MYTHOSAI

MYTHOSAI / LEARNING LIBRARY

Know the risk.
Learn the defence.

Clear, practical guides to protecting accounts, securing systems and understanding the tools. Start with one task. Learn how to check your result.

100 focused guides11 learning topics$0 to read

CHOOSE YOUR NEXT SKILL

Explore by topic

THE COMPLETE LIBRARY

One useful task at a time.

Use a guide to understand a task, then verify it in your own authorised environment.

100 guides

Security basics01

How to recognise a phishing email

Check the request, sender and destination before opening a link or approving a payment.

2 min read · Free guide
Security basics02

A free password-manager workflow for beginners

Replace password reuse with unique credentials and a recovery plan you can actually use.

2 min read · Free guide
Security basics03

Enable MFA without locking yourself out

Add a second sign-in factor and prove you have a usable recovery route.

2 min read · Free guide
Security basics04

Check whether your email appears in a data breach

Use the free Have I Been Pwned email search and turn the result into specific actions.

2 min read · Free guide
Security basics05

What to do when you suspect ransomware

Contain the affected device, preserve useful evidence and protect unaffected backups.

2 min read · Free guide
Security basics06

Clicked a phishing link? Choose the right response

Distinguish viewing a page from disclosing credentials, approving access or running a file.

2 min read · Free guide
Security basics07

Recover a compromised email account

Remove attacker access, check hidden mailbox changes and protect password-reset channels.

2 min read · Free guide
Security basics08

Build a backup routine that can survive ransomware

Use existing storage, keep a separated copy and test a restore before you need it.

2 min read · Free guide
Security basics09

Update software safely without fake update pop-ups

Use trusted update channels, restart deliberately and verify the installed version.

2 min read · Free guide
Security basics10

Audit Chrome browser extensions in ten minutes

Remove unnecessary extensions and restrict access to the websites where they are needed.

2 min read · Free guide
Windows security11

A practical Windows 11 security checklist

Check the built-in protections first and record what is actually enabled.

2 min read · Free guide
Windows security12

Check Microsoft Defender protection status with PowerShell

Inspect real-time protection, signatures and operating mode without changing settings.

2 min read · Free guide
Windows security13

Run and verify a Microsoft Defender scan

Choose quick, full or targeted scanning and inspect the result after it completes.

2 min read · Free guide
Windows security14

Investigate Windows failed sign-ins with Event 4625

Find the failed account, logon type and source without treating every failure as an attack.

2 min read · Free guide
Windows security15

Check Windows Firewall profiles and rules

Confirm the active profile and inspect rules before changing or disabling anything.

2 min read · Free guide
Windows security16

Find which Windows process owns a network connection

Use built-in PowerShell to connect an established TCP session to its process.

2 min read · Free guide
Windows security17

Review Windows startup entries with free Autoruns

Find automatic launch points and disable a questionable entry reversibly before deleting it.

2 min read · Free guide
Windows security18

Check BitLocker status and your recovery-key plan

Confirm which volumes are encrypted before changing firmware, TPM or boot settings.

2 min read · Free guide
Windows security19

Check SMBv1 before removing the legacy Windows feature

Identify dependency risk, remove SMBv1 where safe and keep modern file sharing working.

2 min read · Free guide
Windows security20

Verify a download with SHA-256 in PowerShell

Compare your file with a checksum from the genuine publisher, without running it.

2 min read · Free guide
Linux security21

First security checks on a new Ubuntu server

Inventory the server, apply ordinary updates and reduce exposure without losing remote access.

2 min read · Free guide
Linux security22

Configure UFW without locking yourself out of SSH

Allow the real management path before enabling a deny-incoming policy.

2 min read · Free guide
Linux security23

Create and test an SSH key for Ubuntu access

Add key authentication first and verify it before removing password access.

2 min read · Free guide
Linux security24

Disable SSH password authentication safely on Ubuntu

Validate the effective configuration and test a fresh key-only login before closing access.

2 min read · Free guide
Linux security25

Find failed SSH logins on Ubuntu

Use service logs and time windows to distinguish routine errors from hostile patterns.

2 min read · Free guide
Linux security26

Find listening ports on Linux with ss

Identify protocol, bind address and owning process using the built-in socket inspection tool.

2 min read · Free guide
Linux security27

Check Ubuntu automatic security updates

Inspect unattended-upgrades, test its decision process and verify that important updates complete.

2 min read · Free guide
Linux security28

Understand Linux file permissions with a safe example

Practise owner, group and other permissions on a disposable file instead of changing system directories.

2 min read · Free guide
Linux security29

Troubleshoot a Linux service with journalctl

Read a bounded service timeline and check the result of a change without clearing evidence.

2 min read · Free guide
Linux security30

Configure a basic Fail2ban SSH jail on Ubuntu

Reduce repeated SSH authentication attempts while preserving your trusted management route.

2 min read · Free guide
Tool tutorials31

Nmap for beginners: your first controlled scan

Use a narrow TCP scan in your own lab and distinguish open, closed and filtered ports.

