Browse the Full Catalog
Cybrary’s comprehensive, framework-aligned catalog has been reorganized to provide you with an intentional, guided learning experience. Advance your career, prep for certifications, and build your skills whenever, wherever.








The content and tools you need to build real-world skills
Rapidly develop your skills via an integrated and engaging learning
experience on the Cybrary platform.
Bite-sized Video Training
Manageable instruction from industry experts
Hands-On Learning
Put your skills to the test in virtual labs, challenges, and simulated environments
Practice Exams
Prepare for industry certifications with insider tips and practice exams
Earn Industry Badges
Complete coursework to earn industry-recognized badges via Credly

Comptia Security+ Certification Prep
CompTIA’s Security+ is a globally recognized certification that equips IT professionals with cybersecurity principles and security best practices, and is often used as a requirement for entry-level cybersecurity positions. This certification prep path is designed to provide you with a comprehensive overview of the concepts and skills you will need to pass the certification exam.

IT & Cybersecurity Foundations
Cybrary’s IT and Cybersecurity Foundations career path will equip you with a strong foundation of cybersecurity knowledge and hands-on skills. Over the course of 30 courses and hands-on virtual labs, you will learn essential IT concepts, security best practices, and the technical skills needed for entry-level IT and cybersecurity roles.
Our courses feature thoughtful, bite-sized content from expert instructors who have helped thousands of other beginners grasp fundamental IT and cybersecurity topics.

SOC Analyst
Cybrary’s Security Operations Center (SOC) Analyst career path and associated assessments will equip you with the knowledge and hands-on skills you need and teach you how to become a SOC Analyst. Over the course of 20+ courses and hands-on virtual labs, you will learn defensive security fundamentals, log analysis, network-based detection, and host-based detection.
As you proceed through our SOC Analyst trainings, your progress will be measured in real time using Experience Points (XP) that serve as a comprehensive capability score for each topic.

Penetration Tester
Cybrary’s Penetration Tester career path and associated assessments will equip you with the knowledge and hands-on skills you need to launch your career as a Penetration Tester. Over the course of 20+ courses and hands-on virtual labs, you will learn how to successfully identify, exploit, and remediate security vulnerabilities, and build a strong foundation of ethical hacking knowledge and skills.
As you proceed through the path, your progress will be measured in real time using Experience Points (XP) that serve as a comprehensive capability score for each topic.

Security Engineer
Cybrary’s Security Engineer career path and associated assessments will equip you with the knowledge and hands-on skills you need to launch your career as a Security Engineer. Over the course of 20+ courses and hands-on virtual labs, you will learn security engineering fundamentals, infrastructure and operations security, application security, and data security.
Completing this career path and the associated assessments will start your journey toward a Security Engineer role or prepare you for further specialization in advanced skills like cloud security and cybersecurity architecture.
-p-500%5B1%5D.webp)
Leadership and Management
Effective Leadership and Management is critical to any security-related function. Cybrary’s Leadership and Management Career Path will equip you with essential leadership knowledge and hands-on skills. Over the course of 20+ courses, you will learn Leadership and Management Fundamentals, Soft Skills, Leadership Principles, Cybersecurity Leadership, and Strategic Leadership.
Completing this career path and the associated Assessments will prepare you for pursuing a career as a leader or manager for IT and cybersecurity-related functions.

System Administrator
The courses in the System Administrator Collection will help you build a foundation of knowledge and hands-on skills related to network devices and configurations, maintaining business systems, and leveraging security tools. These skills can start your journey toward your first IT position or prepare you for further industry training and certifications.
Our courses feature thoughtful, bite-sized content from expert instructors who have helped thousands of other beginners grasp fundamental IT and cybersecurity topics. Topics include network architecture, firewalls, secure data storage, and more.

Incident Handler
The courses in the Incident Handler Collection will help you build a foundation of knowledge and hands-on skills related to incident response, including containment, recovery, reconnaissance, basic digital forensics, and more. These skills can start your journey toward a role in cybersecurity operations or prepare you for further industry training and certifications.
Our courses feature thoughtful, bite-sized content from expert instructors who have helped thousands of other learners grasp fundamental incident response topics.

