Browse the Full Catalog
Cybrary’s comprehensive, framework-aligned catalog has been reorganized to provide you with an intentional, guided learning experience. Advance your career, prep for certifications, and build your skills whenever, wherever.









The content and tools you need to build real-world skills
Rapidly develop your skills via an integrated and engaging learning
experience on the Cybrary platform.
Bite-sized Video Training
Manageable instruction from industry experts
Hands-On Learning
Put your skills to the test in virtual labs, challenges, and simulated environments
Practice Exams
Prepare for industry certifications with insider tips and practice exams
Earn Industry Badges
Complete coursework to earn industry-recognized badges via Credly
AI Curriculum

AI Security Lifecycle
This collection provides insight into every stage of the AI Security Lifecycle, from planning and data preparation to deployment, monitoring, and governance—equipping them with the frameworks, tools, and best practices necessary to safeguard AI models and data in enterprise environments.

AI Fundamentals
Learn the basics of Artificial Intelligence! This skill path is designed to provide you with a general understanding of Artificial Intelligence, and how to deploy and secure it within the enterprise. Upon completing the skill path, you will earn a Credly digital badge that will demonstrate to employers that you’re ready for the job.
AI Scams
In this brief course, you will learn the basics of AI scams. AI scams are cyberattacks that use artificial intelligence to trick people. They create emails, videos, voice messages, or websites that look, sound, and read like the real thing, making them far more convincing and harder to detect than traditional scams.
Certification Prep

CompTIA Tech+ (FC0-U71)
CompTIA Tech+ is a beginner-level certification and is perfect for you if you are considering a new career or career change to the IT industry. This certification prep path is designed to provide you with a comprehensive overview of the concepts and skills you will need to pass the certification exam.
Skill Paths

Risk Management
Risk Management is the proactive process of identifying, evaluating, and controlling threats that could prevent an organization from achieving its strategic goals or remaining compliant with laws. This skill path is designed to help you make sure the risks your organization does take are calculated and aligned with your governance strategy. Upon completing the skill path, you will earn a Credly digital badge that will demonstrate to employers that you’re ready for the job.

Governance
Governance is the system of rules, practices, and processes used to direct and control a company. This skill path is designed to provide you with a general understanding of how to align business objectives with ethical practices for how a company operates. Upon completing the skill path, you will earn a Credly digital badge that will demonstrate to employers that you’re ready for the job.

Compliance
Compliance is the act of adhering to all relevant laws, regulations, industry standards (external), and internal policies and controls (corporate). This skill path is designed to provide you with a general understanding of how to ensure an organization operates within legal and ethical boundaries to avoid fines, penalties, and reputational damage. Upon completing the skill path, you will earn a Credly digital badge that will demonstrate to employers that you’re ready for the job.

Cybersecurity Leadership
Becoming an effective Cybersecurity Leader requires you to consider traditional Leadership competencies through a security-centric lens. This skill path is designed to provide you with a general understanding of cybersecurity leadership. Upon completing the skill path, you will earn a Credly digital badge that will demonstrate to employers that you’re ready for the job.

Collaborative Leadership
Collaborative Leadership is the skillset required to work effectively with others. This skill path is designed to provide you with a general understanding of the collaborative skills required to be a successful leader. Upon completing the skill path, you will earn a Credly digital badge that will demonstrate to employers that you’re ready for the job.
Career Paths
-p-500%5B1%5D.webp)
Leadership and Management
Effective Leadership and Management is critical to any security-related function. This career path is designed to provide you with the foundational knowledge and key skills required to succeed as an effective leader within any security domain. Upon completing the career path, you will earn a Credly digital badge that will demonstrate to employers that you’re ready for the job.

GRC Analyst
Every successful cybersecurity program requires judicious risk management and informed oversight. This career path is designed to provide you with the foundational knowledge and key skills required to succeed as a GRC Analyst or in any role that involves managing governance, risk, and compliance. Upon completing the career path, you will earn a Credly digital badge that will demonstrate to employers that you’re ready for the job.
Security Awareness Training
DPDP Act (India)
In this brief course, you will learn the basics of India's Digital Personal Data Protection Act, 2023 (DPDP Act). The DPDP Act is focused on safeguarding personal data and ensuring privacy. It establishes guidelines for organizations handling personal data, emphasizing consent, transparency, security, and accountability.

Government Best Practices
In this brief course, you will learn about best practices for government as part of your required Security Awareness Training. Government institutions are often seen as high-value targets by cyber criminals. This can seem frightening, but by following security best practices, you can protect your employer.
CCPA (United States)
In this brief course, you'll learn the basics of the California Consumer Privacy Act (CCPA). CCPA is a state-level privacy law granting residents more control over personal data. It requires businesses to be transparent about data usage, respect privacy rights, and safeguard against unauthorized access.

PSPF Fundamentals (Australia)
The Australian PSPF is an essential set of guidelines designed to help Australian government entities protect their people, information, and assets. It provides a structured approach to security management, ensuring organizations can effectively navigate the complex landscape of security risks.

ISO 27001 Fundamentals
In this brief course, you will learn the fundamentals of ISO 27001 compliance. ISO 27001 is an internationally recognized standard that outlines the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS) within an organization.
Collections

50 CISO Security Controls
The Security Controls are an essential component of the CRISC certification, and provide you with the information you need to ensure that your organization’s cybersecurity infrastructure has the maturity and structure it needs to meet and exceed the demands of a changing market.

