
Explore hands-on cyber security labs with Security Onion, Wireshark, and Kali Linux. Learn core tools such as Metasploit, Nmap, VirtualBox, and GNS3 to prepare for ccna cyber ops.
This lecture introduces virtualization concepts and VirtualBox, teaching how to create virtual machines, use hypervisor basics, and configure NAT, host-only, bridged, and promiscuous networking.
Download and install VirtualBox to create a lab with Security Onion, Kali Linux, and Metasploitable VMs. Follow the setup steps, including network interface warnings and confirming Oracle trust prompts.
Explore Security Onion, a Ubuntu-based Linux distribution for network security monitoring with intrusion detection and log management, and learn vm setup, tool installation, snapshotting, and data replay techniques.
Download the Security Onion ISO image, a free Linux distribution for intrusion detection, enterprise security monitoring, and log management, which includes Elasticsearch, Logstash, Kibana, Snort, and Suricata.
Create the Security Onion VM in VirtualBox with Linux 64-bit, 4 GB RAM, a 20 GB VMDK, and configure two adapters for internet access and traffic capture with promiscuous mode.
Demonstrates installing the security onion operating system on a virtual machine, mounting the ISO, booting the installer, and completing initial setup with English language and a simple lab password.
This lecture guides you through running the Security Union setup, configuring management and monitoring interfaces, and selecting evaluation mode to install Elsa, Segal, and Squirt with the elastic stack.
Update the Security Onion software via a terminal using sudo to run the update script and enter the password. The process downloads, installs updates, then reboots the VM.
Install VirtualBox guest editions on Linux to improve guest-host integration and performance. Download the ISO, mount it, run the installer with sudo, and reboot to complete the setup.
Take a VirtualBox snapshot of the Security Onion VM to revert to a known state. Name and date the snapshot for future recovery, and note the TV replay command.
Use tcpreplay to replay captured pickup files and simulate network traffic. Run with sudo, select interface (-i), set speed (-M), and packet count (-bp) to mirror malicious patterns.
download more pcap samples from malware traffic analysis sites, extract zip files with the password from the about page, and replay traffic using tcp replay to practice analysis.
Elsa is an open source syslog compiler and search tool that normalizes logs, enables log collection, aggregation, correlation, and reporting, and supports real-time alerts and historical reports.
Explore Elsa, the enterprise log search and archive, for receiving and querying syslog data. Set time ranges and the pro connection class, and view IPs, ports, duration, and country.
Learn to create log summaries in ELSA using group by, report on, and top links to display source IP statistics, adjust limits, and highlight the most active addresses.
Explore how to filter ELSA log data by a specific IP address, using summary links, query fields, and dropdowns to isolate records and view details.
Explore real-time security event analysis with Squeal and Squert, access session data and alerts, decode raw packet data, and classify events into seven categories for rapid escalation.
Explore the Squeal interface to monitor Snort alerts in real time, view alert details, packet data, and Snort rules, and group related events for correlation.
Pivot from Sguil alerts to other tools like Wireshark, VirusTotal, and Elsa to analyze IP data, view host files, and extract or verify potentially malicious files.
Learn how to categorize events in Sguil, assign the virus infection category seven, query by category, adjust dates, and escalate or comment, using quick query, F7, and automatic categorization.
Explore Squert, a graphical web interface over Google, login securely, filter alerts by date and category, classify malware alerts as virus infections, and pivot to tools like Wireshark for analysis.
Discover elastic stack concepts and components—Elasticsearch, Logstash, and Cabana—and how they centralize monitoring, alerting, and logging for thousands of servers.
Discover how to preserve original timestamps with the import pickup script, upgrade Elastic Stack, adjust heap size, and run the script on a downloaded file to view original alerts.
Explore Kibana as a new customer relationship management system, view alert results from a pcap script, and use log summarization, charts, and log aggregation to analyze ip addresses and ports.
Explore GNS3, a free graphical network simulator that designs complex topologies and emulates Cisco and other Windows devices for certification study, with setup options, the GNS3 VM, and IOS images.
Download and install Genesis three (gns3) to use lab network devices, choose components like Wireshark, Dynamix, Chemo, VPC, and SolarWinds, and complete the installation with the setup wizard.
Use the GNS3 setup wizard to configure routers and switches for a lab. Ensure antivirus and firewall allowances, and set the local host IP and RAM for lab attack demonstrations.
Import the Security Onion VM into GNS3 and connect it to the ether switch for the cyber ops lab, then configure the ethernet interface and test connectivity.