Network Engineer
The courses in the Network Engineer Collection will help you build a foundation of knowledge and hands-on skills related to network management, system performance, troubleshooting and diagnosing network issues, and understanding infrastructure protocols, application, and transport. These skills can start your journey toward a Network Engineer position or prepare you for further industry training and certifications.
Our courses feature thoughtful, bite-sized content from expert instructors who have helped thousands of other beginners grasp fundamental IT and cybersecurity topics.

OWASP Top 10 - A08:2021 - Software and Data Integrity Failures

OWASP Top 10 - A04:2021 - Insecure Design

OWASP Top 10 - A09:2021 - Security Logging and Monitoring Failures

OWASP Top 10 - A10:2021 - Server-Side Request Forgery (SSRF)

OWASP Top 10 - A05:2021 - Security Misconfiguration

OWASP Top 10 - A02:2021 - Cryptographic Failures

OWASP Top 10 - A07:2021 - Identification and Authentication Failures

OWASP Top 10 - A06:2021 - Vulnerable and Outdated Components

OWASP Top 10 - A03:2021 - Injection

OWASP Top 10 - A01:2021 - Broken Access Control

OWASP Top 10 - A04:2017 - XML External Entities

Protocol Tunneling

Exfiltration Over Alternative Protocol: Asymmetric Encrypted Non-C2 Protocol

SSH Authorized Keys

Lateral Movement: Windows Remote Management

Persistence via Windows Services

System Binary Proxy Execution and a Spearphish Payload

Server Software Component: Web Shell

Scheduled Task

Registry Run Keys
Connect to an EC2 Instance by Using RDP
Gain hands-on experience creating a Windows Server virtual machine by using Amazon Elastic Compute Cloud (EC2). Lab activities include: creating a new key pair to decrypt the password for an EC2 instance, creating a security group to allow access, and creating and connecting to an EC2 instance using an Amazon Machine Image (AMI) and RDP.

AWS Certified Security Specialty (SCS-C02)
Prepare for the AWS Certified Security Specialist (SCS-C02) exam. Amazon recommends candidates have at least 5 years of IT security experience in designing and implementing security solutions, and hands-on experience securing AWS workloads. The exam covers: Incident Response, Logging & Monitoring, Infrastructure Security, IAM, and Data Protection.

Implement a Security Monitoring Process
Gain hands-on experience implementing a security monitoring process with AWS CloudTrail. Lab activities include: setting up CloudTrail to track management events, configuring a topic by using Amazon SNS, configuring Amazon CloudWatch Logs by using a metric filter, configuring an alarm for a log group, and reviewing the CloudTrail trail.

Implement Protection for Data and Infrastructure
In this lab, you will learn how to protect sensitive information in an AWS environment. First, you will create an Amazon EC2 key pair to provide a secure connection to an instance. Then add and upload the key to the AWS Systems Manager Parameter Store. Finally, you will store a set of access key credentials in the AWS Secrets Manager.

Implement Security by Using an IAM Role
Gain hands-on experience creating an Identity and Access Management (IAM) role to access an Amazon Simple Storage Service (Amazon S3) bucket from an Elastic Compute Cloud (EC2) instance. Activities include: creating an Amazon S3 bucket, creating an IAM policy that provides full control of the bucket, and testing the policy in a new EC2 instance.

Configure Security for an IAM User
Gain hands-on experience creating an Identity and Access Management (IAM) user that has full administrator access. Lab activities include: creating an IAM user, creating a user group, assigning a user to the group, attaching a policy to the group, and implementing multi-factor authentication for the root account.

Implement an IAM Policy
Gain hands-on experience creating an AWS Identity and Access Management (IAM) policy to manage an Amazon S3 bucket. Lab activities include: creating an IAM policy and user group, adding a user account to the group, creating an S3 bucket, adding an object to the bucket, and attempting to delete both the object and the bucket.

AWS CSS: Management and Security Governance
In this AWS CSS: Management and Security Governance course, you will learn about AWS Organizations, designing secure and consistent deployment strategies for cloud resources, and how to identify security gaps through architectureal reviews and cost analysis in AWS.

PenTest+ PT0-003
The CompTIA PenTest+ certification exam is for cybersecurity professionals tasked with penetration testing and vulnerability management. Testers will be required to demonstrate hands-on skills and knowledge to test devices in environments such as the cloud and mobile, in addition to traditional desktops and servers.

