This page is still under construction.

In the meantime, you can still peruse what is currently available while additional content is populated here.


Vision

nss In August of 2020, I set out to build a simple website to host Capture-The-Flag challenges designed by some community members that I had met on a Discord server called The White Circle. I chose a very suggestive domain name purley for shock value to intentionally capture the attention of hackers. I knew that by building something like this, it needed to be resilient to a wide range of attack vectors. By September of the same year, after several rounds of testing, the domain was still standing and the vision grew into a mission for a registered 501(c)3 Nonprofit organization called NoShitSecurity.

Mission

The goal of NoShitSecurity, or NSS, was to foster community interaction, thus it was initially used to host the challenges and content created by community members in a very tight-knit group; and to this day, that content is still available if you know where to look. But there was always a deeper purpose for the mission: the cybersecurity skills gap. What I saw were people complaining about a lack of skilled candidates while standing in front of the door and demanding coin for entry, so I set out to challenge the top cybersecurity training firms in the industry to give their training away for free. Because if you really cared about solving a problem, you would start with open doors.

Core concepts

  1. Start where you are.
  2. What can you do with what you have?
  3. Use what you have to move forward any way you can.
  4. Consider the perspective opposite from you own, and search for answers there.
  5. Dig deeper, dinosaur.
  6. There is always a key.
  7. Build it like you mean breach.*
*This was later updated to reflect the STONE and BREACH frameworks developed by NSS.
Note
Click here for a comprehensive breakdown of each concept and how it was used to teach cybersecurity lessons.

Triassic Trials

I developed a series of CTFs that started easy and gradually got more difficult, with the goal being to help newcomers better understand business concepts and technologies. As the players progressed, they were exposed to designs that embodied the principles found in the Core Concepts that drive the NSS mission. The goal was to create a self-governing community of infosec pros that knew how to architect in Azure, and build that out one team at a time. This became a working a proof of concept called the Triassic Trials.

Beginning in August 2020, I began dropping these CTF challenges unnanounced into The White Circle Discord server. A small group of people responded more than others to the CTFs. The members of the community that responded positively (and also seemed to enjoy the games) began to build trust with each other. Those whom bested the first active CTFs got a shot at being a Keyholder, which put login credentials for a fully configured enterprise Azure tenant directly into their hands as an expression of faith towards their responsibility.

These Keyholders were the first generation of students learning Azure security architecture from NSS. Listed below is the Keyholder's Agenda, and the hands-on skills they developed together.

Note
Click here for a historical look at the first version of the Keyolder's Agenda before we gained a large span of enterprise partnerships.

Jurassic Jungle

jurassicjungle® The same agenda that was first developed during the Triassic Trials pilot project became the foundation for the ASE Bootcamp provided to Keyholders during the Jurassic Jungle® Information Security Internship Program. This apprentice-style internship granted 6 months of full access to several leading enterprise platforms to deliver industry-recognized training and certification vouchers free of charge to NSS students.

ASE Bootcamp

Over the years, the NSS Azure Security Engineering bootcamp evolved into a 6-month series of assignments that followed an established roadmap and gave students the opportunity to demonstrate what they had learned with projects and milestones that yielded tangible proofs in the form of industry-recognized cybersecurity certifications, Credly badges, and other forms of documentation that could be used to satisfy the experience requirements for ISC2 CISSP certification. Students would build a complete tenant and then defend it for 6 months.

Keyholder's Agenda

  1. Any student who completed a CTF on the NSS page was eligible to be an NSS Hopeful.
  2. Students who completed a live CTF in the alloted time frame were eligible to be Keyholders.
  3. Keyholders were immediately granted an NSS credential and full access to our partner platforms.
  4. Keyholders were then assigned to a 50-hour Azure Security Engineering Bootcamp that I hosted myself.
  5. During the ASE bootcamp, students built a feature-complete Azure Cloud tenant from the ground up.
  6. Students then spent the next 30 days producing a perfect Secure Score and building SOAR systems into their tenant.
  7. When they reached a perfect Secure Score with SOAR and BCDR systems in place, they earned a certificate of completion.
  8. Students then intentionally "broke" or misconfigured aspects of the tenant and workloads. (Build it like you mean breach!)
  9. Students were required to design and build their own CTF-style challenge that taught cybersecurity lessons or concepts.
  10. Students would then launch their CTF as an official NSS event and defend their infra while other hackers tried to break in.

Results

The success of the Triassic Trials pilot project was enough to warrant the kind of invesment required to turn the idea into a working program. When money was no longer a barrier and the first roadmap was completed, we launched the Sincera's Pandora Discord server to provide a common area for Hopefuls and Keyholders to gather and collaborate. The Discord server shared the same name as the NSS website, and was heavily integrated across all aspects of the company, and is discussed in further detail on the Pandora page of this website. Our early seasons had a rough start, but Seasons 2 and 3 were very successful. We had thousands of applicants, but only three students completed the program. The rest either gave up and never made it in, or washed out before completing the program and were kicked from the server.

We issued many Credly badges to many Hopefuls, because you could earn a badge without being a Keyholder, which was a much more difficult achievement to earn. Due to the length of time required to produce a quality candidate with proper training under the legal definition of an internship, we could accommodate a maximum of 4 candidates in a single 6-month season. The NSS project in itself had a scheduled extinction date of September 16, 2025. Because I had previously established an "extinction date" or end of life when the project first began, I held true to that promise and helped as many students as were willing to put in the effort to succeed. In September of 2025 we closed our doors indefinitely, retaining all of our intellectual property, trademarks, and brand assets under the ownership of Sincera Labs.

Everything that was built remains preserved on the Sincera's Pandora website and Discord server. All of our partnerships are intact and now serve as a historical marker and a means to market the success of the NSS training initiative, holding true to the promise first made on the NSS About page in September of 2020, mere days after we had completed the Triassic Trials project. Of the three students that completed our program, and in concert with the point being to help you find a job, one got a job at Amazon as Offensive Security Engineer, and another now works as a Software Engineer II at Dell. The third is still searching for his foothold, and helps maintain the remaining NSS infrastructure.

What I've built here will remain as an example of what you can do if you try. Be something. Stand for something real. Something good. The rest will just fall into place naturally.

Shane
Note
Click here to view more information about the Jurassic Jungle® Information Security Internship Program.