Learn how Wireshark, a free open-source network packet analyzer and de facto standard, captures and analyzes traffic using capture and display filters, coloring rules, and promiscuous mode.
download and install wireshark on Windows 7, accept the license, set up desktop shortcuts, enable winpcap, and start capturing icmp traffic (including usb capture option).
Explore the Wireshark GUI, use capture filters to focus on interfaces and protocols, start and stop captures, and view packets in the packet list, details, and hex panes.
Learn to use Wireshark display filters to target protocols and specific traffic, save and apply filters, and manage name resolution settings to optimize performance.
Learn to create and apply coloring rules in Wireshark, color DNS UDP 53 traffic, and export or save specific packet captures using the default format, guided by rule precedence.
Learn to use Wireshark’s follow TCP stream feature to locate and extract potentially malicious files from network traffic, then upload them to VirusTotal for analysis.
Explore Kali Linux, an advanced penetration testing distribution for ethical hacking and network security assessments, covering information gathering, vulnerability analysis, and password and wireless attacks.
explore downloading Kali Linux, selecting an appropriate image, and setting up a VirtualBox VM with 2 GB RAM and 30 GB disk before completing the OS installation.
Explore Kali Linux and its information gathering and vulnerability analysis tools, including Maltego, Nectar, and Scapy, to gather data, analyze targets, and test WiFi security, including password cracking.
Download, install, and configure the metasploit vm in VirtualBox; import Kali Linux, connect VMs, set IPs, and test exploits using Metasploit against a web app showing OWASP top ten vulnerabilities.
Explore how Nmap maps networks, detects operating systems and services, and uses powerful scan types, evasion techniques, and the scripting engine to automate discovery and vulnerability checks.
Learn to use nmap and zenmap to discover hosts, identify open ports and services, perform OS detection, run scripts, and apply timing and decoy options to evade intrusion detection systems.
Explore the Metasploit framework, an open source tool for developing and executing exploit code against a remote target, featuring modular scanners, exploit modules, payloads, encoders, and pivot capabilities.
Master the Metasploit framework and Armitage to perform port scans, login to a Postgres database, and access data using both the command line and Armitage.
*** Very Similar to my INE Course: CCNA Cyber Ops Labs - Create Your Labs ***
Note: This course will be updated frequently. Lectures about theory concepts, tools' usage, and practical labs will be added to the course gradually
It is estimated that there will be about 1.5 million unfilled jobs in cyber security by the year 2020. A more recent statistic increased this number for cyber security unfilled jobs to be 3.5 million by the year 2021. In addition, recent article highlights Cisco Systems intention to become a cyber security force. For these reasons, Cisco created the CCNA Cyber Ops certification, which can become one of the most certifications in demand in the near future. Furthermore, Cisco created a scholarship program for this certification, which emphasis its importance.
In this course you will learn about the tools that you can use for your study of the CCNA Cyber Ops certification and the current Cisco CyberOps Associate certification. Learning the theory side is important, but the hands on side is more important, since the main purpose of your study is to apply your knowledge in production, and since your hands on will enforce your theory knowledge. You can not teach someone how to drive a car by showing him or her how to do it, but you have to let him try and practice how to do that. Furthermore, showing you hands on labs and how to use tools without teaching you how to create these labs and install these tools, might not give you the ultimate benefit from your study . For this reason, I have created this course to teach you how to create your own home labs, and to understand the core usage and important features of the tools used in them. I believe in the saying: "Give a man a fish and you feed him for a day; teach a man to fish and you feed him for a lifetime". If you have access to online labs, such as that offered by Cisco through their scholarship, you still need to know how to create your own home labs to continue practicing and experimenting, which is what this course will help you to achieve. On the other hand, this course will prepare you to go through these online labs quickly, and with confidence, since you will be familiar with the tools used in them. And not just online labs, but any other hands on Cyber Ops courses, like what I intend to publish in the near future.
This course will teach you how to use the following tools:
Security Onion (Including VM installation, working with PCAP files, ELSA, Sguil. Squert, and Kibana).
Wireshark.
Kali Linux.
Metasploit.
Nmap.
VirtualBox.
GNS3.
This course includes several practical assignments and a practice test, in order to asses your understanding of the material included. I strongly recommend that you try the assignments and answer the question included in them, after trying solving the task practically, or even after watching the solution video. Each assignment will give you thorough and comprehensive understanding of the related topic.
I hope that you will join me in this course and start your Cyber security journey. Happy learning!
Very Important: How to use this course
Based on students' feedback, you can view this course by going directly to the section you are interested in. However, it is recommended that you at least skim quickly over the other preceding sections.
For example, you can go to the ELSA and Sguil sections (the core of the course) directly if you are already familiar with VirtualBox and the Security Onion installation process, or skim quickly over those sections as a review.