points each
Building a home lab doesn't require the five-figure investment many assume necessary to start a cybersecurity career. Nimish Datta walked through a practical, step-by-step approach to establishing a home lab using free hypervisor software like VirtualBox and VMware, free operating systems like Ubuntu and Kali Linux, and online resources from YouTube creators like Network Chuck and Josh Macador. The episode maps out five difficulty levels from basic Linux installation to advanced setups involving Active Directory, Metasploitable machines, and vulnerability exploitation. Datta emphasized that the primary cost is a decent I7 or I9 laptop ($500-$2,000), available secondhand through eBay or Facebook Marketplace, with no other significant expenses for beginners. He stressed that home lab scope should grow with knowledge - starting with Linux fundamentals, moving to Active Directory configuration, then progressing to penetration testing frameworks. His experience came largely from self-teaching after a failed interview, mentorship from Michael Bird, and practical application of theoretical knowledge from his master's degree. The discussion clarifies how labs serve as safe, isolated environments to learn exploitation techniques like EternalBlue and SMB vulnerabilities, and how documenting these projects on YouTube builds credibility with employers.
A laptop with an I7 or I9 processor and 12GB of RAM is sufficient; budget $500-$2,000 for a used machine from eBay or Facebook Marketplace. Most operating systems and hypervisor software (VirtualBox, VMware) are free.
Ubuntu Linux is the best starting point for beginners because it's free, stable, and has extensive online tutorials; after mastering Linux basics, add Kali Linux for penetration testing skills.
Active Directory is fundamental to enterprise cybersecurity and is transitioning to cloud environments like Microsoft Entra; mastering its setup, domain controllers, and identity management gives you significant competitive advantage with employers.
Beyond the laptop ($500-$2,000), there are essentially no additional costs - hypervisors like VirtualBox are free, Linux distributions are free, and most learning resources are free on YouTube.
Start by installing a hypervisor like VirtualBox, then install Ubuntu Linux, learn basic Linux commands and scripting, then progress to Windows Server and Active Directory configuration before attempting exploitation techniques.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains practical, actionable advice for building home cyber labs (VirtualBox setup, Ubuntu installation, Active Directory configuration, exploit examples like EternalBlue) that would genuinely help someone breaking into cybersecurity. However, substantial portions consist of basic explanations, repetition of concepts, and generic platitudes ('Google is your best friend,' 'polish your basics'). The screen-sharing technical walkthroughs add concrete value, but overall filler outweighs novel insight.
The first thing that you want to figure out is how do I get a hypervisor in my system
I would highly suggest for any beginner, after you learn how to install Ubuntu on your system, download a Windows server twenty twenty two and configure active directory on it
The core framework - building a home lab with free/cheap tools to learn cybersecurity - is well-trodden and widely discussed in security communities. The specific recommendations (VirtualBox, Ubuntu, Kali Linux, Active Directory) are standard entry-level advice recycled across countless blogs, YouTube channels, and bootcamps. There is no contrarian perspective, novel angle, or first-principles rethinking. The guest follows conventional wisdom throughout.
I've taken a pretty conventional approach in cybersecurity
there are some amazing resources available online. You could have someone like Network Chuck tell you how to run Linux
Nimish is early-career (recently completed master's, newly employed as cybersecurity instructor) rather than a seasoned practitioner or operator at scale. While he has built a home lab and now teaches, he lacks the seniority, domain expertise, or large-scale operational experience that would make this a marquee guest. He explicitly states he took a 'conventional path' and is 'early in his career.' Useful for beginners but not a caliber of guest who moves the needle for experienced operators.
I'm originally from India, all over the place...came to Saint Louis, United States in January of twenty twenty two for my master's degree
I'm currently teaching as a cybersecurity instructor
The episode includes concrete technical specifics: VirtualBox and VMware as hypervisor options, Ubuntu and Kali Linux distributions, Windows Server 2022 for Active Directory, the EternalBlue exploit (MS17-010, port 445, SMB), MetaSploitable for practice, Python/Bash/PowerShell languages, and hardware budgets ($500 - $2,000). The host mentions WannaCry and their own lab costs (data storage, droplets, phone numbers). However, claims lack quantitative evidence (no metrics on job placement, skill lift, interview pass rates) and examples remain illustrative rather than detailed case studies.
