This module introduces file inclusion vulnerabilities in web applications, including Local File Inclusion, Remote File Inclusion, path traversal, PHP filters and wrappers, log poisoning, malicious file uploads, and exploitation paths leading to remote code execution. Through practical exercises and a skills assessment, learners develop hands-on offensive security skills while also learning prevention techniques. The module is designed for learners with basic knowledge of Linux, networking, web requests, and information security fundamentals.
Repositories
Access a wealth of resources including articles, whitepapers, tools, and guides to support your learning.
- Compliance Standards
Technical Competence Requirements for Cyber Resilience Act (CRA) Notified Bodies
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
This ENISA publication outlines the high-level technical competence requirements for Conformity Assessment Bodies (CABs) seeking designation as Notified Bodies under the EU Cyber Resilience Act (CRA). The document focuses on the knowledge, experience, training, and auditing capabilities required for personnel involved in evaluating the cybersecurity conformity of products. It provides guidance for developing qualified assessment teams and supports the consistent implementation of CRA certification and conformity assessment processes across the European Union.
- Risk Management
ENISA NIS360: Maturity and Criticality Assessment of NIS2 Sectors
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
The ENISA NIS360 is an assessment framework that evaluates the maturity and criticality of sectors covered by the NIS2 Directive. Drawing on data from national authorities, organisations operating in critical sectors, and EU-level sources, the tool provides both a comparative overview and detailed sector-specific analysis. It helps Member States, regulators, and stakeholders identify cybersecurity capability gaps, benchmark sector readiness, and prioritise investments and resources to strengthen cyber resilience across critical sectors.
- Cybersecurity Best Practices for End Users
Cyber City Tycoon: Learn Cybercrime Tactics Through Gamified Training
- Published date:
- Author: Cyber Citizen Initiative
Cyber City Tycoon is a free educational game that uses gamification to teach users about common cybercrime tactics and online scams. Players build a fictional cybercrime empire while learning how phishing, fraud, social engineering, trolling, and other cyber threats operate in the real world. Inspired by actual cybercrime techniques, the game helps learners understand attacker behaviour and develop practical skills to recognise and avoid cyber threats in everyday life.
- Compliance Standards
EU AI Act Service Desk and Single Information Platform
- Published date:
- Author: European Commission
The EU AI Act Service Desk and Single Information Platform provide practical tools and guidance to help organisations understand and comply with the European Union AI Act. The platform includes the AI Act Explorer, Compliance Checker, implementation guidance, FAQs, and support services designed to assist stakeholders in assessing obligations related to trustworthy and high-risk AI systems. It supports startups, SMEs, developers, and deployers in navigating AI governance, compliance, and risk management requirements across the EU.
- Compliance Standards
Guidelines for Providers and Deployers of High-Risk AI Systems under the EU AI Act
- Published date:
- Author: European Commission
These European Commission guidelines support providers and deployers in understanding and classifying high-risk AI systems under the EU AI Act. The document explains key obligations, risk categories, and practical implementation considerations, including examples across sectors such as biometrics, critical infrastructure, education, employment, and migration. The guidelines aim to facilitate compliance, improve trustworthy AI deployment, and support the secure and responsible use of AI systems across the European Union.
- Cybersecurity Best Practices for End Users
Cyber First Aid: Reporting and Support Resources for Cybercrime Victims
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
Cyber First Aid is an ENISA online resource that helps individuals report cybercrime incidents and access cybersecurity support services in their country. The platform provides country-specific contacts, reporting channels, consumer protection resources, and guidance for incidents such as online fraud, compromised bank accounts, hacked social media accounts, and other cyber threats. Designed to improve cyber incident awareness and response, the resource supports citizens in taking practical steps after experiencing cybercrime.
- Compliance Standards
ENISA National Cyber Security Strategies Interactive Map
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
This interactive tool by ENISA provides a comprehensive overview of national cybersecurity strategies across EU Member States and selected European countries. Users can explore each country’s strategic priorities, implementation status, key organisations, and supporting initiatives such as ISACs, R&D activities, and public-private partnerships. The platform supports policy awareness, benchmarking, and the exchange of best practices across Europe.
- Introductory Courses to Cybersecurity
Cybersecurity: A Citizen and Professional Guide
- Published date:
- Author: ARQUS European University Alliance
This free, fully online course provides a comprehensive introduction to cybersecurity for both individuals and professionals. Over six weeks, learners explore essential topics such as data protection, encryption, mobile and social media security, and risk management. The course combines practical guidance with real-world case studies, covering cyber threats, digital forensics, international regulations, and emerging challenges like quantum and space-based cybersecurity. It equips participants with the skills to understand risks and develop effective security strategies for personal and workplace environments.
- Introductory Courses to Cybersecurity
Cybersecurity Glossary: Simple Explanations of Key Terms
- Published date:
- Author: Cyber Citizen Initiative
This online cybersecurity glossary provides clear and jargon-free explanations of more than 85 commonly used terms. Designed for a broad audience, it helps learners, professionals, and the general public better understand cybersecurity concepts encountered in everyday digital life, work, or study. Available free of charge in all 24 official EU languages, it serves as an accessible reference tool for improving cybersecurity awareness and digital literacy.