Sunday, October 23, 2022
Network+ 007 - 1.6 Network Services
1.6 Network Services
DHCP (Dynamic Host Configuration Protocol) - Automated IP configuration for network devices.
Scope - IP address range used and reserved IP addresses not to be used.
Exclusion Ranges - IP address range within the scope not to use.
Reservation - IP address reserved to provide as a static IP address.
Dynamic Assignment - Automatic IP address assigning.
Static Assignment - Non-changing IP address, typically to provide to a specific device.
Lease Time - The duration an IP address is assigned for.
Scope Options - Used to set additional network info when a host is assigned an IP address.
Available Leases - IP addresses available to be assigned.
DHCP Relay/IP Helper - Router that converts a device’s DHCP broadcast into a unicast to forward it to a DHCP server.
UDP Forwarding - Used when you are limited to the amount of destination you can communicate to, allows you to forward data to a UDP replicator which then can send to any number of destinations.
DNS (Domain Name System) - Protocol that translates IP addresses/domain names.
Record Types
Address (A vs AAAA) - Used to resolve a domain to IPv4 and IPv6 addresses respectively.
Canonical Name (CNAME) - Maps an alias name to the true domain name.
Mail Exchange (MX) - Indicates how email should be routed based on SMTP
Start of Authority (SOA) - Administrative DNS records for the DNS zone at the cutover point from the parent DNS zone.
Pointer (PTR) - Resolves an IP address to a domain. (reverse DNS lookup)
Text (TXT) - Originally made for human-readable DNS notes, can also be used to filter out spam email and to verify domain ownership.
Service (SRV) - Indicates a host and port for a given service. (VoIP, IM, etc)
Name Server (NS) - Indicates which DNS server is authoritative for a given domain.
Global Hierarchy - Domain Name Space hierarchy
Root DNS Servers - Top level domain in the Domain Name Space hierarchy.
Internal vs. External - IP addresses and Domains that reside within a network (internal) opposed to outside the network (external sites).
Zone Transfers - Process of copying the contents of the zone file on a primary DNS server to a secondary DNS server
Authoritative Name Servers - Contains data to provide in response to questions about domains in its zone.
Time To Live (TTL) - The amount of hops a packet will make before getting discarded.
DNS Caching - Temporarily stored data for previously looked up DNS data.
Reverse DNS/Reverse Lookup/Forward Lookup - Reverse translating a domain from an IP address.
Recursive Lookup - Source domain data from several other DNS servers.
Iterative Lookup - Source domain data directly from the DNS server involved.
NTP - Network Time Protocol, clock synchronization for network devices.
Stratum - Degrees away from “real time” (Atomic clock:0, highly accurate)
Clients - Connects to the network time server for syncing, stratum 2.
Servers - Network Time Server provides time data to network devices, stratum 1.
Sunday, September 25, 2022
Wednesday, September 14, 2022
SY0-601 Exam Simulation - 1st Attempt Results
SY0-601 Exam Simulation
Simulation Date: September 14, 2022
Results:
Score: 61.11%
Points Scored / Total: 55 / 90
Number of Questions: 90
Total Time: 01:12:59
Notes: I felt good about the content I have studied and was able to answer those questions quickly, but I also felt the opposite when I came across questions for content I have not reached yet. I did not prep for this practice test with any prior review the day of the simulated exam.
Saturday, August 27, 2022
PowerShell 007 - Registry Permissions
Registry Permissions
Example:
$key = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("SOFTWARE\Wow6432Node",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::ChangePermissions)
$acl = $key.GetAccessControl()
$rule = New-Object System.Security.AccessControl.RegistryAccessRule (".\USERS","FullControl",@("ObjectInherit","ContainerInherit"),"None","Allow")
$acl.SetAccessRule($rule)
$key.SetAccessControl($acl)
This will take the registry key “SOFTWARE\Wow6432Node” and give the “\USERS” (local users) group permissions to have “FullControl” (Read/Write access).
Breakdown:
$key =
$key is the variable object the code will be set to.
