3MTT Cohort 3 Fellowship (Ethical Hacking & Cloud Security) β documented in public
Documenting my journey through Nigeria's 3MTT Cohort 3 Cybersecurity Fellowship (Ethical Hacking & Cloud Security track) β from the basics up to where I currently am, plus my own personal security research on the side.
Real notes, real commands, real screenshots where possible. Not a polished course β a working log of what I'm actually learning, as I learn it.
/notes
01-foundations/ - Intro to cybersecurity, CIA triad, Linux/Kali,
sysadmin reference, hosting & practice targets
02-networking/ - OSI model, DNS/TCP/UDP, ports & protocols,
subnetting, Wireshark, OSINT/recon tools,
binaries/hex, devices, topologies, wireless,
mobile device security
03-attacks/ - Network attacks, DDoS, password cracking,
social engineering, web app attacks, IoT
04-frameworks-and-governance/ - NIST/ISO frameworks, risk management,
compliance, cryptography, IAM
05-defense-and-assessment/ - Network security, vuln assessment,
pentesting methodology, incident response,
digital forensics
06-web-app-security/ - Burp Suite & manual testing workflow
/research
mitm/ - Personal research: ARP poisoning, other MITM
techniques, Wi-Fi MITM (with/without adapter)
/tools - Tools I build along the way (e.g. subrecon)
/resources - Curated links, wordlists, cheatsheets
/capstone - NDPA 2023 compliance audit capstone (report,
lab setup script, reproducible findings)
- Linux CLI fundamentals & Kali install/setup
- Intro to cybersecurity, CIA triad, daemons
- Networking fundamentals (OSI, DNS, TCP/UDP, ports, subnetting)
- Wireshark basics
- OSINT & recon tools, ProxyChains/Tor, fingerprinting
- Network attacks, DDoS, password attacks, social engineering
- Web app attacks (XSS, SQLi, HTML tampering) + Burp Suite
- IoT security
- Frameworks (NIST/ISO), risk management, compliance
- Cryptography, IAM
- Network security defenses, vulnerability assessment, pentesting methodology
- Incident response & digital forensics concepts
- MITM research (ARP poisoning, Wi-Fi MITM)
- Binaries/hex, network devices, topologies, wireless & mobile device security
- Capstone deep-dive: NDPA 2023 Organizational Compliance Checklist
Note on scope: this repo intentionally excludes malware creation code or other functional offensive payloads - it covers attack concepts, detection, and defense, plus tool usage against explicitly authorized/ legal practice targets only.
I'm David James Omeiza ("Mr Syco") - cybersecurity professional and bug bounty hunter based in Lagos, Nigeria. Find me on GitHub and X / @MrSyco09 for cybersecurity content.