Skip to content

Latest commit

 

History

16 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Awesome Cybersecurity for Middle School

A curated collection of teaching resources, tools, and references for educators bringing AP Cybersecurity and cybersecurity education to middle school and early high school classrooms.

Awesome License: CC BY 4.0


Table of Contents


About

This project organizes resources collected during AP Summer Institute (APSI) training for the AP Cybersecurity course (effective Fall 2026). It is designed for educators — especially those teaching at the middle school or early high school level — who want to:

  • Understand the AP Cybersecurity course framework and exam structure
  • Find interactive, age-appropriate tools for hands-on learning
  • Access curriculum platforms, textbooks, and lab materials
  • Connect with the broader cybersecurity education community

Note: This repository links to publicly available resources. Official AP materials (CED, AP Classroom content) require a College Board educator account. Copyrighted textbooks and platform content are linked but not redistributed here.


Course Framework

AP Cybersecurity is a broad introduction to the field, aligning with a first-year college introductory cybersecurity course. Students learn about threats, vulnerabilities, risk management, and defense-in-depth across physical spaces, networks, devices, and applications.

Course Skills

Skill Category Description
1. Analyze Risk Evaluate risk to organizational assets — identify vulnerabilities, threats, and attack methods
2. Mitigate Risk Implement protective and deterrent security controls to address vulnerabilities
3. Detect Attacks Implement detection systems, monitor, and analyze evidence to classify cyberattacks
4. Collaborate Work with others and monitor AI to accomplish cybersecurity tasks

Course at a Glance

Unit Title Suggested Pacing
1 Introduction to Security ~10 class periods
2 Securing Spaces ~21 class periods
3 Securing Networks ~26 class periods
4 Securing Devices ~23 class periods
5 Securing Applications and Data ~30 class periods

Pacing is based on 45-minute class periods, 5 days/week, for a full academic year. Adjust based on your schedule (block scheduling, etc.).

Exam Structure

Section Type Questions Weight Time
I Multiple-Choice 60 70% 80 minutes
II Free-Response (Device Security Analysis) 1 30% 50 minutes
  • Total exam time: 2 hours 10 minutes
  • MCQ weighting by skill: Analyze Risk (25–40%), Mitigate Risk (25–40%), Detect Attacks (25–40%)
  • FRQ: Students analyze simulated sources (security policies, firewall configs, file-system permissions, log files) about a single digital device to identify security issues, detect attacks, and evaluate security controls.

For the full framework (learning objectives, topic details, sample questions), see:


Official College Board Resources

Resource Description Access
AP Cybersecurity CED Course and Exam Description — the authoritative framework with all units, topics, learning objectives, and sample exam questions Free ( educator account)
AP Classroom Official lesson slide decks, activity zips, topic-level CED PDFs, and progress checks Teacher account required
AP Course Audit Syllabus submission and curricular requirements for AP authorization Teacher account required
AP Cybersecurity on AP Central Official hub for course info, exam dates, and teacher resources Free

Curriculum Platforms & Textbooks

Platform / Textbook Description Link
Paradigm Cyber Adventures Gamified cybersecurity curriculum with labs, CTFs, and course modules aligned to AP Cybersecurity. Includes Instructional Strategies Guide, Resource Guide, and CTF Competition Guide. ap.paradigmcyberadventures.com
Cisco NetAcad — AP Cybersecurity Cisco Networking Academy's instructor-led AP Cybersecurity course with online curriculum. netacad.com/courses/apcyber
Outsmart Cyberthreats NSA/NSF-funded interactive cybersecurity collection from the National Cryptologic Foundation. Includes student book and teacher's guide. cryptologicfoundation.org
CS168 Textbook Free online textbook covering cybersecurity fundamentals. textbook.cs168.io
Fiveable — AP Cybersecurity Free study guides, unit guides, and daily practice for AP Cybersecurity. fiveable.me
APCSP Exam Prep Free practice exams, study guides, and daily practice for AP CSA, CSP, and Cybersecurity. apcsexamprep.com
Teacher Yang's AP Cybersecurity Course Online courseware site developed by Teacher Yang from Wuxi, covering AP Cybersecurity topics with lessons and materials. learn.orzy.top/courses/ap-cybersecurity
eMates Cybersecurity Interactive cybersecurity learning module. eMates
SEED Security Labs 40+ hands-on cybersecurity labs from Syracuse University, covering software, network, web, crypto, and system security. Free lab instructions, VM, PPT slides, and a Chinese textbook. Used by 1000+ schools in 65 countries. seedsecuritylabs.org
《计算机安全导论:深度实践》 Chinese textbook by Prof. Wenliang Du (杜文亮), pairing theory with SEED labs. Published by 高等教育出版社 (2020). handsonsecurity.net/chinese

