Sec Guy

Sec Guy

by Sec Guy
Season 4

Incident Response: Forensics, Diamond Model, IOC, IOA

You don't build an Incident Response plan during a breach. In this video, Sec Guy dissects the massive Salt Typhoon attack to show you how professional responders hunt advanced threats. We break down the Diamond Model of Intrusion Analysis, explain why Indicators of Attack (IOA) are more valuable than Indicators of Compromise (IOC), and walk through the Order of Volatility for capturing forensic evidence before it disappears. πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯ [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 4.1: Incident Response Procedures (Preparation, Detection, Analysis, Containment, Eradication, Recovery) [ ] Domain 4.3: Digital Forensics (Order of Volatility, Chain of Custody, Legal Hold) [ ] Domain 2.3: Indicators of Malicious Activity (IOC vs. IOA) CISSP [ ] Domain 7: Security Operations (Incident Management & Investigations) [ ] Domain 1: Security and Risk Management (Legal & Regulatory Issues in Forensics) CISM [ ] Domain 4: Information Security Incident Management (IR Plans & Playbooks) CRISC [ ] Domain 4: Risk and Control Monitoring (Monitoring for IOCs) CCSP [ ] Domain 5: Cloud Security Operations (Forensics in the Cloud & Data Sovereignty) SecurityX (CompTIA) [ ] Domain 3.0: Security Operations (Threat Hunting & Diamond Model) GIAC GSEC (SANS) [ ] Incident Handling & Response: The IR Lifecycle & Forensics AWS CSS (Certified Security – Specialty) [ ] Domain 4: Incident Response (Automating Forensic Capture in Cloud) Pentest+ (CompTIA) [ ] Domain 5: Reporting and Communication (Post-Exploitation & Cleanup) CEH (Certified Ethical Hacker) [ ] Domain 1: Information Security Overview (Cyber Kill Chain vs. Diamond Model) SecAI+ [ ] AI Security: Analyzing AI-Driven Attacks via Behavioral Indicators (IOA) [Timestamps] 0:00 - Intro: When the Enemy is Already Inside 0:23 - Case Study: Salt Typhoon (APT & Living off the Land) 1:10 - Phase 1: Preparation (Playbooks & Visibility) 1:31 - Phase 2: Detection & Analysis (IOC vs. IOA) 2:20 - The Diamond Model: Adversary, Capability, Infrastructure, Victim 2:53 - Phase 3: Containment (Micro-segmentation vs. Shutdown) 3:20 - Phase 4: Eradication & Recovery (Rootkits & Registry Keys) 3:35 - Digital Forensics: Order of Volatility (RAM vs. Disk) 4:08 - Legal Hold & Chain of Custody (Admissibility) 4:42 - Data Sovereignty: GDPR & Cross-Border Forensics 5:14 - Summary: Speed is Good, Accuracy is Survival 5:36 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=InpBtyDErgk

Security Operations: SOC, SIEM, SOAR and UEBA

A firewall blocks traffic, but a SOC finds the enemy already inside. In this video, Sec Guy breaks down the Tiered SOC Model (Analysts vs. Hunters), explains the critical math of Detection Engineering (Precision vs. Recall), and shows how UEBA uses Machine Learning to catch the "Insider Threat" that traditional rules miss. πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯ [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 4.1: Security Operations (SOC Roles, Playbooks, Runbooks) [ ] Domain 4.2: Monitoring and Detection (SIEM, UEBA, SOAR) [ ] Domain 2.3: Indicators of Malicious Activity (False Positives vs. True Positives) CISSP [ ] Domain 7: Security Operations (Logging and Monitoring Activities) [ ] Domain 1: Security and Risk Management (Security Governance & Roles) CISM [ ] Domain 4: Information Security Incident Management (Incident Response Capabilities) CRISC [ ] Domain 4: Risk and Control Monitoring (Key Performance Indicators - KPI/KRI) CCSP [ ] Domain 5: Cloud Security Operations (Cloud Logging & Monitoring) SecurityX (CompTIA) [ ] Domain 3.0: Security Operations (Threat Detection Engineering & Detection as Code) GIAC GSEC (SANS) [ ] Incident Handling & Response: SIEM & Log Analysis AWS CSS (Certified Security – Specialty) [ ] Domain 4: Incident Response (Centralized Logging with CloudWatch & Security Hub) Pentest+ (CompTIA) [ ] Domain 5: Reporting and Communication (Avoiding Detection by SOC) CEH (Certified Ethical Hacker) [ ] Domain 1: Information Security Overview (SOC Functions & SIEM Concepts) SecAI+ [ ] AI Security: Using AI for Anomaly Detection (UEBA) vs. Traditional Rules [Timestamps] 0:00 - Intro: Manning the Watchtowers 0:25 - The Tiered SOC Model: Tier 1 (Triage), Tier 2 (IR), Tier 3 (Hunters) 1:00 - Detection Engineering: Precision (Quality) vs. Recall (Quantity) 1:40 - UEBA (User & Entity Behavior Analytics): Catching the Insider 2:20 - The SIEM Pipeline: Collection, Normalization, Correlation 3:00 - Cloud Architecture: Security Data Lake vs. SIEM Cost 3:30 - Detection as Code: Git-based Rules & Version Control 3:50 - SOAR (Security Orchestration, Automation, and Response) 4:15 - Summary: Data is Noise until it's Actionable 4:35 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=H1yf0HuiWNQ

