Skip to main content

Command Palette

Search for a command to run...

Cyber Security

Updated
•7 min read•View as Markdown

NETWORK SECURITY TOPIC

23/6/25

There are 8 main types of domains:-

  1. Network

  2. cloud

  3. Data

  4. Email

  5. Identity

  6. SIEM / SOAR

  7. Threat Intelligence

Web types:-

  1. web application:- example(amazon , flipkart, ect)

  2. web:- example(blog)

SOC 4 Layers:-

L1- Monitoring

L2- Analysis

L3- Response

L4- Management

What is a Log(fechars)?

A log is a feature that a computer, network device, or system uses to record events or activities, often for monitoring, troubleshooting, or auditing purposes.

How many types of logs are there in each domain?

  1. Network:- (12 types) Firewall, Router/Switch, IPs, VPN, DNS, Proxy server, Authentication, Netflow, Web server, Email server, Application.

  2. Cloud:- (12 types) VPC(AWS) / NSG(AZURE) / VPC(GCP), Firewall, Load balancer, DNS Query, API gateway, Authentication & Identity, Audit, Security / Threat detection, Proxy & Web traffic, Custom Application, container & Kubernetes, Network performance.

  3. Data:-(8 types) Storage access(AWS, AZURE, GCP), Database, Audit(data services), Data pipeline / ETL, Analytices, Data access(via API), Data loss prevention(DLP), Backup & Restore.

  4. Email:-(8 types) Message, SMTP, Email security, Audit logs, Email routing, Quarantine, Third party mail gateway.

  5. Identity:-(8 types) Authentication, Audit logs(Identity management), Role assumption, Conditional access, privileged access review, Federation/sso, Risk detection / Identity protection.

  6. SIEM:-(13 types) Authentication Logs, Access Logs, Audit Logs, Network Logs, Firewall Logs, Intrusion Detection/Prevention Logs (IDS/IPS), Intrusion Detection/Prevention Logs (IDS/IPS), Application Logs, Email Security Logs, Cloud Infrastructure Logs, Web Server/Proxy Logs, Database Logs, Threat Intelligence Feeds.

    SOAR:-(7 types) Alert Ingestion Logs, Playbook Execution Logs, Action/Response Logs, Case Management Logs, Integration/API Call Logs, Threat Enrichment Logs, User Activity Logs.Th

  7. Threat Intelligence:-(7 types) Indicator Match Logs, Threat Feed Ingestion Logs, Threat Enrichment Logs, Malware Analysis Logs**,** Threat Intelligence Sharing Logs, Threat Actor & TTP Logs, False Positive Logs.

There are three types of security.

TYPES APPLIANCES

  1. Network gateway:- Firewall | WAF | IDS | IPS |

  2. Centralize:- SEAM | SOAR |

  3. End point:- EDR | XDR | UBA |

Which company provides these appliances:-

  1. SIEM:- Splunk (Splunk Enterprise Security), IBM (IBM QRadar SIEM), Microsoft (Microsoft Sentinel – formerly Azure Sentinel), LogRhythm, Elastic (Elastic SIEM), Securonix, Exabeam, Rapid7 InsightIDR

  2. SOAR (Security Orchestration & Automation):- Palo Alto Networks (Cortex XSOAR), IBM (IBM Resilient SOAR), Splunk (Splunk SOAR, formerly Phantom), Swimlane, Rapid7 InsightConnect, Siemplify (acquired by Google)

  3. EDR (Endpoint Detection & Response):- CrowdStrike (Falcon Platform), SentinelOne, Microsoft (Defender for Endpoint), Trellix (formerly McAfee + FireEye), Trend Micro, Bitdefender, Sophos Intercept X, Symantec (Broadcom)

  4. XDR (Extended Detection & Response):- Palo Alto Networks (Cortex XDR), CrowdStrike Falcon XDR, Microsoft Defender XDR, Trend Micro Vision One, Cisco XDR, Fortinet FortiXDR, Trellix XDR

  5. UBA / UEBA (User Behavior Analytics) :- Exabeam , Securonix , Splunk UBA , Microsoft Defender (with UEBA built-in) , LogRhythm , Varonis

24/6/25

command to create a file, user, ip check, port enable, directory, vim installation

To create a directory and a file:-

  1. Ifconfig to check the IP address

  2. pwd to check the location of the file

  3. Ls to check least

  4. mkdir ionx for making a directory

  5. cd ionx Go to the specified directory.

  6. cd to return to the previous one.

