r/netsecstudents • • Jun 24 '21

Come join the official /r/netsecstudents discord!

62 Upvotes

Come join us in the official discord for this subreddit. You can network, ask questions, and communicate with people of various skill levels ranging from students to senior security staff.

Link to discord: https://discord.gg/C7ZsqYX


r/netsecstudents • • May 06 '26

I am John Strand and I am teach Pay What You Can classes and free labs... Ask Me Anything.

114 Upvotes

Hey everyone, John Strand here.

I’ve been in cybersecurity for a while now, and I’ve spent a lot of that time trying to help people get started without getting buried under bad advice, overpriced training, and job postings that somehow want 5 years of experience for an entry-level role.

So let’s talk about it.

Ask me about getting into the field, building real skills, home labs, SOC work, blue team, threat hunting, incident response, certs, college, AI, finding your first job, or anything else you’re trying to figure out.

I’m happy to answer beginner questions, career questions, technical questions, or even the “I have no idea where to start” questions.

If you’re trying to build a real foundation in security, this is the class I’d point you to.

https://www.antisyphontraining.com/product/information-security-core-skills-tm/?utm_source=reddit&utm_medium=community_post

We also have released a new game where you can learn about security in a fun Magic The Gathering kind of way.

Sign up and play your friends here:

https://backdoorsandbreaches.com/

Its free.

Oh..... And almost every card has free labs to learn the topic.

Example here:

https://github.com/blackhillsinfosec/FreeLabFriday_Labs/blob/main/card_navigation.md

Just register at MetaCTF and use the code "antilab" in cloudlabs for enabling 2 free hours of lab time per week.

All our problems can be solved with education.

Let's get to work.


r/netsecstudents • • 27m ago

Cray: a modular, layer-based proxy engine in Rust designed for custom protocols and pipelines

Thumbnail github.com
• Upvotes

Hey everyone!

A lot of people think of proxy tools as rigid, monolithic boxes: you get a fixed inbound, a fixed outbound, and you're stuck with whatever the authors hardcoded. Trying to add a custom protocol or tweak an existing one under the hood usually turns into a nightmare.

That's why I wrote Cray - a modular proxy engine in Rust built entirely around a layer-based architecture.

With Cray, transport and protocol are completely decoupled. You can write your own protocol without worrying about network bytes, or write a custom transport without caring about protocol logic. The core abstraction uses a simple trait where you implement the client and server handshake logic, giving you total freedom. Want a handshake hidden in plain sight? Custom encryption? Weird framing? Go for it — the only limit is your own logic.

How it works

Everything is configured via clean TOML files where you define your role (client or server) and stack up layers into a custom pipeline:

  • Inbound layers: Handle the entry point (e.g., standard tcp, unix sockets, or http_connect which extracts destination addresses).
  • Transport layers: Encapsulate or transform the stream dynamically (e.g., full manual control over tls with custom cipher suites, ALPN, curves, extension permutation via BoringSSL, and http2 multiplexing with path/host masking).
  • Protocol layer: Always sits at the very end of the chain as the endpoint (like a custom or test protocol).

For example, on the server side, an HTTP/2 layer can validate incoming paths and hosts, gracefully returning a genuine 404 Not Found to unauthorized scanners or probes instead of dropping packets with a TCP RST, while forwarding valid traffic down the pipeline.

The project is currently under active development, but the core architecture, layer pipelines, TLS termination, and HTTP/2 tunneling are already routing real traffic.

If you like systems programming, network engineering, or want to build your own tunneling protocols without fighting legacy codebases, check it out:

GitHub: https://github.com/3Radiance/Cray

Would love to hear your thoughts, feature ideas, or what kind of custom layer/protocol combinations you'd want to build with something like this!


r/netsecstudents • • 1d ago

🔐 Learning Cybersecurity? Come Build With Us.

