Posts

Abbreviation's used in IT-Security

XXS - Cross-Site Scripting DOS - Denial of Services DDOS - Distributed Denial of Service IPSec - Internet Protocol Security SSE – Server Side Encryption TLS - Transport Layer Security CSP – Content Security Policy CBSP - Cloud Based Security Providers. AES - Advance Encryption Standards. MFA - Multi-Factor Authentication WAF - Web Application Firewall STS - Security Token Service. RAT - Remote Administration Tool SPF - Sender Policy Framework. CVSS -Common Vulnerability Scoring System SAST -System Application Security Testing WAP - Web Application Protection SCD - Sousse Code Disclosure DSA - Digital Signature Algorithm DES – Data Encription Standard

Essential SOC Tools Every Cybersecurity Professional Should Know!

Image
  In today’s fast-paced digital world, a well-equipped Security Operations Center (SOC) is crucial for defending against cyber threats. Here’s a quick breakdown of must-have tools used in SOC environments to enhance security posture: 1. SIEM (Security Information and Event Management) - Example: Splunk, IBM QRadar, ArcSight - Purpose: Centralized log management and threat detection. 2. IDS/IPS (Intrusion Detection & Prevention Systems) - Example: Snort, Cisco Firepower, Suricata - Purpose: Monitor and block suspicious traffic. 3. EDR (Endpoint Detection & Response) - Example: CrowdStrike, Carbon Black, Microsoft Defender ATP - Purpose: Monitor devices for malicious activities. 4. Threat Intelligence Platforms - Example: Recorded Future, ThreatConnect - Purpose: Stay ahead of emerging cyber threats. 5. Vulnerability Management - Example: Tenable Nessus, Qualys, OpenVAS - Purpose: Identify and patch system vulnerabilities. 6. Firewalls - Example: Palo A...

OSI Model: Layer's, Examples & Attacks

Image
OSI Model The OSI model (Open Systems Interconnection) is a foundational concept that helps us understand how data flows in a network, layer by layer. Each layer has its own unique role. Layer 1(Physical Layer) Role: Physical connection between devices and Sends raw data (1s and Os) over cables or wireless signals. Examples: Ethernet cables, Wi-Fi signals. Attacks: Cable tapping. Note: Hub Operates at Physical Layer of OSI Model. Layer 2(Data Link Layer) Role: Organizes data into frames and ensures error-free delivery between devices on the same network. Examples: MAC, ARP. Attacks: MAC spoofing, ARP poisoning. Note: Switch operates at Data Link Layer of OSI Model. Layer 3(Network Layer) Role: Finds the best path for data to travel between devices on different networks. Examples: IP (IPv4/IPv6), ICMP, BGP, OSPF. Attacks: IP spoofing, route injection. Note: Router Operates at network layer of OSI Model. Layer 4(Transport Layer) Role: Ensures data is delivered completely and correctly, e...

SOC Analyst

Image
  Security Operation Center(SOC) — The SOC analyst are the cybersecurity professionals who works as the first line of defence. They are responsible for monitoring, detecting, analyzing, and responding to security incident within an organization’s IT environment. They work in a SOC team and are critical for ensuring the organization’s system and data are protected from cyber threat. SOC in used for:-        i. Threat Monitoring      ii. Investigation Alerts      iii. Responding Incident Task for L1 SOC Analyst:- i. Monitoring ii. Incident Triage iii. Initial Analysis iv. Escalation v. Communication Task for L2 SOC Analyst:-      i.  Monitoring Alert      ii.  Threat Hunting      iii.  Resource Monitoring      iv.  Creating and Approving Whitelist      v.  Handling Escalated Investigation Task of L3 SOC Analyst:-      i. ...