[Microsoft.Win32.Registry]::
Indicates this will involve the registry, the :: operator accesses members (properties) of a namespace (hierarchy structure).
LocalMachine.OpenSubKey("SOFTWARE\Wow6432Node",
Targets a registry item, path for registry key. *Note: The ( is left open.
[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,
Targets the Microsoft.Win32 namespace, RegistryKeyPermissionCheck property, and accesses the ReadWriteSubTree member. This indicates the code should save over what is there with what is provided.
[System.Security.AccessControl.RegistryRights]::ChangePermissions)
Targets the System.Security.AccessControl namespace (hierarchy), RegistryRights property, ChangePermissions member. *) closes the parenthesis left open from before. This is what the code will replace within this targeted member.
So far the code is targeting a registry item and saving over a targeted member (property under the namespace hierarchy) with provided info.
$acl = $key.GetAccessControl()
The next line sets $acl as a variable object for the above (reg path/overwrite/provided info) targeting its ACL (Windows Access Control List).
$rule = New-Object System.Security.AccessControl.RegistryAccessRule (
Sets a variable object, $rule, as something that target the System.Security.AccessControl namepsace, RegistryAccessRule property.
".\USERS","FullControl",
Give the Users group full control
@("ObjectInherit","ContainerInherit"),"None"
Allows the permissions to be inherited by child objects but not propagated .
,"Allow")
Specifies if access rights are allowed or denied.
$acl.SetAccessRule($rule)
Takes the variable $acl, targets the ACL (Access Control List) properties and sets them to the variable $rule above.
$key.SetAccessControl($acl)
This takes the target $key and applies $acl permissions that had been configured with $rule.
Results:
Targeted registry file:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node
Is updated with permissions below.
IdentityReference: “.\USERS” (local users)
RegistryRights: "FullControl" (get full control)
InheritanceFlags: "ObjectInherit","ContainerInherit" (Inherited to all child objects)
PropagationFlags: “None” (Permissions are not to be propagated to those child objects)
AccessControlType: “Allow” (Access rights are allowed)
Thursday, August 25, 2022
PowerShell 006 - Send Keystrokes
Send Keystrokes
Example:
$wshell = New-Object -ComObject wscript.shell;
$wshell.SendKeys('text')
$wshell.SendKeys(~)
This will type out “text” followed by an Enter keystroke
Breakdown:
$wshell = New-Object -ComObject wscript.shell;
Creates a COM Object with a wscript command and assigns it to the variable $wshell
$wshell.SendKeys([KEYSTROKES])
The Object runs the SendKeys command for what is between (). Use single quotes for ‘text’ or one of the codes for non-displayed keys.
Common Non-Displayed Keys
Key | Code |
BACKSPACE | {BACKSPACE}, {BS}, or {BKSP} |
ENTER | {ENTER} or ~ |
ESC | {ESC} |
DEL or DELETE | {DELETE} or {DEL} |
PRINT SCREEN | {PRTSC} (reserved for future use) |
TAB | {TAB} |
You can combo these with SHIFT, CTRL, and/or ALT by starting with the keys
Key | Code |
SHIFT | + |
CTRL | ^ |
ALT | % |
Tuesday, July 26, 2022
Security+ 008 - 1.8 Techniques used in Pentesting
1.8 Techniques used in Pentesting
Penetration Testing
Known Environment - Tester is familiar with environment
Unknown Environment - Tester knows nothing about the environment
Partially Known Environment - Partially known and unknown, tester goes with info they have
Rules of Engagement - Agreed systems tester can target and what is to be tested
Lateral Movement - Moving from device to device within a network.
Privilege Escalation - Administrator access
Persistence - On-going access
Cleanup - Reverting systems back to original setting from before the test
Bug Bounty - System owner offers a reward for finding and reporting bugs in their system.
Pivoting - Using a system as a jump off point or a relay to access other parts of the network.
Passive and Active Reconnaissance
Drones - Surveillance
War Flying - WiFi enabled drone that can pick up networks and collect data about them.