Secure SDLC: DevSecOps, OWASP, SBOM, SAST, and BOLA

In a cloud-native world, your code is your infrastructure. If the code is hollow, the fortress falls. In this video, Sec Guy breaks down the Secure SDLC, explains how to use STRIDE for Threat Modeling, and details the difference between SAST (Whitebox) and DAST (Blackbox) testing. We also tackle the #1 API threat: BOLA (Broken Object Level Authorization). πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯ [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 3.2: Application Security (OWASP Top 10, Injection, BOLA) [ ] Domain 4.2: Security Operations (Vulnerability Scanning: SAST, DAST) [ ] Domain 5.1: Risk Management (Supply Chain Risk, SBOM) CISSP [ ] Domain 8: Software Development Security (SDLC, STRIDE, Fuzzing) [ ] Domain 3: Security Architecture (High Cohesion, Low Coupling, Encapsulation) CISM [ ] Domain 3: Information Security Program (Secure Development Practices) CRISC [ ] Domain 2: IT Risk Assessment (Application Vulnerabilities) CCSP [ ] Domain 4: Cloud Application Security (SAST/DAST in CI/CD, API Security) SecurityX (CompTIA) [ ] Domain 2.0: Security Architecture (Secure Coding Practices & Input Validation) GIAC GSEC (SANS) [ ] Application Security: OWASP, Fuzzing, & Defense in Depth AWS CSS (Certified Security – Specialty) [ ] Domain 5: Data Protection (Encryption at Rest/Transit in Apps) Pentest+ (CompTIA) [ ] Domain 3: Attacks and Exploits (SQL Injection, XSS, IDOR/BOLA) CEH (Certified Ethical Hacker) [ ] Domain 10: Web Server & Application Hacking (OWASP Top 10) SecAI+ [ ] AI Security: AI-Generated Code Vulnerabilities & Supply Chain Attacks [Timestamps] 0:00 - Intro: Code is Infrastructure 0:25 - Environment Isolation: Dev, Test, Staging, Prod (Data Masking) 0:48 - Threat Modeling: The STRIDE Framework (Spoofing, Tampering, etc.) 1:06 - Secure Design Patterns: Encapsulation & Polymorphism 1:24 - CISSP Concepts: High Cohesion vs. Low Coupling 1:40 - Testing: Fuzzing (Mutation vs. Generational) 2:06 - Defending Against Injection: Input Validation vs. Parameterization 2:31 - API Security: BOLA (Broken Object Level Authorization) & IDOR 3:00 - Supply Chain Security: SCA & SBOM (Software Bill of Materials) 3:13 - The Toolchain: SAST (Whitebox) vs. DAST (Blackbox) 3:26 - Runtime Defense: IAST & RASP (The Bodyguard) 3:44 - Summary: Security is an Architectural Requirement 3:52 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=f31bpUbkefs

