r/cybersecurityindia 4d ago

Weekly Mentorship - Post All Career, Resume, Education and Job questions here!

12 Upvotes

This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!

Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.

Note - This post template has been copied from cybersecurity subreddit.


r/cybersecurityindia 4d ago

Request Everyone to Post/Reply to comments in Weekly Mentorship Thread

9 Upvotes

Hello,

We created a Weekly Mentorship thread for the subreddit.

We urge everyone to post all career and education related questions and advice in this thread.

There are a lot of folks requesting mentorship, career help, guidance, resume reviews, job search, etc.

We request everyone to priodically review the Weekly Mentorship thread and reply/egage with people.


r/cybersecurityindia 1d ago

Tools Free monitoring tools for a small company?

14 Upvotes

Hi everyone,

I'm working as a System Administrator and I'm also a cybersecurity student who likes learning and building new things.

I'm looking for free or open-source tools to monitor company PCs and servers. I'd like to track basic things like system health, logs, and whether company devices are being used for work or spending excessive time on sites like YouTube during office hours.

Any recommendations or real-world setups would be greatly appreciated.


r/cybersecurityindia 1d ago

Technical Discussion Random government domain showing up in Google searches for League of Legends?

7 Upvotes

I was searching up some League of Legends (LoL) stuff today and stumbled upon something this(above pic). I ended up doing a Google search for league of legends site:obpsudma.wb.gov.in (which is an official Indian government domain) and got a ton of strange gaming-related results.

None of these sites are actually working. The links are completely dead and won't open, but they just keep showing up all over the Google search results like normal pages.

What is this? Why is this happening to an official government domain? Is this some kind of search glitch or a known exploit?


r/cybersecurityindia 14h ago

News 6 days vs. 1 hour to Fix the Same Vulnerability: Check Point's Exposure Gap Report AMA

Thumbnail
1 Upvotes

r/cybersecurityindia 1d ago

Starting Cybersecurity Career bhai how to get an internship in cybersecurity i will be starting my second year now or ye bhi batado kya padna chahiye cubersecurity mein us regarding cuz i cant find cybersec internship anywhere and moreover people are telling ki isme fresher ki j*b hi nahi lagti

9 Upvotes

same as above


r/cybersecurityindia 1d ago

Starting Cybersecurity Career Every Way to Get a Cybersecurity Job in India - RANKED (Fresher Tier List)

Thumbnail
youtu.be
9 Upvotes

r/cybersecurityindia 1d ago

Personal Support & Help Looking to connect with local CyberSec enthusiasts & BD/Sales folks in Bhopal!

Thumbnail
1 Upvotes

r/cybersecurityindia 2d ago

Other Weekly Blog 6

5 Upvotes

Sorry for the delay guys. My account was banned and at the same time college started.

So, couldn't work on the blog and here is this week's Blog.

I know its too small and basic info. Will do better next week. Thank you.

Please feel free to give suggestions.


r/cybersecurityindia 3d ago

Personal Support & Help CyberPeace & Government-backed Hackathon winners still haven't received prize money after 9+ months

43 Upvotes

Hi everyone,

Posting anonymously.

My team won a prize at the CCTV Surveillance Security & Forensics Hackathon 2.0 held in New Delhi in September 2025. The event was organized by CyberPeace Foundation in collaboration with BPR&D and NCRB (Ministry of Home Affairs).

Before the event, the official prize amounts were announced, but on the day of the event they were reduced. We accepted that and continued participating.

After winning, we were told the prize money would be released within 6 months.

It has now been over 9 months, and none of the winners have received the prize money.

Since then, we have:

  • Sent multiple emails.
  • Made numerous phone calls.
  • Followed up repeatedly with CyberPeace, our primary point of contact.

Every time we are told that the payment is pending with the higher authorities, but there has been no clear timeline or update.

We're just students and cannot afford legal action. We only want the prize money that was promised to the winners.

Has anyone dealt with a similar situation? What is the best way to escalate this?

I can provide official documents and proof if needed.


r/cybersecurityindia 4d ago

SIEM SIEM home lab

7 Upvotes

Has anyone tried making a SIEM lab on personal(home) system ? if yes , could you please guide

- how did you achieve it ?

- what open source tools did you use ?

- any git hub project available to make it possible?


r/cybersecurityindia 5d ago

Starting Cybersecurity Career 3 methods for freshers to get into cybersecurity, from someone who went from 15k stipend to 40lpa In 4 years.

