SECTION 9 Cyber Security: Recent Episodes

SECTION 9

Just two people trying to do IT and Security the right way.

View Details

Time to start looking into cyber security frameworks. For this episode we’re looking at the the NIST Cyber Security Framework. We’re also explaining what a cyber security framework is and how they can help.

LINKS

  1. NIST Cyber Security Framework (CSF)

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Time for another maintenance episode where we review our systems and management process. This time were looking at our Digital Ocean servers, Automox patch management, Fortinet Firewalls, and the password manager Bitwarden.

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Almost roasted our VMware server to death. Don’t do what I did. Enjoy!

LINKS

  1. VMware Server: Super Micro SYS-E300-9D-8CN8TP

  2. Fans: Noctua NF-A4x20 PWM

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

LastPass was hacked last year. As LastPass customers we need to evaluate the impact that has on Section 9. Should we continue to use the product? Should we migrate to a different password manager? How do we evaluate a password manager?

Consider this the start of a longer conversation about LastPass and password managers.

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Found some really interesting and helpful videos. One walks you through an Active Directory hacking lab. Another talks about default configurations and bad passwords as a way to hack into systems. The last one is about building a home lab.

These are just what I needed.

LINKS

  1. SANS Workshop – NTLM Relaying 101: How Internal Pentesters Compromise Domains

  2. The Top $ num Reasons You Got Hacked in 2022 with Kent & Jordan | 1 Hour

  3. How to Build a Home Lab for Infosec with Ralph May | 1 Hour

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Found a video that walks you through the process of setting up an Active Directory Lab for hacking. I wouldn’t be able to do this without a starting point.

LINKS

  1. Mitre ATT&CK Matrix

  2. How to Build an Active Directory Hacking Lab

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Last episode was about my crazy study plan, or lack of one. Time to put together a proper study plan. One that works.

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Last episode was about my crazy study plan, or lack of one. Time to put together a proper study plan. One that works.

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Time to jump into my crazy, unorganized study process. Trying to study or learn the CISSP, pentesting, risk assessments, and keep up with my current certification requirements. I’ve also signed up for two Antisyphon classes.

Beginner Classes

  1. SOC Core Skills

  2. Getting Started In Security With BHIS and Mitre Att&ck

  3. Active Defense & Cyber Deception

Advanced Classes

  1. Introduction to Pentesting

  2. Red Team: Getting Access

  3. Professionally Evil CISSP Mentorship Program

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Time to create a policy for asset inventory. This will help us define what we need in our asset inventory. It will also help us define what we need in our procedures. The process we use to manage the inventory.

LINKS

  1. Enterprise Asset Management Policy Template

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

We’re scanning our network with runZero to get an inventory of devices. What did it find? What can we learn from this inventory? How well does it work?

LINKS

  1. runZero - Active discovery tool for asset inventory

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

We’re in the process of implementing the CIS controls. This will take time. We’re also very busy. Are there any gaping security holes that we need to fix? Do we have any security controls in place? Can we wait to implement the CIS controls?

LINKS

  1. runZero - Active discovery tool for asset inventory

  2. Enterprise Asset Management Policy Template

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Time to get an accurate inventory of the devices on our network. Once we have an inventory, we can move on to policies and procedures.

LINKS

  1. runZero - Active discovery tool for asset inventory

  2. Enterprise Asset Management Policy Template

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Time for another maintenance episode. This time were going back to the CIS Controls. This time were using version 8. Hoping to implement the first 7.

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Time to start learning Azure. We’ve had Azure AD and Microsoft 365 for years. Just added Azure to the mix. Lots to learn.

LINKS

Free Azure Account

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Time to go down the OSINT rabbit hole. What is it? What are we looking for? What are some of the tools we can use?

LINKS

  1. Kali Linux

  2. Shodan

  3. Spiderfoot

  4. theHarvester

  5. OSINT Framework

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Time to dig in and start learning the tools.

LINKS

  1. Kali Linux

  2. Nmap

  3. Shodan

  4. Gophish

  5. Zap

  6. Burp Suite

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Got a new job. This makes our lab environment more important than ever. Some labs will be for me. Others will be for work. We need to make sure everything is working. We also need good documentation. No more messing around.

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

There could be a new job in my future. Before that happens, we need to organize our IT. We’re looking at patching, Microsoft Defender for Business, and data recovery.

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Time for some new projects. Still have a few things to do with Wazuh. Once that’s done, I’ll need something new to work on. Python is the big one. Seems everyone is asking for Python skills these days.

LINKS

  1. The Azure Sandbox – Purple Edition

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Wazuh! It works! Not only does it work, but it’s awesome. We’re also covering detection as part of a security program. You can’t have good security without detection. We’re also throwing in a bit of VMware management. Can’t manage labs in VMware without some management know how.