2 min read · Free guide
Tool tutorials32

Discover devices on your authorised network with Nmap

Use host discovery to compare live responses with an expected device inventory.

2 min read · Free guide
Tool tutorials33

Check specific ports and service versions with Nmap

Separate basic reachability, version probing and a real application test.

2 min read · Free guide
Tool tutorials34

Your first Wireshark packet capture

Capture a short piece of your own traffic and learn the three main views.

2 min read · Free guide
Tool tutorials35

Wireshark display filters you can explain

Find DNS, TLS and one host’s traffic without confusing display and capture filter syntax.

2 min read · Free guide
Tool tutorials36

Find the busiest conversations in Wireshark

Use endpoint pairs and byte counts to explain traffic volume without guessing its intent.

2 min read · Free guide
Tool tutorials37

Use Burp Suite Community Edition in a free learning lab

Inspect one lab request with the built-in browser and repeat it without buying Pro.

2 min read · Free guide
Tool tutorials38

Run Kali Linux in a virtual machine for learning

Practise without replacing your main operating system or interrupting a server workload.

2 min read · Free guide
Tool tutorials39

Use VirusTotal without uploading confidential files

Search an existing file hash first and interpret detections as evidence, not a verdict.

2 min read · Free guide
Tool tutorials40

Inspect HTTP security headers with curl

Read the response headers from your own site and understand what they do—and do not—prove.

2 min read · Free guide
Monitoring41

Wazuh for beginners: what runs where

Understand the agent, manager, indexer and dashboard before deploying a monitoring stack.

2 min read · Free guide
Monitoring42

Install and verify a Wazuh Windows agent

Use the manager-generated enrollment command and prove the endpoint sends fresh data.

2 min read · Free guide
Monitoring43

Create a small Wazuh file-integrity monitoring lab

Monitor a dedicated test directory and explain a file-change alert without touching business data.

2 min read · Free guide
Monitoring44

Check Wazuh Windows Event Channel collection

Confirm a specific Windows event channel reaches the manager before writing an alert rule.

2 min read · Free guide
Monitoring45

Zabbix active and passive agents explained

Choose the connection direction deliberately and match the agent, host and item configuration.

2 min read · Free guide
Monitoring46

Design useful low-disk-space alerts in Zabbix

Check actual collection, combine practical thresholds and test delivery without filling a real drive.

2 min read · Free guide
Australian business47

Essential Eight: a practical starting map for small businesses

Turn the eight mitigation strategies into an evidence-based improvement list.

2 min read · Free guide
Australian business48

Check suspicious bank and delivery text messages in Australia

Verify through the genuine app instead of trusting a sender name or a convincing link.

2 min read · Free guide
Australian business49

Where to report a scam or cybercrime in Australia

Prioritise containment, then choose the official reporting route for what happened.

2 min read · Free guide
Australian business50

A free-first security checklist for a small business

Organise the controls you already have and test whether they protect the business’s actual workflow.

2 min read · Free guide
Privacy and devices51

Review Android app permissions by purpose

Find unnecessary access to location, camera and microphone without disabling an essential feature blindly.

2 min read · Free guide
Privacy and devices52

Prepare for a lost phone before it disappears

Check remote-device controls and recovery dependencies using the accounts and equipment you already have.

2 min read · Free guide
Privacy and devices53

Handle an unknown USB drive without plugging it in

Use an ownership and reporting process instead of exposing a work computer to an untrusted device.

2 min read · Free guide
Privacy and devices54

Review clipboard history before copying a secret

Understand where copied passwords, tokens and screenshots may remain or synchronise.

2 min read · Free guide
Privacy and devices55

Make a small data-retention inventory

Find redundant copies and assign an owner before deleting business information.

2 min read · Free guide
Privacy and devices56

Review website camera, microphone and notification permissions

Remove stale browser permissions without breaking an expected meeting or business workflow.

2 min read · Free guide
Privacy and devices57

Understand what private browsing does and does not hide

Choose a browser session for local privacy without mistaking it for anonymity.

2 min read · Free guide
Privacy and devices58

Separate work and personal browser profiles

Reduce account mix-ups while understanding that a profile is not a strong device-security boundary.

2 min read · Free guide
Privacy and devices59

Sanitise a screenshot before asking for support

Share the error and relevant context while removing credentials and unrelated personal information.

2 min read · Free guide
Privacy and devices60

Review who can open a cloud file-sharing link

Distinguish a named recipient from anyone holding a link before sharing business information.

2 min read · Free guide
Incident recovery61

Set recovery-time and data-loss targets

Turn backup frequency into a business decision about how much downtime and lost work are tolerable.

2 min read · Free guide
Incident recovery62

Restore a test file without overwriting the working copy

Prove that a specific backup can deliver usable content through the normal recovery route.

2 min read · Free guide
Incident recovery63

Check who can delete your backups

Find whether an ordinary compromised account could remove the recovery copies you rely on.

2 min read · Free guide
Incident recovery64

Plan a known-good rebuild of an affected computer

List trusted installation sources, recovery data and account changes before reusing a compromised device.

2 min read · Free guide
Incident recovery65

Close an incident with evidence and follow-up actions

Distinguish restored service from a complete response and assign the remaining improvements.