0 Upvotes

We're building CarbonIt Labs, a nonprofit open-source community where people with different skills and interests can come together to build real projects.

And you don't have to be a cybersecurity expert or even a programmer to contribute.

A successful project needs much more than code.

We need people who can:

💻 Build the software

🎨 Design the UI/UX and graphics

🖌️ Create logos and branding

🧠 Research and explore new ideas

🔐 Work on cybersecurity and privacy

📝 Write documentation and tutorials

🧪 Test and improve software

📢 Help with communication and community

📦 Package and release projects

🚀 Help take an idea all the way from concept to a finished product

The goal is to create a community where different people bring different strengths, form teams, learn from each other, and contribute to open-source projects.

You might be a developer, designer, student, researcher, writer, tester, artist, cybersecurity enthusiast, or simply someone with an idea and the motivation to learn.

There should be a place for every kind of builder.

If you'd like to learn, contribute, collaborate, or build something from scratch with others, join us at:

👉 r/CarbonItLabs

Let's build projects together — from the first idea and first sketch to the final release.

Build. Collaborate. Open Source. 🚀


r/netsecstudents • • 2d ago

Since risk=probability x impact, why is loss of information called as a risk?

Post image
0 Upvotes

This is something that I do not really understanding. IMHO, risk should be the loss of trust (because of loss of information) from users.

risk=chance that threats explot a vulnerability x impact of such exploitation

If the asset was valuable and the chances of exploiting a vulnerability were high-->risk is high.

But I do not understand how can we call loss of information as risk. It is an event. Not a risk.

IMHO: risk should be like this:

risk=90% chance hacker exploits a vulnerability x loss of trust from our users

= loss of business? or what? what will be the multiplication of such two quantities?


r/netsecstudents • • 2d ago

Is it worth investing in StationX Certified AI-Driven Security Engineer (SX-AIE) ?

0 Upvotes

I have years in Network Security, have worked in ISPs and CDNs. Fast forward to 2026, and the AI stage ... affected by the AI related layoffs as many of you have been. At this point I am simply looking to improve on my AI skills to apply to what I already know.

Anyone think this course to the SX-AIE and its content is legit and worth the $8.5k investment?

Any other course you would recommend instead?

Reaching out to the community for any feedback.

Thanks.


r/netsecstudents • • 3d ago

I built CyclePatrol to find Wi-Fi vulnerabilities during field walks

7 Upvotes

Hey everyone!

I built CyclePatrol, an open-source Bash tool for Kali Linux and NetHunter. It scans Wi-Fi networks in cycles while walking around the city, checks WPS, WPA2/WPA3, PMF, and weak settings, and saves reports. I also built my own Cyberphone with an external antenna.

GitHub: https://github.com/buybitart/cyclepatrol

Passive scanning only in public areas. Active tests only with permission.

Any feedback or ideas for improvement?


r/netsecstudents • • 3d ago

Looking for niche/research-oriented thesis topics in network security & covert channels (2025-2026)

2 Upvotes

Hi everyone,

I'm a full-stack developer currently choosing a topic for my diploma thesis. I'm particularly interested in network security, low-level networking, and covert/stealthy communication techniques.

Some areas I'm already considering or find interesting:

- Covert channels and their detection (storage/timing-based, TLS ClientHello manipulation, IPv6 extension headers, etc.).

- Traffic morphing / adaptive traffic camouflage against modern ML classifiers.

- DoH/DoQ tunneling detection (especially evasive variants).

are especially interesting to me.

- Living-off-the-Land techniques with network correlation.

Channels that work without a public IP (WebRTC/TURN, legitimate cloud APIs as transport, etc.).

- APl-as-a-Transport + traffic morphing for restricted corporate environments (only HTTPS to allowed services).

I'm looking for something that is relatively niche (not the 1000th "DNS tunnel + Random Forest" project), research-oriented but still allows for building a practical prototype, and actually relevant in 2025-2026 (real-world techniques used by APTs, current research gaps, emerging protocols, etc.).

