Sec Guy

Sec Guy

Download on the App Store

Sec Guy episodes

  • Social Engineering: Phishing, Vishing, and Smishing

    You don't need a zero-day exploit to hack a Fortune 500 company—you just need a phone and a story. In this video, Sec Guy breaks down the MGM Resorts Breach, explaining how attackers used Vishing to trick a help desk into resetting credentials. We also cover the rise of AI Deepfakes in CEO Fraud, why Tailgating works because of human courtesy, and how Business Email Compromise (BEC) stole $100M from Facebook and Google.

    New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    ✅ Training Videos & Practice Tests

    ✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    ✅ Discord Access (Study sessions & Industry networking)

    👉 Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    🔥 Salary Negotiator Workshop

    🔥 Experience Builder: Real-world projects to fill your resume

    👉 Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 2.4: Social Engineering (Phishing, Vishing, Smishing, BEC, Pretexting)

    [ ] Domain 2.1: Threat Actors (Motivation: Financial vs. Chaos)

    CISSP

    [ ] Domain 1: Security and Risk Management (Social Engineering Training & Awareness)

    [ ] Domain 7: Security Operations (Physical Security: Tailgating & Piggybacking)

    CISM

    [ ] Domain 3: Information Security Program (Human Firewall & Security Culture)

    CRISC

    [ ] Domain 2: IT Risk Assessment (Human Element Risks)

    CCSP

    [ ] Domain 1: Cloud Concepts (Social Engineering Cloud Admins)

    SecurityX (CompTIA)

    [ ] Domain 3.0: Security Operations (Analyzing Social Engineering Campaigns)

    GIAC GSEC (SANS)

    [ ] Social Engineering: Principles of Persuasion (Authority, Consensus, Urgency)

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 1: Threat Detection (Identifying Compromised Credentials via Phishing)

    Pentest+ (CompTIA)

    [ ] Domain 3: Attacks and Exploits (Social Engineering: Pretexting & Elicitation)

    [ ] Domain 1: Planning and Scoping (Physical Assessments: Tailgating)

    CEH (Certified Ethical Hacker)

    [ ] Domain 9: Social Engineering (Types, Phases, & Countermeasures)

    SecAI+

    [ ] AI Security: Deepfake Audio & Synthetic Voice Attacks (Vishing)

    [Timestamps]

    0:00 - Intro: Hacking Humans, Not Hardware

    0:22 - Case Study: MGM Resorts (Vishing the Help Desk)

    1:08 - AI Threats: Synthetic Voice & Deepfake CEO Fraud

    1:40 - Physical Security: Tailgating & Piggybacking (The Pizza Trick)

    2:03 - Reconnaissance: Dumpster Diving for Intel

    2:30 - Business Email Compromise (BEC): The $100M Invoice Scam

    3:13 - Defense: Out-of-Band Verification

    3:30 - Summary: The Human Firewall

    3:50 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=VKcS9eeH4Ys

    5 min
  • Penetration Testing: NMAP, Enumeration, Scanning, and Exploitation

    It isn't enough to know the phases; you have to master the mechanics. In this video, Sec Guy goes deep into the offensive toolkit. We move from Passive Reconnaissance to Active Scanning with Nmap and hping3, explain how to poison networks with Responder, and show you how to automate SQL Injection with SQLMap. If you are studying for CEH or PenTest+, this is your tactical field guide.

    New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    ✅ Training Videos & Practice Tests

    ✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    ✅ Discord Access (Study sessions & Industry networking)

    👉 Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    🔥 Salary Negotiator Workshop

    🔥 Experience Builder: Real-world projects to fill your resume

    👉 Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 4.2: Security Operations (Vulnerability Scanning vs. Penetration Testing)

    [ ] Domain 2.2: Vulnerabilities (SQL Injection, XSS)

    CISSP

    [ ] Domain 6: Security Assessment and Testing (Penetration Testing Methodologies)

    CISM

    [ ] Domain 3: Information Security Program (Managing Technical Assessments)

    CRISC

    [ ] Domain 2: IT Risk Assessment (Technical Vulnerabilities & Exploits)