War Driving - Similar to War Flying, but done with a car driving around instead of a flying drone.
Footprinting - Mapping the network, packet captures could see this happening.
OSINT - Open-source/public intel
Exercise Types
Red Team - Attackers
Blue Team - Defenders
White Team - Oversees blue/red team activity on a network
Purple Team - A team that consists of both offense and defense team members
Monday, July 25, 2022
Security+ 007 - 1.7 Techniques used in Security Assessments
1.0 Attacks, Threats, and Vulnerabilities
1.7 Techniques used in Security Assessments
Threat Hunting - Detecting and locating threats/vulnerabilities
Intelligence Fusion - Aggregating raw data and logs into a database
Threat Feeds - Information alerts, often 3rd party provided
Advisories and Bulletins - Security reports
Maneuver - Deployment of security tools and automated deployment
Vulnerability Scans
False Positives - Flagged event that doesn’t pose a threat
False Negatives - Vulnerability is on a device, but does not get flagged/detected
Log Reviews - Pull data sourced from device logs
Credentialed - Scan as if you have authorized account access
Non-Credentialed - Scan as if you have no access
Intrusive - Tries to use found exploits
Non-Intrusive - Only looks for exploits, but does not use them
Application - Scans software (anti-virus)
Web Application - Scans for XSS (cross-site scripting), sql/code injections
Network - Scans network for open ports and other network vulnerabilities
Common Vulnerabilities and Exposures (CVE) - Reference for public knowledge on known exploits.
Common Vulnerability Scoring System (CVSS) - Scoring system to indicate severity of known exploits.
Configuration Review - Scan device or software for misconfigurations
Syslog/Security Info and Event Management (SIEM) - Software, central hub for security info
Review Reports - Generate reports based on diverse data
Packet Capture - Monitor network traffic
Data Inputs - Feed raw data into SIEM (authentications, VPN connections, firewall logs, denied network traffic)
User Behavior Analysis - Set a baseline and use it as a risk-trigger
Security Monitoring - Constant monitoring of real-time info flow, track stats, send alerts when risk is found, automated ticket generation
Security Operations Center (SOC) - Centralized location to do security monitoring.
Log Aggregation - Database all logs
Log Collectors - Retrieves/accepts and stores all logs.
Security Orchestration, Automation and Response (SOAR) - Automate tedious and routine tasks, connecting multiple tools together, auto-responsive to maintain real-time security.
Sunday, July 24, 2022
Security+ 006 - 1.6 Security Concerns Associated with Vulnerabilities
1.6 Security Concerns Associated with Vulnerabilities
Cloud-Based Vulnerabilities - Vulnerabilities for a cloud environment. More available to target, data breach/loss, potential privacy issues
On-Premises Vulnerabilities - In house data center, requires regular maintenance and additional fault resilience, more susceptible to physical-based events (nature, power outage)
Zero-Day Vulnerabilities - A previously unknown vulnerability/exploit
Weak Configurations
Open Permissions - No authentication requirements.
Unsecure Root Accounts - No authentication admin.
Errors - Errors should not include too much details to give an attacker extra info on a network/system, just need to be specific enough to say where to look.
Weak Encryption - Obsolete encryption methods, encryption that can easily be decrypted.
Unsecure Protocols - Unencrypted protocols
Default Settings - OEM/Factory set (public) credentials
Open Ports and Services - Manage Ports and traffic flow with a Firewall, open ports are open to communication and can be targeted.
Third-Party Risks
Vendor Management - Managing and monitoring vendor risk and vulnerabilities
System Integration - 3rd party device or access to inside the network
Lack of Vendor Support - Vendor doesn’t/slow to patch vulnerabilities.
Supply Chain - Vulnerabilities in the sources of what builds your capabilities.
Outsourced Code Development - 3rd party developers, isolate from the production environment.
Data Storage - On-prem or in cloud, needs proper protocols in place to secure and set access controls.
Improper or Weak Patch Management
Firmware - Commonly not patched often, can lead to devices being vulnerable.
