Sunday, October 23, 2022

Network+ 007 - 1.6 Network Services

1.0 Networking Fundamentals

1.6 Network Services


DHCP (Dynamic Host Configuration Protocol) - Automated IP configuration for network devices.

Scope - IP address range used and reserved IP addresses not to be used.

Exclusion Ranges - IP address range within the scope not to use.

Reservation - IP address reserved to provide as a static IP address.

Dynamic Assignment
- Automatic IP address assigning.

Static Assignment
- Non-changing IP address, typically to provide to a specific device.

Lease Time
- The duration an IP address is assigned for.

Scope Options - Used to set additional network info when a host is assigned an IP address.

Available Leases - IP addresses available to be assigned.

DHCP Relay/IP Helper
- Router that converts a device’s DHCP broadcast into a unicast to forward it to a DHCP server.

UDP Forwarding - Used when you are limited to the amount of destination you can communicate to, allows you to forward data to a UDP replicator which then can send to any number of destinations.


DNS (Domain Name System) - Protocol that translates IP addresses/domain names.

Record Types
        Address (A vs AAAA) - Used to resolve a domain to IPv4 and IPv6 addresses respectively.

        Canonical Name (CNAME) - Maps an alias name to the true domain name.

Mail Exchange (MX) - Indicates how email should be routed based on SMTP

Start of Authority (SOA) - Administrative DNS records for the DNS zone at the cutover point from the parent DNS zone.

Pointer (PTR) - Resolves an IP address to a domain. (reverse DNS lookup)

Text (TXT) - Originally made for human-readable DNS notes, can also be used to filter out spam email and to verify domain ownership.

Service (SRV) - Indicates a host and port for a given service. (VoIP, IM, etc)

Name Server (NS) - Indicates which DNS server is authoritative for a given domain.

Global Hierarchy
- Domain Name Space hierarchy

Root DNS Servers
- Top level domain in the Domain Name Space hierarchy.

Internal vs. External - IP addresses and Domains that reside within a network (internal) opposed to outside the network (external sites).

Zone Transfers - Process of copying the contents of the zone file on a primary DNS server to a secondary DNS server

Authoritative Name Servers - Contains data to provide in response to questions about domains in its zone.

Time To Live (TTL) - The amount of hops a packet will make before getting discarded.

DNS Caching - Temporarily stored data for previously looked up DNS data.

Reverse DNS/Reverse Lookup/Forward Lookup - Reverse translating a domain from an IP address.

Recursive Lookup - Source domain data from several other DNS servers.

Iterative Lookup - Source domain data directly from the DNS server involved.

NTP - Network Time Protocol, clock synchronization for network devices.

        Stratum - Degrees away from “real time” (Atomic clock:0, highly accurate)

        Clients - Connects to the network time server for syncing, stratum 2.

        Servers - Network Time Server provides time data to network devices, stratum 1.

Wednesday, September 14, 2022

SY0-601 Exam Simulation - 1st Attempt Results

SY0-601 Exam Simulation

Simulation Date: September 14, 2022


Results:
Score: 61.11%

Points Scored / Total: 55 / 90

Number of Questions: 90

Total Time: 01:12:59

 

Notes: I felt good about the content I have studied and was able to answer those questions quickly, but I also felt the opposite when I came across questions for content I have not reached yet. I did not prep for this practice test with any prior review the day of the simulated exam.

Saturday, August 27, 2022

PowerShell 007 - Registry Permissions

Registry Permissions

        Example:

                $key = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("SOFTWARE\Wow6432Node",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::ChangePermissions)
                $acl = $key.GetAccessControl()
                $rule = New-Object System.Security.AccessControl.RegistryAccessRule (".\USERS","FullControl",@("ObjectInherit","ContainerInherit"),"None","Allow")
                $acl.SetAccessRule($rule)
                $key.SetAccessControl($acl)

This will take the registry key “SOFTWARE\Wow6432Node” and give the “\USERS” (local users) group permissions to have “FullControl” (Read/Write access).


Breakdown:

                $key =

        $key is the variable object the code will be set to.