    CCSP

    [ ] Domain 4: Cloud Application Security (OWASP Testing)

    SecurityX (CompTIA)

    [ ] Domain 3.0: Security Operations (Advanced Enumeration & Exploitation)

    GIAC GSEC (SANS)

    [ ] Penetration Testing: Tools & Techniques (Nmap, Metasploit)

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 1: Threat Detection (Recognizing Port Scanning & Enumeration)

    Pentest+ (CompTIA)

    [ ] Domain 3: Attacks and Exploits (Network Attacks, Web App Attacks, Wireless Attacks)

    [ ] Domain 2: Information Gathering (Nmap, Enumeration)

    CEH (Certified Ethical Hacker)

    [ ] Domain 3: Scanning Networks (Nmap, Hping3)

    [ ] Domain 4: Enumeration (SNMP, SMB, RPC)

    [ ] Domain 10: Web Server Hacking (SQLMap, XSS)

    SecAI+

    [ ] AI Security: Automating Vulnerability Scanning with AI Agents

    [Timestamps]

    0:00 - Intro: From Passive Observer to Active Explorer

    0:23 - Scanning: Packet Crafting with Hping3 & Nmap (Idle Scans)

    0:40 - Enumeration: Extracting Usernames via SNMP, RPC, and SMB (Enum4Linux)

    1:16 - System Hacking: Cracking Passwords & Escalating Privileges

    1:26 - Network Poisoning: LLMNR/NBT-NS with Responder

    1:37 - Password Cracking: Hashcat & John the Ripper

    1:53 - Web App Hacking: SQL Injection (SQLMap) & XSS (BeEF)

    2:24 - Wireless Hacking: Aircrack-ng (WPA2 Handshakes) & Reaver (WPS)

    2:49 - Mobile & IoT: ADB & MobSF (APK Analysis)

    3:00 - Cloud Exploitation: S3 Buckets & Container Escape

    3:16 - Post-Exploitation: Clearing Tracks (Shred Command & Event Viewer)

    3:39 - Outro: Get the Reps In.

    Original Sec Guy video: https://www.youtube.com/watch?v=UXHs3dsmPGQ

    5 min
  • Vulnerability Management: RBVM, EPSS, CISA KEV, CVSS, Asset Discovery

    A deep dive into the vulnerability lifecycle. We cover authenticated vs. agent-based scanning, the shift from CVSS severity to EPSS probability, and how to build a Risk-Based Vulnerability Management (RBVM) program.

    New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide

    Timestamps:

    00:00 – Intro: The Maintenance of the Fortress

    01:15 – Asset Discovery: The "Step Zero"

    02:30 – Scanning: Authenticated, Unauthenticated, and Agent-based

    04:00 – CVSS Explained: Base, Temporal, and Environmental

    05:30 – Prioritization: EPSS and the CISA KEV Catalog

    07:15 – The Patch Lifecycle and Regression Testing

    08:45 – Vulnerability Disclosure Programs (VDP)

    10:00 – Outro and Labs (secguy.org)

    Original Sec Guy video: https://www.youtube.com/watch?v=Ct5ILeDSM5w

    6 min
  • Secure SDLC: DevSecOps, OWASP, SBOM, SAST, and BOLA

    In a cloud-native world, your code is your infrastructure. If the code is hollow, the fortress falls. In this video, Sec Guy breaks down the Secure SDLC, explains how to use STRIDE for Threat Modeling, and details the difference between SAST (Whitebox) and DAST (Blackbox) testing. We also tackle the #1 API threat: BOLA (Broken Object Level Authorization).

    🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    ✅ Training Videos & Practice Tests

    ✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    ✅ Discord Access (Study sessions & Industry networking)

    👉 Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    🔥 Salary Negotiator Workshop

    🔥 Experience Builder: Real-world projects to fill your resume

    👉 Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 3.2: Application Security (OWASP Top 10, Injection, BOLA)

    [ ] Domain 4.2: Security Operations (Vulnerability Scanning: SAST, DAST)

    [ ] Domain 5.1: Risk Management (Supply Chain Risk, SBOM)

    CISSP

    [ ] Domain 8: Software Development Security (SDLC, STRIDE, Fuzzing)

    [ ] Domain 3: Security Architecture (High Cohesion, Low Coupling, Encapsulation)

    CISM

    [ ] Domain 3: Information Security Program (Secure Development Practices)

    CRISC

    [ ] Domain 2: IT Risk Assessment (Application Vulnerabilities)

    CCSP

    [ ] Domain 4: Cloud Application Security (SAST/DAST in CI/CD, API Security)

    SecurityX (CompTIA)

    [ ] Domain 2.0: Security Architecture (Secure Coding Practices & Input Validation)

    GIAC GSEC (SANS)

    [ ] Application Security: OWASP, Fuzzing, & Defense in Depth

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 5: Data Protection (Encryption at Rest/Transit in Apps)

    Pentest+ (CompTIA)

    [ ] Domain 3: Attacks and Exploits (SQL Injection, XSS, IDOR/BOLA)

    CEH (Certified Ethical Hacker)

    [ ] Domain 10: Web Server & Application Hacking (OWASP Top 10)

    SecAI+

    [ ] AI Security: AI-Generated Code Vulnerabilities & Supply Chain Attacks

    [Timestamps]

    0:00 - Intro: Code is Infrastructure

    0:25 - Environment Isolation: Dev, Test, Staging, Prod (Data Masking)

    0:48 - Threat Modeling: The STRIDE Framework (Spoofing, Tampering, etc.)

    1:06 - Secure Design Patterns: Encapsulation & Polymorphism

    1:24 - CISSP Concepts: High Cohesion vs. Low Coupling

    1:40 - Testing: Fuzzing (Mutation vs. Generational)

    2:06 - Defending Against Injection: Input Validation vs. Parameterization

    2:31 - API Security: BOLA (Broken Object Level Authorization) & IDOR

    3:00 - Supply Chain Security: SCA & SBOM (Software Bill of Materials)

    3:13 - The Toolchain: SAST (Whitebox) vs. DAST (Blackbox)

    3:26 - Runtime Defense: IAST & RASP (The Bodyguard)

    3:44 - Summary: Security is an Architectural Requirement

    3:52 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=f31bpUbkefs

    5 min
  • Security Operations: SOC, SIEM, SOAR and UEBA

    A firewall blocks traffic, but a SOC finds the enemy already inside. In this video, Sec Guy breaks down the Tiered SOC Model (Analysts vs. Hunters), explains the critical math of Detection Engineering (Precision vs. Recall), and shows how UEBA uses Machine Learning to catch the "Insider Threat" that traditional rules miss.

    🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    ✅ Training Videos & Practice Tests

    ✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    ✅ Discord Access (Study sessions & Industry networking)

    👉 Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    🔥 Salary Negotiator Workshop

    🔥 Experience Builder: Real-world projects to fill your resume

    👉 Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 4.1: Security Operations (SOC Roles, Playbooks, Runbooks)

    [ ] Domain 4.2: Monitoring and Detection (SIEM, UEBA, SOAR)

    [ ] Domain 2.3: Indicators of Malicious Activity (False Positives vs. True Positives)

    CISSP

    [ ] Domain 7: Security Operations (Logging and Monitoring Activities)

    [ ] Domain 1: Security and Risk Management (Security Governance & Roles)

    CISM

    [ ] Domain 4: Information Security Incident Management (Incident Response Capabilities)

    CRISC

    [ ] Domain 4: Risk and Control Monitoring (Key Performance Indicators - KPI/KRI)

    CCSP

    [ ] Domain 5: Cloud Security Operations (Cloud Logging & Monitoring)

    SecurityX (CompTIA)

    [ ] Domain 3.0: Security Operations (Threat Detection Engineering & Detection as Code)

    GIAC GSEC (SANS)

    [ ] Incident Handling & Response: SIEM & Log Analysis

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 4: Incident Response (Centralized Logging with CloudWatch & Security Hub)

    Pentest+ (CompTIA)

    [ ] Domain 5: Reporting and Communication (Avoiding Detection by SOC)

    CEH (Certified Ethical Hacker)