LINKS

  1. Wazuh · The Open Source Security Platform

  2. Lab Instructions - Emulation of ATT&CK techniques and detection with Wazuh

  3. Sysmon config from SwiftOnSecurity

  4. Wazuh Server Rules

  5. Video: Installing The EDR Solution Wazuh

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Time for more Wazuh and Sysmon. This time we’re adding Atomic Red Team for testing. This is starting to look really good. Unfortunately we’re missing something.

LINKS

  1. Wazuh · The Open Source Security Platform

  2. Lab Instructions - Emulation of ATT&CK techniques and detection with Wazuh

  3. Sysmon config from SwiftOnSecurity

  4. Wazuh Server Rules

  5. Video: 163. Use Sysinternals Sysmon with Wazuh: The Swiss Army Knife for Windows Monitoring

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

We’ve packed a lot into one episode. We’re reviewing Dorothy’s lab, Wazuh & Sysmon and Microsoft 365. We do have some good news. Got Sysmon installed. We also have access to good Microsoft 365 instructions and a book. We’re moving in the right direction.

LINKS

  1. Sysmon Installation

  2. Microsoft 365 Business Premium Partner Playbook and Readiness Series

  3. Office 365 for IT Pros

  4. ITProMentor: The Microsoft 365 Consultant’s Bundle

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

There are many ways to answer this question. First, you need some skills. For this ongoing project we’ve decided to focus on Windows. Server 2019, Windows 10 and 11, and a bit of networking for good measure. One has to start somewhere.

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

We’re in the process of testing Microsoft Defender for Business. This includes vulnerability management, endpoint detection and response and a lot more. This could be the security solution we’ve been looking for.

LINKS

  1. Overview of Microsoft Defender for Business

  2. Video: Onboarding Windows 10 devices to Defender for Business

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Of course security solutions aren’t 100% perfect. So, why are people building security programs around perfect solutions?

LINKS

  1. YouTube Video: "Prevention First": An Approach to Cybersecurity w/ Minerva Labs!

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Time to go deeper down the Sysmon rabbit hole. Looks like Wazuh does a lot more than we thought.

LINKS

  1. Sysmon

  2. Wazuh

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Time to start thinking about our Sysmon deployment. There are a lot of moving parts to this project. It won’t be a simple install on Windows 10. That’s just a small part of the project.

LINKS

  1. Security Onion

  2. Getting started with Elastic Stack

  3. Sysmon

  4. Wazuh

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

We’re conducting a mini security audit. We’ve got our short list of things we’re doing for security. Are they working for us? Are there things we need to change? How are we doing?

LINKS

  1. Security Onion

  2. Getting started with Elastic Stack

  3. Sysmon

  4. AppLocker

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

It works! We have application allow listing with AppLocker. Pushed out the settings from Intune. This is awesome!

NOTE: No links to instructions for Intune and AppLocker. I need to find good documentation or write my own.

LINKS

  1. Security Onion

  2. Getting started with Elastic Stack

  3. Sysmon

  4. AppLocker

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

We’ve come up with a short list of things we should do for security. These are industry recommended solutions. They make it extremely hard for an attacker to get in.

LINKS

  1. Security Onion

  2. Getting started with Elastic Stack

  3. Sysmon

  4. AppLocker

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Security in a lab is one thing. Security in the real world is something else. Time to start thinking of real world solutions.

LINKS

  1. Pay What You Can Training - List of Antisyphon training that includes John Strands classes.

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Do you know what devices are on your network? Do you have an accurate inventory? Discover what’s really connected to your network with Rumble.run. This is an awesome network discovery tool.

LINKS

  1. Rumble.run

  2. Nmap - Nice but not as cool as Rumble

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

Time for another round of security training. This time it’s John Strands Cyber Deception class. We’re also talking about job hunting Jason Blanchard style.

LINKS

  1. Active Defense & Cyber Deception w/ John Strand - Starts 1-24-22

  2. Jason Blanchard: Twitter Account

  3. Jason Blanchard: Twitch Account

FIND US ON

  1. Twitter - DamienHull

  2. YouTube

View Details

A proper explanation of our Fortinet firewall licensing. Goals, tasks, and lessons learned.

LINKS

  1. FortiGate 60F - We have two of these.

  2. Overlay Controller VPN (OCVPN)

FIND US ON

  1. Twitter - DamienHull

View Details

Time to get licenses for our Fortinet firewalls. They expire next month. We’re also planning for next year.

LINKS

  1. Free Python Class - Focused on network automation.

  2. FortiGate 60F - We have two of these.

FIND US ON

  1. Twitter - DamienHull

View Details

We’re talking Python classes, Wi-Fi issues, security training and more. We’re also beginning to plan for next year. Yup, the new year is right around the corner.

LINKS

  1. Free Python Class - I’m not ready for this class. Might go back to it when I’ve learned the basics.

FIND US ON

  1. Twitter - DamienHull

View Details

What’s next for our lab? What should we focus on? What kinds of things can we add to it?

FIND US ON

  1. Twitter - DamienHull

View Details

It use to take us forever to build a lab. Lots of documentation, testing and planning has changed that. Big step in the right direction.