Interactive Learning Tools

Hands-on tools that make abstract cybersecurity concepts tangible for students.

Cryptography & Hashing

Tool What It Demonstrates Link
Blockchain Hash Demo Real-time visual demo of how cryptographic hashing works (blockchain context). andersbrownworth.com/blockchain/hash
Cryptosystem Demo Simplistic symmetric & asymmetric key encryption — short keys, weak but straightforward. Great for teaching the concept. kerryveenstra.com/cryptosystem.html
KEJSON Symmetric Encryption Interactive symmetric encryption demo. kejson.com/en/encrypt/symmetric
CyberChef The "Cyber Swiss Army Knife" — encode, decode, encrypt, hash, and analyze data. Endlessly useful for classroom demos. cyberchef.org

Web Vulnerabilities

Tool What It Demonstrates Link
Hacksplaining Real-time, interactive demos of common cyberattacks (XSS, SQL injection, CSRF, etc.). Very intuitive and student-friendly. hacksplaining.com/lessons
Google Gruyere Codelab showing how web apps are attacked via XSS, XSRF, and other vulnerabilities. Students exploit a cheesy (literally) vulnerable app. google-gruyere.appspot.com
xkcd: Exploits of a Mom Classic comic about SQL injection — great hook for making the topic fun. xkcd.com/327

Threat Intelligence & Awareness

Tool Description Link
Have I Been Pwned Check if an email/account has appeared in known data breaches. Excellent for teaching real-world impact of breaches. haveibeenpwned.com
CWIS Security — Threat Actors Guide Comprehensive guide to cyber threat actors (APT groups, hacktivists, insiders, etc.). cwsisecurity.com

Game-Based Learning

Tool Description Link
Padlet Arcade Create simple educational games and interactive boards for classroom activities. padlet.com / arcade.padlet.com
Cyber Case Files Interactive cyber case files (GitHub Pages project built from a template). nascar-paul.github.io/cyber-case-files

CTF & Competition Platforms

Capture The Flag (CTF) platforms are the single most effective way to engage middle school students in hands-on cybersecurity. Start with beginner-friendly options.

Platform Level Description Link
picoCTF Beginner Free, beginner-friendly CTF from Carnegie Mellon University. Designed specifically for students. The best starting point. picoctf.org
CyberPatriot Beginner–Intermediate National Youth Cyber Education Program by the U.S. Air Force Association. Team-based competition focusing on securing virtual OS images. uscyberpatriot.org
National Cyber League (NCL) Intermediate Seasonal CTF competitions with individual and team modes. Good for motivated students. nationalcyberleague.org
CyberSkyline Intermediate Skills assessment and competition platform that maps performance to job roles. cyberskyline.com
CyLab Academy Intermediate CMU's online cybersecurity learning and assessment platform. cylabacademy.org

💡 Teaching Tip: For middle school, start with picoCTF — it has a gentle learning curve, built-in hints, and challenges sorted by difficulty. CyberPatriot is excellent for team-based learning and teaches practical OS hardening skills.


SEED Security Labs

SEED Labs (SEcurity EDucation) is a hands-on lab platform developed by Prof. Wenliang Du at Syracuse University, covering 40+ labs across 7 categories. All lab instructions, VM images, and lecture slides are free. Used by 1000+ schools in 65 countries.