    [ ] Domain 1: Information Security Overview (SOC Functions & SIEM Concepts)

    SecAI+

    [ ] AI Security: Using AI for Anomaly Detection (UEBA) vs. Traditional Rules

    [Timestamps]

    0:00 - Intro: Manning the Watchtowers

    0:25 - The Tiered SOC Model: Tier 1 (Triage), Tier 2 (IR), Tier 3 (Hunters)

    1:00 - Detection Engineering: Precision (Quality) vs. Recall (Quantity)

    1:40 - UEBA (User & Entity Behavior Analytics): Catching the Insider

    2:20 - The SIEM Pipeline: Collection, Normalization, Correlation

    3:00 - Cloud Architecture: Security Data Lake vs. SIEM Cost

    3:30 - Detection as Code: Git-based Rules & Version Control

    3:50 - SOAR (Security Orchestration, Automation, and Response)

    4:15 - Summary: Data is Noise until it's Actionable

    4:35 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=H1yf0HuiWNQ

    6 min
  • Incident Response: Forensics, Diamond Model, IOC, IOA

    You don't build an Incident Response plan during a breach. In this video, Sec Guy dissects the massive Salt Typhoon attack to show you how professional responders hunt advanced threats. We break down the Diamond Model of Intrusion Analysis, explain why Indicators of Attack (IOA) are more valuable than Indicators of Compromise (IOC), and walk through the Order of Volatility for capturing forensic evidence before it disappears.

    🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    ✅ Training Videos & Practice Tests

    ✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    ✅ Discord Access (Study sessions & Industry networking)

    👉 Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    🔥 Salary Negotiator Workshop

    🔥 Experience Builder: Real-world projects to fill your resume

    👉 Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 4.1: Incident Response Procedures (Preparation, Detection, Analysis, Containment, Eradication, Recovery)

    [ ] Domain 4.3: Digital Forensics (Order of Volatility, Chain of Custody, Legal Hold)

    [ ] Domain 2.3: Indicators of Malicious Activity (IOC vs. IOA)

    CISSP

    [ ] Domain 7: Security Operations (Incident Management & Investigations)

    [ ] Domain 1: Security and Risk Management (Legal & Regulatory Issues in Forensics)

    CISM

    [ ] Domain 4: Information Security Incident Management (IR Plans & Playbooks)

    CRISC

    [ ] Domain 4: Risk and Control Monitoring (Monitoring for IOCs)

    CCSP

    [ ] Domain 5: Cloud Security Operations (Forensics in the Cloud & Data Sovereignty)

    SecurityX (CompTIA)

    [ ] Domain 3.0: Security Operations (Threat Hunting & Diamond Model)

    GIAC GSEC (SANS)

    [ ] Incident Handling & Response: The IR Lifecycle & Forensics

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 4: Incident Response (Automating Forensic Capture in Cloud)

    Pentest+ (CompTIA)

    [ ] Domain 5: Reporting and Communication (Post-Exploitation & Cleanup)

    CEH (Certified Ethical Hacker)

    [ ] Domain 1: Information Security Overview (Cyber Kill Chain vs. Diamond Model)

    SecAI+

    [ ] AI Security: Analyzing AI-Driven Attacks via Behavioral Indicators (IOA)

    [Timestamps]

    0:00 - Intro: When the Enemy is Already Inside

    0:23 - Case Study: Salt Typhoon (APT & Living off the Land)

    1:10 - Phase 1: Preparation (Playbooks & Visibility)

    1:31 - Phase 2: Detection & Analysis (IOC vs. IOA)

    2:20 - The Diamond Model: Adversary, Capability, Infrastructure, Victim

    2:53 - Phase 3: Containment (Micro-segmentation vs. Shutdown)

    3:20 - Phase 4: Eradication & Recovery (Rootkits & Registry Keys)

    3:35 - Digital Forensics: Order of Volatility (RAM vs. Disk)

    4:08 - Legal Hold & Chain of Custody (Admissibility)

    4:42 - Data Sovereignty: GDPR & Cross-Border Forensics

    5:14 - Summary: Speed is Good, Accuracy is Survival

    5:36 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=InpBtyDErgk

    6 min
  • Cryptography: PKI & Certificates: CA, OSCP, CRL, TLS

    Encryption protects your data, but PKI protects your trust. If you don't understand how a Certificate Authority (CA) validates a server, or why OCSP Stapling is faster than a CRL, you don't understand how the internet works. In this video, Sec Guy breaks down the "Trust Anchor" model, explains the difference between the Root CA and Intermediate CA, and walks you through the modern TLS 1.3 Handshake.

    🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    ✅ Training Videos & Practice Tests

    ✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    ✅ Discord Access (Study sessions & Industry networking)

    👉 Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    🔥 Salary Negotiator Workshop

    🔥 Experience Builder: Real-world projects to fill your resume

    👉 Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 1.1: Cryptographic Concepts (PKI, CA, RA, CRL, OCSP)

    [ ] Domain 3.1: Secure Network Architecture (TLS 1.3, SSL Inspection)

    CISSP

    [ ] Domain 3: Security Architecture (PKI Trust Models, Key Management Lifecycle)

    [ ] Domain 4: Communication & Network Security (Secure Protocols - TLS)

    CISM

    [ ] Domain 2: Information Risk Management (Managing Trust & Digital Certificates)

    CRISC

    [ ] Domain 2: IT Risk Assessment (Risks of Expired Certificates & Weak CAs)

    CCSP

    [ ] Domain 2: Cloud Data Security (Key Management Services & BYOK)

    SecurityX (CompTIA)

    [ ] Domain 2.0: Security Architecture (Implementing Enterprise PKI)

    GIAC GSEC (SANS)

    [ ] Cryptography: Public Key Infrastructure & Certificates

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 2: Data Protection (AWS Certificate Manager - ACM & Private CA)

    Pentest+ (CompTIA)

    [ ] Domain 3: Attacks and Exploits (Certificate Pinning Bypass & MITM)

    CEH (Certified Ethical Hacker)

    [ ] Domain 4: Cryptography (PKI Attacks & Fake Certificates)

    SecAI+

    [ ] AI Security: Signing AI Models with PKI for Integrity

    [Timestamps]

    0:00 - Intro: The Problem with Public Keys (Trust)

    0:27 - The Certificate Authority (CA): The Ultimate Trust Anchor

    1:04 - Hierarchy of Trust: Root CA (Offline) vs. Intermediate CA

    1:36 - The Registration Authority (RA): Verifying Identity vs. Signing

    2:08 - Revocation: CRL (Slow List) vs. OCSP (Fast Query)

    2:50 - OCSP Stapling: The Efficient Modern Standard

    3:07 - TLS 1.3 Handshake: Asymmetric for Key Exchange, Symmetric for Data

    3:48 - Certificate Transparency Logs (CT Logs) & Post-Quantum Crypto

    4:28 - How to Build Your Own CA (Lab)

    4:53 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=HMazc2OpIeo

    6 min
  • Identity Access Management: PAM, JIT, JEA, ABAC, SAML, OAuth

    In a cloud-native world, firewalls don't matter if your identity is compromised. "Identity is the New Perimeter." In this video, Sec Guy explains why Permanent Admin Rights are a security failure, how to implement Just-in-Time (JIT) access to stop attackers, and clearly defines the difference between SAML (XML/Enterprise), OAuth (Authorization), and OIDC (Authentication).

    🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    ✅ Training Videos & Practice Tests

    ✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    ✅ Discord Access (Study sessions & Industry networking)

    👉 Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    🔥 Salary Negotiator Workshop

    🔥 Experience Builder: Real-world projects to fill your resume

    👉 Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 1.3: Identity and Access Management (SAML, OAuth, OIDC, ABAC vs. RBAC)

    [ ] Domain 1.4: Access Control Schemes (PAM, JIT, JEA)

    CISSP

    [ ] Domain 5: Identity and Access Management (Federated Identity, SAML, OIDC, Authorization vs. Authentication)

    CISM

    [ ] Domain 3: Information Security Program (Identity Lifecycle & Access Governance)

    CRISC

    [ ] Domain 2: IT Risk Assessment (Privileged Access Risks)