FIND US ON

  1. Twitter - DamienHull

View Details

We need to build a new network. One that includes a Firewall, Windows Domain Controller, Windows 10 and Windows 11 workstations. This will be our starting lab. One we can add to in the future.

FIND US ON

  1. Twitter - DamienHull

View Details

As the title says, we’re analyzing logs with Logwatch. Big step in the right direction. Started this back in episode 218. Couldn’t get email to work. It works! Not only does it work, but we can catch evil.

LINKS

  1. Logwatch

  2. Postfix

  3. How To Install and Configure Postfix on Ubuntu 20.04

  4. Rsyslog TLS configuration : Ubuntu simple step-by-step

FIND US ON

  1. Twitter - DamienHull

View Details

Found a new tool called Netbox. This tool was designed to document large data centers. We’re trying to use it to document our network. Lots of cool features and lots of moving parts to think about.

LINKS

  1. What is NetBox - FREE Network Documentation System?

  2. i HATE network documentation....but NetBox might help // ft. Jeremy Cioara

  3. Installing Netbox in 10 Minutes or Less

FIND US ON

  1. Twitter - DamienHull

View Details

Time to analyze our cloud server logs. For that we’re going to use Logwatch. This will require the Postfix SMTP server for sending email. We also need the UFW firewall. Once again, lots of moving parts.

LINKS

  1. Logwatch

  2. Postfix

  3. How To Install and Configure Postfix on Ubuntu 20.04

FIND US ON

  1. Twitter - DamienHull

View Details

We’re talking Windows 11 and VMware Updates. Did an Install of Windows 11 in our VMware environment. This required a virtual TPM. Moved on to VMware updates. This included updates to ESXi and VCSA. Lots of moving parts to these projects.

LINKS

  1. Create a Virtual Machine with a Virtual Trusted Platform Module

  2. Configuring and Managing vSphere Native Key Provider

FIND US ON

  1. Twitter - DamienHull

View Details

We’re trying to get the most out of 365. That includes learning how to use apps like Teams, Planner, OneNote and more. There’s a lot of moving parts to this. Installing, configuring, training, standards and more. We’re still at the beginning stages of this process. We have a long way to go.

FIND US ON

  1. Twitter - DamienHull

View Details

Time to plan for a new Wi-Fi Access Point. We’re replacing our old Asus Wi-Fi router with a Fortinet Access Point. What are the risks? How much downtime will there be? What’s our backout plan?

FIND US ON

  1. Twitter - DamienHull

View Details

Time to add another DNS server to the network. This could be considered a small project. It still has a lot of moving parts. What OS should we use? What hardware should we use? Can we manage another server?

FIND US ON

  1. Twitter - DamienHull

View Details

Dorothy want’s to speed up the installation of Windows Server 2019 in the lab. We’re looking into an automated install. We’re also looking at all the steps leading up to the install. How do we connect to our VMware server? How do we create a VM? How do we make everything faster?

FIND US ON

  1. Twitter - DamienHull

View Details

Yes we can! We’re using Intune, Azure AD and Automox to manage two laptops. The same process we use for two could be applied to 1,000. Settings, applications and updates can all be pushed out with a few mouse clicks.

FIND US ON

  1. Twitter - DamienHull

View Details

I’ve had 3 job interviews this year. Here’s what I’ve learned so far.

FIND US ON

  1. Twitter - DamienHull

View Details

We’re focusing on basic Microsoft 365 security. We’re also reviewing our Microsoft 365 Business Premium Licensing.

LINKS

  1. m365maps.com

  2. Basic Security Set Up for Microsoft 365

FIND US ON

  1. Twitter - DamienHull

View Details

Got a nice email from a listener who happens to be managing Microsoft 365. He made some interesting suggestions. This got me thinking about how we use 365. Ended up falling down the rabbit hole. We still have a lot to learn about Microsoft 365.

LINKS

  1. CBT Nuggets

  2. Connect Azure Active Directory (Azure AD) data to Azure Sentinel

FIND US ON

  1. Twitter - DamienHull

View Details

Time to review our IT management process. We have some work to do.

FIND US ON

  1. Twitter - DamienHull

View Details

The Cybersecurity & Infrastructure Security Agency has a mandate for the print spooler service vulnerability. This mandate includes step by step instructions for fixing the vulnerability. For people like us, this is awesome!

LINKS

  1. us-cert.cisa.gov - Their website.

  2. Emergency Directive 21-04

FIND US ON

  1. Twitter - DamienHull

View Details

PrintNightmare and the out of band patch forced us to change. We needed to evaluate the way we handle out of band patches. Fortunately for us, this wasn’t a big deal.

LINKS

  1. CVE-2021-34527 - For those that want to dive a little deeper.

  2. Sans Internet Storm Center Podcast - Episode that talks about PrintNightmare

FIND US ON

  1. Twitter - DamienHull

View Details

Time to look for a new job and brush up on my skills. Following Jason Blanchard’s tips on job hunting. I’m also trying to improve my SIEM skills. A skill that I’ve seen a few job postings.