Thumbnail
youtu.be
41 Upvotes

r/cybersecurityindia 4d ago

Starting Cybersecurity Career Is RedTeam Hacker Academy in Bengaluru worth it, and how is their placement record ?

7 Upvotes

r/cybersecurityindia 4d ago

Career Questions and Discussions Help me choose my first Certification.

2 Upvotes

I have basic knowledge of Blue teaming stuff, Knows Networking, Linux fundamentals. Completed SOC L1 career path on THM. I built some projects. Didn't do certification before because no money 🥲🥲. So which one should I go with if I am aiming for SOC analyst L1, security analyst L1 or other entry level Blue team roles?

175 votes, 2d ago
103 comptia Security+
14 Microsoft SC 200
4 Microsoft SC 900
31 Microsoft SC 200 + comptia Security+
23 something else (comments)

r/cybersecurityindia 4d ago

Career Questions and Discussions TCS HackQuest JL update please take a min

1 Upvotes

Anybody got the JL this month guys?


r/cybersecurityindia 5d ago

Tools Maldev project - GhostlyIAT, A project about hiding and obfuscating IAT and stealthily calling functions from DLLs

9 Upvotes

When a Windows program calls an API like VirtualAllocEx, the compiler writes that function’s name and its parent DLL into the Import Address Table (IAT). Security tools inspect the IAT for suspicious combinations – for instance, seeing VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread together is an immediate red flag.

A common trick is to load the function at runtime using GetProcAddress and GetModuleHandle, which keeps VirtualAllocEx out of the IAT. But this still leaves two problems:

  • The strings "VirtualAllocEx" and "kernel32.dll" are still present in the binary.
  • GetProcAddress and GetModuleHandle themselves appear in the IAT, and they’re well‑known indicators that a program is trying to hide something.

This project takes it a step further: it replaces both GetModuleHandle and GetProcAddress with fully custom implementations that walk the Process Environment Block (PEB) and parse export tables using DJB2 hashes.So even the plain‑text DLL or function names exist do not exist in the binary, which makes the binary even more evasive against static analysis, and the two “hiding” APIs are never imported in the IAT.

The result is a clean executable whose static IAT reveals nothing malicious – all API resolution happens silently, by hand, inside the process’s own memory.

project link - https://github.com/Adroxz1122/GhostlyIAT


r/cybersecurityindia 6d ago

Blog The Invisible Guardians of the Internet: An Introduction to Content Moderation & Trust & Safety

Thumbnail
medium.com
3 Upvotes

We Use Social Media Every Day, But How Many of Us Actually Think About Content Moderation?

I was scrolling through social media today and realized something interesting: we spend hours looking at what appears on our feeds, but almost never think about everything that doesn't.

Every day, platforms deal with spam, scams, hate speech, graphic content, fake accounts, misinformation, and countless policy violations. Most users never see the work happening behind the scenes to keep these platforms usable.

I work in the Content Moderation and Trust & Safety space, and I've found that it's one of the least understood areas of the tech industry. People often assume AI handles everything or that moderation is simply "deleting posts," but there's a lot more nuance involved.

That inspired me to write the first article in a series introducing the field to a general audience. It covers what Content Moderation is, what Trust & Safety means, why these teams exist, and why they matter more than most people realize.

I'd genuinely love to hear what this community thinks.

Have you ever wondered how social media platforms decide what stays online and what gets removed?

Do you think AI will eventually replace human moderators?

What's the biggest misconception you've heard about content moderation?

If you're interested, here's the article: https://medium.com/@sagarpaul07/the-invisible-guardians-of-the-internet-an-introduction-to-content-moderation-trust-and-safety-05828e8e1eb8?sharedUserId=sagarpaul07

I'm also planning more articles on topics like how moderation decisions are made, the role of AI, and what it's actually like working in Trust & Safety. I'd appreciate any feedback or suggestions for future topics.


r/cybersecurityindia 6d ago

Personal Support & Help Laptop recommendation for cybersecurity student

25 Upvotes

Hi all im joining college this year and my course is cse cybersecurity and i want you guys to recommend a laptop for me, i was thinking of getting the macbook air m5 (after gst discount etc for 90k) but people say that mac os is not compatible with it, im open to any option


r/cybersecurityindia 6d ago

Other Has AI made phishing emails almost impossible to spot?

9 Upvotes

We're seeing phishing emails become much harder to spot. Instead of the obvious scams, they're now well written, personalized, time-sensitive and often impersonating executives or finance teams. Many organizations invest in awareness training, but I'm wondering if that's enough anymore.