Vulnerability Management: RBVM, EPSS, CISA KEV, CVSS, Asset Discovery

A deep dive into the vulnerability lifecycle. We cover authenticated vs. agent-based scanning, the shift from CVSS severity to EPSS probability, and how to build a Risk-Based Vulnerability Management (RBVM) program. New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide Timestamps: 00:00 – Intro: The Maintenance of the Fortress 01:15 – Asset Discovery: The "Step Zero" 02:30 – Scanning: Authenticated, Unauthenticated, and Agent-based 04:00 – CVSS Explained: Base, Temporal, and Environmental 05:30 – Prioritization: EPSS and the CISA KEV Catalog 07:15 – The Patch Lifecycle and Regression Testing 08:45 – Vulnerability Disclosure Programs (VDP) 10:00 – Outro and Labs (secguy.org) Original Sec Guy video: https://www.youtube.com/watch?v=Ct5ILeDSM5w

Penetration Testing: NMAP, Enumeration, Scanning, and Exploitation

It isn't enough to know the phases; you have to master the mechanics. In this video, Sec Guy goes deep into the offensive toolkit. We move from Passive Reconnaissance to Active Scanning with Nmap and hping3, explain how to poison networks with Responder, and show you how to automate SQL Injection with SQLMap. If you are studying for CEH or PenTest+, this is your tactical field guide. New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 4.2: Security Operations (Vulnerability Scanning vs. Penetration Testing) [ ] Domain 2.2: Vulnerabilities (SQL Injection, XSS) CISSP [ ] Domain 6: Security Assessment and Testing (Penetration Testing Methodologies) CISM [ ] Domain 3: Information Security Program (Managing Technical Assessments) CRISC [ ] Domain 2: IT Risk Assessment (Technical Vulnerabilities & Exploits) CCSP [ ] Domain 4: Cloud Application Security (OWASP Testing) SecurityX (CompTIA) [ ] Domain 3.0: Security Operations (Advanced Enumeration & Exploitation) GIAC GSEC (SANS) [ ] Penetration Testing: Tools & Techniques (Nmap, Metasploit) AWS CSS (Certified Security – Specialty) [ ] Domain 1: Threat Detection (Recognizing Port Scanning & Enumeration) Pentest+ (CompTIA) [ ] Domain 3: Attacks and Exploits (Network Attacks, Web App Attacks, Wireless Attacks) [ ] Domain 2: Information Gathering (Nmap, Enumeration) CEH (Certified Ethical Hacker) [ ] Domain 3: Scanning Networks (Nmap, Hping3) [ ] Domain 4: Enumeration (SNMP, SMB, RPC) [ ] Domain 10: Web Server Hacking (SQLMap, XSS) SecAI+ [ ] AI Security: Automating Vulnerability Scanning with AI Agents [Timestamps] 0:00 - Intro: From Passive Observer to Active Explorer 0:23 - Scanning: Packet Crafting with Hping3 & Nmap (Idle Scans) 0:40 - Enumeration: Extracting Usernames via SNMP, RPC, and SMB (Enum4Linux) 1:16 - System Hacking: Cracking Passwords & Escalating Privileges 1:26 - Network Poisoning: LLMNR/NBT-NS with Responder 1:37 - Password Cracking: Hashcat & John the Ripper 1:53 - Web App Hacking: SQL Injection (SQLMap) & XSS (BeEF) 2:24 - Wireless Hacking: Aircrack-ng (WPA2 Handshakes) & Reaver (WPS) 2:49 - Mobile & IoT: ADB & MobSF (APK Analysis) 3:00 - Cloud Exploitation: S3 Buckets & Container Escape 3:16 - Post-Exploitation: Clearing Tracks (Shred Command & Event Viewer) 3:39 - Outro: Get the Reps In. Original Sec Guy video: https://www.youtube.com/watch?v=UXHs3dsmPGQ

Social Engineering: Phishing, Vishing, and Smishing

You don't need a zero-day exploit to hack a Fortune 500 companyβ€”you just need a phone and a story. In this video, Sec Guy breaks down the MGM Resorts Breach, explaining how attackers used Vishing to trick a help desk into resetting credentials. We also cover the rise of AI Deepfakes in CEO Fraud, why Tailgating works because of human courtesy, and how Business Email Compromise (BEC) stole $100M from Facebook and Google. New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 2.4: Social Engineering (Phishing, Vishing, Smishing, BEC, Pretexting) [ ] Domain 2.1: Threat Actors (Motivation: Financial vs. Chaos) CISSP [ ] Domain 1: Security and Risk Management (Social Engineering Training & Awareness) [ ] Domain 7: Security Operations (Physical Security: Tailgating & Piggybacking) CISM [ ] Domain 3: Information Security Program (Human Firewall & Security Culture) CRISC [ ] Domain 2: IT Risk Assessment (Human Element Risks) CCSP [ ] Domain 1: Cloud Concepts (Social Engineering Cloud Admins) SecurityX (CompTIA) [ ] Domain 3.0: Security Operations (Analyzing Social Engineering Campaigns) GIAC GSEC (SANS) [ ] Social Engineering: Principles of Persuasion (Authority, Consensus, Urgency) AWS CSS (Certified Security – Specialty) [ ] Domain 1: Threat Detection (Identifying Compromised Credentials via Phishing) Pentest+ (CompTIA) [ ] Domain 3: Attacks and Exploits (Social Engineering: Pretexting & Elicitation) [ ] Domain 1: Planning and Scoping (Physical Assessments: Tailgating) CEH (Certified Ethical Hacker) [ ] Domain 9: Social Engineering (Types, Phases, & Countermeasures) SecAI+ [ ] AI Security: Deepfake Audio & Synthetic Voice Attacks (Vishing) [Timestamps] 0:00 - Intro: Hacking Humans, Not Hardware 0:22 - Case Study: MGM Resorts (Vishing the Help Desk) 1:08 - AI Threats: Synthetic Voice & Deepfake CEO Fraud 1:40 - Physical Security: Tailgating & Piggybacking (The Pizza Trick) 2:03 - Reconnaissance: Dumpster Diving for Intel 2:30 - Business Email Compromise (BEC): The $100M Invoice Scam 3:13 - Defense: Out-of-Band Verification 3:30 - Summary: The Human Firewall 3:50 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=VKcS9eeH4Ys

Cloud Models: IaaS to Serverless, Shared Responsibility, and Soverignty

If your data is breached in the cloud, is it Amazon's fault or yours? In this video, Sec Guy breaks down the Shared Responsibility Model, explaining why Capital One was liable for their massive breach (SSRF) despite using a secure cloud provider. We also cover the evolution from IaaS to Serverless (FaaS) and why Data Sovereignty (Microsoft Ireland Case) means your data is subject to the laws of the physical land it sits on. New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 3.2: Cloud Computing Concepts (IaaS, PaaS, SaaS, Public/Private/Hybrid) [ ] Domain 5.3: Third-Party Risk Management (Shared Responsibility Model) [ ] Domain 2.2: Vulnerabilities (SSRF - Server-Side Request Forgery) CISSP [ ] Domain 3: Security Architecture (Cloud Service Models & Microservices) [ ] Domain 1: Security and Risk Management (Legal & Regulatory Issues - Data Sovereignty) CISM [ ] Domain 2: Information Risk Management (Cloud Risk Assessment) CRISC [ ] Domain 2: IT Risk Assessment (Outsourcing & Cloud Vendor Risk) CCSP [ ] Domain 1: Cloud Concepts (IaaS, PaaS, SaaS, FaaS, Shared Responsibility)\ [ ] Domain 6: Legal, Risk, and Compliance (Cross-Border Data Transfer & GDPR) SecurityX (CompTIA) [ ] Domain 2.0: Security Architecture (Cloud Native Security Controls - CNAPP, CWPP, CSPM) GIAC GSEC (SANS) [ ] Cloud Security: Fundamentals & Shared Responsibility AWS CSS (Certified Security – Specialty) [ ] Domain 2: Infrastructure Security (Shared Responsibility Model) Pentest+ (CompTIA) [ ] Domain 3: Attacks and Exploits (Cloud Metadata Attacks & SSRF) CEH (Certified Ethical Hacker) [ ] Domain 11: Cloud Computing (Cloud Attacks & Misconfigurations) SecAI+ [ ] AI Security: Securing AI Models on Serverless Infrastructure (FaaS) [Timestamps] 0:00 - Intro: The Cloud is Just Someone Else's Computer? 0:37 - IaaS (Infrastructure as a Service): Renting the House (AWS EC2) 1:00 - PaaS (Platform as a Service): Staying in a Hotel (Google App Engine) 1:23 - SaaS (Software as a Service): Dining Out (Salesforce, Gmail) 1:38 - FaaS (Serverless): The Ultimate Abstraction (AWS Lambda) 2:10 - The Shared Responsibility Model: Security "OF" vs. Security "IN" 2:45 - Case Study: Capital One Breach (SSRF & Misconfiguration) 3:30 - Data Sovereignty: The Microsoft Ireland Case & GDPR 4:20 - The Cloud Security Stack: CSPM, CWPP, CASB, & CNAPP 5:20 - Summary: Control vs. Convenience 5:40 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=oxDZf-7dzVQ