I would suggest if you can buy a decent I five or I seven laptop, I would highly recommend an I Seven laptop. If you can get an Eye nine, that would be amazing. So anything from five hundred to two thousand dollars
There was this Eternal Blue exploit that had happened a couple years ago. It used to it would exploit the SMB file sharing service, which is port four four five
The host (Tony/Brian) asks generally soft, open-ended questions that allow the guest to deliver prepared remarks ('What is a lab and range?', 'Where did you start?') but rarely probes deeper, challenges claims, or pushes back. Follow-ups are minimal and non-adversarial. The host does add personal anecdotes (Microcenter, WannaCry experience, their own lab), which is conversational but doesn't constitute sharp interviewing. No moment of productive disagreement or intellectual tension emerges.
So Nimish, thanks for joining us today. I've had a great pleasure of getting to know you. I'd love to have you take a second introduce yourself
I'm sure somebody listening right now is by thinking there, I can never do this
Computed from the transcript - who did the talking, and the words that came up most.
Get ready for an exciting new episode of the LevelUp Cyber Show with special guest Nimish Datta , Cybersecurity Instructor, and host Tony Bryan, Executive Director of CyberUp, as they uncover the secrets of "How to Build Your Own Cyber Lab!" Join Nimish as he walks us through the process of building a personalized cyber lab. Learn about the essential tools, resources, and strategies needed to create your own lab for hands-on experience and skill development in cybersecurity.
Transcribed and scored by The B2B Podcast Index.
Good afternoon, and welcome to this week's episode of Level of Cyber My name is Tony and Brian, your host and executive director of Cyber Up. Thanks again for joining us today. I hope you know, for those of tune in each week you like our guests and like our show. This one is a little bit different.
I'm excited about today's topic, but we're going to jump into the world of kind of cyber labs and how to build one at your home. I know it's been a thing that we have talked about for years and a great way to highlight skills and really show a little bit of extra initiative for individuals trying to make that transition into that first job. And recently had the opportunity to meet the mission data our guest today, and he is, you know, is early in his career building out what he wants to do and trying to find his own path and journeying.
In the process of that, has built out his own home lab and range, which is exciting to hear about. So Nimish, thanks for joining us today. I've had a great pleasure of getting to know you. I'd love to have you take a second introduce yourself, share a little bit about your own kind of career journey and how you got to where you're at today in your career.
Hi. Hi Tony, Good afternoon. First of all, thank you for having me. For the people who don't know me.
My name is Nimesh Data. I'm originally from India, all over the place. My father was in the Air Force, traveled a lot and came to Saint Louis, United States in January of twenty twenty two for my master's degree in cybersecurity. I've actually taken the conventional path in cybersecurity where I went and got my degree, spent tens of thousands of dollars, got my certifications, and in that manner, I'm trying to get into this industry.
So I've taken a pretty conventional approach. And what I've learned from it is that you don't have I mean, anyone who is coming into this field doesn't have to do or spend as much as I have in order to break in. And I hope we can talk about talk a little bit about that and I can showcase a little bit about how you can upscale yourself and get into this field. Yeah, So a lab and arrange.
Right, there's a lot of commercial products, there's a lot of opportunities and things that are out there and a way to learn, right, and you know, let's just let's start with the very basics here. And I think it's probably an important part just to set ground the ground floor of a rat like what is a lab and a range? You know, what is what is the intended purposes? What would what would one person do with it?
Like, let's start at the very basics and just start like what is a lab and arrange and what is its purpose? Right? So, in the context of cybersecurity, a home lab would be a virtualized environment which you can control. So in a traditional environment, you have multiple computers in a network.
You have five or six or ten or maybe hundreds of people working in an environment. All of their computers need to be network so that they can commute with each other. There needs to be. Switches, routers, all of this enterprise setup available to them.