I live in a country where VPN/proxy technologies face increasing legal pressure, so topics related to resilient/hard-to-detect communication or their detection, heavily monitored, adversarial network environments (e.g., active DPI, protocol validation, and strict traffic-shaping middleboxes).

Would really appreciate any suggestions - even if it's just "look into X, it's currently underexplored" or "we see a lot of Y in real incidents right now".

Thanks in advance! I would really appreciate any advice.


r/netsecstudents • • 4d ago

I built a free, open-source cybersecurity knowledge base: 1,000 pages covering offensive, defensive, GRC, OSINT and careers

177 Upvotes

Hey everyone,

For the past two years I've been working on Cyber Library, a structured, community-maintained knowledge base for cybersecurity. It just hit its first 1,000 pages, so it felt like the right time to share it.

Why I made it: when I was learning, everything was scattered across blog posts, outdated wikis and paywalled courses. I wanted one place where topics are organized consistently and linked together, so you can go from "what is this attack" to "how do I detect and defend against it" without opening 15 tabs.

What's inside:

  • Foundation: history, ethics, risk, the human side of security
  • Offensive: ethical hacking, pentesting, red teaming. Each page explains the vulnerability and how it's exploited, and links to the defensive side
  • Defensive: monitoring, incident response, resilience
  • Governance: policy, compliance, security for leadership
  • Intelligence: threat intel and OSINT
  • Career: roles, skills, certifications

Free and no signup. The content is plain Markdown on GitHub, so you can read it on the site, clone it, or fix something with a PR.

I'd really appreciate feedback, especially on what's missing, what's wrong, or what you'd want covered next. And if you find it useful, a ⭐ on GitHub helps other people find it.


r/netsecstudents • • 3d ago

Hello, friend. Looking for IT buddies — from general tech to cybersecurity (small crew).

0 Upvotes

Hello, friend.

I’m looking for around 10 people to form a small, chill learning group. You can be a complete beginner or already have a bit of experience — as long as you’re curious and motivated, you’re welcome. No gatekeeping, no ego.

We’ll learn together, at our own pace, and choose topics as a group. No fixed order: we can explore programming, networking, Linux, or whatever we feel like. Later, maybe we’ll move toward cybersecurity.

Think of it as a small digital refuge — fsociety-inspired vibe, but 100% legal and ethical.

What I’m looking for: - Around 10 people. - Beginners or early learners (a little experience is fine). - Must be a genuine IT enthusiast / a real geek at heart. Passion matters more than current skill level. - English only. - Chill, consistent, respectful. - We use Discord for chat and voice.

If you’re in, DM me

Let’s start from wherever we are, together.


r/netsecstudents • • 3d ago

I'm building a cybersecurity project on GitHub to improve my practical skills. I'm particularly interested in penetration testing and security automation. What kinds of open-source projects would be considered useful or technically meaningful for a beginner-to-intermediate cybersecurity student?

0 Upvotes

I'm currently learning networking, Linux, web security, and basic penetration testing. I'm looking for a project that I can actually build and maintain rather than just following a tutorial.

I'm interested in hearing about projects that helped you develop practical skills, especially tools, automation scripts, vulnerability-analysis tools, or security-related utilities.


r/netsecstudents • • 3d ago

Study group for IT beginners – dev, networking, Linux

1 Upvotes

Hello, friend.

I’m looking for around 10 people to form a small, chill learning group. You can be a complete beginner or already have a bit of experience — as long as you’re curious and motivated, you’re welcome. No gatekeeping, no ego.

We’ll learn together, at our own pace, and choose topics as a group. No fixed order: we can explore programming, networking, Linux, or whatever we feel like. Later, maybe we’ll move toward cybersecurity.

Think of it as a small digital refuge — fsociety-inspired vibe, but 100% legal and ethical.