💡 For Middle School: SEED labs are college-level, but many are adaptable. Web Security and Cryptography labs are the most accessible entry points. Use the provided PPT slides to teach concepts, then select guided labs for hands-on practice.

Lab Environment

Component Description Link
Lab Instructions All 40+ lab guides (HTML/PDF), organized by category seedsecuritylabs.org/Labs_20.04
Pre-built VM SEED Ubuntu 20.04 VirtualBox image (4 GB), all tools pre-configured seedsecuritylabs.org/labsetup
Apple Silicon (M1/M2) VMware Fusion setup guide for ARM-based Macs GitHub — seed-labs
Cloud VM Run SEED labs on cloud (Google Cloud, AWS, etc.) — minimal 1 CPU / 2 GB RAM Cloud Setup Guide

Labs by Category

Category AP Unit # of Labs Middle School Suitability
Web Security Unit 5 5 ★★★ Most accessible — guided, pre-built vulnerable apps
Cryptography Unit 5 8 ★★★ Concepts teachable via PPT; select labs for practice
Network Security Unit 3 13 ★★ ARP/TCP attacks are engaging; requires networking basics
Software Security Unit 4 9 ★ Requires C/assembly — advanced students only
System Security Unit 4 2 ★ Meltdown/Spectre — very advanced
Blockchain Unit 5 3 ★★ Smart contract attacks; needs blockchain background
Mobile Security Unit 4 2 ⚠ Deprecated — no longer supported
Web Security Labs (Unit 5: Securing Applications and Data) — click to expand
Lab Description PPT Slides Lab Link
Cross-Site Scripting (XSS) Launch XSS attacks on a web app; experiment with countermeasures Slides Lab
Cross-Site Request Forgery (CSRF) Launch CSRF attacks; experiment with countermeasures Slides Lab
SQL Injection Launch SQL injection attacks; experiment with countermeasures Slides Lab
Clickjacking Launch clickjacking attacks on a cupcakes website Slides Lab
Shellshock Exploit the Shellshock vulnerability (discovered 2014) Slides Lab
Cryptography Labs (Unit 5: Securing Applications and Data) — click to expand
Lab Description PPT Slides Lab Link
Secret-Key Encryption Explore secret-key encryption and its applications using OpenSSL Slides Lab
One-Way Hash Function MD5 collision attack & hash length extension attack Slides Lab 1 / Lab 2
Public-Key Encryption (RSA) Implement RSA for encryption, decryption, signing, and verification Slides Lab
PKI (Public Key Infrastructure) Explore PKI, digital signatures, and certificates using OpenSSL Slides Lab
TLS (Transport Layer Security) Write TLS client, server, and proxy in Python Slides Lab
Padding Oracle Attack Conduct padding oracle attack to derive secret messages Lab
Pseudo Random Number Generation Generate cryptographically strong random numbers Lab
Network Security Labs (Unit 3: Securing Networks) — click to expand
Lab Description PPT Slides Lab Link
Packet Sniffing & Spoofing Sniff and spoof packets using Python and C Slides Lab
ARP Cache Poisoning ARP cache poisoning & man-in-the-middle attacks Slides Lab
ICMP Redirect Attack IP-layer attacks, ICMP redirect, and MITM Slides Lab
TCP Attacks Session hijacking, SYN flooding, TCP reset attacks Slides Lab
The Mitnick Attack Classic Mitnick attack — a special case of TCP session hijacking Lab
DNS Attacks (5 labs) Local DNS attack, remote DNS attack, DNS rebinding, DNS infrastructure, DNSSEC Slides DNS Labs
Firewall Exploration Build a packet-filter firewall; experiment with Linux firewall Slides Lab
Firewall Evasion Bypass firewalls using port forwarding and VPN Slides Lab
VPN Tunneling Build a simple VPN using TUN/TAP interface Slides Lab
BGP Exploration & Attack Configure BGP, launch BGP attacks using Internet simulator Slides Lab
Morris Worm Write a simple Internet worm and test it in an emulator Lab
Heartbleed Attack Steal secrets from a remote server via Heartbleed vulnerability Slides Lab
Software Security Labs (Unit 4: Securing Devices) — click to expand
Lab Description PPT Slides Lab Link
Environment Variable & Set-UID Attacks on privileged Set-UID root programs; risks of environment variables Slides Lab
Buffer Overflow (Set-UID) Exploit buffer-overflow in privileged Set-UID programs Slides Lab
Buffer Overflow (Server) Exploit buffer-overflow in a server program Slides Lab
Return-to-Libc Attack Defeat non-executable stack countermeasure using return-to-libc technique Slides Lab
Shellcode Development Write shellcode from scratch Slides Lab
Format String Vulnerability Exploit format string vulnerability to crash, steal info, and inject code Slides Lab
Race Condition Vulnerability Exploit race condition in privileged programs Slides Lab
Dirty COW Attack Exploit Linux kernel Dirty COW vulnerability to gain root Slides Lab
System Security Labs (Unit 4: Securing Devices) — click to expand
Lab Description PPT Slides Lab Link
Meltdown Attack Exploit Meltdown vulnerability in Intel CPUs Slides Lab
Spectre Attack Exploit Spectre vulnerability in Intel CPUs Slides Lab
Blockchain Security Labs (Unit 5: Securing Applications and Data) — click to expand
Lab Description Lab Link
Blockchain Exploration Learn blockchain basics: accounts, wallets, transactions, blocks Lab
Smart Contract Learn smart contract development, deployment, and invocation Lab
Smart Contract Reentrancy Attack Exploit reentrancy vulnerability in smart contracts Lab