So when you start off protecting a cybersecurity environment, you ideally would like to have a lab that's as big as that where you can work on all these computers, learn how to protect them, set up active directory, you can figure identity and access management to perform vulnerability scanning. But if you don't have a job or you don't have access to all those machines, it can be a little tricky. So in that case, what you do is you set up a virtualized environment all within your own house, inside your little fifteen inch laptop, where you can just install a bunch of virtualized machines or virtual machines within a hypervisor environment, and you can have different operating systems which you can work on, try to understand, and then have them network with each other and communicate with each other.
For the range, I would suggest if you can buy a decent I five or I seven laptop, I would highly recommend an I seven laptop. If you can get an Eye nine, that would be amazing. So anything from five hundred to two thousand dollars depending on your budget, is more than enough to get you started. That's a great answer.
So you know, I'm sure most people think and you just alluded a little bit to the price. I mean to do this, it's going to cost me nine million dollars, right, Like, there's there's all this technology, Like I really want to get splunk in my thing, or I want to start adding these softwares and technologies, right, So of course it's going to cost me a gazillion dollars to have all of these things to do, and I don't I don't necessarily think that's the case. You know, you alluded to it a little bit.
I know what we talked about just a little bit before we have on. So, like, you know what, as you sat down and made the decision this is something that you want to do, you know what, what approach did you take? I'm sure there was a project plan or maybe laid out or some sort of like like framework that you wanted to build. Like where did you start to come up with the ideas to drive and inform what you were putting into your ring?
Okay, so I've got I've got a funny story about how I got started into making my own home lab and setting up all these different virtual machines and just trying to figure out how all these things work. It happened from a failed interview. So I was sitting in an interview. I won't mention the company's name, but I just embarrassed myself.
I had absolutely no clue what was going on, and it was for position that was way above my pay grade at the time, so but the interviewer was actually extremely nice and she pointed me to a couple areas where I could get started off. She told me how I could get started in the industry, what I could do, what kinds of software I could install on my computer and get started with that. So as soon as that interview happened, and I took a couple of days to get back to baseline in terms of my mental condition.
But after that, I just hopped onto YouTube found as many free resources I could. There's a bunch of amazing content creators out there like Josh Macador and Network Chuck, Josh Hammond, all these people. They just keep posting amazing cybersecurity projects. And you know YouTube is full of all these free source, free resource materials.
I just chose a project in the beginning where I had to set up I had to set up a cloud environment in Azure Active Director in Microsoft Azure, and then I set up Azure Sentinel and I just opened my computer to the whole world and let them attack on it. And then basically I wanted to see which countries I was getting attacked from. So that was the first kind of project that I started on. Later on, I downloaded these hypervisor environments like virtual box or VMware.
For the people who don't know this, it's these are free applications that are available on the internet. Downloaded them, and after that I downloaded ISO files. So these are these are virtualized, virtualized machines which you can install onto your system. I installed Ubuntu.
This is for anyone who wants to learn Linux. Linux is actually very important for any person who's trying to get into cyber So that's one of the first machines that I installed onto my system, onto my Windows machine, and then I installed a Kali Linux operating system. Those were the first two virtual machines that I started getting used to. I learned Linux on them, learned a little bit of scripting, and that was my initial initial days of working.
Now, if you built this out, have you had support with others or has just been an entirely solo adventure for you? In the beginning, it was an entirely solo adventure. But as I kept moving forward, I got into the current current position that I'm in. I'm currently teaching as a cybersecurity instructor.
I had built quite a few skills by that moment until that time. Whatever I had learned, I had learned by myself. But I got an exponential boost as soon as I came in contact with my mentor and teacher who was also my supervisor at the time, mister Michael Bird. He had developed an amazing he had developed an amazing curriculum for himself.
All the things that he had learned. I had the pleasure of learning them firsthand from him, and anywhere I would get stuck, he would just point me to fifteen different resource materials, and that basically expounded and expounded my growth. So he had He actually taught me how to set up active directory. It was from him that I learned the whole concept of active directory, how you can set it up, how you can perform identity.