LINKS

  1. Jason Blanchard - Twitter

  2. Jason Blanchard - Twitch

  3. ELK - Free SIEM Solution

  4. Install ELK on Ubuntu 20.04 Focal Fossa Linux - The instructions I followed to setup ELK

FIND US ON

  1. Twitter - DamienHull

View Details

A couple episodes ago, we got to interview John Strand of Black Hills Information Security. He gave us a lot of really good information. In our last episode, we talked about the technical half of the interview. In this episode, we’re looking at the training he recommended.

LINKS

  1. Training Trail - Organized list of training from Johns training company Antisyphon Training

  2. Antisyphon Training Courses - This is where Johns training lives

  3. Hack The Box

  4. Holiday Hack Challenge 2020 - No Answers

  5. Past Holiday Hack Changes

  6. Answers to the 2019 Holiday Hack Challenge

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

In our last episode, we interviewed John Strand of Black Hills Information Security. Now it’s time to analyze what he said. For this episode, we’re looking at the technical side of the interview. We’re saving the training portion for another episode.

LINKS

  1. The Essential 8 from Australia

  2. DeepBlueCLI

  3. Sysmon

  4. Elastic Stack - ELK

  5. Security Onion

  6. LogonTracer

  7. sigma

  8. JPCERT Tools

  9. JPCERT: Tool Analysis Results Sheet

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Yes, we got to Interview John Strand from Black Hills Information Security. He was kind enough to donate his time. We covered first steps to improving security, best practice, tools and training.

Links to some of thing things John mentioned.

  1. LogonTracer

  2. sigma

  3. JPCERT Tools

  4. JPCERT: Tool Analysis Results Sheet

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We’re looking into version 8 of the Critical Security Controls.

LINKS

  1. The 18 CIS Controls

  2. SANS: CIS Controls v8

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

This is episode 200. We’ve come a long way in 200 episodes.

LINKS

  1. Project Management for the Unofficial Project Manager

  2. Shared Calendar - Teams, Sharepoint and Calendar

  3. Planner - Teams, Sharepoint and Planner

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We’ve been busy. We figured out how to push an emergency patch. Then version 8 of the CIS Critical Security Controls was released. Simplified and reorganized. We’re slowly working our way through the list. Lots to do.

LINKS

  1. Automox - Our patch management tool

  2. CIS Controls Version 8

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

I did a lot of work to get our VMware server environment configured. Turns out we’re running out of drive space.

LINKS

  1. Our VMware Server - mitxpc.com

  2. Grafana dashboard for monitoring vCenter

  3. Storage requirements for vCenter

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Our VMware server is back online with new NVME drives. This project was more work than we had planned for. Still, typical for an IT project. They never go the way you expect them to.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

I wanted to “Release the hounds” with bloodhound. I managed to get it working. That’s about all I can say. It was way more work than I thought it would be.

LINKS

  1. Attacking Active Directory - Bloodhound - This guy knows bloodhound

  2. BadBlood - Generate random users and groups in AD

  3. Kali Linux - Incase you need it

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Our VMware server is offline. We’re missing a part we need to install the drives. While we track that down, we need something to do. Planning labs, learning Visio, and project management are on the todo list.

LINKS

  1. Project Management for the Unofficial Project Manager

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Time to do a security test of Active Directory. Going to be using Bloodhound, Plumhound, mimikats and Ping Kastle. Never used them before. First time for everything.

LINKS

  1. Bloodhound

  2. Plumhound

  3. Mimikatz

  4. PingCastle

  5. BadBlood

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Running into some issues with our VMware ESXi server. The not so good news, we don’t have enough drive space. The good news, we can fix that. The really good news, we have way more CPU power than I thought.

LINKS

  1. Our VMware Server: Supermicro SYS-E300-9D-8CN8TP

  2. Alternative VMware Server: Supermicro AS-E301-9D-8CN4

  3. SUPERMICRO DUAL NVME M.2 PCI-E 3.0

  4. SUPERMICRO 1U PCIE X8 RISER CARD (RSC-RR1U-E8)

  5. SUPERMICRO DUAL NVME M.2 PCI-3.0 - Amazon

  6. Samsung (MZ-V7S1T0B/AM) 970 EVO Pluss SSD 1TB

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We just put up a tools section on our website. It’s a list of tools we use and some we would like to use. Most are security tools. Things you wouldn’t see outside of security.

LINKS

  1. Tools

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Looks like we need to learn more about Windows Hello. Dorothy got locked out of her laptop. Couldn’t reset her Windows Hello pin.

LINKS

  1. Microsoft Doc: PIN reset - Didn’t work for me.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We’re using our project management process to migrate to new iPhones. It might seem like a simple process. It isn’t. Not when you have to migrate authentication apps for 2FA. If we’re not carful, we could lock our selves out of things.

LINKS

  1. Book: Project Management for the Unofficial Project Manager

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We’re working on a project management process. Turns out we’ve been doing it wrong. A good book and few simple steps is all we needed.