Cybrary Challenge: Motor Mayhem

Challenge: Memory Mysteries

Challenge: Between Two Numbers

Challenge: Saving A Fellow Spy

Challenge: Space Mission

Challenge: A Message Within A Message

Challenge: Don't Believe What You Hear

Challenge: Chatting with ChatGPT

Challenge: Saving a Fellow Monster

Challenge: Gobble Gobble Conceal & Deceive

Challenge: For the Rebellion or the Empire

Challenge: Update B4 It's 2Late

Challenge: MFA ... All Day Every Day

Challenge: Episode II - Attack of the Encoders

Challenge: The Base(64)ics

Challenge: Spiny Shell

CVE Series: Jenkins Arbitrary File Leak Vulnerability (CVE-2024-23897)
CVE-2024-23897 is a critical security flaw affecting Jenkins, a Java-based open-source automation server widely used for application building, testing, and deployment. It allows unauthorized access to files through the Jenkins integrated command line interface (CLI), potentially leading to remote code execution (RCE).

CVE Series: Authentication Bypass in Apache Superset (CVE-2023-27524)
CVE-2023-27524 is a critical vulnerability in Apache Superset, affecting versions up to 2.0.1. It enables attackers to bypass authentication by exploiting weak or default SECRET_KEY values. Attackers can forge session cookies to gain admin access, leading to potential remote code execution and unauthorized data access.

CVE Series: Confluence Authentication Vulnerability (CVE-2023-22515)
Confluence suffers from a Broken Access Control vulnerability that affects Data Center and Server versions 8.0.0 to 8.3.2, 8.4.0 to 8.4.2, and 8.5.0 to 8.5.1. Threat actors exploit this vulnerability to obtain administrator access to Confluence servers. Put on your Red Team hat to create your own malicious admin account leveraging this CVE!

CVE Series: WinRar Vulnerability (CVE-2023-38831)

CVE Series: Openfire (CVE-2023-32315)

CVE Series: Dirty Pipe (CVE-2022-0847)

CVE Series: Polkit (CVE-2021-4034)

CVE Series: Log4J (CVE-2021-44228)

CVE Series: InstallerFileTakeOver (CVE-2021-41379)

CVE Series: MSHTML Vulnerability (CVE-2021-40444)

CVE Series: HiveNightmare (CVE-2021-36934)

CVE Series: PrintNightmare (CVE-2021-1675 and CVE-2021-34527)

CVE Series: Ghostcat (CVE-2020-1938)

CVE Series: Atlassian Bitbucket Command Injection (CVE-2022-36804)

CVE Series: Grafana Directory Traversal (CVE-2021-43798)

CVE Series: Apache HTTPD (CVE-2021-42013)

CVE Series: Apache Spark (CVE-2022-33891)

CVE Series: Django (CVE-2022-34265)

CVE Series: Follina (CVE-2022-30190)

CVE Series: Confluence RCE (CVE-2022-26134)

CVE Series: Redis (CVE-2022-0543)

CVE Series: Spring4Shell (CVE-2022-22965)

Royal Ransomware Group
Royal is a spin-off group of Conti, which first emerged in January of 2022. The group consists of veterans of the ransomware industry and brings more advanced capabilities and TTPs against their victims. Begin this campaign to learn how to detect and protect against this newer APT group!

Raspberry Robin
Raspberry Robin is a malware family that continues to be manipulated by several different threat groups for their purposes. These threat actors (Clop, LockBit, and Evil Corp) specialize in establishing persistence on a compromised host and creating remote connections to use later. Once established, these C2 connections can be used for multiple purposes, including data exfiltration, espionage, and even further exploitation.

Double Trouble with Double Dragon

Weak Link in the Supply Chain

Spinning a Web Shell for Initial Access

Exfiltration and Extortion
Threat actors will use stolen data exfiltrated from victim systems to extort organizations. Once they gain a foothold, they delete critical system files and threaten to release the data or disrupt operations if the victims do not pay up. Understanding these techniques is vital to defending your organization from such attacks.

Ransomware for Financial Gain
Threat actors continue to leverage ransomware to extort victim organizations. What was once a simple scheme to encrypt target data has expanded to include data disclosure and targeting a victim’s clients or suppliers. Understanding the techniques threat actors use in these attacks is vital to having an effective detection and mitigation strategy.
Our Instructors
Industry seasoned. Cybrary trained.
Our instructors are current cybersecurity professionals trained by Cybrary to deliver engaging, consistent, quality content.