And access management. And yes, most of what I'd learned in the beginning was my own, but as soon as I got in touch with him, it went from zero two hundred real quickly. So let's let's take a second and like maybe map out, because I'm sure somebody listening right now is by thinking there, I can never do this. There's you know what I mean, And I think, to your point, there's a lot of this as you explored and asked questions and found videos and tools and things to help you do it, so it's not an insurmountable thing, but maybe walk through you know what an upfront kind of level we'll call level one because I can't think of a better term off the top of my head, Like a level one lab or range that you would do a you know, very basic set of skills up to maybe a level two, three, four, or five, right like level five being we'll call it an academic level of kind of range or lab right where there's tons of resources and things and maybe threes of community based lab right.
So like let's say in your cident, you know, at one point you were one, you're probably at a two right now as you've built some more things out, Like where do I start? Where can I go? You know I find? You know, is there should I make a list of priorities?
Should I focus it on the type of careers that I think I want to have? And I just answer that riddled you with like seventeen questions. But in the process of this, where do I start? You know what I mean?
Like, how do I know where to begin and build this thing out? All right? Let's take it from the basics. So the first thing that you want to figure out is how do I get a hypervisor in my system?
Would it be okay if I shared my screen? Yeah, absolutely, it'd be great. Right. Let me go ahead and share my screen.
So I have a Firefox browser open in front of me. The first thing that I want to point out is virtual Box, and I do want to point out Google is your best friend. If you had any doubts or any questions, please do not hesitate to do a simple Google search anything that you require answers to. It's just a couple clicks away.
So the first thing I want to install is a software like virtual Box or dmware. I would suggest VirtualBox because this is an easier software to install for most beginners. Once I download that and install it onto my system, it looks something like this. All right, I have virtual Box on my system, and the next thing I would want to do is install a Linux distribution.
Now, there are multiple Linux distributions to choose from. The one that I prefer for beginners is Ubuntu. So you can go onto the Ubuntu website and you can click on this second link, which is download u burn to desk Rop. Once you're on this page.
You can just click on download twenty four dot four dot one LTS. This is the latest. Version of you're going to and it will download an ISO file. Make sure that you have good distinctions in your folder.
Just let me get to the get to this particular folder. As you can see, I've made a folder in my computer where I have I have you know, organized and segregated all of the different operating systems that I have. You should get a file like this to dot you went to twenty four dot four Desktop AMB sixty four dot ISO. Once you have these two components, what you want to do is you want to click in your Oracle Virtual Box Manager and you want to add a new machine.
And now what's going to happen is if I could just be is there a whiteboard in this setting which I could use? If not, then I'll just I'll just explain it orally. So what I usually do is how I explain this to students. You're your host machine, which could be your Windows machine, which could be your macmachine.
It has a specific set of resources. Let's say you're using a laptop with twelve gigs of fram and one terabyte of storage. That storage can be divided amongst these different operating systems. So you could decide to give Ubuntu.
I could just type in the name Ubuntu, and I can select an ISO image. I can choose the image that I had downloaded. So let's say, for example, I choose this. Let me just go into that directly and choose that image.
A second, going to document virtual machine ISOs. Let's say for the sake of demonstration, I choose one of these ISOs. I'm not able to find that at the moment, but let's just choose. Let's say, for example, you downloaded that particular file that I just showed you.
This right here, you can choose that. Over here, you can click next, and then you can start allogating resources to all of your different virtual machines. So you can allocate let's say four gigs of RAM, you can allogate storage for this device. Now, when you have your computer set up, you can just start working on this machine as if this is a separate laptop, as if this is a separate machine that you have.
So this would be one of the first steps as a complete beginner. The next resource I would want one to point out toward for anyone that wants to learn Linux, go on YouTube. Search for Linux tutorials, and I would. Have as I was telling you, there are some amazing, some amazing resources available online.
