Hi everyone!
I’ve been diving deep into cybersecurity theory lately (I completed the Google Cybersecurity Professional Certificate) and I feel I have a solid grasp of the fundamentals (Scrum/Agile workflows, networking basics, etc.). However, I’m struggling to bridge the gap between "knowing" and "doing."
So far, my hands-on experience is limited: I’ve set up a few VMs, done some basic Nmap scans, and a couple of simple SQL injection exercises. I want to build a portfolio that actually shows I can handle real-world tools, but I’m a bit lost on where to start for both Red and Blue team paths.
What I’m looking for:
Project Ideas: What are some "must-have" projects for a first internship/junior role? (e.g., building a SOC home lab, active directory exploitation, etc.)
Platforms/Labs: Besides the usual suspects, are there specific labs that helped you "click"?
YouTube Channels: Who are the best creators for step-by-step practical walk-throughs that aren't just "press this button"?
Resume Tips: How do you effectively list "Home Lab Experience" on a CV when you don't have professional experience yet?
My goal is to document everything in a GitHub repo or a blog to show my process. Any guidance on specific tools or methodologies (like documenting MITRE ATT&CK mapping) would be greatly appreciated!
Thanks in advance for the help!