Teaching Resources

Resource Description Link
Lecture Slides (PPT) Complete PPT slide decks for all SEED topics, organized by category handsonsecurity.net/resources
Video Courses (Udemy) Full video lectures by Prof. Du — Computer Security, Network Security, Web Security, Cryptography Udemy — Computer Security
Chinese Textbook 《计算机安全导论:深度实践》by 杜文亮 — pairs theory with SEED labs. 高等教育出版社 (2020). ISBN: 9787040538823 handsonsecurity.net/chinese
SEED GitHub Source code, VM build scripts, and lab setup documentation github.com/seed-labs

For the full lab listing with AP unit mapping and middle school adaptation notes, see:


Community & Teacher Notes

Shared notes and resources from fellow AP Cybersecurity educators.

Resource Description Link
Robert's Cybersecurity Padlet Unit-by-unit class notes and attachments from APSI training, organized by AP unit (Units 1–4). Shared by Robert from HQIS. padlet.com/robertvischer/cybersecurity

💡 Have your own notes to share? Open an issue or pull request — we'd love to add your resources here too!


Resources by Unit

Each unit below includes the official topic breakdown plus curated resources aligned to those topics.

Unit 1: Introduction to Security

~10 class periods | Personal security in everyday life

Topic Title
1.1 Understanding Social Engineering
1.2 Suspicious Website Logins
1.3 Best Practices for Public Networks
1.4 AI-Based Cybersecurity Attacks
1.5 Leveraging AI in Cyber Defense

Key Resources:


Unit 2: Securing Spaces

~21 class periods | Physical security in organizational contexts

Topic Title
2.1 Cyber Foundations
2.2 Physical Vulnerabilities and Attacks
2.3 Protecting Physical Spaces
2.4 Detecting Physical Attacks

Key Resources:


Unit 3: Securing Networks

~26 class periods | Network vulnerabilities, protections, and attack detection

Topic Title
3.1 Network Vulnerabilities and Attacks
3.2 Protecting Networks: Managerial Controls and Wireless Security
3.3 Protecting Networks: Segmentation
3.4 Protecting Networks: Firewalls
3.5 Detecting Network Attacks