LINKS

  1. Book: Project Management for the Unofficial Project Manager

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Our patch process is in place. Time to do a quick weekly patch review. We’ve got this process down to a couple of minutes. That’s it. That’s how long it takes us to review our patch process.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Our endpoint management process is awesome. We can push settings to Windows 10 and we’ve got patching under control. A weekly email tells us how we’re doing. We can manage our systems while sipping coffee.

LINKS

  1. Microsoft Endpoint Manager

  2. Automox

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

It’s a new year with new goals. This year we’re focusing on IT management, Security and certifications. We’re also trying our best to finish our endpoint management project. We won’t be able to automate everything. Not yet anyway.

LINKS

  1. Microsoft Endpoint Manager

  2. Automox

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

No break for us this year. We’re diving strait into workstation and laptop management. We’re doing this with Microsoft Endpoint Manger and Automox.

LINKS

  1. Microsoft Endpoint Manager

  2. Automox

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

You wake up, the servers down and there’s no DR plan. Good times! Nothing teaches you more then a disaster you weren’t prepared for. On the bright side, there’s SOC training to prep for.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

How can Microsoft 365 business premium help us? How can it make our lives easier? Are their features we should be using? We migrated to 365. We got the basics working. Now it’s time to dig a little deeper.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

The end of the year is right around the corner. Time to start thinking about next year. We’re also adding another tool to our toolkit.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Learning some interesting things about ITIL and Microsoft 365 conditional access. ITIL will help us organize Section 9. 365 conditional access will help us lock down Azure AD. This should make it harder for the hackers to get in.

LINKS

  1. ITIL - Wikipedia Article for those who don’t know what this is

  2. What is Conditional Access?

  3. Manage emergency access accounts in Azure AD

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

This week we’re working on DR plans and Password Polices. The DR plan is for our DNS servers. We can’t afford to lose them. The password policy is about reducing risk with longer passwords. We’ve also got another tool for the toolbox.

LINKS

  1. psftp

  2. SANS Polices

  3. SANS Password Policy - Link to the PDF

  4. Wireshark

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We don’t know much about 365 conditional access polices, but they look awesome. We’re also adding tools to the toolbox and deploying new devices. No rest for the crazy.

LINKS

  1. What is Conditional Access?

  2. What are security defaults?

  3. Nmap

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Our Microsoft 365 has failed logins from Russia. What do we do? Time for a risk assessment. We’re going to make our 365 more secure.

Microsoft 365

  1. Error Codes - Lookup the error codes

  2. Security Defaults

DeepBlueCLI

  1. DeepBlueCLI - The GitHub site

  2. Webcast: Attack Tactics 7 – The Logs You Are Looking For - Covers DeepBlueCLI

  3. Log Analysis Part 2 – Detecting Host Attacks: Or, How I Found and Fell in Love with DeepBlueCLI - Good article

Sysmon

  1. Getting Started With Sysmon

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We’re talking about weekly tasks, 365 authentication issues, and training. On the training front we have ITIL 4, SOC and Windows 10.

LINKS

  1. The SOC Age Or, A Young SOC Analyst's Illustrated Primer - Presentation from BHIS

  2. SOC Core Skills w/ John Strand

  3. ITIL 4 Foundation Course

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

This week we connected Jitibt to 365, found hidden licensing and learned how to be a SOC analyst. You can now contact us by sending email to support@section9.us.

LINKS

  1. Black Hills Information Security Youtube Channel

  2. CIS Benchmarks

  3. Jitbit

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We’re learning how to manage emergency accounts and data retention in 365. The good news, Microsoft has some pretty cool tools for data retention. The bad news, retention policies are a bit confusing.

LINKS

  1. MJFChat: How to Handle Office 365 Backups

  2. Microsoft 365 Retention Policies

  3. Manage emergency access accounts in Azure AD

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We’re slowly creating our test environment for Microsoft 365. We’re also looking at ways we can backup 365. Slow and steady wins the race. We’re two people learning to be 365 admins. Breaking something could equal a lot of downtime. We can’t afford downtime.

LINKS

  1. MJFChat: How to Handle Office 365 Backups

  2. Microsoft 365 Retention Policies

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We did it! We migrated to 365. There were a few bumps along the way. Nothing major. We’re doing a quick review of the process and next steps. We have to learn how to be 365 admins.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Time to prep for a long winter with Covid-19. We want a nice environment for IT projects and studying. We still need to finish our Windows 10 cert. We’ve got other Microsoft 365 certs to look at. I’m finally going to get the ITIL cert. Lots to do this winter.

LINKS

  1. Microsoft Learn

  2. ITIL Training - This is the one I’m looking at. I’m sure there are others.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Yup, another 365 migration review. Overall we’re doing pretty good. We still need to make sure we’re moving in the right direction. Are we achieving our goals? What are our goals? How are we doing? How do we feel about the project?

LINKS

  1. Microsoft 365: Getting started - Even at this stage this is still relevant

  2. Plan your setup of Microsoft 365 for business - We’re close to running the setup wizard

  3. Microsoft 365 identity models and Azure Active Directory - Windows 10 Authentication

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We’re starting over again. Yup! Two steps forward, one step back. This time it’s not so bad. We found more documentation on Microsoft 365. Based on this, we’ve decided to review the signup process. The only way to do that is to start over.

LINKS

  1. Microsoft 365: Getting started

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

As the title says, we got it wrong. It happens. Unfortunately this is not a topic you want to get wrong.

LINKS

  1. SANS Webcast: Why as a DoD Contractor Do I need to Be CMMC Compliant

  2. Certified Professionals and Assessors

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We’re moving forward with our Microsoft 365 migration. Signed up for an account using the 365 Business Premium license. Setup admin accounts for our selves. Getting ready to setup test accounts with Business Premium Licenses.

LINKS

  1. Plan your setup of Microsoft 365 for business - We used this document

  2. Get started - More documentation on Microsoft 365

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

You can’t have a good security program without Polices and Procedures. We’re not the best at writing Polices. Truth is, we’re like most people. Where do I start? How do I write a policy?

Lucky for us, there are resources out there to help us get started. This is a big step in the right direction for us. However, we’re just scratching the surface. We have a long way to go.

SANS Polices

  1. Security Policy Templates - All of the SANS policies

  2. Software Installation Policy - We will be using this

  3. Password Protection Policy - We will be using this

  4. Pandemic Response Planning Policy - Never thought we would need this

Security Resources

  1. Small Business Cybersecurity Corner

  2. Cybersecurity Resources Road Map

  3. SANS CIS Critical Security Controls: Guidelines

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Another episode on migrating to Microsoft 365. Most organizations are using it. It’s almost a standard in the business world. Should we be using Microsoft 365? Can we?

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Time to start thinking about our Critical Security Controls audit. This will include policies and procedures. We can’t avoid good documentation.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Lots to talk about in this episode. We’re using pfSense firewalls in our virtual lab environment. We’ve been documenting things on slab.com. And we’ve been evaluating cloud security.

Links

  1. pfSense

  2. slab.com

  3. CMMC - Cybersecurity Maturity Model Certification

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Time to review the security of notion.so. They are responsible for protecting our data. We are responsible for putting it there. We need to make sure their security meats our requirements. If they don’t, we’ll have to look for a different solution.

LINKS

  1. notion.so

  2. notion security - an overview of their security

  3. 9 Common Questions About SOC 2 Compliance

  4. Small Business Information Security: The Fundamentals

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We’re taking a step back and focusing on documentation. We spend a lot of time looking things up. Time that could have been spent learning new things. Better documentation means less time spent looking things up. To help fix this problem, we’re looking into notion.so.

Notion.so is a web application designed for things like documentation. We’re still in the testing phase. So far, things are looking good. We have a long way to go.

LINKS

  1. notion.so

  2. notion security - an overview of their security

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We signed up for the Purple Teaming class put on by Black Hills Information Security. It was a bit overwhelming, but we learned a lot.

LINKS

  1. Class Git Hub Repository

  2. Sysmon

  3. The Hunting ELK

  4. BadBlood

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We’re doing a quick review of the Verizon Data Breach report. We’ere also looking at Micosoft 365 options. We’d like to migrate to it if we can.

LINKS

  1. Verizon Data Breach Report

  2. Microsoft 365 for business

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Black Hills has put out another amazing blog post. This one is titled “A Pentester’s Voyage - The First Few Hours”. We’re not pentesters, but we can learn a lot from the process.

LINKS

  1. A Pentester’s Voyage - The First Few Hours

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We need to make sure our projects are useful. To help us do that, were mapping our projects to the Critical Security Controls. We’re also looking at the Black Hills presentation on How to Build a Home Lab. This is full of good information.

LINKS

  1. Security Onion

  2. Black Hills - How to Build a Home Lab

  3. The Critical Security Controls

  4. Atomic Red Team

  5. Scythe

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Its been an interesting week. Wireshark saved me at work. Wasn’t expecting that. I’ve been using the Security Onion training. Learning how to set it up and install test data. I’ve also realized that a security lab needs evil. How do you look for evil if you don’t have any?

LINKS

  1. Security Onion

  2. Windows logging Cheat Sheets

  3. Black Hills - How to Build a Home Lab

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Good news. Everything works! We still have to manage IP address, subnets, vlans, firewall rules and more. That hasn’t changed. What has changed is that it all works. Our hard work is paying off.

LINKS

  1. Malware Archaeology

This website includes the WindowsLogging Cheat Sheet, the Windows Advanced Logging Cheat Sheet and the Windows Sysmon Logging Cheat Sheet.

  1. Sysmon

  2. Sysmon Config

  3. Webcast: Think You’re Compromised? What Do We Do Next?

Black Hills Information Security webcast. This is where I got most of my info.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

That’s right, we have a new VMware server. We also have a new set of problems. How do we manage VMware? How do we access it over a vpn connection? What Fortinet firewall rules do we need? What IP address do we need? What subnets do we need?

