I've talked about DFIR, bug bounty, offensive security basics and my own journey through this field, still learning most of it as I go.
October's gonna be different. I'll be going deeper into cybersecurity as a whole, job roles, what SOC analysts actually do, what pentesters do day to day, what skills actually get you hired and not just tool tutorials.
If you're confused about where to even start in this field or what role fits you, next month is for you.
See you tomorrow 🔥
I saw a list of GitHub repos combining AI with cybersecurity work going around and it's a good snapshot of where this is actually heading.
Tools like PentestGPT and Caido are trying to reason through pentest workflows alongside you. Others like Semgrep and Gitleaks catch vulnerable code and leaked secrets before they ever ship. Wazuh and Prowler handle monitoring and cloud compliance checks at scale.
None of it replaces actually knowing the methodology. What it does is cut down the repetitive grunt work, so more time goes into the stuff that actually needs a human brain.
I saw a list of GitHub repos combining AI with cybersecurity work going around and it's a good snapshot of where this is actually heading.
Tools like PentestGPT and Caido are trying to reason through pentest workflows alongside you. Others like Semgrep and Gitleaks catch vulnerable code and leaked secrets before they ever ship. Wazuh and Prowler handle monitoring and cloud compliance checks at scale.
None of it replaces actually knowing the methodology. What it does is cut down the repetitive grunt work, so more time goes into the stuff that actually needs a human brain.
Cybersecurity Awareness Month tip.
Check your email's "forwarding" settings right now. Attackers who compromise an email account often quietly set up auto-forwarding rules so they keep reading your mail even after you change your password.
Most people never check this setting unless something looks wrong.
Cybersecurity Awareness Month tip.
Check your email's "forwarding" settings right now. Attackers who compromise an email account often quietly set up auto-forwarding rules so they keep reading your mail even after you change your password.
Most people never check this setting unless something looks wrong.
I'm running through a cybersecurity role every day this month.
Day 6: GRC (Governance, Risk and Compliance)
This is the least talked about role, probably the most underrated. GRC isn't hands-on-keyboard hacking, it's making sure the company actually follows security frameworks (ISO 27001, SOC 2, NIST), manages risk properly and stays compliant with regulations.
Sure it sounds boring until you realize this is often the role deciding what gets prioritized and funded. A pentester finds the vulnerability, GRC decides whether fixing it is mandatory, optional, or a regulatory requirement with a deadline attached.
If you're more into policy, process and the business side of security than pure technical work, this is a real career path, not a fallback.
I'm running through a cybersecurity role every day this month.
Day 6: GRC (Governance, Risk and Compliance)
This is the least talked about role, probably the most underrated. GRC isn't hands-on-keyboard hacking, it's making sure the company actually follows security frameworks (ISO 27001, SOC 2, NIST), manages risk properly and stays compliant with regulations.
Sure it sounds boring until you realize this is often the role deciding what gets prioritized and funded. A pentester finds the vulnerability, GRC decides whether fixing it is mandatory, optional, or a regulatory requirement with a deadline attached.
If you're more into policy, process and the business side of security than pure technical work, this is a real career path, not a fallback.
Gm CT
September was pure trenches. I took the hits, cut size and respected the invalidation.
This month has been the same energy,with no revenge apes and not chasing every call 💰 don’t care about feelings
Cybersecurity Awareness Month tip.
Stop clicking "Remind me later" on software updates. Most updates exist specifically to patch a vulnerability that's already being exploited somewhere.
If an update's available, especially for your OS or browser, do it today, not next week.
Cybersecurity Awareness Month tip.
Stop clicking "Remind me later" on software updates. Most updates exist specifically to patch a vulnerability that's already being exploited somewhere.
If an update's available, especially for your OS or browser, do it today, not next week.
I'm running through a cybersecurity role every day this month.
Day 5: Cloud Security Engineer.
As more companies move everything to AWS, Azure and GCP this role exists to make sure none of it's left wide open.
Most cloud breaches aren't some advanced exploit, they're misconfigurations. An S3 bucket set to public when it shouldn't be. An IAM role with way more permissions than it needs.
A database exposed to the internet because someone skipped a setting during setup.
This role is part security, part cloud architecture. You need to understand how the infrastructure actually works, not just how to scan it.
It's one of the fastest-growing specialties right now because almost nobody has enough people who are good at it yet.
I'm running through a cybersecurity role every day this month.
