CySA+ v4
Practical labs
Build your toolkit, then connect the evidence. Each handout lists what you need, steps to follow, and tasks to try.
Start with each lab’s prerequisites. Lab 4 prepares Docker; Lab 12 builds the range used in Labs 14–17. Lab 5 prepares Wireshark for Lab 16.
The practical course
Your lab sequence
17 labs · By Michael Stout
Lab 1
Install Ollama and run DeepHat-V1-7B on Windows
Local AI For Security Analysts
Open labLab 2
Score a risk with NIST SP 800-30
Risk Assessment
Open labLab 3
Harden a host against a CIS Benchmark
System Hardening
Open labLab 4
Containerize an app with Docker Desktop
Infrastructure Concepts
Open labLab 5
Capture and analyze traffic with Wireshark
Malicious Activity
Open labLab 6
Investigate a live host with Sysinternals
Host-Related Indicators
Open labLab 7
Decode and defang artifacts with CyberChef
Decoding And Parsing Data
Open labLab 8
Write and test a YARA rule
Malicious Activity
Open labLab 9
Profile a threat actor, then rank what you found
Threat Classification
Open labLab 10
Research safely and anonymously with Tor Browser
Open-Source Intelligence
Open labLab 11
Scan and fingerprint a network with Nmap
Reconnaissance
Open labLab 12
Give Nmap real targets to scan
Reconnaissance
Open labLab 13
Install Ollama and run Gemma 4 (31B)
Local AI, At A Larger Scale
Open labLab 14
Scan Metasploitable with OpenVAS
Vulnerability Scanning
Open labLab 15
Validate the OpenVAS finding with Metasploit
Vulnerability Scanning
Open labLab 16
Capture and read the attack in Wireshark
Malicious Activity
Open labLab 17
Test DVWA with OWASP ZAP
Vulnerability Scanning
Open lab