You could have someone like Network Chuck tell you how to run Linux, and you'll find multiple different courses. All you need is that you go into system something like this video to get you started sixty Linux commands that you need to know in ten minutes, get a basic understanding of what you want to work on, and once you have that understanding, then you are ready to move on to level two. That's what I would suggest in the beginning. So that's great, I mean, and I think it's just I think it's a testament towards you to your point of like, this doesn't have to be complicated, right, We as humans have a tendency to make things a lot more complicated most of the time for stuff.
But there are a lot of great resources information on YouTube of people just like yourself. Right. And actually, if you want to take this just one step further, you know a lot of folks you know that build up these labs or ranges actually create the content and how to on YouTube, because it does give you an extra place to point people to, to show and highlight your skills, right, Like, you know, that's the number one thing when I think of these technical interviews where they try to ask you these questions to think through.
Not necessarily you've got to have the right answer, but they're really looking for your thought process and the logic you of what you're going to bring to your employer, right as a solution if you get stuck on something. So even the sheer fact of what you're doing, of trying to plan out the range and the lab and solving problems and then sharing that with others gives you a leg up and an advantage over many folks, right, just from the sheer fact that you're showing others how to do it and you're walking through more so than just the click clickity click, you know, the shows that you know what you're doing rather than just you know, kind of winging it.
So great answer. So as you look to kind of your next chapter, right, what what do you hope that you do? You have greater plans for your home lab. They continue to build on that, do you what what what's kind of on the horizon for you with what you're building.
So what I showed you in the beginning was just a very basic version of what you can do in your home environment. I do want to iterate, I do want to emphasize for anyone that's trying to break into this industry, you only can expand your lab to whatever knowledge you have present in front of you. For example, if you don't know much about the space, there's there's not much room for expansion right For example, if you if you only know about the four walls within your home and you don't know there's a whole world out there, you only try to navigate your environment within those four walls.
There's nothing wrong with that. But the more you find out about this field, the more you learn, the more you read, the more kind of resources you gather information from, the more your home lab experience will also will also flourish and we'll get enriched. For example, if I'll just share my screen once again, there was an exploit that had happened a couple years ago. There was this Eternal Blue exploit that a lot of people talk about.
It used to it would exploit the SMB file sharing service, which is port four four five, And now again I have given up a lot of information in this What is SMB file sharing? What is port four four five. What do I do with all of this information? So the first things first, you need to understand that you need to go on Google dive up SMB, try to understand what a server message block is, read up on it.
Then you can use an environment like Karlie Linux, and then you can use up any of these YouTube tutorials on how to exploit the Eternal Blue Eternal Blue vulnerability or MS one seven zero one zero, and then that lets you learn. More and more. You can keep doing these small projects on the side. But the one big thing that I think is not going away anytime soon is active directory.
It's going to shift from a traditional server environment onto the cloud environment nowadays that's called Microsoft ady Entra. If it's it's on Azure. So I would highly suggest for any beginner, after you learn how to install Ubuntu on your system, download a Windows server twenty twenty two and configure active directory on it. There are there should be money with videos online on how to configure active directory.
Just choose any of these ones. Try to understand what active directory is. Try to understand how you can set up a domain controller, how you can set up member servers, how you can set up a Linux machine in that how you can give resources, how you can provide identity and access management to these different resources. That will significantly upscale you and it will give you a lot more to talk about to any potential employer.
So that's what I've been doing as well. In my home lab, I have these different types of virtual machines, so metas floitable is an intentionally vulnerable machine that a lot of penetration testers and offensive cybersecurity individuals can use to break into, hack into it. It's all these different things that you can do. You can perform sequel injection, cross site scripting attacks, and you can host all of your websites on this.
But then again it comes back to that basic conversation of how much do I know, how how much do I need to learn? And on the basis of that, how can I bring what I've learned into life? So you do need to have a foundational foundational aspect where you understand what cybersecurity is, what the CIA try ad is, what vulnerability scanning is, what word scanning is. All of these things can then be brought to life in the real world.
Yeah, it's a great model on a great concept. Have you had much help, Like if you had other folks have jumped in, or you've have you kind of collaborated with other folks to give into the range, or have you kind of kept this to yourself. Now, I have had massive help from a lot of individuals that I've interacted with. As I told you, mister bird, he taught me a lot about this space.