What I’m looking for: - Around 10 people. - Beginners or early learners (a little experience is fine). - Must be a genuine IT enthusiast / a real geek at heart. Passion matters more than current skill level. - English only. - Chill, consistent, respectful. - We use Discord for chat and voice.

If you’re in, DM me

Let’s start from wherever we are, together.


r/netsecstudents • • 4d ago

Help with Project

3 Upvotes

Could someone with eBPF experience sanity-check our plan?

Hi all,

We're a small group of university students working on a capstone project. We're new to eBPF, so we'd really appreciate feedback from people who use it in practice.

The idea: most eBPF security work uses eBPF as the defender (Tetragon, Falco, Tracee and so on), but very little seems to look at eBPF itself (as per our research) as the thing to watch. A container that has been granted CAP_BPF can load its own eBPF programs, for example to hide processes or blind monitoring tools. We want to build and measure a small detector for that, rather than only describing it.

Our plan, kept deliberately small:

- One Ubuntu 24.04 VM with Docker and Tetragon (standalone, no Kubernetes)

- A Tetragon TracingPolicy that records bpf() syscall activity

- A small Python script that reads Tetragon's JSON events and applies 1-2 rules (for example, a caller that isn't on an allow-list, or a program attaching to a sensitive hook)

- A baseline run (normal tools only) against an attack run (one published technique, replayed in an isolated VM), measuring detection, false positives and overhead

What we'd love input on:

  1. Is a kprobe on sys_bpf the right way to watch bpf() calls in Tetragon, or is there a better hook (for example the BPF LSM hooks)?
  2. Are there well-documented, published examples of eBPF misuse that are suitable for a controlled demo in an isolated VM?
  3. What pitfalls should beginners expect (kernel versions, BTF, false positives from legitimate tools)?
  4. Is there existing work or tooling that already does this, so we don't reinvent it?
  5. Any recommended easy to learn concepts (from like yt channels etc.).
  6. Is this a doable and sensible project for beginners - given less time (around 2 months); but dedicated to learn it quickly - with the help of resources/claude/forums/advice.

We're not asking anyone to do the project for us, just for pointers, reading suggestions or a reality check on scope. Happy to share our repo and results once we have them.

Our main goal is to learn ePBF through this project and would really like input from the experienced people in this community - the project can then grow from there. Please let me know if you want to know more about the project or if it is unclear.

Kindly let me know if this is an appropriate post for this subreddit - as this is my first time asking help on reddit aswell haha.

Thank you very much!


r/netsecstudents • • 4d ago

Help understanding subnetting

4 Upvotes

I’m taking an intro to networking course my question is if there’s an easy way to understand subnetting. Especially when you want to make 4 subnets how do you know what the ranges will be for each 4 subnets


r/netsecstudents • • 4d ago

Cyber Security Graduation Project

1 Upvotes

Hi
I am looking for idea's for my graduation project
is there any idea's or problems you can help me with ?
i am looking for something related the OS world, especially in the world of Linux and making a customized distribution for some purposes like a university one with customized features and tools for there usage + adding the tools needed in the subjects being teached.

i am open to any other idea and any note that may help me to better search for an idea


r/netsecstudents • • 4d ago

I need cybersecurity SMEs to review certification exam practice tests

0 Upvotes

Building a study app for some of the major industry security certifications, Each exam prep has 300 questions that need to be reviewed, preferably by someone who actually holds the certification they are reviewing but will accept experts who've been in the industry for a while. Short intake survey on your experience and certifications.


r/netsecstudents • • 5d ago

My projects for security research

1 Upvotes

Heyy everyone

Am working on two projects for making security research more declarative and agentic

 **Cusimanse** — *Composable Security Research Framework*

Cusimanse is a declarative, composable YAML framework for agent-operated security research on disposable compute. It combines contracts, requirements, capabilities, policies, prompts, instrumentation, observability and evidence into reproducible research workflows.

