Networking Concepts
-
Introduction to Networking Fundamentals
-
Types of Networks (LAN, WAN, VPN)
-
IP Addressing and Types of IP Addresses
-
Common Ports and Associated Services
-
Service Communication Over Different Ports
-
Well-Known Ports and Their Risks
Linux Usage
-
Linux Commands and Operations
-
Linux File System Structure
-
User Permissions and Security in Linux
VAPT
-
Host Discovery with Nmap
-
Windows and Linux Exploitation
-
Brute-Force Attacks with Hydra on SMB, SSH, and HTTP
-
Malware Development with WinSpy
MITRE ATT&CK
-
Understanding MITRE ATT&CK Techniques
-
Malware Detection and Response
-
Tactics, Techniques, and Procedures (TTPs) – Practical Exercises
Log Analysis – Splunk
-
Overview of Splunk and Log Management
-
Splunk Interface and Key Components
-
Log Analysis with Splunk
-
Searching, Filtering, and Visualizing Log Data
-
Detecting Suspicious Activities and Attacks
-
Creating and Simulating Security Incidents
-
Analyzing Simulated Security Incidents
-
Creating Alerts and Incident Response
Log Analysis – Azure Sentinel
-
Azure VM Configuration and Deployment
-
Connecting Azure VM to Sentinel for Real-Time Monitoring
-
Creating Detection Rules for Cyber Attacks
-
Creating Log Analytics Workspaces
-
Log Analysis Using KQL
-
Creating Real-Time Monitoring Dashboards
-
Logic Apps Integration and Usage
IDS and IPS
-
Overview of IDS and IPS
-
Understanding Firewalls and Their Functions
-
Introduction to Snort IDS
-
Writing and Using Snort Rules
-
Writing Rules to Detect Nmap Scans
-
Blocking Malicious Traffic Using Snort
-
Snort Rule Syntax and Application
EDR – Wazuh
-
File Integrity Monitoring
-
Malware Detection and Removal Using VirusTotal
-
Threat Hunting with Wazuh
-
Command Monitoring
-
Web Attack Testing Using DVWA
-
Alerts and Notifications
-
Email Alert Notifications
-
Incident Response Automation
-
Brute-Force Attack Detection and Blocking
Phishing Analysis
-
Types of Phishing Attacks
-
Email Analysis: Headers and Sender Information
-
Email Authentication Methods
-
Email Content Analysis
-
Understanding URL Anatomy
-
IP Reputation Checks
Threat Hunting
-
Identifying ARP Spoofing Attacks
-
MAC Flooding Detection
-
Denial-of-Service (DoS) Attacks
-
Identifying Large ICMP Traffic
-
Normal TCP Traffic vs. Nmap Scanning Traffic
-
DHCP Traffic Monitoring
-
DNS Traffic Monitoring
-
Identifying Malware Communication Using Wireshark
-
Endpoint Threat Hunting
-
Understanding Windows Processes
-
PowerShell for Threat Hunting
-
Investigating Windows Processes Using PowerShell
Malware Analysis
-
Introduction to Malware Analysis
-
Static Analysis Techniques
-
Dynamic Analysis Techniques
-
Practical Challenge – PuTTY Malware Analysis