There were other colleagues that I would ask for help, and then for the most part I did. I used to go online try to look for courses that I could learn, either paid or for free, and then most of the information that I've gathered is from those sources. And since I since I did the master's program, there was a lot a lot of theoretical understanding of the area that I had already gotten, which I could then later on go into the practical aspects of Yeah. What think.
It's always the number one challenge, right, whether you're a college or a boot camp or whatever, is how do you take those verbal skills you're hearing right of the concepts that you're learning in those classes and actually begin to apply those in an environment that makes sense. And so obviously you can't just go and make viruses and hack things. You know, legally go to go try and build your skills or you know or intentionally you know, drop exploits on people. That's you know, frowned upon in twenty twenty four and probably now on the attorney of time.
But but find you know, hearing things like I know, we had a lab and arrange several years ago or in the process of building one back here in the same Lost market. But that was the heyday of Wanna cry exploit, right, That was you know, a pretty big one several years ago. So you know, we wanted to help people find ways to stop and prevent it. Right, And if I remember correctly, that breach happened to get accidentally stopped, right, like somebody happened to stumble across a thing or some code or script.
If I remember it correctly, then it like accidentally stopped the bleeding from the Wanna cry breach. Right, And so you know, what better way than to put it into a droplet or some sort of containerized environment that you can click a button to your which is alluded to earlier, find a way to solve the problem or that challenge and spin it up and either you know, stop it or not, but in a safe environment that if you don't you have the ability to not let it separate out and obviously infect other environments that are that are adjacent to your network and stuff.
So a lot of interesting kind of best practices there to do and to build that I think most folks would necessarily think about because you're like, oh, it's a breach. It is what it is, it happened. I'm never going to get a play with it, you know, so final those things. So I know you and I alluded a little bit earlier before I hopped on you know, you know quick number you told me before I have around but you get into this right, But you know what, what's a what's a reasonable person expect to spend on a lab or range, you know, to build this out.
So I, as I specified before as well, the main expense that you're going to face is with the laptop. Other than that, your Wi. Fi bill can also be included as another expense in this whole project. But other than that, there's not there's not a lot of extra extra expenses in the beginning.
At least later on, you can expand it to a hardware firewall that you can figure, you can configure in your house. You can have I d S, I p A systems, or you can pay for something like a like a splunk sim you can you can pay for Nessus, you can pay for burp Suite. It can be as expensive as you would like, but at the very bare bones of the project, I would suggest, if you want a good I seven or I nine laptop and you don't want to spend a lot of money, look for resources like eBay, Facebook, Marketplace.
Those places you could find good laptops for a decent price, and anywhere from five hundred to one thousand dollars is more than enough on such a venture. Other than that, there's there's no added expenses or costs to that. I would suggest if you have a resource like YouTube available, try to spend as much time as possible on that and then build your lap from there. Yeah, I mean I think I know.
The stuff that we spent for ours was you know, some of the data storage and the droplets there to be able to put the content into the cloud. We ran a couple we'll call them simulations if you will, and ran a couple of things that require hired a couple extracoutrements, right like we bought five or six phone numbers that we needed to use for for a for a project we were working on. You know, similar things like that where you may have to buy some periphery things, but to your point, you really don't need to spend a ton of money to have servers and racks.
This could all be done via laptop. And then my advice, you know, we're very fortunate Saint Louis to have a microcenter. Microcenter is fantastic. You know, you can realistically, to Nims's point, go find yourself a five hundred dollars I five you know, a great and good process or a laptop that's going to do just about anything you could possibly want it to do.
I know for us, we've we have found kind of gaming laptops there that are actually cheaper, you know, on sale prices than some of your more up to date laptops that would be business just because you know, maybe it's a processor that's old, but these are coming with I sevens and an advanced graphics card for all under five hundred bucks. So, like you know, Microcenter doesn't pay me to promote them by any means. I just know that they generally take good care of their customers.
