Browse CTFs New CTF Sign in
Back to Learning Paths
Information System Security Officer / Generalist
Applied Wave 3 Draft

Information System Security Officer / Generalist

25.0h estimated 3 Courses

Applied-level certification for ISSO/governance roles. CTF-supported content for technical controls; requires non-CTF governance capsules.

Sign in to enroll

Governance, Risk, Compliance and Security Policies [Non-CTF]

0 cards

No cards in this course yet.

Vulnerability Oversight, Incidents and Controls

31 cards

Correlating Multi-Host Authentication Anomalies to Detect Lateral Movement

log_analysis_siem Difficulty 1–5 30 min

Correlating Audit Events Across Linux and Windows Privilege Escalation Transitions

log_analysis_siem Difficulty 1–5 30 min

QR code decode

log_analysis_siem Difficulty 1–5 30 min

Sigreturn-Oriented Programming: Signal Frame Hijacking for Full CPU Register Control with Minimal Gadgets

log_analysis_siem Difficulty 1–5 30 min

Morse Code Decoding: Timing Analysis, Delimiter Identification and Transcription Methodology

log_analysis_siem Difficulty 1–5 30 min

Bacon cipher

log_analysis_siem Difficulty 1–5 30 min

Zero-width steganography

log_analysis_siem Difficulty 1–5 30 min

Brainfuck encoding

log_analysis_siem Difficulty 1–5 30 min

NATO phonetic alphabet

log_analysis_siem Difficulty 1–5 30 min

Multi-layer encoding chain

log_analysis_siem Difficulty 1–5 30 min

QR Code Forensics: Error Correction Analysis and Partially Damaged Payload Reconstruction

log_analysis_siem Difficulty 1–5 30 min

Baudot encoding

log_analysis_siem Difficulty 1–5 30 min

Leetspeak obfuscation

log_analysis_siem Difficulty 1–5 30 min

Azure RBAC Misconfiguration: Subscription-Scope Role Assignments and Service Principal Abuse

log_analysis_siem Difficulty 1–5 30 min

AWS Service Control Policy Misconfiguration: Cross-Account Permission Escalation

log_analysis_siem Difficulty 1–5 30 min

S3 Bucket Policy Misconfiguration: Public Access, Cross-Account Grants and Transport Gaps

log_analysis_siem Difficulty 1–5 30 min

AWS Cognito Unauthenticated Identity Pool Exploitation: Anonymous Credential Escalation

osint_collection Difficulty 1–5 30 min

Terraform State Manipulation: Injecting Malicious Resource Definitions via Backend Write Access

osint_collection Difficulty 1–5 30 min

AWS CloudFormation Credential Exposure: Extracting Secrets from Stack Templates

osint_collection Difficulty 1–5 30 min

AWS Lambda Execution Role Privilege Escalation: Function Invocation for IAM Abuse

osint_collection Difficulty 1–5 30 min

AWS Secrets Manager Access Control Weaknesses: Scoping IAM Policies for GetSecretValue

osint_collection Difficulty 1–5 30 min

AWS Confused Deputy Attack: Cross-Account Role Assumption Without External ID Enforcement

osint_collection Difficulty 1–5 30 min

Reconstructing SMTP Email Sessions and Extracting Attachments from Network Traffic Captures

osint_collection Difficulty 1–5 30 min

Parsing FTP Command and Response Traffic with Passive Mode Data Channel Reconstruction

osint_collection Difficulty 1–5 30 min

Parsing Telnet IAC Command Sequences and Reconstructing Plaintext Sessions from PCAP

osint_collection Difficulty 1–5 30 min

Reconstructing IRC Sessions via Protocol PCAP Analysis and Channel Message Content Recovery

osint_collection Difficulty 1–5 30 min

Reconstructing LDAP Directory Queries via PCAP Analysis and Enumeration Pattern Detection

osint_collection Difficulty 1–5 30 min

Analyzing WebSocket PCAP Captures via HTTP Upgrade Detection and Frame Payload Extraction

osint_collection Difficulty 1–5 30 min

Reconstructing SIP Call Dialogs and Extracting RTP Stream Parameters for VoIP Forensics

osint_collection Difficulty 1–5 30 min

Enumerating Local Services via mDNS PCAP Multicast Record Analysis and Host Fingerprinting

osint_collection Difficulty 1–5 30 min

Interpreting Modbus/TCP Function Codes and Extracting PLC Register Values from PCAP

osint_collection Difficulty 1–5 30 min

Executive Communication and Decision-Making [Non-CTF]

0 cards

No cards in this course yet.

🏅

CTFFactory ISSO / Cyber Governance Practitioner

Applied credential — awarded upon completion