We would love to start our Windows and security projects. That’s not going to happen until we get everything under control. Time for more documentation and process creation.

OUR VMWARE SERVER

VMWARE CERTIFIED - Supermicro SYS-E300-9D-8CN8TP

  1. Processor: 8 core Xeon

  2. RAM: 128GB

  3. M.2 SSD: 250GB

  4. 2.5” SSD: 500GB

VMWARE VIDEOS - We using version 7. The process is the same.

  1. Installing Vmware ESXi 6.7 Tutorial

  2. How to install VMware vSphere Hypervisor | ESXi 6.7 Free Install

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Time to document our Fortinet equipment and plan for our VMware server. Dorothy will do the documentation. She needs to see how the network was put together. Once some of that’s done, we can pick out a server. The sooner we get the server the better.

LINKS - We’re panning to get one of these servers

  1. VMWARE CERTIFIED - Supermicro SYS-E300-9D-8CN8TP

  2. VMWARE CERTFIED - SuperMicro SYS-E200-8D

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Meraki firewall is out, Fortinet equipment is in. It works!

Things to think about:

  1. How many devices do you have?

  2. How many Subnets will you need?

  3. How many switch ports do you need?

  4. What kind of features do you need?

  5. What kind of security do you want?

  6. What’s high priority?

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We have a VMware server. It’s kinda wimpy with only 32GB of RAM. We need more power. More power means we can do more things. We’re looking at hardware options.

LINKS - Hardware Options

  1. VMWARE CERTIFIED - Supermicro SYS-E300-9D-8CN8TP

  2. VMWARE CERTFIED - SuperMicro SYS-E200-8D

  3. More Virtualization Solutions from mitxpc.com

  4. Server Monkey - Refurbished Servers

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We installed Dorothy’s FortiGate Firewall. It works! Not only that, but we can see network traffic. What online apps are we using? What websites do we go to? Once we have this information we can plan for better security.

Note: We’ve given up on FortiClud Manager and FortiAnalyzer Cloud. For now.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

It Works! Well, sort of. Our stack of Fortinet equipment is working. Unfortunately we’re not sure why. We just know it works. Another bit of good news is that we managed to do all the configuration from FortiManager Cloud. This is a big step in the right direction. We might make our April deadline after all.

We still have a long way to go.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Another Saturday, another issue with our Fortinet project. We’re not sure what happened. We had plans to configure the switch and the wireless access point. It wasn’t meant to be.

The firewall lost its connection to FortiManager Cloud. We had to call support for this one. Then our switch configuration wouldn’t work. Couldn’t push the change from FortiManager Cloud to the device.

Again, two steps forward, one step back.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Can we do a basic Fortinet firewall configuration? Yes we can. The trick is to start simple and work your way up to fancy. We still have no idea how to use the FortiManager Cloud configuration tool. We don’t know what to do with hardware switch interfaces. We’re not sure why vlan’s weren’t recommended. This is a two steps forward, one step back kind of episode.

At least we can create a basic configuration on the local device. That’s a big step in the right direction.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Time to get things connected to the cloud. FortiManager is Fortinets enterprise management solution. They have two versions. On prem and cloud. We went with the cloud version. Getting things connected was a bit tricky. Lucky for us Fortinet tech support is awesome.

LINKS

  1. FortiManager

  2. FortiManager Cloud

  3. SSL VPN Vulnerability

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We’re unboxing and connecting our Fortinet gear. There’s a lot to do before we start configuring our new Firewalls. Once again, we chose to go with the FortiGate 60F. This is the device we’re starting with. We will be going over each devices as we get to them.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Our FortiNet gear is on the way. It’s time to start thinking about our network design. What kind of traffic do we want going in and out of our network? Where do we place our servers? Do we need new IP space? Lots to think about before we deploy anything.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

After carefully examining our options, I ordered our Fortinet equipment. How did we choose this hardware? What factors go into selecting a firewall? This is an expensive perches. Make sure you do your home work before you buy anything.

LINKS - These are the devices we’re getting

  1. FortiGate 60F Data Sheet - We’re getting 2 of them.

  2. ForitSwitch 108E-FPOE - Link takes you to a list of 100 series switches.

  3. FortiAP 223E - Link takes you to a list of Standard AP models.

  4. Fortinet’s 360 Protection Bundle - We’re getting one year of 360 protection.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We’re moving forward with our Fortinet firewall project. We’ve picket out a firewall, switch and access point. There’s still a lot of work to do before we order anything. We’re working with the Cisco Network Life Cycle. This will help us organize the project. We don’t want to miss anything.