Operating System (OS) - Core software running a device vulnerabilities
Applications - Software exploits
Legacy Platforms - No longer supported, retired software/hardware still in use
Impacts
Data Loss - Hardware failure, malicious removal, potentially can ruin a business.
Data Breaches - Access to data, can lead to extortion, potential loss of profits
Data Exfiltration - Malicious data transfer, unauthorized, can lead to ransomware/extortion
Identity Theft - Can lead to financial damages or unintended authorization
Financial - Interruption of business, loss of profits, unauthorized money transfers
Reputation - Loss of trust in the business
Availability Loss - Denial of service, loss of profits
Friday, July 22, 2022
Security+ 005 - 1.5 Threat Actors, Vectors, and Intelligence Sources
1.5 Threat Actors, Vectors, and Intelligence Sources
Actors and Threats - Entity responsible for an event that has an impact on the safety of another entity.
Advanced Persistent Threat (APT) - Stays in your network until removed, can act as reconnaissance for a larger attack.
Insider Threats - Potential employee, contractor, or vendor is a threat actor.
State Actors - Nation state, governmental threat actor.
Hacktivists - Threat actors with a goal or (political) purpose as motive.
Script Kiddies - Outside threat actor who uses many simple scripts until they find one that lets them into a network.
Criminal Syndicates - Professional organized groups of threat actors.
Hackers - Broadly, a person who is good with technology
Authorized - Hired to find network weaknesses and vulnerabilities, has permission.
Unauthorized - Malicious, looking to cause harm.
Semi-authorized - Researcher-type, looks for vulnerabilities and network access without direct permission, but does not act on them if found.
Shadow IT - Those within an organization that fulfill their own IT needs outside the purview of the property IT processes and procedures.
Competitors - Threat actors from an outside organization that you share a market with.
Attributes of Actors
Internal - Threat from within the organization.
External - Threat from outside of the organization.
Level of Sophistication/Capacity - Complexity/severity potential of the attack.
Resources/Funding - Sophisticated attacks often require higher costs.
Intent/Motivation - Goal of the attack.
Vectors
Direct Access - Physical Access
Wireless - Through a shared wireless network or rogue access point
Email - Malicious links/phishing
Supply Chain - Trusted 3rd party is compromised
Social Media - Malicious links and scams/phishing, unintended employee over-sharing
Removable Media - Auto-run code from hot-swappable media (USB drives, CDs, disks)
Cloud - Manipulated or malicious cloud-based applications
Threat Intelligence Sources - Places to get data
Open-Source Intelligence (OSINT) - Public data
Closed/Proprietary - Payed for data
Vulnerability Databases - Compiled information from multiple sources on vulnerabilities
Public/Private Info Sharing Centers - Organizations that collect and disseminate data
Dark Web - Black market data
Indicators of Compromise - DNS queries/network traffic, location data, Identify attack and reverse engineer
Automated Indicator Sharing (AIS) - Automated process to share security data between organizations.
Structured Threat Information eXpression (STIX) - Standard format for shared security data, contains info such as motive, ability, capability, and response info.
Trusted Automated eXchange of Intelligence Info (TAXII) - Security Data transfer protocol
Predictive Analysis - Using real-time data to try to identify compromise.
Threat Maps - Visual representation of where the attacks may be from and going.
File/Code Repositories - Databases of code shared between developers.
Research Sources
Vendor Websites - Vendor discovered/published data
Vulnerability Feeds - Government and private org provided vulnerability databases
Conferences - Convention, you can learn new research from presenters
Academic Journals - Peer-reviewed published research
Request For Comments (RFC) - Published by ISOC, often written by engineers on known issues/standards, best practices, and experimental and historical practices
Local Industry Groups - Geographically local meet-up
Social media - Groups often post to social media, keyword monitoring, public conversations
Threat Feeds - Automated threat feed sourced from multiple organizations
Adversary Tactics, Techniques, and Procedures (TTP) - What are threat actors doing to get access, what is their typical goal when in a network, where do they spend most of their time, which attack vectors do they like to use.