Cloud Architecture Security: CSPM, CASB, Zero Trust

If your cloud environment is a skyscraper, CSPM is the building inspector checking the foundation, while CASB is the security guard checking everyone who walks through the door. In this video, Sec Guy explains the critical difference between securing infrastructure (IaaS) and securing SaaS applications, breaks down Forward vs. Reverse Proxy deployment modes, and shows how a Zero Trust Policy Decision Point (PDP) can stop an identity attack in real-time. New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 3.2: Cloud Computing Concepts (CASB, CSPM) [ ] Domain 3.3: Network Designs (Zero Trust: PDP & PEP) [ ] Domain 5.2: Risk Management (Shadow IT & Data Loss Prevention) CISSP [ ] Domain 3: Security Architecture (Cloud Security Tools & Deployment Modes) [ ] Domain 4: Communication & Network Security (TLS Inspection & Proxies) CISM [ ] Domain 2: Information Risk Management (Cloud Misconfigurations) CRISC [ ] Domain 2: IT Risk Assessment (Shadow IT Risks) CCSP [ ] Domain 1: Cloud Concepts (NIST 800-207 Zero Trust) [ ] Domain 4: Cloud Application Security (CASB Deployment Modes: API, Forward/Reverse Proxy) SecurityX (CompTIA) [ ] Domain 2.0: Security Architecture (Implementing CNAPP & CASB) GIAC GSEC (SANS) [ ] Cloud Security: Monitoring & Posture Management AWS CSS (Certified Security – Specialty) [ ] Domain 2: Infrastructure Security (AWS Config vs. CSPM) Pentest+ (CompTIA) [ ] Domain 3: Attacks and Exploits (Cloud Misconfigurations & S3 Buckets) CEH (Certified Ethical Hacker) [ ] Domain 11: Cloud Computing (Shadow IT & Data Exfiltration) SecAI+ [ ] AI Security: Using AI to Automate CSPM Remediation [Timestamps] 0:00 - Intro: Tools of the Trade 0:16 - CSPM (Cloud Security Posture Management): The Building Inspector 0:44 - Case Study: Accenture & Twilio (Open S3 Buckets) 1:08 - Shift Left: Scanning Terraform (IaC) in the Build Pipeline 1:28 - CASB (Cloud Access Security Broker): The Bouncer for SaaS 1:50 - CASB Modes: Forward Proxy vs. Reverse Proxy vs. API 2:17 - The Visibility Gap: TLS Inspection & User Privacy 2:42 - Zero Trust Architecture (NIST 800-207): Never Trust, Always Verify 3:00 - The Brain & The Brawn: Policy Decision Point (PDP) vs. Enforcement Point (PEP) 3:28 - Contextual Access: Blocking Impossible Travel (Seattle to London) 3:50 - Free Resources: Zero Trust Logic Map & Labs 4:26 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=GjTDgXsMK60

