Monitoring an Attack With LimaCharlie EDR

Homelab project using Endpoint Detection and Response software to monitor a live attack on a Windows 11 virtual machine. Includes creating Detection & Response rules for an EDR, learning how to analyze telemetry from a Windows 11 machine to identify malicious traffic, scan for malicious files by YARA signature, analyze detections to see if they are false positives, and how to limit the rate of false positives by crafting better D&R rules.

Nessus Vulnerability Management Lab

Homelab using Nessus vulnerability scanner to run non-credentialed and credentialed scans on a Windows 11 virtual machine. Using Nessus to learn more about specific vulnerabilities, compare scan results when unpatched software is installed, and learning about the role that vulnerability management plays in an organization.

SOC Analyst Training Simulation With Security Onion

Using Security Onion in a homelab environment to simulate what a SOC Analyst would experience during an attack. Using a packet capture from a real world attack to recreate the same SIEM logs and alerts experienced by the SOC during the attack. Learning to analyze the packet captures and logs to identify data exfiltration. Learning how to properly document, communicate, and make recommendations as a SOC analyst.

Hardening Firefox

A quick and easy way to get much better privacy and security from Firefox by using Arkenfox’s user.js. Why Harden Firefox? There are several reasons for privacy and security. To start with some of the benefits for privacy, hardening Firefox will greatly reduce websites’ ability to track you across the Read more…