CySA+ v4

Practical labs

Build your toolkit, then connect the evidence. Each handout lists what you need, steps to follow, and tasks to try.

Start with each lab’s prerequisites. Lab 4 prepares Docker; Lab 12 builds the range used in Labs 14–17. Lab 5 prepares Wireshark for Lab 16.

The practical course

Your lab sequence

17 labs · By Michael Stout

  1. Lab 1

    Install Ollama and run DeepHat-V1-7B on Windows

    Local AI For Security Analysts

    Open lab
  2. Lab 2

    Score a risk with NIST SP 800-30

    Risk Assessment

    Open lab
  3. Lab 3

    Harden a host against a CIS Benchmark

    System Hardening

    Open lab
  4. Lab 4

    Containerize an app with Docker Desktop

    Infrastructure Concepts

    Open lab
  5. Lab 5

    Capture and analyze traffic with Wireshark

    Malicious Activity

    Open lab
  6. Lab 6

    Investigate a live host with Sysinternals

    Host-Related Indicators

    Open lab
  7. Lab 7

    Decode and defang artifacts with CyberChef

    Decoding And Parsing Data

    Open lab
  8. Lab 8

    Write and test a YARA rule

    Malicious Activity

    Open lab
  9. Lab 9

    Profile a threat actor, then rank what you found

    Threat Classification

    Open lab
  10. Lab 10

    Research safely and anonymously with Tor Browser

    Open-Source Intelligence

    Open lab
  11. Lab 11

    Scan and fingerprint a network with Nmap

    Reconnaissance

    Open lab
  12. Lab 12

    Give Nmap real targets to scan

    Reconnaissance

    Open lab
  13. Lab 13

    Install Ollama and run Gemma 4 (31B)

    Local AI, At A Larger Scale

    Open lab
  14. Lab 14

    Scan Metasploitable with OpenVAS

    Vulnerability Scanning

    Open lab
  15. Lab 15

    Validate the OpenVAS finding with Metasploit

    Vulnerability Scanning

    Open lab
  16. Lab 16

    Capture and read the attack in Wireshark

    Malicious Activity

    Open lab
  17. Lab 17

    Test DVWA with OWASP ZAP

    Vulnerability Scanning

    Open lab