                [Microsoft.Win32.Registry]::

        Indicates this will involve the registry, the :: operator accesses members (properties) of a namespace (hierarchy structure).


                LocalMachine.OpenSubKey("SOFTWARE\Wow6432Node",

        Targets a registry item, path for registry key. *Note: The ( is left open.


                [Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,

        Targets the Microsoft.Win32 namespace, RegistryKeyPermissionCheck property, and accesses the ReadWriteSubTree member. This indicates the code should save over what is there with what is provided.


                [System.Security.AccessControl.RegistryRights]::ChangePermissions)

        Targets the System.Security.AccessControl namespace (hierarchy), RegistryRights property, ChangePermissions member. *) closes the parenthesis left open from before. This is what the code will replace within this targeted member.

So far the code is targeting a registry item and saving over a targeted member (property under the namespace hierarchy) with provided info.


                $acl = $key.GetAccessControl()

        The next line sets $acl as a variable object for the above (reg path/overwrite/provided info) targeting its ACL (Windows Access Control List).


                $rule = New-Object System.Security.AccessControl.RegistryAccessRule (

        Sets a variable object, $rule, as something that target the System.Security.AccessControl namepsace, RegistryAccessRule property.


                ".\USERS","FullControl",

        Give the Users group full control


                @("ObjectInherit","ContainerInherit"),"None"

        Allows the permissions to be inherited by child objects but not propagated .


                ,"Allow")

        Specifies if access rights are allowed or denied.


                $acl.SetAccessRule($rule)

        Takes the variable $acl, targets the ACL (Access Control List) properties and sets them to the variable $rule above.

                $key.SetAccessControl($acl)

        This takes the target $key and applies $acl permissions that had been configured with $rule.


        Results:

        Targeted registry file: 

                HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node

        Is updated with permissions below.

                IdentityReference: “.\USERS” (local users)
                RegistryRights: "FullControl" (get full control)
                InheritanceFlags: "ObjectInherit","ContainerInherit" (Inherited to all child objects)
                PropagationFlags: “None” (Permissions are not to be propagated to those child objects)
                AccessControlType: “Allow” (Access rights are allowed)

Thursday, August 25, 2022

PowerShell 006 - Send Keystrokes

Send Keystrokes

        Example:

                $wshell = New-Object -ComObject wscript.shell;
                $wshell.SendKeys('text')
                $wshell.SendKeys(~)

        This will type out “text” followed by an Enter keystroke


        Breakdown:

                $wshell = New-Object -ComObject wscript.shell;

        Creates a COM Object with a wscript command and assigns it to the variable $wshell


                $wshell.SendKeys([KEYSTROKES])

        The Object runs the SendKeys command for what is between (). Use single quotes for ‘text’ or one of the codes for non-displayed keys.


Common Non-Displayed Keys

Key

Code

BACKSPACE

{BACKSPACE}, {BS}, or {BKSP}

ENTER

{ENTER} or ~

ESC

{ESC}

DEL or DELETE

{DELETE} or {DEL}

PRINT SCREEN

{PRTSC} (reserved for future use)

TAB

{TAB}


You can combo these with SHIFT, CTRL, and/or ALT by starting with the keys

Key

Code

SHIFT

+

CTRL

^

ALT

%

Tuesday, July 26, 2022

Security+ 008 - 1.8 Techniques used in Pentesting

1.0 Attacks, Threats, and Vulnerabilities

1.8 Techniques used in Pentesting



Penetration Testing
Known Environment - Tester is familiar with environment

Unknown Environment - Tester knows nothing about the environment

Partially Known Environment - Partially known and unknown, tester goes with info they have

Rules of Engagement - Agreed systems tester can target and what is to be tested

Lateral Movement - Moving from device to device within a network.

Privilege Escalation - Administrator access

Persistence - On-going access

Cleanup - Reverting systems back to original setting from before the test

Bug Bounty - System owner offers a reward for finding and reporting bugs in their system.

Pivoting - Using a system as a jump off point or a relay to access other parts of the network.


Passive and Active Reconnaissance

Drones - Surveillance

War Flying - WiFi enabled drone that can pick up networks and collect data about them.

War Driving - Similar to War Flying, but done with a car driving around instead of a flying drone.

Footprinting - Mapping the network, packet captures could see this happening.

OSINT - Open-source/public intel


Exercise Types
Red Team
- Attackers

Blue Team - Defenders

White Team - Oversees blue/red team activity on a network

Purple Team - A team that consists of both offense and defense team members

Monday, July 25, 2022

Security+ 007 - 1.7 Techniques used in Security Assessments

1.0 Attacks, Threats, and Vulnerabilities

1.7 Techniques used in Security Assessments



Threat Hunting - Detecting and locating threats/vulnerabilities

Intelligence Fusion - Aggregating raw data and logs into a database

Threat Feeds - Information alerts, often 3rd party provided

Advisories and Bulletins - Security reports

Maneuver - Deployment of security tools and automated deployment


Vulnerability Scans
False Positives - Flagged event that doesn’t pose a threat

False Negatives - Vulnerability is on a device, but does not get flagged/detected

Log Reviews - Pull data sourced from device logs

Credentialed - Scan as if you have authorized account access

Non-Credentialed - Scan as if you have no access

Intrusive - Tries to use found exploits

Non-Intrusive - Only looks for exploits, but does not use them

Application - Scans software (anti-virus)

Web Application - Scans for XSS (cross-site scripting), sql/code injections

Network - Scans network for open ports and other network vulnerabilities

Common Vulnerabilities and Exposures (CVE) - Reference for public knowledge on known exploits.

Common Vulnerability Scoring System (CVSS) - Scoring system to indicate severity of known exploits.

Configuration Review - Scan device or software for misconfigurations


Syslog/Security Info and Event Management (SIEM) - Software, central hub for security info
Review Reports - Generate reports based on diverse data

Packet Capture - Monitor network traffic

Data Inputs - Feed raw data into SIEM (authentications, VPN connections, firewall logs, denied network traffic)

User Behavior Analysis - Set a baseline and use it as a risk-trigger

Security Monitoring - Constant monitoring of real-time info flow, track stats, send alerts when risk is found, automated ticket generation

        Security Operations Center (SOC) - Centralized location to do security monitoring.

Log Aggregation - Database all logs

Log Collectors - Retrieves/accepts and stores all logs.


Security Orchestration, Automation and Response (SOAR)
- Automate tedious and routine tasks, connecting multiple tools together, auto-responsive to maintain real-time security.

Sunday, July 24, 2022

Security+ 006 - 1.6 Security Concerns Associated with Vulnerabilities

1.0 Attacks, Threats, and Vulnerabilities

1.6 Security Concerns Associated with Vulnerabilities



Cloud-Based Vulnerabilities - Vulnerabilities for a cloud environment. More available to target, data breach/loss, potential privacy issues

On-Premises Vulnerabilities - In house data center, requires regular maintenance and additional fault resilience, more susceptible to physical-based events (nature, power outage)

Zero-Day Vulnerabilities - A previously unknown vulnerability/exploit


Weak Configurations
Open Permissions
- No authentication requirements.

Unsecure Root Accounts - No authentication admin.

Errors - Errors should not include too much details to give an attacker extra info on a network/system, just need to be specific enough to say where to look.

Weak Encryption - Obsolete encryption methods, encryption that can easily be decrypted.

Unsecure Protocols - Unencrypted protocols

Default Settings - OEM/Factory set (public) credentials

Open Ports and Services - Manage Ports and traffic flow with a Firewall, open ports are open to communication and can be targeted.


Third-Party Risks
Vendor Management -
Managing and monitoring vendor risk and vulnerabilities

System Integration - 3rd party device or access to inside the network

Lack of Vendor Support - Vendor doesn’t/slow to patch vulnerabilities.

Supply Chain - Vulnerabilities in the sources of what builds your capabilities.

Outsourced Code Development - 3rd party developers, isolate from the production environment.

Data Storage - On-prem or in cloud, needs proper protocols in place to secure and set access controls.


Improper or Weak Patch Management
Firmware
- Commonly not patched often, can lead to devices being vulnerable.