Sunday, July 17, 2022
AZ-500 003 - Deploy Azure AD Identity Protection
AZ-500: Microsoft Azure Security Technologies
Manage Identity and Access: Deploy Azure AD Identity Protection
Deploy and configure Identity Protection
Configure MFA for users, groups, and applications
Create Conditional Access policies to ensure your security
Create and follow an access review process
Azure AD Identity Protection - A tool that enables an org to automate the detection and remediation of ID-based risks, and assists with data logs in the portal or with a 3rd party utility.
ID Protection Default Policies
Azure MFA Registration Policy, Sign-in Risk Policy, Custom Conditional Access Policy
User Risk Policy - Identifies and responds to user accounts that may have compromised credentials. Can prompt the user to create a new password.
Sign-in Risk Policy - Identifies and responds to suspicious sign-in attempts. Can prompt the user to provide additional forms of verification using Azure AD Multi-Factor Authentication.
MFA Registration Policy - Makes sure users are registered for Azure AD Multi-Factor Authentication. If a sign-in risk policy prompts for MFA, the user must already be registered for Azure AD Multi-Factor Authentication.
Example Risk Detection Triggers:
Users with leaked credentials.
Sign-ins from anonymous IP addresses.
Impossible travel to atypical locations.
Sign-ins from infected devices.
Sign-ins from IP addresses with suspicious activity.
User Risk - User risk is a calculation of probability that an ID has been compromised.
User Risk Policy
Risky Users Report - Contains data for which users are at risk for up to the past 30 days, remediated risk, or had risk dismissed. Also has details about detection types, a history of all risky sign-ins, Conditional Access policies applied, MFA details, and device/app/location info.
Admin can set a response to a given condition/trigger, responses include:
Force a password reset
Confirm user compromised
Dismiss user risk
Block or Allow the sign-in
Investigate further using Azure ATP (Advanced Threat Protection)
Example Condition Triggers:
Location
Client Apps - Browser-based apps, mobile apps, and desktop clients
Risky Sign-ins
Azure Active Directory Multi-Factor Authentication (MFA) - Provides additional security by requiring a second form of authentication.
Authentication methods include:
Something you know (password/PIN)
Something you have (generated code, a specific device)
Something you are (biometrics)
MFA options
MFA Settings
Account Lockout - Set number of attempts allowed before lockout, time until lockout counter resets, time until account is auto unlocked.
Block/Unblock Users - Blacklist/whitelist user accounts
Fraud Alert - Configure so users can report fraud attempts, set auto block users when fraud is reported, fraud blocks account for 90 days or until released by an admin, and admin can review sign-in logs.
Notifications - Configure email notifications for fraud reports (typically sent to an ID admin).
OATH Tokens - Azure AD supports OATH-TOTP SHA-1 (keychain) tokens that refresh codes every 30 or 60 seconds.
Trusted IPs - Feature to allow federated users or IP address ranges to bypass MFA (only for inside of the company intranet)
Enable MFA - Azure AD>User Properties>Multi-Factor Authentication
All users start out Disabled. When you enroll users in per-user Azure AD Multi-Factor Authentication, their state changes to Enabled. When enabled users sign in and complete the registration process, their state changes to Enforced. Administrators may move users between states, including from Enforced to Enabled or Disabled.
Azure AD Conditional Access - Tool used by AAD (Azure AD) to bring signals together to make decisions and enforce org policy. Enables an identity driven control plane (control of traffic).
Identity as a Service (IDaaS)
Conditional Access
Conditions: user/group, cloud application, device state, location (IP range), client application, and sign-in risk
Azure AD Access Reviews - Manage group membership, access to enterprise apps, and role assignments. User’s access can be reviewed on a regular basis.
When to access review:
Too many users in privileged roles
When automation is infeasible
When a new group is used for a new purpose
Business critical data access
To maintain a policy’s exception list
Ask group owners to confirm they still need guests in their groups
Have reviews recur periodically