Key Resources:


Unit 4: Securing Devices

~23 class periods | Device vulnerabilities, authentication, and protection

Topic Title
4.1 Device Vulnerabilities and Attacks
4.2 Authentication
4.3 Protecting Devices
4.4 Detecting Attacks on Devices

Key Resources:

  • 🔧 Have I Been Pwned — password strength & breach checking
  • 🔬 SEED Software Security Labs — 9 labs: Set-UID, buffer overflow, format string, race condition, Dirty COW (★ advanced, requires C/assembly)
  • 💡 The FRQ (Device Security Analysis) is directly tied to this unit — practice analyzing device configs, permissions, and logs. See Exam Preparation.

Unit 5: Securing Applications and Data

~30 class periods | The largest unit — application security, cryptography, and data protection

Topic Title
5.1 Application and Data Vulnerabilities and Attacks
5.2 Protecting Applications and Data: Managerial Controls and Access Controls
5.3 Protecting Stored Data with Cryptography
5.4 Asymmetric Cryptography
5.5 Protecting Applications
5.6 Detecting Attacks on Data and Applications

Key Resources:


Podcasts, Videos & Media

Resource Description Link
Darknet Diaries True stories from the dark side of the internet — hacks, breaches, and cybercrime. Engaging narrative format. Preview for age-appropriateness before classroom use. darknetdiaries.com
YouTube — Cybersecurity Videos Various educational videos shared during APSI training. YouTube link
xkcd Web comics that make cybersecurity concepts memorable (SQL injection, etc.). xkcd.com

Professional Development

Resource Description Link
AP Summer Institute (APSI) Official College Board professional development for AP Cybersecurity teachers. AP Central — PD
AP Classroom Teacher Guide Guide to using AP Classroom effectively (shared by fellow educator Regina). AP Classroom Guide
UC San Diego Extended Studies Cybersecurity education programs. extendstudies.ucsd.edu
WPI Career Training Worcester Polytechnic Institute cybersecurity career training. careertraining.wpi.edu
Regina's AP Cybersecurity Resource Folder Teaching resources shared by a fellow AP educator. OneDrive Folder

Exam Preparation

Resource Description
AP Cybersecurity CED Contains sample MCQ and FRQ questions with scoring guidelines
APCSP Exam Prep apcsexamprep.com — free practice exams and study guides
Fiveable fiveable.me — unit study guides and daily practice
Practice Exams (SG/TB) Student Guide & Test Bank practice exams (MCQ + FRQ)
FRQ Focus: Device Security Analysis Practice analyzing: security policies, firewall configurations, file-system permissions, and log files. Students must cite evidence and explain reasoning.

FRQ Task Verbs

Verb Meaning
Identify Provide information about cybersecurity concepts or evidence from given sources
Explain Provide reasons that support a solution, using specific evidence
Describe Provide information about a cybersecurity process or outcome
Determine Provide a specific result by applying appropriate criteria or reasoning
Write Express a proper command that has the indicated effect

Community & Forums

Resource Description Link
AP Cybersecurity Teacher Community College Board's official teacher community for sharing resources and asking questions. AP Community
CyberPatriot Community Active community of cybersecurity educators and competitors. uscyberpatriot.org
LearnOrzy Online course platform with cybersecurity courses. learn.orzy.top/courses

Contributing

Contributions are welcome! Please read the Contributing Guidelines before submitting a pull request.

We welcome:

  • New interactive tools or platforms
  • Lesson plans and classroom activities
  • Unit-specific resource recommendations
  • Translations or adaptations for different age groups
  • Corrections or updates to existing resources

License

This work is licensed under a Creative Commons Attribution 4.0 International License.

Linked external resources retain their respective licenses. Official AP materials are © College Board and are referenced, not redistributed.

About

A curated collection of teaching resources, tools, and references for educators bringing AP Cybersecurity and cybersecurity education to middle school and early high school classrooms.

Topics

Resources

Code of conduct

Contributing

Stars

10 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors