Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Misconfigurations Management
Rating: 4.5 out of 5(1 rating)
1,070 students

Misconfigurations Management

Misconfigurations Management for effective security defense
Created byRichea Perry
Last updated 9/2024
English
English [Auto],

What you'll learn

  • An awareness of the Top common cybersecurity misconfigurations found in large organizations that leads to cyber attacks.
  • How to establish security baselines in Windows Cloud Environments (Azure) to mitigate misconfigurations leading to cyber attacks.
  • An in-dept understanding of cyber risks associated with these misconfigurations and how they are exploited by attackers.
  • Application of AI(ChatGPT, Gimini) to execute various lab activities involving misconfiguration mitigation
  • Best Practice recommendations for mitigating these cyber risks associated with these misconfigurations
  • How to use MITRE ATT&CK for Technical Mitigation of attacks as a result of these misconfiguartions
  • How to secure your cloud (Azure) environment from misconfigurations via Red Team-Azure Penetration Testing
  • An Introduction to root cause analsysis and its benefits to a cybersecurity mindset
  • Open-Source Tools for Configurations Management to mitigate cyber attacks
  • How develop a Root cause analysis for selected security misconfigurations
  • How to address various scenarios involving the skills of Red or Blue Teamer as it relates to protecting systems from these top 10 misconfiguartions.
  • A better understanding of cyber risks in order to develop appropriate policies & conduct effective risks assessments policies as a GRC Professional

Course content

4 sections51 lectures4h 19m total length
  • Introduction2:39

    Develop a holistic understanding of misconfigurations that lead to cyber attacks and how red and blue teams collaborate to defend networks, with hands-on exercises to establish a baseline security posture.

  • Course Agenda.mp44:16

    Explore three sections on misconfiguration defense for red and blue teams, guided by the NSA and CISA advisory on the top ten weaknesses in active directory environments.

  • Intro to Systemic weaknesses in relation to cybersecurity misconfigurations7:25

    Explore systemic weaknesses behind cybersecurity misconfigurations and the ten common network misconfigurations. Use proactive risk assessments, security frameworks, continuous monitoring, and employee training to mitigate cascading failures and persistent threats.

  • Intro to the top 10 NSA & CISA Misconfigurations2:52

    Top ten misconfigurations identified by NSA and CISA, including default configurations, improper privilege separation, insufficient monitoring, lack of segmentation, weak MFA, poor credential hygiene, and unrestricted code execution.

  • Misconfiguration #18:28

    Address default configurations and default credentials in software and devices to reduce misconfigurations and vulnerabilities. Implement best practices, update patches, and enforce secure permissions to strengthen security posture.

  • Misconfiguration #27:53

    Misconfiguration #2 explains how improper separation of user and administrator privileges expands attack surface and enables privilege escalation, accidental misuse, and regulatory violations; emphasize ongoing privilege management and monitoring.

  • Misconfiguration #37:08

    Identify how insufficient internal network monitoring creates blind spots that enable lateral movement and advanced threats. Improve defenses by configuring host-based and network sensors, monitoring traffic, and detecting anomalies.

  • Misconfiguration #45:49

    Illustrates how lack of network segmentation creates security boundaries between user production and critical systems, enabling lateral movement, data breaches, and ransomware risks, and emphasizes risk management and continuous monitoring.

  • Misconfiguration #56:16

    Explore misconfiguration #5 and patch management as critical cybersecurity practices, identifying, acquiring, and installing updates to close vulnerabilities, prevent data breaches, and defend against malware and ransomware.

  • Misconfiguration #63:42

    Misconfiguration #6: bypassing system access controls drives data breaches, malware infections, and operational disruptions; understand legal ramifications and the risks of elevating privileges or moving laterally via compromised authentication methods.

  • Misconfiguration #74:44

    Misconfiguration #7 discusses weak MFA methods like SMS and push, exposing accounts to phishing, social engineering, and man-in-the-middle attacks, and highlights misconfigurations, outdated tech, and password-hash risks with mitigation strategies.

  • Misconfiguration #86:26

    Misconfiguration #8 highlights how insufficient access control on network shares risks data breaches, data manipulation, and malware spread. It stresses tightening ACLs to strengthen security and compliance.

  • Misconfiguration #93:36

    Explore the risks of poor credential hygiene, including data breaches, account takeovers, and reputational damage. Learn how strong passwords and MFA mitigate threats and support a move toward passwordless authentication.

  • Misconfiguration #105:16

    Misconfiguration #10 explains unrestricted code execution, its risks like data theft, system damage, and backdoors, and outlines mitigation strategies to protect networks from phishing scams and attacks.

  • End of Section 1 Quiz2:28

    Review the end of section one quiz questions to identify misconfigurations such as default credentials and weak patching, and how access control, network segmentation, and best practices prevent data breaches.

Requirements

  • AnUnderstanding of the fundmentals of networking, information security principles, & the ability to setup up your own cloud or on-premise virtual lab environment.
  • Having a basic to advanced understanding of Penetration testing steps or phases and tools used at each phase.
  • A curious mind to research and go beyond the surface.

Description

This course is designed for aspiring Red & Blue Teamers, Security leaders, Network defenders and those thinking of transitioning into cybersecurity, or even those already into cybersecurity that needs that holistic view of how both red and blue teams can work together efficiently in keeping people, processes and technology infrastructures secure by understanding the most common misconfigurations that leads to cyber attacks and most importantly how to prevent these attacks from occurring. The learner will gain knowledge and practical skills where applicable in regards to the following:

  • The Top 10 most common cybersecurity misconfigurations found in both mid to large size organizations that leads to cyber attacks.

  • Establishing security baselines in Windows Cloud Environments (Azure) to mitigate misconfigurations leading to cyber attacks.

  • How to practically address the following top 10 misconfigurations that leads to network\cyber attacks:

    1-Default configurations of software and applications

    2-Improper separation of user/administrator privilege

    3-Insufficient internal network monitoring

    4-Lack of network segmentation

    5-Poor patch management

    6-Bypass of system access controls

    7-Weak or misconfigured multi-factor authentication (MFA) methods

    8-Insufficient access control lists (ACLs) on network shares and services

    9-Poor credential hygiene

    10-Unrestricted code execution

  • Cyber risks associated with these misconfiguration and how they are exploited by attackers.

  • Best Practice recommendations for mitigating these cyber risks associated with these misconfigurations

  • Use of MITRE ATT&CK Technical recommendations for Mitigating these attacks resulting from these misconfiguration

  • Introduction to root cause analysis and its benefits to a cybersecurity mindset

  • Intro to Open-Source Tools for Configurations Management to mitigate cyber attacks

  • Ways to Improve Monitoring and Hardening of Networks for Blue & Network Admin Teams against cyber attacks

  • Use of AI to generate defense checklist that can be used as guides by network defenders to prevent these misconfigurations.

  • Securing your cloud (Azure) environment from misconfigurations via Red Team-Azure Penetration Testing

The misconfigurations to be explored in this course are based on NSA and CISA teams conducting comprehensive security assessments of numerous network enclaves within various organizations and during these assessments, they identified the 10 most common network misconfigurations, which are systemic weaknesses across many networks leading to system compromises.


Who this course is for:

  • This course is designed for aspiring Red & Blue Teamers, Cyber Security Leaders, Network defenders and those thinking of transitioning into cybersecurity, or even those already into cybersecurity that needs that holistic view of how both red and blue teams can work together efficiently in keeping people, processes and technology infrastructures secure by understanding the most common misconfigurations that leads to cyber attacks and most importantly how to prevent these attacks from occurring.