Info

Cybersecurity is the practice of protecting systems, networks, and data from unauthorised access, damage, or disruption. It spans a wide range of disciplines — from defensive practices like hardening systems and monitoring for intrusions, to offensive practices like penetration testing and reverse engineering, to the underlying cryptography and protocols that everything else depends on.

About Me and Cybersecurity:

Whilst I would place myself at the higher end of technological literacy, the world of cybersecurity for me is pretty new. I am engaged with studies slow and part time at the Canberra institute of Technology, so I can be as full capable and literate as I can be in this area. there is still a long way to go. This section of this Obsidian vault is where I will be mapping out what I learn, practicing some skills in the Homelab and try to bring together what I have learned in life and community sector with cyber knowledge that is accessible to those sections of the community generally passed over by tech professionals looking to find careers in the corporate world. Data on Cybercrime in Australia reveals a a reality that no area of society is out of reach across the socioeconomic spectrum. So… this is not an exhaustive reference on cybersecurity, its not intended to be, it is more like contextualisation and structure to inform future notes and the further shaping of a passion project.

Cyber Attacks

Cyber attacks are defined and distinguished by the method(s) an attacker uses to gain initial access and what they’re trying to achieve once inside. Some strategies exploit technical weaknesses directly; unpatched software, misconfigured services, weak or reused credentials; while others such as Social Engineering exploit human psychology, tricking a person into granting access or handing over information voluntarily rather than breaking through a technical barrier. Most attacks blend both and now have the power of Artificial Intelligence to automate, and conduct sustained and highly targeted attacks that find exploits where human eyes have previously passed over.

Attack Strategies

An attack pathway is the sequence of steps an attacker takes to move from initial access to their end goal; for example, phishing an employee, using their stolen credentials to log into a corporate VPN, then moving laterally across the network to reach sensitive data. The attack surface, by contrast, is the total set of points where an attacker could potentially attempt to gain access in the first place; that means every exposed service, open port, employee inbox, third-party integration, and piece of internet-facing infrastructure an organisation, business or home has. A larger, more complex attack surface gives attackers more potential pathways to choose from This is why things like closing unused ports, retiring old accounts, (see Stale Credential ), limiting third-party access, segmenting networks are such effective yet simple defensive strategies available, independent of the nature of the threat.

Sub areas within Cybersecurity

  • Offensive security / penetration testing — simulating attacks against systems to find weaknesses before real attackers do, using tools for password cracking, vulnerability scanning, and exploit development
  • Reverse engineering — analysing compiled software or binaries to understand how they work, often to find vulnerabilities or understand malware behaviour
  • Network security — protecting data in transit, securing infrastructure, and monitoring traffic for malicious activity
  • Application security — finding and fixing vulnerabilities in software during and after development
  • Digital forensics and incident response — investigating breaches after they occur, tracing what happened and how
  • Cryptography — the mathematical foundations underpinning secure communication, password storage, and data protection

Documenting Cybersecurity Actions

This page is the base for sharing learning experiences within my Homelab to build skills in Cybersecurity, and work toward a qualification in this area. Learning experiences worth sharing are documented below:

Date AddedNoteSummary
22nd Aug 2026KVM Virtualisation ConflictOpen WebUI was tied into a Docker setup that relied on KVM, while the Kali VM was being run through VirtualBox. KVM and VirtualBox both wanted access to the machine’s hardware virtualisation features.
26th Aug 2026Stale CredentialA security check of a decommissioned and thought to be hardened ex-home server found to have a vulnerability worth documenting.

Position in this vault

This structural note serves as the anchor for cybersecurity-related notes in this vault — covering specific tools, techniques, and hands-on work as they’re documented.