
Explore hands-on malware analysis using ELSA and PCAP files, and learn to build your own home labs and leverage online labs to practice cybersecurity tools.
Explore Security Onion, a Linux distribution for intrusion detection, network security monitoring, and log management; install and configure it in VirtualBox, then work with alerts and packet captures.
Learn to download the Security Onion iso image, a free open source Linux distribution for intrusion detection, enterprise security monitoring, and log management, featuring Elasticsearch, Logstash, Kibana, and Elsa.
Create a Security Onion VM in VirtualBox with Linux 64-bit, enable BIOS virtualization, allocate 4 GB RAM and a 20 GB VMDK, using an internal network for sniffing.
Install the Security Onion operating system on the Security Onion VM by booting from the ISO image, selecting language and location, creating a user, and preparing for tool setup.
Install the security onion tools with the setup wizard, configure management and sniffing interfaces, reboot, then run evaluation mode to deploy ELSA, Sig, Squert, and the elastic stack.
Update the Security Onion VM by running the sudo update script in a terminal to download and install updates. Reboot to complete the process and prepare for the August edition.
Install VirtualBox guest additions for Linux by downloading the August editions ISO, mounting it, and running the installer with sudo to improve VM integration; install before updating to keep Elsa.
Take a snapshot of the Security Onion VM in VirtualBox to revert to a known good state, naming the snapshot and recording a date and description.
Learn to use tcpreplay to replay pcap files, generating simulated network traffic with open source utilities for intrusion detection and prevention systems and malware analysis.
Download additional pcap samples from malware traffic analysis sites, extract password-protected zip files, and replay the captured traffic to practice malware analysis with ELSA.
Explore Elsa, an open source centralized log management and siem tool for log collection, normalization, grouping, aggregation, and reporting with real-time alerts.
Learn to use Elsa, the enterprise log search and archive, by selecting time ranges and classes (e.g., pro connection), viewing source and destination IPs, ports, duration, bytes, packets, and country.
Explore how to summarize log data in ELSA using the group by clause, displaying source IPs and records, adjusting limits, and interpreting results for focused malware analysis.
Filter ELSA results for a specific IP using the summary link, manual query, or term dropdown, then view detailed records with get cap to inspect operating system and client-server transactions.
*** Part of the best selling course: CCNA Cyber Ops Tools: Sec Onion, Wireshark, and Kali Linux ***
*** The Only standalone course about ELSA (Enterprise Log Search and Archive) on Udemy***
It is estimated that there will be about 1.5 million unfilled jobs in cyber security by the year 2020. A more recent statistic increased this number for cyber security unfilled jobs to be 3.5 million by the year 2021. In addition, recent article highlights Cisco Systems intention to become a cyber security force. For these reasons, Cisco created the CCNA Cyber Ops certification, which can become one of the most certifications in demand in the near future. Furthermore, Cisco created a scholarship program for this certification, which emphasis its importance.
In this course you will learn about the tools that you can use for your study of the CCNA Cyber Ops certification. Learning the theory side is important, but the hands on side is more important, since the main purpose of your study is to apply your knowledge in production, and since your hands on will enforce your theory knowledge. You can not teach someone how to drive a car by showing him or her how to do it, but you have to let him try and practice how to do that. Furthermore, showing you hands on labs and how to use tools without teaching you how to create these labs and install these tools, might not give you the ultimate benefit from your study . For this reason, I have created this course to teach you how to create your own home labs, and to understand the core usage and important features of the tools used in them. I believe in the saying: "Give a man a fish and you feed him for a day; teach a man to fish and you feed him for a lifetime". If you have access to online labs, such as that offered by Cisco through their scholarship, you still need to know how to create your own home labs to continue practicing and experimenting, which is what this course will help you to achieve. On the other hand, this course will prepare you to go through these online labs quickly, and with confidence, since you will be familiar with the tools used in them. And not just online labs, but any other hands on Cyber Ops courses, like what I intend to publish in the near future.
In this course you will learn about how to use the tcpreplay command, and where to download PCAP files that can be used with this command to recreate network packets in order to practice with malware analysis using ELSA. You will go through the steps of log normalization,log summarization, and log aggregation.
Because you will need to install and learn security onion before start working with ELSA, I have a section for that.
I hope that you will join me in this course and start your Cyber security journey. Happy learning!