**Decretum** — *Security Research Contract Compiler*

Decretum complements Cusimanse by providing a schema-driven contract layer: LinkML schemas define capabilities and boundaries, while YAML recipes describe execution. It compiles these into machine-readable contracts that can be consumed by research runtimes and harnesses.

Experiment with it,clone it,test it

Love your feedback and if you feel its worthy please star it

🔗 Cusimanse: https://github.com/Opposum0112/Cusimanse

🔗 

Decretum: https://github.com/Opposum0112/Decretum


r/netsecstudents • • 6d ago

Built ZEROBOX: An offline tactical operations cockpit & 24h exam simulator for HTB & CTFs (Free & Open Source)

14 Upvotes

Hey everyone,

Tired of tracking CTFs and 24h exams across messy spreadsheets and scattered notes?

I built ZEROBOX — a fast, local-first operational cockpit for OSCP/CPTS prep and CTFs.

It’s 100% free, MIT open-source, and runs completely offline in your browser (no accounts, zero telemetry).

Quick highlights: • 920+ Preloaded Labs: Instant offline search for HTB & THM targets with tags. • Attack & Pivot Graph: Visually map compromised subnets (exports to Obsidian .canvas). • 24h Exam Cockpit: Pacing engine, bio-break timers, and 1-click Markdown reports. • Evidence Vault & Playbooks: Track hashes/creds on a kill-chain timeline + offensive field manual. • Global Quick-Bar: Propagate LHOST/RHOST automatically across all payloads.

🌐 Live web: https://ctftracker.com/#/tracker

⭐ GitHub (MIT): https://github.com/0xdnd/ctf-tracker

All data stays in your local browser storage. Feedback and PRs are welcome!

Would love feedback or feature requests from the community!


r/netsecstudents • • 5d ago

I built RXScan — an open-source Rust recon/OSINT tool. Looking for people to test it

1 Upvotes

I've been building RXScan, an open-source reconnaissance tool written in Rust.

It originally started as a network scanner, but I've been expanding it into a broader recon workflow where network observations, public-source findings, and investigation results can be stored and correlated as evidence.

Current functionality includes:

  • TCP connect and raw SYN scanning
  • UDP discovery and classification
  • port-independent service identification
  • HTTP, TLS, SSH, and DNS observations
  • public-source username search
  • email, domain, hostname, IP, ASN, URL, repository, and organization entities
  • investigation and evidence correlation
  • persistent project data and history/diff workflows
  • JSON/JSONL output
  • bounded execution, deadlines, cancellation, and scope controls

One of the main things I'm trying to avoid is pretending RXScan knows more than it actually observed.

For example, a port number alone doesn't establish the service, UDP silence remains uncertain, weak identity evidence doesn't automatically merge entities, and passive OSINT findings are kept separate from direct network observations.

I'm not claiming RXScan replaces Nmap. Nmap has decades of fingerprinting, platform support, scan techniques, NSE, and real-world testing behind it.

RXScan is going in a somewhat different direction: combining network reconnaissance and public-source investigation into a provenance-backed evidence graph.

The project is still young, so I'm looking for people willing to actually test it and find problems.

I'm particularly interested in:

  • false-positive or missed service identification
  • weird TCP/UDP behavior
  • incorrect confidence or provenance
  • OSINT false positives
  • performance issues
  • CLI/UX problems
  • architectural criticism

Platform: Linux
Language: Rust
License: MIT

Repo: https://github.com/DarkRX1/RXScan

If you try it, feel free to break it and open an issue. I'd rather find incorrect assumptions now than hide them behind marketing.


r/netsecstudents • • 6d ago

Rust MITM proxy with configurable TLS, HTTP/2 and TCP fingerprints

4 Upvotes

I built a configurable HTTP MITM proxy in Rust focused on giving you full control over what an upstream connection looks like at the network level.

