Cyber Security
NETWORK SECURITY TOPIC
23/6/25
There are 8 main types of domains:-
Network
cloud
Data
Email
Identity
SIEM / SOAR
Threat Intelligence
Web types:-
web application:- example(amazon , flipkart, ect)
web:- example(blog)
SOC 4 Layers:-
L1- Monitoring
L2- Analysis
L3- Response
L4- Management
What is a Log(fechars)?
A log is a feature that a computer, network device, or system uses to record events or activities, often for monitoring, troubleshooting, or auditing purposes.
How many types of logs are there in each domain?
Network:- (12 types) Firewall, Router/Switch, IPs, VPN, DNS, Proxy server, Authentication, Netflow, Web server, Email server, Application.
Cloud:- (12 types) VPC(AWS) / NSG(AZURE) / VPC(GCP), Firewall, Load balancer, DNS Query, API gateway, Authentication & Identity, Audit, Security / Threat detection, Proxy & Web traffic, Custom Application, container & Kubernetes, Network performance.
Data:-(8 types) Storage access(AWS, AZURE, GCP), Database, Audit(data services), Data pipeline / ETL, Analytices, Data access(via API), Data loss prevention(DLP), Backup & Restore.
Email:-(8 types) Message, SMTP, Email security, Audit logs, Email routing, Quarantine, Third party mail gateway.
Identity:-(8 types) Authentication, Audit logs(Identity management), Role assumption, Conditional access, privileged access review, Federation/sso, Risk detection / Identity protection.
SIEM:-(13 types) Authentication Logs, Access Logs, Audit Logs, Network Logs, Firewall Logs, Intrusion Detection/Prevention Logs (IDS/IPS), Intrusion Detection/Prevention Logs (IDS/IPS), Application Logs, Email Security Logs, Cloud Infrastructure Logs, Web Server/Proxy Logs, Database Logs, Threat Intelligence Feeds.
SOAR:-(7 types) Alert Ingestion Logs, Playbook Execution Logs, Action/Response Logs, Case Management Logs, Integration/API Call Logs, Threat Enrichment Logs, User Activity Logs.Th
Threat Intelligence:-(7 types) Indicator Match Logs, Threat Feed Ingestion Logs, Threat Enrichment Logs, Malware Analysis Logs**,** Threat Intelligence Sharing Logs, Threat Actor & TTP Logs, False Positive Logs.
There are three types of security.
TYPES APPLIANCES
Network gateway:- Firewall | WAF | IDS | IPS |
Centralize:- SEAM | SOAR |
End point:- EDR | XDR | UBA |
Which company provides these appliances:-
SIEM:- Splunk (Splunk Enterprise Security), IBM (IBM QRadar SIEM), Microsoft (Microsoft Sentinel – formerly Azure Sentinel), LogRhythm, Elastic (Elastic SIEM), Securonix, Exabeam, Rapid7 InsightIDR
SOAR (Security Orchestration & Automation):- Palo Alto Networks (Cortex XSOAR), IBM (IBM Resilient SOAR), Splunk (Splunk SOAR, formerly Phantom), Swimlane, Rapid7 InsightConnect, Siemplify (acquired by Google)
EDR (Endpoint Detection & Response):- CrowdStrike (Falcon Platform), SentinelOne, Microsoft (Defender for Endpoint), Trellix (formerly McAfee + FireEye), Trend Micro, Bitdefender, Sophos Intercept X, Symantec (Broadcom)
XDR (Extended Detection & Response):- Palo Alto Networks (Cortex XDR), CrowdStrike Falcon XDR, Microsoft Defender XDR, Trend Micro Vision One, Cisco XDR, Fortinet FortiXDR, Trellix XDR
UBA / UEBA (User Behavior Analytics) :- Exabeam , Securonix , Splunk UBA , Microsoft Defender (with UEBA built-in) , LogRhythm , Varonis
24/6/25
command to create a file, user, ip check, port enable, directory, vim installation
To create a directory and a file:-
Ifconfigto check the IP addresspwdto check the location of the fileLsto check leastmkdir ionxfor making a directorycd ionxGo to the specified directory.cdto return to the previous one.touch ionx.txtto create a filesudo apt install vimto install vimvim ionx(file name) To add file content. alternate command
sudo nano ionxto add file content.
