Maik Ro Profile picture
May 1 β€’ 11 tweets β€’ 9 min read Twitter logo Read on Twitter
Day 4️⃣

Building the πŸ’™ Blue Team πŸ’™ course in public

Security Infrastructure Overview: Image
For the Course, I have planned 3 sections

1. Active Directory (Setup / Monitoring / Attack Vectors)

2. Security Infrastructure (SIEM / SOC / IDS / VPN / Firewall etc)

3. External Servers/Services (Cloud / Webserver/-services / Container)
Our focus today is on Topic #2 - Security Infrastructure

The focus of the course is on SOC analysts (level 2) and those who want to become one

We will have to define what that means though:
Typically, SOC lvl 1 analysts are able to:
β€’ detect threats with predefined rules and subsequently follow playbooks/SOPs
β€’ forward cases/tickets to level 2 analysts
β€’ document & summarize past incidents
β€’ search internet/dark web for new TTPs / threats

we start exactly here
I assume if you want to take the course you are able to do those tasks, OR can learn quickly πŸƒβ€β™€οΈ

We will:
β€’ the creation of Standard Operating Procedures (SOPs) / Playbooks
β€’ case software handling & setup
β€’ log generation / ingestion
β€’ SIEM setup from scratch & automation
β€’ Rules / Alerts / Protection automation
β€’ Network Setup / Segmentation / Analysis
β€’ Intrusion Detection/Protection System setup
β€’ Proxy setup
β€’ VPN setup
β€’ Hard-/Software firewalls and their setup

among others.
Currently, the tech stack looks something like this:

SIEM - @wazuh
IDS - @snort / maybe suricata
proxy / local DNS - pihole / maybe @squidproxy
VPN - @wireguard or @OpenVPN
case management - @TheHive_Project or @Jira
firewall - opensense or pfsense
malware lab - flareVM, REMnux
@wazuh @snort @squidproxy @OpenVPN @TheHive_Project @Jira The idea is that most / all of the tools are available for free so if you need to set this up for a company you only have to pay for hosting/traffic/storage

We will go through the setup, configuration and use-cases
@wazuh @snort @squidproxy @OpenVPN @TheHive_Project @Jira Question: Which tool / software would you want to see added?
@wazuh @snort @squidproxy @OpenVPN @TheHive_Project @Jira If you liked this thread
feel free to follow me @maikroservice for frequent updates on the course I am building

If you want to have updates with more text/pictures head to:
subscribepage.io/maikroservice-…

β€’ β€’ β€’

Missing some Tweet in this thread? You can try to force a refresh
γ€€

Keep Current with Maik Ro

Maik Ro Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @maikroservice

May 2
Day 5️⃣

Building the πŸ’™ Blue Team πŸ’™ course in public

External Servers & Services: Image
For the course I have 3 sections

1. Active Directory (Setup / Monitoring / Attack Vectors)

2. Security Infrastructure (SIEM / SOC / IDS / VPN / Firewall etc)

3. External Services & Servers (Cloud / Webserver/-services / Container)
Our focus today is on topic #3 - External Services & Servers

All companies have a mix of internal + external services they use.

External services are typically reachable via the internet and because of that they are targets.
Read 11 tweets
May 2
Day 5️⃣

Building the πŸ’™ Blue Team πŸ’™ course in public

External Servers & Services: Image
For the course I have 3 sections

1. Active Directory (Setup / Monitoring / Attack Vectors)

2. Security Infrastructure (SIEM / SOC / IDS / VPN / Firewall etc)

3. External Services & Servers (Cloud / Webserver/-services / Container)
Our focus today is on topic #3 - External Services & Servers

All companies have a mix of internal + external services they use.

External services are typically reachable via the internet and because of that they are targets.
Read 8 tweets
Apr 30
Day 3️⃣

Building the πŸ’™ Blue Team πŸ’™ course in public

Today course sections:
Currently, I have planned three sections

1. Active Directory (Setup / Monitoring / Attack Vectors)

2. Security Infrastructure (SIEM / SOC / IDS / VPN etc)

3. External Servers/Services (Cloud, Webservers/-services, Container)
Our focus today is on point #1 - Active Directory

Obviously it has to be part of the course - because >90% of companies run it.

My experience on the offensive side will help with that (hopefully 😈)

So what do I want to cover?
Read 12 tweets
Apr 28
Day 2️⃣

Building the πŸ’™ Blue Team πŸ’™ course in public:
Today, we will define the people that might benefit the most from the πŸ’™Β Blue Team course πŸ₯Ό

If you would not mind sharing - What is your current role and what would you want to gain from the course?
The course will focus on being hands-on first and trying to be as realistic as possible

The latter is limited by us being in a lab environment πŸ₯Ό

and having limited company funds frankly πŸ’Έ

but I believe that the best way to learn is by doing.
Read 8 tweets
Apr 26
I will try something new:

Building in Public ▢️

Remember when I said I was building a course? πŸ₯Ό

Actually, there are two courses. 😎

One is done already and in beta, the other one is work in progress. βœοΈπŸ™†β€β™‚οΈ / πŸ› οΈ

Lets dive right in, shall we?! 🀿
First up - What is building in public?

It is a movement where people openly build their products/courses and

share progress πŸ“ˆ
failures πŸ₯Ή
questions 🧐

and more during the process.

A few people who do that are: @arvidkahl @MeetKevon @AlexandraAllen_

Go follow them!
@arvidkahl @MeetKevon @AlexandraAllen_ Ok cool but maikroservice you are a cybersecurity professional, right? 😈

What does that have to do with building in public?!

Good question, allow me to share my perspective.

I struggle(d) with knowing how to structure the blue team course I promised

I was (am) overwhelmedπŸ˜…
Read 14 tweets
Mar 28
How to use SSH Tunnels in Offensive Security Tests 😈:
Imagine the following situation:
You are on an assignment for a client and should try to hack their super cool web app

The only issue:

You don't have internet and also no network.

Your computer is sad, because it wants to talk to their friends.
Luckily, your router was only offline for a couple of minutes after your neighbor set fire to the garden.

Now you can hack again, and your computer has access to all its friends.

Well... something is missing though.
Read 20 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(