Cloud IAM: STS, Roles, SCP, and Policies

A password can be stolen, but a temporary token expires. In this video, Sec Guy explains why Long-Term Access Keys are a "security smell" and how to replace them with IAM Roles and the STS (Security Token Service). We break down the critical difference between Identity-Based Policies (What I can do) and Resource-Based Policies (Who can access this bucket), and show you how to use SCPs (Service Control Policies) to create an unbreakable ceiling on permissions. New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 1.3: Identity and Access Management (Roles vs. Accounts) [ ] Domain 3.2: Cloud Computing Concepts (IAM Policies, SCPs) [ ] Domain 5.2: Risk Management (Least Privilege & Guardrails) CISSP [ ] Domain 5: Identity and Access Management (Authorization Mechanisms, Role-Based Access Control) [ ] Domain 3: Security Architecture (Cloud Identity Services) CISM [ ] Domain 3: Information Security Program (Identity Governance & Policy Enforcement) CRISC [ ] Domain 2: IT Risk Assessment (Cloud Misconfiguration Risks) CCSP [ ] Domain 4: Cloud Application Security (IAM, STS, & Temporary Credentials) [ ] Domain 1: Cloud Concepts (Multi-Tenancy & Resource Policies) SecurityX (CompTIA) [ ] Domain 1.0: Security Architecture (Implementing Service Control Policies) GIAC GSEC (SANS) [ ] Cloud Security: IAM Roles & Policies AWS CSS (Certified Security – Specialty) [ ] Domain 3: Infrastructure Security (IAM Policies, SCPs, Permissions Boundaries) [ ] Domain 1: Threat Detection (Detecting Principal Misuse) Pentest+ (CompTIA) [ ] Domain 3: Attacks and Exploits (Cloud Privilege Escalation) CEH (Certified Ethical Hacker) [ ] Domain 11: Cloud Computing (IAM Misconfigurations & Key Theft) SecAI+ [ ] AI Security: Limiting AI Agent Permissions via SCPs [Timestamps] 0:00 - Intro: Accounts vs. Roles (The "Hat" Analogy) 0:30 - STS (Security Token Service): The Temporary Badge Office 0:58 - Identity-Based Policies: "I am allowed to..." 1:32 - Resource-Based Policies: "This bucket allows..." 1:42 - Case Study: Imperva Breach (SSRF & Metadata Service) 2:12 - The Wildcard (*) Danger: Granular Permissions 2:30 - SCPs (Service Control Policies): The Organization Kill Switch 2:58 - Permissions Boundaries: Setting the Ceiling for Developers 3:21 - Summary: Identity is the Perimeter 3:36 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=4z-v9k5qIWM

AI Threat Landscape: Model Poisoning and Prompt Injection

When you type a password, the computer knows it's data. But when you talk to an AI, your instructions and your data are the exact same thingβ€”just tokens in a stream. That single flaw is the root of every AI attack. In this video, Sec Guy explains the math behind Universal Adversarial Triggers, reveals how Indirect Prompt Injection can turn a resume into a weapon, and shows why Token Smuggling allows malware to slip right past your firewall. New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 2.6: Artificial Intelligence (Prompt Injection, Training Data Poisoning) [ ] Domain 2.2: Vulnerabilities (Supply Chain Attacks - Poisoned Models) CISSP [ ] Domain 8: Software Development Security (Input Validation in AI Systems) [ ] Domain 1: Security and Risk Management (AI Risk Assessment) CISM [ ] Domain 2: Information Risk Management (Emerging Tech Risks: AI & ML) CRISC [ ] Domain 2: IT Risk Assessment (Adversarial AI & Model Theft) CCSP [ ] Domain 4: Cloud Application Security (Securing AI APIs & Rate Limiting) SecurityX (CompTIA) [ ] Domain 3.0: Security Operations (Detecting Adversarial ML Attacks) GIAC GSEC (SANS) [ ] Emerging Threats: AI & LLM Security AWS CSS (Certified Security – Specialty) [ ] Domain 1: Threat Detection (Anomalous API Usage & Cost Attacks) Pentest+ (CompTIA) [ ] Domain 3: Attacks and Exploits (Prompt Injection & Jailbreaking LLMs) CEH (Certified Ethical Hacker) [ ] Domain 10: Web Server & Application Hacking (AI-Specific Injection Vectors) SecAI+ [ ] AI Security: Universal Adversarial Triggers (UAT), Indirect Injection, Token Smuggling, Model Inversion [Timestamps] 0:00 - Intro: Data vs. Instructions (The Core Flaw) 0:48 - Context Mixing: The "System Prompt" Vulnerability 1:28 - Type 1: Persona Modification ("Do Anything Now" / DAN) 1:54 - Type 2: Logical Bypass (Translation & Educational Intent) 2:25 - Type 3: Universal Adversarial Triggers (The Math of "ZXCVB") 3:05 - Indirect Prompt Injection: The Resume Scanner Attack (Zero Click) 3:50 - RAG Poisoning: When the AI Searches a Malicious Site 4:22 - Token Smuggling: Bypassing Firewalls via Payload Splitting 4:54 - Availability Attacks: Wallet Exhaustion & Recursive Loops 5:37 - Defense: Prompt Firewalls & Canary Tokens 5:56 - Homework: Glitch Tokens 6:14 - Outro: Train Hard, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=ELWi8OXZoQ0
3 of 7