2 min read · Free guide
Incident recovery66

Write a useful first-hour incident note

Capture observations and actions without turning an early suspicion into an unsupported conclusion.

2 min read · Free guide
Incident recovery67

Plan device isolation during a suspected incident

Reduce further connectivity while documenting what isolation can interrupt or change.

2 min read · Free guide
Incident recovery68

Preserve security logs before routine cleanup

Keep a reproducible evidence copy with its collection context and access controls.

2 min read · Free guide
Incident recovery69

Make an incident contact sheet that works offline

Prepare verified contacts and decision owners before email or the network becomes unavailable.

2 min read · Free guide
Incident recovery70

Run a small ransomware tabletop exercise

Practise decisions and recovery dependencies without encrypting files or deploying malware.

2 min read · Free guide
Email and domains71

Verify a supplier bank-detail change

Use an independent approval route before an authentic-looking invoice redirects payment.

2 min read · Free guide
Email and domains72

Inspect the real domain in an email link

Separate a convincing label, subdomain and redirect from the service you intended to visit.

2 min read · Free guide
Email and domains73

Handle an unexpected attachment without running it

Verify the business request and file type before allowing an attachment to become an executable action.

2 min read · Free guide
Email and domains74

Review DNS changes for a business domain

Check authoritative settings and important records before blaming a website or mail outage on propagation.

2 min read · Free guide
Email and domains75

Protect the account that controls your domain

Review registrar access, recovery and change alerts for a critical business dependency.

2 min read · Free guide
Email and domains76

Read an email authentication result without overtrusting it

Use trusted message headers to understand SPF, DKIM and DMARC while still checking the request.

2 min read · Free guide
Email and domains77

Plan an SPF record from a sender inventory

List legitimate sending services before editing the DNS policy for your domain.

2 min read · Free guide
Email and domains78

Verify DKIM signing for a domain you manage

Check the selector, DNS publication and real-message result before declaring signing complete.

2 min read · Free guide
Email and domains79

Introduce DMARC monitoring before enforcement

Use aggregate evidence to find legitimate senders before applying a stricter domain policy.

2 min read · Free guide
Email and domains80

Check mailbox forwarding and filters after suspicious activity

Find rules that copy, hide or redirect messages without deleting useful evidence.

2 min read · Free guide
Network security81

Check what encrypted DNS protects

Separate DNS transport privacy from malware filtering, browser security and VPN behaviour.

2 min read · Free guide
Network security82

Test a free threat-filtering DNS service safely

Use a provider's harmless test domain instead of browsing a real malicious website.

2 min read · Free guide
Network security83

Test a specific connection with PowerShell

Separate a reachable host from a reachable application port using a focused read-only check.

2 min read · Free guide
Network security84

Document a small-business network boundary

Turn a vague trusted network into a list of permitted connections and owners.

2 min read · Free guide
Network security85

Use public Wi-Fi with a practical safety routine

Verify the network, protect sign-ins and remove unnecessary sharing on a device you already own.

2 min read · Free guide
Account security86

Create a passkey and test your recovery route

Practise a phishing-resistant sign-in without losing your existing account recovery options.

2 min read · Free guide
Account security87

Review apps connected to your Google account

Distinguish signing in with Google from giving an app access to account data.

2 min read · Free guide
Account security88

Review account sessions and sign out old devices

Identify stale sessions without treating every unfamiliar device label as an attacker.

2 min read · Free guide
Account security89

Separate administrator access from everyday work

Reduce the tasks that run with elevated privileges while retaining a tested administration route.

2 min read · Free guide
Network security90

Build a network inventory before changing security settings

Identify the devices, owners and dependencies already present on your network.

2 min read · Free guide
Network security91

Secure router administration without losing access

Review management exposure, credentials and firmware with a safe recovery route.

2 min read · Free guide
Network security92

Test whether guest Wi-Fi isolates local devices

Check what a guest can reach instead of assuming a separate network name creates separation.

2 min read · Free guide
Network security93

Review port forwarding and automatic port mappings

Find unnecessary inbound exposure without breaking a service that still has an owner.

2 min read · Free guide
Network security94

Use nslookup to check a DNS answer

Compare a hostname, resolver and response before changing network settings.

2 min read · Free guide
Account security95

Make an account recovery map without exposing secrets

Find circular dependencies before a lost phone prevents access to every important account.

2 min read · Free guide
Account security96

Respond to an MFA prompt you did not initiate

Handle repeated approval requests without accidentally authorising an attacker.

2 min read · Free guide
Account security97

Find and retire old app passwords

Reduce long-lived credentials left behind by mail clients and retired integrations.

2 min read · Free guide
Account security98

Offboard a user with an access inventory

Remove access systematically while preserving required business records.

2 min read · Free guide
Account security99

Store recovery codes for a lost-device scenario

Keep emergency sign-in material available without leaving it beside an exposed password.

2 min read · Free guide
Account security100

Verify a support caller before granting remote access

Create a callback process that prevents a convincing voice from becoming administrator access.

2 min read · Free guide