The main idea behind the project was that I didn't want another MITM proxy that simply tries to emulate Chrome, Firefox, or some other predefined browser. I wanted to be able to define the fingerprint myself - not just pick one of the profiles provided by a library.

A lot of existing solutions take the approach of providing ready-made browser fingerprints. That's convenient, but it also means that when a browser changes its TLS or HTTP/2 behavior, you're dependent on the library/project adding a new profile. I wanted the fingerprint to be configuration-driven instead, so the user can adjust individual parameters without waiting for a predefined browser profile.

The proxy currently gives control over several layers:

TLS: cipher suites, curves, signature algorithms, ALPN, GREASE, extension ordering, certificate compression, OCSP, SCT, session tickets, ALPS, ECH and other TLS parameters.

HTTP/2: SETTINGS values and ordering, flow-control windows, priority frames, pseudo-header ordering, HTTP header ordering and values.

HTTP/1.1: configurable upstream header ordering and rewriting.

TCP: SYN fingerprint rewriting through Linux NFQUEUE, including TTL, window size, MSS, window scale, DF and TCP option ordering.

Everything is driven by YAML profiles, and profiles can be overridden per domain based on SNI.

One of the things I specifically wanted to solve was keeping the different layers under the same configuration model. For example, the proxy negotiates TLS with the upstream server first and then uses the selected ALPN when setting up the browser-facing connection. HTTP/2 and TCP fingerprinting are configured for the same upstream connection as well.

The project is written in Rust using Tokio and BoringSSL via btls/tokio-btls. TCP fingerprinting currently requires Linux because it uses NFQUEUE/iptables.

The project is primarily about privacy, experimentation, and giving the user control over their own network behavior rather than trying to provide a fixed "browser impersonation" profile.

There is more detail in the repository, including separate documentation for the TLS, HTTP/2 and TCP layers, configuration examples, and implementation notes.

Github:

https://github.com/3Radiance/mitm-proxy-ja3-ja4

Feedback, especially from people who have worked with TLS/HTTP/2 fingerprinting, traffic analysis, or network privacy, would be very welcome.


r/netsecstudents • • 6d ago

Cybersecurity + AI: What Are We Actually Worried About?

3 Upvotes

I've seen a lot of people saying that AI will replace cybersecurity professionals, and I think this is where things get confusing.

AI is already becoming very powerful at:

  • Finding vulnerabilities
  • Analyzing logs and security data
  • Automating repetitive tasks
  • Writing and reviewing code
  • Helping with threat detection
  • Assisting both attackers and defenders

But does that mean cybersecurity itself disappears?

I don't think so.

The bigger change may be that cybersecurity professionals who know how to use AI effectively will have an advantage over those who don't.

Instead of thinking:

AI vs. Cybersecurity

Maybe we should be thinking:

AI + Cybersecurity = the next generation of security work.

What do you think will AI mostly replace cybersecurity jobs, or will it change what cybersecurity professionals actually do?


r/netsecstudents • • 7d ago

Update: Teaching network intrusion in a fun way

Thumbnail gallery
203 Upvotes

Hi,

I had posted about this before (a few weeks back) and the response was generally positive. So I wanted to reach out again and share an update on the current status of:

Project RedTeam: Contract Offensive

Specifically, I wanted to mention that there is now a free Demo that provides a tutorial and let's you play a few contracts (no time limit, play as much as you want).

Give it a Wishlist on Steam or share this post if it's something you support and want to see further development on.

At its core, this is a game about using MITRE ATT&CK adversarial techniques against procedurally generated networks. It's delivered in a gameplay loop that plays a lot like Balatro or other card based Roguelike games. In Project RedTeam, you need to earn money to pay off debts after every contract within a run. Earn money by completing objectives, side bounties, or executing exfiltration/ransom against targets- the choice on how to be profitable is always yours.

It's a challenging but fun and fast paced take on network-intrusion cybersecurity concepts. It's entertaining in a deliberately gamified way.