For those working in HR, IT, or Security, Have you increased phishing simulations? Do employees actually report suspicious emails? Has your company considered cyber insurance as part of its risk strategy?


r/cybersecurityindia 7d ago

News Hiring Interns for threat intelligence role (paid)

36 Upvotes

Hi,

Safe Security is hiring for Threat Intelligence interns from Cyber Unbound.

Requirements

1) Good at POC recreation of CVEs ( videos / writeups)

2) Skilled with creating docker containers / VMs

3) Good writeup skills

4) Great experience with CTFs on HTB/ competition

5) Should work from office in Delhi ( 6 months) (not a remote role)

6) Past experience with making CVE based / real world vulnerabilities based CTF challs

7) cert like CJCA /CPTS /EJPT / O.S.C.P are good to have but not a requirement for this role

What you get :

1) 20k stipend + shot at PPO at Safe ( 12-24 LPA CTC)

2) Work directly with Rahul Tyagi

Duration: 6 months in person

Location: Delhi

send your r-esume/cv to [[email protected]](mailto:[email protected]) :)


r/cybersecurityindia 7d ago

Other False positives block requesting to delist our domain!!

Thumbnail
3 Upvotes

r/cybersecurityindia 7d ago

Technical Discussion [IND] What kind of verification is this?

Thumbnail
1 Upvotes

r/cybersecurityindia 8d ago

Career Questions and Discussions The Technical Interview Prep List for Blue Team Roles (As Promised FollowUp of Last Post)

22 Upvotes

As I promised in my last post, here's the technical side checklist of preparing for interview. Whether you're a fresher, switching from another IT role, or transitioning careers entirely, this is what I'd tell you to actually prepare, not just read, before a Blue Team technical round. I have been on both sides of table now and I understand the mindset of interviewer, and now after conducting multiple mock interviews and giving interviews, this is it. Save It or write it down somewhere.

Study real attacks, properly. Not just what is phishing. Pick an actual case, walk through how it played out, and make yourself to answer like what would detection context look like here, what's the process tree telling me like whats your inference from it, what do the network and file logs show, what response actions would I take and in what order. Interviewers love scenario based what if questions precisely because most candidates have only memorized definitions, not the flow of an actual investigation.

Know Windows authentication. Kerberos, NTLM, how a logon actually happens, what an event ID 4624 versus 4625 means. This comes up very often, even in interviews that aren't explicitly Windows internals focused.

A lot of interview questions sound simple on the JD but those are deliberately built to see how you think, not just what you know. This is the mindset shift that matters more than any single topic. If your instinct is to immediately start answering the second the question finishes, stop. Ask a clarifying question first, even if you're fairly sure you know what they're asking, even if you don't think you need it. Something like "Are we assuming this is an on prem environment or cloud?" or "When you say suspicious login, do you mean failed attempts or a successful one from an unusual location?" or "What is the scale of environment" .

This shows you think like an analyst who gathers context before jumping to conclusions, which is exactly the part they're testing for. Always Think Out Loud.

Know your fundamentals by heart, not just recognize them when you see them written down. OSI layers, basic OS concepts, common web vulnerabilities, core network protocols. You should be able to explain these out loud without hesitating, because a hesitant answer on something this basic signals a bad foundation on your end.

And always expect the classic behavioral technical hybrid like "Describe a time you encountered a particularly challenging security incident and how you handled it." Have a real one ready, not a hypothetical. Structure it like an actual case, what you saw, what you checked, what you ruled out, what you did, what the outcome was.

If you're a fresher without a real incident from work, use a home lab scenario you genuinely investigated yourself, just be honest that it's lab based.

Let me know what technical question that actually you feel you could answer better in an official interview. Or any of your doubts regarding Interview Mindset.


r/cybersecurityindia 9d ago

Other Open to New Opportunities | Senior DFIR | Incident Response | Digital Forensics | Cyber Investigations | 7+ Years

Thumbnail
3 Upvotes

r/cybersecurityindia 10d ago

Personal Support & Help How do one land their first cyber job ??I

7 Upvotes

I'm starting my last year of college and I want to get into defensive security.

Till now I have pretty decent knowledge of networking and apart from that I have completed the security, pre security path of tryhackme and is currently starting the soc l1 path .

First thing I want to know is , should I start applying for internships ??or should I complete the soc l1 path first .

Secondly, I would really appreciate it if u guys can give a good insight on how to proceed forward and be better than others and grab a job in this field .

32 votes, 8d ago
12 yes
20 no