Day 5: Cloud Security Engineer.
As more companies move everything to AWS, Azure and GCP this role exists to make sure none of it's left wide open.
Most cloud breaches aren't some advanced exploit, they're misconfigurations. An S3 bucket set to public when it shouldn't be. An IAM role with way more permissions than it needs.
A database exposed to the internet because someone skipped a setting during setup.
This role is part security, part cloud architecture. You need to understand how the infrastructure actually works, not just how to scan it.
It's one of the fastest-growing specialties right now because almost nobody has enough people who are good at it yet.
Cybersecurity Awareness Month tip.
Check which apps on your phone still have access to your location, camera, or contacts from months ago.
Most people grant permission once and forget it's still active.
Go into your settings and revoke anything an app doesn't actually need to function right now.
Cybersecurity Awareness Month tip.
Check which apps on your phone still have access to your location, camera, or contacts from months ago.
Most people grant permission once and forget it's still active.
Go into your settings and revoke anything an app doesn't actually need to function right now.
I'm running through a cybersecurity role every day this month.
Day 4: AppSec Engineer.
It's totally different from pentesting. A pentester shows up, tests what's already built and leaves. An AppSec engineer is embedded with the dev team, trying to catch vulnerabilities before the code ever ships.
Think code reviews, threat modeling during design, setting up automated scanning in the CI/CD pipeline so issues get caught on every commit, not once a year during an audit.
It's less break things and more of stopping things from being breakable in the first place. It requires actual coding ability since you're often fixing the vulnerable code yourself not just reporting it.
If you like building as much as breaking, this role sits right in between.
I'm running through a cybersecurity role every day this month.
Day 4: AppSec Engineer.
It's totally different from pentesting. A pentester shows up, tests what's already built and leaves. An AppSec engineer is embedded with the dev team, trying to catch vulnerabilities before the code ever ships.
Think code reviews, threat modeling during design, setting up automated scanning in the CI/CD pipeline so issues get caught on every commit, not once a year during an audit.
It's less break things and more of stopping things from being breakable in the first place. It requires actual coding ability since you're often fixing the vulnerable code yourself not just reporting it.
If you like building as much as breaking, this role sits right in between.
Cybersecurity Awareness Month tip.
Public WiFi isn't the villain everyone makes it out to be, but using it for banking or logging into sensitive accounts without a VPN is still a bad habit. Attackers on the same network can intercept unencrypted traffic.
If you must use public WiFi for something sensitive, use a VPN or just wait until you're on your own network
Cybersecurity Awareness Month tip.
Public WiFi isn't the villain everyone makes it out to be, but using it for banking or logging into sensitive accounts without a VPN is still a bad habit. Attackers on the same network can intercept unencrypted traffic.
If you must use public WiFi for something sensitive, use a VPN or just wait until you're on your own network
I'm running through a cybersecurity roles every day this month.
DFIR / Incident Responder.
This is the role that shows up after something's already gone wrong. A breach happened and your job is figuring out what, how and how bad.
You're pulling logs, checking timestamps, looking for the first point of entry and not to point fingers but to understand the full timeline; when they got in, what they touched, whether they're still in there.
Speed matters here, but so does not destroying evidence while you work. Every action you take during an investigation has to be documented, because what you find might end up in a legal or compliance process later.
It's part detective work, part discipline. You don't guess, you prove.
I'm running through a cybersecurity roles every day this month.
DFIR / Incident Responder.
This is the role that shows up after something's already gone wrong. A breach happened and your job is figuring out what, how and how bad.
You're pulling logs, checking timestamps, looking for the first point of entry and not to point fingers but to understand the full timeline; when they got in, what they touched, whether they're still in there.
Speed matters here, but so does not destroying evidence while you work. Every action you take during an investigation has to be documented, because what you find might end up in a legal or compliance process later.
It's part detective work, part discipline. You don't guess, you prove.
I'm running through a cybersecurity role every day this month.
Day 2: Pentester.
Forget what movies show you, no hoodie, no typing random code that magically breaks in. Real pentesting is slower and way more methodical.
Most of the work is recon, before you even touch a system. Subdomains, open ports, exposed services, outdated software. You're looking for the door someone left unlocked, not breaking down a locked one.
Once you find something, you don't just exploit it and move on. You document how you found it, how to reproduce it, and what it'd actually cost the business if a real attacker found it first.
That report is the real deliverable. Not the exploit.