  7. touch ionx.txt to create a file

  8. sudo apt install vim to install vim

  9. vim ionx(file name) To add file content. alternate command

  • sudo nano ionx to add file content.
  1. Check I in content, then type hello (when you use vim command)

  2. esc+:wq To save content in Vim, follow these steps**(when you use vim command)**

    ctrl+s and ctrl+x To save content in nano, follow these steps

  3. rm to remove any file

To create a user:-

  1. sudo adduser ionx to make a user

  2. sudo adduser ionx - -allow-bad-names if bad user name

To create a user into a root user:-

  1. sudo usermod -aG sudo ionx

Ubuntu firewall enable:-

  1. sudo ufw enable on the firewall

    TO off ufw:-

  2. sudo ufw disable off the firewall

To enable ports:-

  1. sudo systemctl start SSH

    To stop port:-

  2. sudo systemctl stop ssh

Allow ports to UFW:-

SSH command:-

  1. sudo UFW allow ssh

    Block or Deny ports:-

    sudo ufw deny ssh

  2. sudo apt install openssh-server

To check the status of the SSH port:-

  1. sudo systemctl status SSH

FTP command:-

  1. sudo apt install vsftpd

    sudo apt-get install ftp

  2. sudo ufw allow ftp

  3. sudo systemctl start vsftpd

  4. sudo sysytemctl status vsftp

HTTP command:-

  1. sudo apt install apache2 -y

  2. sudo apt update

  3. sudo systemctl start apache2

  4. sudo systemctl enable apache2

  5. sudo systemctl status apache2

  6. sudo ufw allow http

To check the status of all ports:-

  1. sudo UFW status

Delete a rule(Remove ports):-

  1. sudo ufw delete allow ssh

25/6/25

Which file should be given how much and what kind of permission:-

  1. First, create a file.

  2. ls is the file.

  3. ll see the permissions of files.

To remove any permission:-

  1. chmod -rw ionx.txt

To add permission:-

  1. chomd +r ionx.txt

  2. chomd +w ionx.txt

  3. chomd +x ionx.txt

user remove:-

  1. sudo su

  2. password enter pass

  3. sudo deluser --remove-home ionx(user name).

30/6/25

RED TEAM

  • Victim is {employee, web server, organization's network, company}

  • Attacher is {us}

CKC→ Cyber kill chain

  1. Reconnaissance**(Spying)**

    • What happens: The attacker secretly gathers information about you or your company.

    • Example: Checking LinkedIn, company websites, or scanning for weak systems.

    • ✅ Goal: Find weak spots.

  2. Weaponization**(Making a weapon)**

    • What happens: The attacker builds a "trap" – like a file that hides a virus.

    • Example: A fake PDF file that installs malware when opened.

  3. Delivery**(Sending the weapon)**

    • What happens: The attacker sends the trap to you.

    • Example: A phishing email with the infected PDF attached

  4. Exploitation**(Triggering the trap)**

    • What happens: You click or open something that gives the attacker access.

    • Example: You open the fake PDF, and it silently installs malware.

  5. Installation**(Setting up a base)**

    • What happens: The attacker installs software to stay inside your system.

    • Example: Malware creates a secret backdoor for future access.

  6. Command and Control (C2 or C&C)(Remote control)

    • What happens: The infected computer talks to the attacker’s server.

    • Example: The attacker can now send commands and control your system.

  7. Actions on Objectives**(Final goal)**

    • What happens: The attacker does what they originally planned.

    • Examples:

      • Steal data 📁

      • Lock files with ransomware 🔐

      • Spy on you 🕵️‍♂️

      • Destroy systems 💥

LOGS:-

  1. Auth.log → sudo nano /var/log/auth.log

  2. Syslog → sudo nano /var/log/syslog

To see failed password logs:-

sudo journalctl -u ss --grep“failed”

To see Accept password logs:-

sudo journalctl -u ss --grep“accept”

1/7/25

commands

See logs for a specific day:

journalctl --since "today"

See the logs for a specific second, min and hours:-

journalctl -S '-5 sec'

journalctl -S '-5 min'

journalctl -S '-5 hours'

journalctl -S '2025-07-02 12:05' -U '2025-07-02 12:10'

If you're not sure from the logs, you can also manually check recent users by seeing who was added last:

tail /etc/passwd

30/6/25

IDS(Intrusion Detection System){compliance}→ snort Tools install

Definition of IDS (Intrusion Detection System):-

"An IDS is a security system that watches a computer or network to detect any suspicious or harmful activity and alerts the user or admin."

Snort Tools→ Very popular, open-source, signature-based network IDS

  • Enable ufw

  • Enable the SSH port

  • than follow these steps

  • Find ip add (ifconfig)

sudo apt install snort -y [for installing the snort tool]
sudo apt-get update
sudo snort --version [To check version]
ifconfig  [TO check ports and IP address]
sudo ip link set enp0s3 promisc [To enable ports]
man snort [man - help]
ls -al /etc/snort [To check rules]
sudo nano /etc/snort/snort.conf  [to change rules]

in step 1:- ipvar HOME_NET 10.10.10.0/24 (change ip address)

To save it, press { ctrl+o}
To come back press {ctrl+x}
sudo snort -T -i enp0s3 -c /etc/snort/snort.conf
sudo snort -A console -q -u snort -g snort -c /etc/snort/snort.conf -i enp0s3

KALI CONFIGURATION:-

  • ifconfig

  • sudo apt install nmap

  • sudo nmap 10.10.10.1 (IP)

More from this blog

shreiya

36 posts