Weekly cyber walkthroughs · Cyber concepts

One challenge a week. Solved, written up, shared.

CTF walkthroughs and certification study guides, free to read. The goal is always to retain the knowledge — not to memorise it.

What you will find here

Three things, and all of them free.

CTF walkthroughs

Weekly challenges, worked through properly. Tools used, filters used, and the reasoning behind each step — including the ones that led nowhere.

Certification study guides

Written from the notes I actually used to pass. What is on the exam, how the questions are worded, and how I planned the study time.

Cyber concepts

The ideas underneath the tooling, explained clearly. Once a concept clicks, the commands stop being something you memorise.

Latest walkthroughs

One a week, with the video alongside. Each one says up front whether it spoils the answers.

LetsDefend: AWS PerSEStence — building a timeline from CloudTrail

This one was a fun one. A hard cloud IR challenge: making thousands of CloudTrail JSON events readable with jq, and turning them into the story of how an attacker stayed in.

LetsDefend: Compromised ICS Device — a PLC, a water pump and Modbus

A water treatment plant with a compromised PLC. Learning Modbus from scratch, tracing the brute force, and the one-space filter mistake that cost me an hour.

LetsDefend: ICS FuelStation — finding the attack in the packet capture

This week I tackled ICS FuelStation. One tool, three Wireshark filters, and an incident response report at the end. Here is exactly how I worked through it.

Certification study guides

Every one of these is a cert I sat myself.

GIAC GSTRT — Strategic Planning, Policy and Leadership

The cert that made me a better engineer, not just a better manager. What GSTRT tests, how to build the index that passes it, and why the "soft" cert is the hard one.

AWS Certified Security – Specialty (SCS-C02) — the complete study guide

The hardest AWS security exam, domain by domain: detection and response, logging, infrastructure, IAM, data protection and governance — plus the service comparisons it tests relentlessly.

CompTIA CySA+ CS0-003 — the complete study guide

CySA+ is Security+ with the training wheels off: real log analysis, real vulnerability prioritisation, real incident response. Here is what it tests and how to prepare.

Cyber concepts

The ideas underneath the tooling, explained clearly.

VPC peering: six ways an attacker abuses it

Why I learn how a feature is enabled before I learn how to secure it. Lateral movement, permissive NACLs, DNS spoofing, exfiltration, privilege escalation and configuration abuse.

Bringing AI into your business: the security questions to answer first

Guidance for businesses adding AI to their workflow. What AI genuinely improves in threat detection, and the five security considerations that decide whether it helps or hurts.

Security savings tips for your business

A running series on where AWS security features pay for themselves — automated assessments, backup encryption, budget monitoring, and the total cost of getting the architecture right.

Written by someone who sat the exams

Every study guide here comes from a certification I actually earned — not summarised from a syllabus.

Amazon Web Services

AWS Certified Security – Specialty

Specialty-level exam on securing AWS workloads: identity, detection, incident response, infrastructure and data protection.

Amazon Web Services

AWS Certified Cloud Practitioner

Foundational AWS exam covering cloud concepts, core services, the shared responsibility model, billing and support.

GIAC

GIAC Certified Incident Handler

Hands-on incident handling: detection, containment, eradication and recovery, plus the attacker techniques behind each.

CompTIA

CompTIA Cybersecurity Analyst (CySA+)

Behavioural analytics, threat detection, vulnerability management and incident response from the SOC analyst’s seat.

GIAC

GIAC Strategic Planning, Policy, and Leadership

Building a security strategy that survives contact with the business: strategic planning, writing policy people actually follow, and leading the team that delivers it.

CompTIA

CompTIA Security+

The baseline security certification: threats, architecture, operations, and governance, risk and compliance.

How I do this

I learn in public. That means you get the progress and the setbacks, because the setbacks are usually where the lesson is.

So when something did not work, I say so. When I went down the wrong path for an hour, that goes in too. A walkthrough that only shows the clean route teaches you nothing about how to think when you are stuck — and you will be stuck.

It takes longer to write this way. But the goal is that you can go and do it yourself afterwards, not that you watched me do it.

Keep practising!

New walkthrough every week.

Watch it on YouTube, then read the written version here with every command and filter you can copy.

Questions I get asked

No. Each walkthrough says what you need up front, and links out to the concepts it leans on. If a step needs background you have not covered yet, there is a path to go and get it.

Every walkthrough tells you before you scroll. Ones labelled “Full solution” contain the answers — those are the challenges I have already published a full video walkthrough for, so writing it down spoils nothing that is not already public. Ones labelled “No spoilers” give you the tools, the filters and the reasoning with the answers left out, so you can still work it out yourself.

The writing is not, and it never will be. Every walkthrough, study guide and concept post is free to read — no paywall, no account, no email gate. Cost should never be the reason somebody cannot start in this field. What I do sell is time: one-to-one coaching, resume reviews and a study accountability group, all on the Work with me page. Nothing that is free today moves behind a payment later.

Please do — requests genuinely shape what I write next. Leave a comment under any walkthrough, or message me on LinkedIn and tell me what you are stuck on.

Hand to paper and flowcharts, every time. I read the material once for understanding, then go back and build an index or a set of notes in my own words. The goal is to retain it and be able to explain it — not to memorise it for one exam day.

Digital Sentinel — cyber walkthroughs and certification study guides