Lab Outline
Lab 1.1: Tool Setup
Part 1: Booting the Windows and Ubuntu VMs
Part 2: Tools Setup on the Windows VM
Part 3: Set Up Firefox for Lab Use
Part 4: Setup Nessus Essentials
Part 5: Set Up OpenOffice Software
Part 6: Set Up AWS Access on Windows
Part 7: Set Up Azure Access on Windows
Part 8: Set Up AWS and Azure Access on Ubuntu
Part 9: Update Lab File Repositories on Ubuntu
Part 10: Reboot the Windows VM
Lab 1.2: Discovery
Part 1: Host Discovery Techniques
Part 2: SYN Stealth vs. SYN Connect Scanning
Part 3: Version Fingerprinting with Nmap
Part 4: Nmap Output Files and Continuous Monitoring
Part 5: Nessus Discovery Scan
Appendix: Output of Nmap Help Command
Lab 1.3: Cloud Service Provider Tools
Part 1: Explore AWS CLI and PowerShell Commands
Part 2: Explore Azure CLI and PowerShell Commands
Part 3: Processing JSON with jq
Part 4: Processing JSON with PowerShell
Lab 1.4: Cloud Service Provider Inventory
Part 1: AWS Inventory - Web Console
Part 2: AWS Inventory - CLI/PowerShell
Part 3: Azure Inventory - Web Console
Part 4: Azure Inventory - CLI/PowerShell
Lab 2.1: Intro to PowerShell
Part 1: Navigating PowerShell
Part 2: PowerShell Objects
Part 3: Selecting and Sorting
Part 4: Output Formatting
Lab 2.2: Windows System Measurements
Part 1: OS and Patching Information
Part 2: Registry Settings
Part 3: Installed Software
Part 4: Services and Ports
Part 5: Osquery
Lab 2.3: Users, Permissions, and Logging
Part 1: Connect to AUD507 Range VPN
Part 2: Local Users and Groups
Part 3: File and Share Permissions
Part 4: Windows Logging
Part 5: Windows Domain Measurements
Lab 2.4: Compliance and Testing at Scale
Part 1: Fleet DM
Part 2: CIS Benchmark with CIS-CAT
Part 3: Review Nessus CIS Compliance Scan Results
Part 4: Setup Authenticated Vulnerability Scan
Part 5: Review Imported Credentialed Scan Results
Part 6: (Optional) Review Your Credentialed Scan Results
Lab 3.1: Linux System Information and Permissions
Part 1: System Information on Ubuntu Host
Part 2: System Information on Alma Host
Part 3: Osquery on Ubuntu Host
Part 4: Start Nessus Credentialed Scan of Linux Hosts
Lab 3.2: File Integrity, Kernel Settings, and Services
Part 1: File Integrity Monitoring
Part 2: Linux Kernel Settings
Part 3: Profiling Network Services
Part 4: Profiling Startup Services
Part 5: Osquery for Services and Ports
Lab 3.3: Linux Logging
Part 1: System Logging Facilities
Part 2: Systemd Logging
Part 3: Auditd
Lab 3.4: Linux System Audits
Part 1: Lynis System Audit
Part 2: InSpec Benchmark Scan of Ubuntu
Part 3: InSpec Benchmark Scan of Alma
Part 4: Review Nessus Credentialed Scans
Lab 4.1: Docker and Kubernetes
Part 1: Docker Manual Testing
Part 2: Docker-Bench-Security
Part 3: Kubernetes Manual Testing
Part 4: Kubernetes Benchmark with Kube-Bench
Lab 4.2: Cloud Identity and Access Management
Part 1: IAM in AWS
Part 2: Testing AWS IAM with Prowler
Part 3: Testing AWS IAM with Custodian
Lab 4.3: Cloud Infrastructure
Part 1: AWS Trusted Advisor
Part 2: Testing AWS Ingress with Custodian
Part 3: Testing AWS Ingress with Prowler
Part 4: Infrastructure SAST
Lab 4.4: Cloud Benchmarks
Part 1: Manual Tests of S3 Settings
Part 2: Manual Tests of Compute Settings
Part 3: Prowler for Benchmark Testing
Part 4: Sync CSP Resource Data to CloudQuery
Part 5: Explore CloudQuery Database Schema
Part 6: CloudQuery Resource Views
Part 7: Compliance Checks with CloudQuery
Lab 5.1: Web App Auditing with Burp
Part 1: Examine the Juice Shop Application
Part 2: Use Burp to Analyze Juice Shop
Part 3: Use Burp Intercept to Manipulate Traffic
Part 4: Use Burp Repeater to Manipulate Traffic
Lab 5.2: Server Configuration and Static Analysis
Part 1: Using SSLyze to Inventory Protocols and Ciphers
Part 2: Use Nmap to Inventory Certificates and Ciphers
Part 3: Audit Server Configuration
Part 4: Analyzing Components Used in Juice Shop
Part 5: Analyze Juice Shop Source Code
Lab 5.3: Fuzzing with Burp
Part 1: Fuzzing for Injection Flaws
Part 2: Fuzzing for Enumerating Usernames
Part 3: Brute Forcing Authentication
Lab 5.4: Injection Flaws
Part 1: HTML and Script Injection
Part 2: SQL Injection to Bypass Authentication
Part 3: SQL Injection to Extract Data
20 Total Labs 93 Total Sections