Operating System (OS) - Core software running a device vulnerabilities

Applications - Software exploits

Legacy Platforms
- No longer supported, retired software/hardware still in use


Impacts
Data Loss
- Hardware failure, malicious removal, potentially can ruin a business.

Data Breaches - Access to data, can lead to extortion, potential loss of profits

Data Exfiltration
- Malicious data transfer, unauthorized, can lead to ransomware/extortion

Identity Theft - Can lead to financial damages or unintended authorization

Financial - Interruption of business, loss of profits, unauthorized money transfers

Reputation - Loss of trust in the business

Availability Loss - Denial of service, loss of profits

Friday, July 22, 2022

Security+ 005 - 1.5 Threat Actors, Vectors, and Intelligence Sources

1.0 Attacks, Threats, and Vulnerabilities

1.5 Threat Actors, Vectors, and Intelligence Sources



Actors and Threats - Entity responsible for an event that has an impact on the safety of another entity.

Advanced Persistent Threat (APT) - Stays in your network until removed, can act as reconnaissance for a larger attack.

Insider Threats - Potential employee, contractor, or vendor is a threat actor.

State Actors - Nation state, governmental threat actor.

Hacktivists - Threat actors with a goal or (political) purpose as motive.

Script Kiddies - Outside threat actor who uses many simple scripts until they find one that lets them into a network.

Criminal Syndicates - Professional organized groups of threat actors.

Hackers - Broadly, a person who is good with technology

        Authorized - Hired to find network weaknesses and vulnerabilities, has permission.

        Unauthorized - Malicious, looking to cause harm.

        Semi-authorized - Researcher-type, looks for vulnerabilities and network access without direct permission, but does not act on them if found.

Shadow IT - Those within an organization that fulfill their own IT needs outside the purview of the property IT processes and procedures.

Competitors - Threat actors from an outside organization that you share a market with.


Attributes of Actors
        Internal - Threat from within the organization.

        External - Threat from outside of the organization.

        Level of Sophistication/Capacity - Complexity/severity potential of the attack.

        Resources/Funding - Sophisticated attacks often require higher costs.

        Intent/Motivation - Goal of the attack.


Vectors
         Direct Access - Physical Access

        Wireless - Through a shared wireless network or rogue access point

        Email - Malicious links/phishing

        Supply Chain - Trusted 3rd party is compromised

        Social Media - Malicious links and scams/phishing, unintended employee over-sharing

        Removable Media - Auto-run code from hot-swappable media (USB drives, CDs, disks)

        Cloud - Manipulated or malicious cloud-based applications


Threat Intelligence Sources - Places to get data

Open-Source Intelligence (OSINT) - Public data

Closed/Proprietary - Payed for data

Vulnerability Databases - Compiled information from multiple sources on vulnerabilities

Public/Private Info Sharing Centers - Organizations that collect and disseminate data

Dark Web - Black market data

Indicators of Compromise - DNS queries/network traffic, location data, Identify attack and reverse engineer

Automated Indicator Sharing (AIS) - Automated process to share security data between organizations.

        Structured Threat Information eXpression (STIX) - Standard format for shared security data, contains info such as motive, ability, capability, and response info.

        Trusted Automated eXchange of Intelligence Info (TAXII) - Security Data transfer protocol

Predictive Analysis - Using real-time data to try to identify compromise.

Threat Maps - Visual representation of where the attacks may be from and going.

File/Code Repositories - Databases of code shared between developers.


Research Sources
Vendor Websites - Vendor discovered/published data

Vulnerability Feeds - Government and private org provided vulnerability databases

Conferences - Convention, you can learn new research from presenters

Academic Journals - Peer-reviewed published research

Request For Comments (RFC) - Published by ISOC, often written by engineers on known issues/standards, best practices, and experimental and historical practices

Local Industry Groups - Geographically local meet-up

Social media - Groups often post to social media, keyword monitoring, public conversations

Threat Feeds - Automated threat feed sourced from multiple organizations

Adversary Tactics, Techniques, and Procedures (TTP) - What are threat actors doing to get access, what is their typical goal when in a network, where do they spend most of their time, which attack vectors do they like to use.

