π Day 52 β First Steps with Python and JavaScript for Security
π― Goal
Todayβs goal was to begin exploring basic programming concepts through two introductory TryHackMe rooms:
- Python Simple Demo
- JavaScript Simple Demo
The objective was not to become a programmer yet, but to understand how scripting languages work, because in cybersecurity these languages are frequently used for:
- automation
- malware
- detection engineering
- offensive security tooling
- security research
Learning the basics now helps me understand what attackers automate and how defenders analyze scripts.
π What I Did
Today I completed the following TryHackMe rooms:
- https://tryhackme.com/room/pythonsimpledemo
- https://tryhackme.com/room/javascriptsimpledemo
Python Simple Demo
This room introduced the core idea that Python is a scripting language used heavily in cybersecurity because it is:
- simple
- readable
- extremely powerful with libraries
- widely used in security tooling
Examples of things Python is commonly used for in security include:
- vulnerability scanners
- brute-force tools
- automation scripts
- malware prototypes
- log analysis
Some of the basic concepts covered included:
- printing output
- simple variables
- executing small scripts
- understanding how code runs step by step
Even though the examples were simple, the important realization is that many real offensive security tools are essentially larger versions of scripts like these.
JavaScript Simple Demo
The JavaScript room focused on how JavaScript runs inside the web browser environment.
Unlike Python, JavaScript is deeply connected to:
- web pages
- user interaction
- client-side logic
Important ideas introduced:
- JavaScript runs inside the browser
- it can interact with the page (DOM β Document Object Model)
- it reacts to user actions such as clicks
- it can modify page content dynamically
This is extremely important in cybersecurity because many web attacks rely on JavaScript behavior.
Examples include:
- Cross-Site Scripting (XSS)
- malicious scripts injected into webpages
- browser-based exploitation
Understanding how JavaScript works helps when investigating web application attacks.
π Key Cybersecurity Connections
Although these rooms were beginner-level programming introductions, the concepts connect directly to real cybersecurity work.
Python in security
Python is used in tools such as:
- Reconnaissance tools
- Exploit scripts
- Automation frameworks
- Log analysis utilities
Many penetration testing tools are built with Python or use Python modules.
Examples include:
- parts of Metasploit modules
- many OSINT tools
- custom red-team scripts
JavaScript in security
JavaScript is central to many web attacks.
For example:
XSS (Cross-Site Scripting) happens when attackers inject malicious JavaScript into a webpage that other users load.
When the victim loads the page:
Browser loads page
β
Malicious JavaScript executes
β
Attacker steals cookies or session data
SOC analysts and web security engineers must understand JavaScript behavior to detect these attacks.
π Investigation Questions
When analyzing suspicious scripts or malicious code behavior, a SOC analyst might investigate questions such as:
- What script or code was executed on the system?
- What process launched the script interpreter (Python, JavaScript, PowerShell, etc.)?
- Did the script perform network connections or downloads?
- Was the script executed from a user-writable directory?
- Did the script spawn additional processes or modify system files?
- Are similar scripts being executed across multiple endpoints?
These questions help determine whether a script is legitimate automation or part of a malicious activity.
π¨ Detection Opportunities
Possible detection strategies involving scripts include:
- monitoring unusual execution of scripting interpreters such as Python or PowerShell
- detecting scripts executed from temporary or user-controlled directories
- identifying suspicious network activity initiated by scripts
- monitoring browser activity for JavaScript injection behavior
- detecting abnormal process spawning patterns associated with scripts
Telemetry sources useful for these detections include:
- endpoint process logs
- network logs
- browser telemetry
- EDR monitoring systems.
π§ MITRE ATT&CK Techniques
Malicious scripting activity often relates to several MITRE ATT&CK techniques:
- T1059 β Command and Scripting Interpreter
- T1059.007 β JavaScript
- T1059.006 β Python
- T1059.001 β PowerShell
These techniques describe how attackers use scripting environments to execute malicious code during attacks.
β Challenges
The main challenge today was not the difficulty of the material, but rather understanding how these programming concepts connect to cybersecurity.
The rooms are intentionally simple demonstrations, so the important takeaway is recognizing:
- where these languages appear in real attacks
- how attackers automate things with scripts
- how defenders analyze suspicious code
Another challenge is accepting that programming will likely become a necessary skill over time for security work.
π What I Learned
Key lessons from today:
- Python is one of the most important languages in cybersecurity
- JavaScript is critical for web security understanding
- scripting languages allow attackers to automate attacks
- defenders must understand scripts to analyze malicious behavior
Even basic scripts can evolve into:
- malware loaders
- phishing page scripts
- exploit automation
- data exfiltration tools
So learning the basics early is important.
β‘ Next Steps
Next steps moving forward:
- continue exploring scripting fundamentals
- learn how Python is used in security automation
- understand how malicious JavaScript appears in web attacks
- continue completing TryHackMe rooms related to programming and security
As my studies progress, I expect scripting to become a tool for:
- log analysis
- detection engineering
- automation in SOC workflows
π§ Reflection
Todayβs rooms were a reminder that cybersecurity is not only about tools and investigations.
A large part of security involves understanding code, because attackers frequently use scripts to automate their operations.
Even though the rooms were introductory, they reinforce an important idea:
To become effective in cybersecurity, it helps to understand the languages attackers use.
π§© Lessons Learned
What worked
- Simple TryHackMe demos helped introduce programming concepts without overwhelming complexity.
What broke
- The rooms are intentionally basic, so the cybersecurity connection is not immediately obvious without thinking about real-world usage.
Why it broke
- Programming tutorials focus on syntax, but security professionals need to think about how code is used operationally.
Fix / takeaway
- Continue learning programming concepts while always asking:
How would an attacker use this?
How would a defender detect this?
π Skill Progression Context
This learning step fits into the broader progression of building a cybersecurity skillset.
So far my journey has included:
- Linux command line investigation
- log analysis
- SOC investigation mindset
- detection engineering concepts
- Windows telemetry and Sysmon lab setup
Learning Python and JavaScript now adds another layer:
- understanding how scripts are written
- recognizing malicious code patterns
- eventually writing security automation tools
Over time this will support:
- detection engineering
- threat hunting
- malware analysis
- red team automation