    CCSP

    [ ] Domain 4: Cloud Application Security (Federated Identity Management & XML/JSON usage)

    SecurityX (CompTIA)

    [ ] Domain 1.0: Security Architecture (Implementing Zero Trust Identity)

    GIAC GSEC (SANS)

    [ ] Access Control & Password Management: Federation & OAuth

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 3: Infrastructure Security (IAM Roles, Federation, & Temporary Credentials)

    Pentest+ (CompTIA)

    [ ] Domain 3: Attacks and Exploits (Token Theft & Forging SAML Assertions)

    CEH (Certified Ethical Hacker)

    [ ] Domain 6: System Hacking (Privilege Escalation via Misconfigured IAM)

    SecAI+

    [ ] AI Security: Workload Identity Federation for AI Agents (Non-Human Identities)

    [Timestamps]

    0:00 - Intro: Identity is the New Perimeter

    0:32 - Privileged Access Management (PAM): The Keys to the Kingdom

    1:00 - Just-In-Time (JIT) vs. Just-Enough-Administration (JEA)

    1:56 - ABAC vs. RBAC: Why Context Matters (Time/Location/Device)

    2:32 - Federated Identity: Moving Trust Across the Internet

    2:45 - SAML (XML): The Enterprise SSO Standard

    3:05 - OAuth 2.0 (Authorization): "What You Can Do" vs. "Who You Are"

    3:22 - OIDC (Authentication): The JSON Layer on Top of OAuth

    3:42 - The Cryptography of Tokens: Signing & Hashing (JWTs)

    4:42 - Non-Human Identities (NHI): Securing AI Agents & Service Accounts

    5:14 - Summary: Identity is Proof, Not Just a Username

    5:31 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=y_2UfJnrYtM

    6 min
  • Risk Management: BCP, DRP, RTO/RPO & Risk Math

    In cybersecurity, we don't plan for if—we plan for when. In this video, Sec Guy explains why the old "3-2-1 Backup Rule" is no longer enough to stop ransomware, how to calculate the cost of a disaster using SLE, ARO, and ALE, and the critical difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP).

    🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    ✅ Training Videos & Practice Tests

    ✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    ✅ Discord Access (Study sessions & Industry networking)

    👉 Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    🔥 Salary Negotiator Workshop

    🔥 Experience Builder: Real-world projects to fill your resume

    👉 Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 5.2: Risk Management Processes (SLE, ALE, ARO, Risk Acceptance)

    [ ] Domain 5.4: Redundancy & Backup (RTO, RPO, MTBF, MTTR, 3-2-1 Rule)

    CISSP

    [ ] Domain 1: Security and Risk Management (Quantitative Risk Analysis)

    [ ] Domain 7: Security Operations (BCP/DRP, Testing Strategies)

    CISM

    [ ] Domain 4: Information Security Incident Management (RTO/RPO Definition)

    CRISC

    [ ] Domain 4: Risk and Control Monitoring (Reliability Metrics: MTBF/MTTR)

    CCSP

    [ ] Domain 1: Cloud Concepts (Cloud-to-Cloud Backup & Immutability)

    SecurityX (CompTIA)

    [ ] Domain 5.0: Security Operations (Disaster Recovery Planning)

    GIAC GSEC (SANS)

    [ ] Incident Handling: Business Continuity & Disaster Recovery

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 4: Incident Response (Automated Backup & Restore)

    Pentest+ (CompTIA)

    [ ] Domain 1: Planning and Scoping (Impact Analysis)

    CEH (Certified Ethical Hacker)

    [ ] Domain 1: Information Security Overview (Risk Terminology)

    SecAI+

    [ ] AI Security: Immutable Backups (WORM) to Prevent Training Data Corruption

    [Timestamps]

    0:00 - Intro: Planning for "When," Not "If"

    0:35 - The Math of Risk: Qualitative vs. Quantitative Analysis

    1:13 - Calculating Risk: SLE, ARO, and ALE (The $10,000 Laptop Example)

