Related Posts
Are we officially called EY Parthenon yet?
When is a 3 page resume acceptable?
More Posts
Salary nyc pwc tax?
“Fuck it I’m going to PDF this bitch"
Additional Posts in Consulting Exit Opportunities
New to Fishbowl?
Download the Fishbowl app to
unlock all discussions on Fishbowl.
unlock all discussions on Fishbowl.







Google it?
For security interviews! This is my prep guide
Foundational books and general infosec references:
Counterhack Reloaded - http://www.amazon.com/Counter-Hack-Reloaded-Step-Step/dp/0131481045
Hacking exposed - http://www.hackingexposed.com/
Phrack ‘zine and back catalog - www.phrack.com
[Advanced] Silence on the Wire by Michal Zalewski
Security Engineering
Security Engineering by Ross Anderso
Web Application Security
Tangled Web by Michal Zalewski
Web App Hacker’s Handbook by Dafydd Stuttard and Marcus Pinto
Operating System Security
Mac Hacker’s handbook by Charlie Miller, Dino Dai Zovi
Cryptography
Handbook of Applied Cryptography by Menezes et al.
Cryptography Engineering by Niels Ferguson, Bruce Schneier, Tadayoshi Kohno
Applied Cryptography by Bruce Schneier
Reverse Engineering
Practical Reverse Engineering by Bruce Dang
Secrets of Reversing by Eldad Eilam
Assessments / Pen-Testing / Exploitation
[Assessment] The Art of Software Security Assessment by Mark dowd, John McDonald, Justin Schuh
[Exploitation] Hacking: Art of Exploitation by Jon Erickson
[Pentesting/Intro] Network Security Assessment by Chris McNab
[Malware] Practical Malware Analysis by Michael Sikorski, Andrew Honig
[Pentesting] The Hacker Playbook 2: Practical Guide to Penetration testing by Peter Kim
[Exploitation] Shellcoders Handbook by Chris Anley
Scripting/Coding
[Python] Violent Python: A cookbook for Hackers, Forensic Analysts, Penetration testers and Security Engineers by TJ O’Conor
[Python] Dive into Python and Dive into Python 3 [free e-books and exercises]
[Algorithms] Introduction to Algorithms by Thomas Cormen, Charles Leiserson, Ronald Rivest, Clifford Stein
Programming Pearls by Jon Bentley
Detection strategies
https://www.sans.org/reading-room/whitepapers/detection
Well Known CTFs
CSAW CTF: https://ctf.isis.poly.edu/
Plaid CTF: http://play.plaidctf.com/
Defcon CTF: https://www.defcon.org/html/links/dc-ctf.html
Hands on Security Challenges
http://www.root-me.org/?lang=en
http://www.crackmes.de/
http://www.malware-traffic-analysis.net/
http://contagiodump.blogspot.com/2013/04/collection-of-pcap-files-from-malware.html
Training Courses
http://www.sans.org/course/intrusion-detection-in-depth
https://www.sans.org/course/hacker-techniques-exploits-incident-handling
https://www.sans.org/media/security-training/courses/sec_essentials.php
Network fundamentals and protocols
Various layers of the OSI (http://en.wikipedia.org/wiki/OSI_model) or IP (http://en.wikipedia.org/wiki/Internet_protocol_suite) models
DHCP, DNS, IP Suite, HTTP, etc. (there are too many protocols to list that are interesting or important)
Examples:
HTTP: http://www.tutorialspoint.com/http/
DNS: https://technet.microsoft.com/en-us/library/cc775637(v=ws.10).aspx
Identifying malware on the network + IDS signatures:
https://lists.emergingthreats.net/mailman/listinfo/emerging-sigs
Malware Analysis:
https://zeltser.com/mastering-4-stages-of-malware-analysis/
https://www.virustotal.com/
https://www.blackhat.com/docs/us-15/materials/us-15-MarquisBoire-Big-Game-Hunting-The-Peculiarities-Of-Nation-State-Malware-Research.pdf
Cryptography:
http://www.cs.umd.edu/~waa/414-F11/IntroToCrypto.pdf
http://www.amazon.com/Applied-Cryptography-Protocols-Algorithms-Source/dp/0471117099
http://www.sans.edu/research/security-laboratory/article/hash-functions
Host forensics
http://windowsir.blogspot.com/
Some miscellaneous topic agnostic resources:
https://github.com/kbandla/APTnotes
https://www.reddit.com/r/netsec/wiki/start
http://www.covert.io/security-datascience-papers/
Some analysis of common mass malware and current events:
http://malware.dontneedcoffee.com/
https://www.fireeye.com/blog.html
http://contagiodump.blogspot.com/
Tools:
http://holisticinfosec.blogspot.com/
Meetups and groups:
CitySec: https://www.reddit.com/r/netsec/wiki/meetups/citysec
Local Defcon: https://www.defcon.org/html/defcon-groups/dc-groups-index.html
BSides: http://www.securitybsides.com/w/page/12194156/FrontPage
I’ll let you know how it goes when I’ve read all this. Prob finish in the next 9 years.
Which role? Happy to help.
Security Engineer role