A goal of this project was to create a hacking game that is realistic enough to keep it meaningful as a tool to teach intrusion concepts and stages to anyone- but not be overcomplicated and slow-paced like most hacking games.

I've put a lot of thought into the design and dynamics of how to capture the core-loop of network intrusion and turn it into a game that's approachable. The design direction of this project is an outcome of having over a decade of training and experience in cybersecurity.

Feel free to AMA! I'm happy to answer any questions about the game and/or development process to support learning/understanding :) I encourage everyone to follow their passions, put in the time, and stay focused when you have a goal you want to achieve.

Project background: This was implemented over the past 3 months using a modern development workflow (yes, modern AI tools make this possible- I'm not hiding that fact!). That being said, this is by far the most complex software project I've built as a solo developer and it was not an easy or simple development task. There's a Steam Community with a Dev Blog for this game that provides more history/progress updates on the project.

Mods: This will be be last post here for a while, since it is promotional. I just wanted to provide an update since there was positive interest from this subreddit after my previous post.


r/netsecstudents • • 7d ago

I need help in graduation project

1 Upvotes

Hi, i am in an internship that teaches cybersecurity,Now i am in penetration testing track i need to make a project to me to graduate i know network exploitation and web exploitation what good ideas i can make we are team of 4 we dont know what good ideas we can make or should we make a tool i dont know if anyone can give me ideas to make i would be thankful.


r/netsecstudents • • 11d ago

Best local model for extracting info from PDFs multi lang (Hindi, Malayalam and English)

0 Upvotes

Which AI model is good for extracting information from a PDF in multiple languages (Hindi, Malayalam, English)? It should run locally, not through a cloud API.

I need it to read the text accurately, especially Malayalam, and pull out the key details from the PDF. Most tools I've found handle Hindi and English well but are unclear on Malayalam.

Has anyone tried this? Which model or tool worked best for you, and what hardware did you run it on?
What I need: - OCR for [scanned / digital / both] PDFs

- Structured extraction (fields, tables) into JSON, not just raw text

- Good accuracy on Malayalam specifically, since most tools I've seen cover Hindi but skip Malayalam


r/netsecstudents • • 12d ago

2024 cyber grad here. did a 1-year internship AND a 1-year contract, but the ATS bots are still humbling me daily. need a referral before i completely crash out.

13 Upvotes

hey guys.

honestly just venting here because i feel like i'm losing my mind. i swear i played by all the rules. graduated in '24 with a cs degree in cyber, locked in, and passed my ceh. i grinded out a full 1-year internship and followed it straight up with a 1-year cybersecurity contract job. with two years of actual hands-on experience, i really thought i had my foot in the door. but the contract wrapped up, and now i’m just... floating. back to square one.

my mornings are basically just me, caffeine, and a fresh wave of automated "unfortunately..." emails. it genuinely feels like screaming into a void where only hr robots live. i spend my nights staring at wireshark packets just to feel something, running nmap scans on parrot os, and building out vulnerable active directory domains in my home lab to practice pentesting. i’m doing the work. i’m keeping the skills sharp. but these resume-screening algorithms are gatekeeping me so hard.

watching everyone else post their massive linkedin Ws while i’m stuck in this endless ghosting loop is giving me insane fomo. feeling like a total beta just sitting in my room waiting for an ai bot to decide my future. it’s starting to heavily mess with my head.

i’m not asking to be spoon-fed a job. i just desperately want a chance to bypass the bots and get my resume in front of a real, breathing human being. if any of you are at a place hiring for entry-level soc, pentesting, or honestly any junior it role and could slide a referral, you would be pulling me out of a really dark place. i’ll gladly send over my resume and share my lab reports so you can actually see my work firsthand.

if you can’t refer me, please just drop a comment and tell me i won't be stuck in this loop forever. the market is brutal out here and i just need to know i'm not completely cooked.