LINKS

  1. FortiGate 60F Data Sheet - We’re leaning in this direction.

  2. ForitSwitch 108E-FPOE - Link takes you to a list of 100 series switches.

  3. FortiAP 223E - Link takes you to a list of Standard AP models.

  4. Fortinet’s 360 Protection Bundle - We’re getting this.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We’re getting a new firewall! That’s one of several projects happening early next year. Also on the list is our Azure migration and our certifications. We’re applying our relaxed company culture to these projects. We don’t want any unnecessary pressure on us. A lot of companies are go go go, get it done yesterday. We’d like to take our time. To do that, we’re giving our selves a lot of time. Time to make sure we get these projects done right.

Did I mention we’re switching from Meraki to Fortinet?

LINKS

  1. Fortinet.com

  2. FortiGate 60F Data Sheet - We’re leaning in this direction.

  3. FortiGate Product Matrix

  4. avfirewalls.com - I haven’t talked to them yet, but the website looks good.

  5. Fortinet’s 360 Protection Bundle - We’re getting this.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

This episode is about PlexTrac, security audits and company culture. We had planned to do security audits for others as part of our business. How can we do a security audit if we can’t even produce a podcast properly? Some of our show’s have been published with the wrong information. Not a big deal, but it is a sign that we’re doing things wrong.

We need a company culture that includes things like procedures. A company culture that promotes best practice. We’re working on it.

LINKS

  1. PlexTrac

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Time to start planning for the Windows 10 certification. The modern desktop administrator associate. Why do we want this cert? What’s on the test? How do you study for it? What are some good study materials? We cover all of that. This isn’t our first cert test.

LINKS

  1. Microsoft 365 Certifiied: Modern Desktop Administrator Associate

  2. Modern Desktop Administrator learning path - Seems to include some free training

  3. Microsoft 365 - Modernize your enterprise deployment with Windows 10 and Office 365 ProPlus - Free training from Microsoft

  4. Windows 10 Exam Ref MD-100 - Microsoft book on Amazon

  5. CBT Nuggets: Reducing the Barrier to Learning - Info about monthly pricing

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We did okay this year. Managed to take a few steps in the right direction. Automated patching with Automox was one of them. It’s now time to start planning for 2020. We have a few certs and projects we want to work on. Microsoft is pushing cloud. Looks like we’re moving in that direction.

One more thing. Azure Works!

LINKS

  1. Azure Security Engineer Associate

  2. Microsoft 365 Certified Fundamentals

  3. Microsoft 365 Certified: Security Administrator Associate

  4. CBTnuggets: What You Need to Know about the New Windows 10 Exams

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We’re running away to Hawaii for a week. What do we do with our systems? Something to think about when you’re IT team is just two people. Just like everything else we do here at Section 9. We need to plan for this.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

The Microsoft Azure tutorial we’ve been following is more work than we thought. Accessing the Windows server 2016 VM in Azure is tricky. They want this directly connected to the internet with RDP wide open. That might work for testing. That’s not going to cut it log term. We need to lock this down. Easier said than done.

LINKS

  1. Create an Azure Bastion host

  2. Manage virtual machine access using just-in-time

  3. Tutorial: Create and configure an Azure Active Directory Domain Services instance - The tutorial we’ve been following.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Thanks to Jack, a listener of the show, we’re looking at Azure pricing. What are we paying for? We’re not sure. Microsoft says they’re being transparent with Azure pricing. I’m not sure sure about that.

LINKS

  1. Azure Pricing Calculator

  2. Azure Support Plans

  3. Pay-As-You-Go

  4. Intro to the Cisco Lifecycle Services Approach - PDF

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

More Azure! We’ve added a custom domain and configured a password rest option. We’ve also made Dorothy an owner of the Azure subscription. It took a bit of research to get this done. The tutorial is good, but it doesn’t cover everything. We still have a long way to go.

LINKS

  1. What is Azure Active Directory Domain Services?

  2. Tutorial: Create and configure an Azure Active Directory Domain Services instance - This is the tutorial we’re using

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Time to learn about Azure. Last episode we talked about Azure Active Directory Federated Services. What we really want is Azure AD DS.

LINKS

  1. What is Azure Active Directory Domain Services?

  2. Tutorial: Create and configure an Azure Active Directory Domain Services instance - This is the tutorial we’re using

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

We’re looking into new technology like Azure AD FS. Before we can start new projects, we need to get the operational side of things in order. We’ve done a good job of clearly defining a patch management process. It’s time to work on change, incident and project management.

LINKS

  1. Deploying AD FS

  2. Azure AD Connect

  3. What is ITIL Incident Management?

  4. Change Management

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

Are fancy security solutions like Palo Alto firewalls, ExtraHop or LogRhythm going to keep you secure? By them selves, no. It doesn’t matter what the vendor says. There’s no such thing as a security solution that magically saves the day. A good solid security process and best practice is the key to any security program.

FIND US ON

  1. Facebook

  2. Twitter - DamienHull

View Details

How do we do section 9 projects, keep systems running, and record a weekly podcast while having full time jobs? We need the right combination of tools and process.

LINKS

monday.com

lucidchart.com

jitbit.com

FIND US ON

  1. Facebook

  2. Twitter - DamienHull