It gets you out of a box store, you know, and I'm there's nothing wrong with the Target or Walmart or SAMs clubs for your computers, but like they're more mass produced for just general daily type of things and word processing where where you're you know, you're describing it is probably a little bit more advanced, but doesn't require a mega supercomputer for the federal government to try it, right, you know, as you look ahead, you know, and one you know, would you be open if people wanted to reach out to you and maybe kind of learn more about your you know, your lab and space and maybe you find some friends to contribute more and more things, Like you know, is this is this a forever project for you or do you think you know, you kind of hit an endpoint where you start adding things onto it.
Uh. Well, I think there's a lot that can be expanded on. Uh in the interim. I think for the next couple of years, there's a lot of things that I could learn.
I am planning on getting into application cybersecurity as well, because that's where I see the trend moving on. In the future. So before I have to shell out any actual hard cash for hardware, I think for the next couple of years, I am sorted. There's a lot of things that I could be learning.
So that's that Also alluding to your point about if anyone wants to reach out to me, I'd be more than happy to collaborate with them. There's a lot more that I can learn from people and add a lot more than I can provide to people as well. So both aspects, I think I answer your question. Yeah, I mean there's a lot of great ways, you know, and I think the advice that I generally give if you start following capture the flags right and again, I think the frameworks of a capture of flag and the lab all too often are very similar things.
The idea is right, here is a problem, here is a solution. How do you put it into it? So it is a great way to help build out challenges and things in a safe way for folks to practice with, you know, So finding national seats right, that happened because if you know you find a CTF time, I think it is there's tons of websites that promote those and then find after the completion of those, actually finding the videos and the how to guides are an incredible resource right where folks compete, maybe they get stuck and can't figure it out, so they do a write up about it, or maybe they solve it and they want to give out the keys.
But it is a really great way to learn the tools and tricks that you just alluded to to build out challenges and scenarios and a lab and arrange, right, and it's going to help you get ideas and facilitate some of those thoughts and thinking for everybody to really get ahead of the power curve. So we're at the end of our thirty which again always goes fast. You know everybody gets the same last question, But what advice would you give to somebody looking to level up their cybersecurity career?
Right? If anyone wants to get into this field, level up their career, I would say, start from the basics. Keep polishing your basics still if you feel like you're there, and then go back and polish them some more. Learn subnetting.
Subnetting is extremely important from a networking point of view. You need to know how to subnet different computers, how to create v lands. You need to understand the concept of v lands. That's one.
Learn Learn Shell scripting, learn Bash, learn PowerShell is extremely extremely functional, very important also learn how you can navigate a Linux based environment. Most of the cybersecurity that happens in an enterprise environment is within Linux. Learn that and all. Learning a programming language like Python will always benefit you, no matter what anyone else says, no matter how many strides, ch, GPT or any other AI takes in the future, anyone who has a programming background will definitely benefit in the cybersecurity space.
So if there's nowhere else, go ahead from learn the basics of cybersecurity, learn Bash scripting, learn to navigate to the Nix environment, and learn Python. Those are the four things that I would say you can do to level up your skills. It's really good advice. The Python is one of the sticks, and I hope that the point around the AI stuff and just different tools to help write that.
I don't I don't think you take the human aspect out of this, because enemies will continue to be humans, right, I mean I think we I think there will be tools that will make things easier. By at the end of the day, it's still going to be a person to a person trying to figure out what makes that other person weak or vulnerable to find those breaches. So man, I am very appreciative. This is a topic that I've been going to cover for quite a while, so appreciate your you know, enthusiasm to labs home labs and sharing to share kind of best practices with everybody today.
For those that are tuned in, I encourage you to reach out and if you have questions or want to you know, get support or figure out a way to build your own lab. You know, Nims has already offered he would do it, but you know, don't sleep on his advice of YouTube is a great resource for it. So Nimis, thank you so much for joining us today. Appreciate yeah, appreciate the words of wisdom, and thank you everybody for tuning in till next time.
I hope everybody has a great week and we'll see you soon. Thanks a lot.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.