Sunday, July 17, 2022

AZ-500 003 - Deploy Azure AD Identity Protection

AZ-500: Microsoft Azure Security Technologies

Manage Identity and Access: Deploy Azure AD Identity Protection

         Deploy and configure Identity Protection
         Configure MFA for users, groups, and applications
         Create Conditional Access policies to ensure your security
         Create and follow an access review process

Azure AD Identity Protection - A tool that enables an org to automate the detection and remediation of ID-based risks, and assists with data logs in the portal or with a 3rd party utility.

ID Protection Default Policies
Azure MFA Registration Policy, Sign-in Risk Policy, Custom Conditional Access Policy


User Risk Policy - Identifies and responds to user accounts that may have compromised credentials. Can prompt the user to create a new password.

Sign-in Risk Policy - Identifies and responds to suspicious sign-in attempts. Can prompt the user to provide additional forms of verification using Azure AD Multi-Factor Authentication.

MFA Registration Policy - Makes sure users are registered for Azure AD Multi-Factor Authentication. If a sign-in risk policy prompts for MFA, the user must already be registered for Azure AD Multi-Factor Authentication.

Example Risk Detection Triggers:
        Users with leaked credentials.
        Sign-ins from anonymous IP addresses.
        Impossible travel to atypical locations.
        Sign-ins from infected devices.
        Sign-ins from IP addresses with suspicious activity.


User Risk - User risk is a calculation of probability that an ID has been compromised.

User Risk Policy



Risky Users Report - Contains data for which users are at risk for up to the past 30 days, remediated risk, or had risk dismissed. Also has details about detection types, a history of all risky sign-ins, Conditional Access policies applied, MFA details, and device/app/location info.

Admin can set a response to a given condition/trigger, responses include:
        Force a password reset
        Confirm user compromised
        Dismiss user risk
        Block or Allow the sign-in
        Investigate further using Azure ATP (Advanced Threat Protection)

Example Condition Triggers:
         Location
         Client Apps - Browser-based apps, mobile apps, and desktop clients
         Risky Sign-ins

Azure Active Directory Multi-Factor Authentication (MFA) - Provides additional security by requiring a second form of authentication.


Authentication methods include:
         Something you know (password/PIN)
         Something you have (generated code, a specific device)
        Something you are (biometrics)

MFA options



MFA Settings


Account Lockout - Set number of attempts allowed before lockout, time until lockout counter resets, time until account is auto unlocked.

Block/Unblock Users - Blacklist/whitelist user accounts

Fraud Alert - Configure so users can report fraud attempts, set auto block users when fraud is reported, fraud blocks account for 90 days or until released by an admin, and admin can review sign-in logs.

Notifications - Configure email notifications for fraud reports (typically sent to an ID admin).

OATH Tokens - Azure AD supports OATH-TOTP SHA-1 (keychain) tokens that refresh codes every 30 or 60 seconds.

Trusted IPs - Feature to allow federated users or IP address ranges to bypass MFA (only for inside of the company intranet)


Enable MFA - Azure AD>User Properties>Multi-Factor Authentication


All users start out Disabled. When you enroll users in per-user Azure AD Multi-Factor Authentication, their state changes to Enabled. When enabled users sign in and complete the registration process, their state changes to Enforced. Administrators may move users between states, including from Enforced to Enabled or Disabled.

Azure AD Conditional Access - Tool used by AAD (Azure AD) to bring signals together to make decisions and enforce org policy. Enables an identity driven control plane (control of traffic).


Identity as a Service (IDaaS)



Conditional Access
 

Conditions: user/group, cloud application, device state, location (IP range), client application, and sign-in risk


Azure AD Access Reviews - Manage group membership, access to enterprise apps, and role assignments. User’s access can be reviewed on a regular basis.

When to access review:
         Too many users in privileged roles
         When automation is infeasible
         When a new group is used for a new purpose
         Business critical data access
         To maintain a policy’s exception list
         Ask group owners to confirm they still need guests in their groups
         Have reviews recur periodically