    2:02 - Risk Treatment: Mitigate, Transfer, Avoid, Accept

    2:40 - BCP Metrics: Maximum Tolerable Downtime (MTD) vs. RTO

    3:28 - Business Impact Analysis (BIA) & Supply Chain Risk

    4:00 - Testing the Plan: Tabletop vs. Full Interruption

    4:40 - The Golden Metrics: RTO (Time) vs. RPO (Data Loss)

    5:25 - Reliability Metrics: MTBF vs. MTTR

    6:02 - The New Standard: 3-2-1-1-0 Backup Rule (Air-Gapped & Verified)

    7:00 - Recovery Sites: Hot, Warm, Cold & Cloud

    7:52 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=7E1qTrSz2LU

    9 min
  • Modern Network Security: From Firewalls to Agentic AI Defense

    A firewall is no longer just a box—it's a policy enforcement engine. In this deep dive, Sec Guy explains why WAFs have evolved into WAAPs to stop API attacks, why VPNs are being replaced by ZTNA and SASE, and how to use "Sticky MAC" and 802.1X to lock down your physical ports. If you are prepping for Security+, CISSP, or CCSP, this is your masterclass in network defense.

    🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    ✅ Training Videos & Practice Tests

    ✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    ✅ Discord Access (Study sessions & Industry networking)

    👉 Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    🔥 Salary Negotiator Workshop

    🔥 Experience Builder: Real-world projects to fill your resume

    👉 Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+ (SY0-701)

    [ ] Domain 3.3: Network Designs (SASE, ZTNA)

    [ ] Domain 2.3: Indicators of Malicious Activity (Heuristic vs. Anomaly)

    [ ] Domain 1.2: Security Controls (NGFW, WAF/WAAP)

    CISSP

    [ ] Domain 3: Security Architecture (Radius vs. TACACS+, 802.1X)

    [ ] Domain 4: Communication & Network Security (Secure Design Principles)

    CISM

    [ ] Domain 3: Information Security Program (Infrastructure Protection)

    CRISC

    [ ] Domain 2: IT Risk Assessment (Network Vulnerabilities)

    CCSP

    [ ] Domain 1: Cloud Concepts (SASE, CASB)

    [ ] Domain 2: Cloud Data Security (DLP)

    SecurityX (CompTIA)

    [ ] Domain 1.0: Security Architecture (Micro-segmentation & eBPF)

    GIAC GSEC (SANS)

    [ ] Access Control & Password Management: 802.1X & Port Security

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 2: Infrastructure Security (Security Groups vs. NACLs vs. WAF)

    Pentest+ (CompTIA)

    [ ] Domain 3: Attacks and Exploits (Bypassing NAC, VLAN Hopping)

    CEH (Certified Ethical Hacker)

    [ ] Domain 6: Evading IDS, Firewalls, and Honeypots

    SecAI+

    [ ] AI Security: Defending Against Agentic AI & Non-Human Identities (NHI)

    [Timestamps]

    0:00 - Intro: Weapons on the Wall

    0:30 - Firewalls vs. NGFW: Deep Packet Inspection

    0:48 - WAAP: Protecting APIs & Stopping Mass Assignment

    1:27 - IDS vs. IPS: Signature, Heuristic, & Anomaly Detection

    2:42 - The New Threat: Agentic AI & Low/Slow Recon

    2:54 - NDR & DNS Sinkholing: Catching Lateral Movement

    3:18 - Bot Management: Behavioral Fingerprinting

    3:40 - 802.1X: Supplicant, Authenticator, & Radius Server

    4:12 - Port Security: Sticky MAC & Loop Protection

    4:28 - RADIUS vs. TACACS+: The CISSP Distinction

    5:22 - The Shift: VPN vs. ZTNA (Identity Aware Proxies)

    5:48 - SASE: Converging SD-WAN, CASB, & DLP

    6:16 - Non-Human Identities (NHI) & Micro-segmentation (eBPF)

    7:11 - Summary: Identity is the New Perimeter

    7:25 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=T6wtE8hDmw0

    8 min

About Sec Guy

From the publisher's feed

Real cybersecurity training for the real world. We take the complex theories of CompTIA Security+ and SecAI+ and translate them into actionable skills. Whether…