Check
Iin content, then type hello (when you use vim command)esc+:wqTo save content in Vim, follow these steps**(when you use vim command)**ctrl+sandctrl+xTo save content in nano, follow these stepsrmto remove any file
To create a user:-
sudo adduser ionxto make a usersudo adduser ionx - -allow-bad-namesif bad user name
To create a user into a root user:-
sudo usermod -aG sudo ionx
Ubuntu firewall enable:-
sudo ufw enableon the firewallTO off ufw:-
sudo ufw disableoff the firewall
To enable ports:-
sudo systemctl start SSHTo stop port:-
sudo systemctl stop ssh
Allow ports to UFW:-
SSH command:-
sudo UFW allow sshBlock or Deny ports:-
sudo ufw deny sshsudo apt install openssh-server
To check the status of the SSH port:-
sudo systemctl status SSH
FTP command:-
sudo apt install vsftpdsudo apt-get install ftpsudo ufw allow ftpsudo systemctl start vsftpdsudo sysytemctl status vsftp
HTTP command:-
sudo apt install apache2 -y
sudo apt update
sudo systemctl start apache2
sudo systemctl enable apache2
sudo systemctl status apache2
sudo ufw allow http
To check the status of all ports:-
sudo UFW status
Delete a rule(Remove ports):-
sudo ufw delete allow ssh
25/6/25
Which file should be given how much and what kind of permission:-
First, create a file.
lsis the file.llsee the permissions of files.
To remove any permission:-
chmod -rw ionx.txt
To add permission:-
chomd +r ionx.txt
chomd +w ionx.txt
chomd +x ionx.txt
user remove:-
sudo supasswordenter passsudo deluser --remove-home ionx(user name).
30/6/25
RED TEAM
Victim is {employee, web server, organization's network, company}
Attacher is {us}
CKC→ Cyber kill chain
Reconnaissance**(Spying)**
What happens: The attacker secretly gathers information about you or your company.
Example: Checking LinkedIn, company websites, or scanning for weak systems.
✅ Goal: Find weak spots.
Weaponization**(Making a weapon)**
What happens: The attacker builds a "trap" – like a file that hides a virus.
Example: A fake PDF file that installs malware when opened.
Delivery**(Sending the weapon)**
What happens: The attacker sends the trap to you.
Example: A phishing email with the infected PDF attached
Exploitation**(Triggering the trap)**
What happens: You click or open something that gives the attacker access.
Example: You open the fake PDF, and it silently installs malware.
Installation**(Setting up a base)**
What happens: The attacker installs software to stay inside your system.
Example: Malware creates a secret backdoor for future access.
Command and Control (C2 or C&C)(Remote control)
What happens: The infected computer talks to the attacker’s server.
Example: The attacker can now send commands and control your system.
Actions on Objectives**(Final goal)**
What happens: The attacker does what they originally planned.
Examples:
Steal data 📁
Lock files with ransomware 🔐
Spy on you 🕵️♂️
Destroy systems 💥
LOGS:-
Auth.log → sudo nano /var/log/auth.log
Syslog → sudo nano /var/log/syslog
To see failed password logs:-
sudo journalctl -u ss --grep“failed”
To see Accept password logs:-
sudo journalctl -u ss --grep“accept”
1/7/25
commands
See logs for a specific day:
journalctl --since "today"
See the logs for a specific second, min and hours:-
journalctl -S '-5 sec'
journalctl -S '-5 min'
journalctl -S '-5 hours'
journalctl -S '2025-07-02 12:05' -U '2025-07-02 12:10'
If you're not sure from the logs, you can also manually check recent users by seeing who was added last:
tail /etc/passwd
30/6/25
IDS(Intrusion Detection System){compliance}→ snort Tools install
Definition of IDS (Intrusion Detection System):-
"An IDS is a security system that watches a computer or network to detect any suspicious or harmful activity and alerts the user or admin."
Snort Tools→ Very popular, open-source, signature-based network IDS
Enable ufw
Enable the SSH port
than follow these steps
Find ip add (ifconfig)
sudo apt install snort -y [for installing the snort tool]
sudo apt-get update
sudo snort --version [To check version]
ifconfig [TO check ports and IP address]
sudo ip link set enp0s3 promisc [To enable ports]
man snort [man - help]
ls -al /etc/snort [To check rules]
sudo nano /etc/snort/snort.conf [to change rules]
in step 1:- ipvar HOME_NET 10.10.10.0/24 (change ip address)
To save it, press { ctrl+o}
To come back press {ctrl+x}
sudo snort -T -i enp0s3 -c /etc/snort/snort.conf
sudo snort -A console -q -u snort -g snort -c /etc/snort/snort.conf -i enp0s3
KALI CONFIGURATION:-
ifconfig
sudo apt install nmap
sudo nmap 10.10.10.1 (IP)