12 Competencies of the Effective CISO
These competencies are also shown to provide an excellent career development and learning roadmap for anyone desiring advancement in the enterprise security management field. Lectures address the twelve insights with invited experts from the field offering their key insights and advice for participants. Learning Objectives Participants will develop the valuable insights and insider knowledge necessary to support (1) optimizing career success and performance in their current enterprise security management or leadership role, and/or (2) increasing their chances of successful promotion to a senior leadership position, including the CISO role, within their present or future organization. Target Participants The course is designed for working practitioners of enterprise security, at all possible stages of career growth, within business or government environments, who are either currently in management and leadership roles, or who aspire to improve their chances of promotion into executive roles, such as CISO. The Competencies: Innovation Finance & Administration Business Operations Cybersecurity Expertise Discretion & Trust Public Speaking Personal Productivity Information Technology Threat Insights Balancing Compliance Risk Orientation Team Leadership and Vision
Collections

Lateral Movement: Windows Remote Management
In order to achieve lateral movement, threat actors will use a valid account to access remote systems, such as the Windows Remote Management service. In this way, the threat actor can move around the network and search for valuable information or greater access. Learn more and get hands-on with this technique by detecting it in our virtual lab.

Disable Windows Event Log and Timestomp
Sophisticated threat actors like APT29 will use the techniques Disable Windows Event Logging and Timestomp for defense evasion to prevent defenders from seeing their presence on the network. You will detect this nefarious activity in our virtual lab so you can react to advanced attackers and outsmart them.

Unsecured Credentials and Domain Accounts
Threat actors use the techniques Unsecured Credentials and Domain Accounts to obtain credential access and gain persistence. In this emulation of how the threat group APT29 would use these techniques, you will get hands-on practice detecting this activity so you can protect your organization from highly sophisticated advanced persistent threats.

Compromise Software Supply Chain
Threat actors use the technique Compromise Software Supply Chain by altering software that they know their victims will use. They include a backdoor that will give them access to their victim's network once the software is installed. You will detect this technique in a virtual lab and master how to mitigate this threat.

Remote System Discovery and Remote Desktop Protocol
Adversaries want to understand your environment and will use Remote System Discovery to do so. They can also leverage the same Remote Desktop Protocol (RDP) you'd use to access systems remotely. And, with the right credentials, they can move laterally through your system. Outwit them by detecting and blocking these techniques today.

Spearphishing Attachment and PowerShell
Phishing is one of the top techniques leveraged in breaches today, and adversaries use it to send malicious attachments to targeted users. PowerShell is a powerful scripting tool that adversaries can exploit to perform recon and run executables. You will detect these adversary techniques and discover ways to mitigate them.

Registry Run Keys
Many organizations do not monitor for additions to the Windows Registry that could be used to trigger autostart execution on system boot or logon. This allows adversaries to launch programs that run at higher privileges and paves the way for more damaging activity. Learn how to detect and mitigate this activity to secure your network.

Scheduled Task
Some organizations do not configure their operating systems and account management to properly protect the use of task scheduling functionality. As a result, adversaries can abuse this capability to execute malicious code on a victim’s system. Get hands-on practice detecting this technique so you can protect your organization.

User Discovery

Server Software Component: Web Shell
Bad actors can gain persistence on your network by abusing software development features that allow legitimate developers to extend server applications. In this way, they can install malicious code for later use. Learn to detect and thwart this activity and protect your network.

System Binary Proxy Execution: Msiexec

CVE Series: Atlassian Bitbucket Command Injection (CVE-2022-36804)

CVE Series: Openfire (CVE-2023-32315)

CVE Series: Spring4Shell (CVE-2022-22965)

CVE Series: Log4J (CVE-2021-44228)

CVE Series: PrintNightmare (CVE-2021-1675 and CVE-2021-34527)

CVE Series: MSHTML Vulnerability (CVE-2021-40444)

OWASP Top 10 - A01:2021 - Broken Access Control

OWASP Top 10 - A02:2021 - Cryptographic Failures

OWASP Top 10 - A03:2021 - Injection

OWASP Top 10 - A04:2021 - Insecure Design

OWASP Top 10 - A05:2021 - Security Misconfiguration

OWASP Top 10 - A06:2021 - Vulnerable and Outdated Components

Registry Run Keys
Many organizations do not monitor for additions to the Windows Registry that could be used to trigger autostart execution on system boot or logon. This allows adversaries to launch programs that run at higher privileges and paves the way for more damaging activity. Learn how to detect and mitigate this activity to secure your network.

Scheduled Task
Some organizations do not configure their operating systems and account management to properly protect the use of task scheduling functionality. As a result, adversaries can abuse this capability to execute malicious code on a victim’s system. Get hands-on practice detecting this technique so you can protect your organization.

User Discovery

Server Software Component: Web Shell
Bad actors can gain persistence on your network by abusing software development features that allow legitimate developers to extend server applications. In this way, they can install malicious code for later use. Learn to detect and thwart this activity and protect your network.

System Binary Proxy Execution: Msiexec
Our Instructors
Industry seasoned. Cybrary trained.
Our instructors are current cybersecurity professionals trained by Cybrary to deliver engaging, consistent, quality content.



























