Skip to content

Lab Outline


Lab 1.1: Tool Setup

Part 1: Booting the Windows and Ubuntu VMs

Part 2: Tools Setup on the Windows VM

Part 3: Set Up Firefox for Lab Use

Part 4: Setup Nessus Essentials

Part 5: Set Up OpenOffice Software

Part 6: Set Up AWS Access on Windows

Part 7: Set Up Azure Access on Windows

Part 8: Set Up AWS and Azure Access on Ubuntu

Part 9: Update Lab File Repositories on Ubuntu

Part 10: Reboot the Windows VM


Lab 1.2: Discovery

Part 1: Host Discovery Techniques

Part 2: SYN Stealth vs. SYN Connect Scanning

Part 3: Version Fingerprinting with Nmap

Part 4: Nmap Output Files and Continuous Monitoring

Part 5: Nessus Discovery Scan

Appendix: Output of Nmap Help Command


Lab 1.3: Cloud Service Provider Tools

Part 1: Explore AWS CLI and PowerShell Commands

Part 2: Explore Azure CLI and PowerShell Commands

Part 3: Processing JSON with jq

Part 4: Processing JSON with PowerShell


Lab 1.4: Cloud Service Provider Inventory

Part 1: AWS Inventory - Web Console

Part 2: AWS Inventory - CLI/PowerShell

Part 3: Azure Inventory - Web Console

Part 4: Azure Inventory - CLI/PowerShell


Lab 2.1: Intro to PowerShell

Part 1: Navigating PowerShell

Part 2: PowerShell Objects

Part 3: Selecting and Sorting

Part 4: Output Formatting


Lab 2.2: Windows System Measurements

Part 1: OS and Patching Information

Part 2: Registry Settings

Part 3: Installed Software

Part 4: Services and Ports

Part 5: Osquery


Lab 2.3: Users, Permissions, and Logging

Part 1: Connect to AUD507 Range VPN

Part 2: Local Users and Groups

Part 3: File and Share Permissions

Part 4: Windows Logging

Part 5: Windows Domain Measurements


Lab 2.4: Compliance and Testing at Scale

Part 1: Fleet DM

Part 2: CIS Benchmark with CIS-CAT

Part 3: Review Nessus CIS Compliance Scan Results

Part 4: Setup Authenticated Vulnerability Scan

Part 5: Review Imported Credentialed Scan Results

Part 6: (Optional) Review Your Credentialed Scan Results


Lab 3.1: Linux System Information and Permissions

Part 1: System Information on Ubuntu Host

Part 2: System Information on Alma Host

Part 3: Osquery on Ubuntu Host

Part 4: Start Nessus Credentialed Scan of Linux Hosts


Lab 3.2: File Integrity, Kernel Settings, and Services

Part 1: File Integrity Monitoring

Part 2: Linux Kernel Settings

Part 3: Profiling Network Services

Part 4: Profiling Startup Services

Part 5: Osquery for Services and Ports


Lab 3.3: Linux Logging

Part 1: System Logging Facilities

Part 2: Systemd Logging

Part 3: Auditd


Lab 3.4: Linux System Audits

Part 1: Lynis System Audit

Part 2: InSpec Benchmark Scan of Ubuntu

Part 3: InSpec Benchmark Scan of Alma

Part 4: Review Nessus Credentialed Scans


Lab 4.1: Docker and Kubernetes

Part 1: Docker Manual Testing

Part 2: Docker-Bench-Security

Part 3: Kubernetes Manual Testing

Part 4: Kubernetes Benchmark with Kube-Bench


Lab 4.2: Cloud Identity and Access Management

Part 1: IAM in AWS

Part 2: Testing AWS IAM with Prowler

Part 3: Testing AWS IAM with Custodian


Lab 4.3: Cloud Infrastructure

Part 1: AWS Trusted Advisor

Part 2: Testing AWS Ingress with Custodian

Part 3: Testing AWS Ingress with Prowler

Part 4: Infrastructure SAST


Lab 4.4: Cloud Benchmarks

Part 1: Manual Tests of S3 Settings

Part 2: Manual Tests of Compute Settings

Part 3: Prowler for Benchmark Testing

Part 4: Sync CSP Resource Data to CloudQuery

Part 5: Explore CloudQuery Database Schema

Part 6: CloudQuery Resource Views

Part 7: Compliance Checks with CloudQuery


Lab 5.1: Web App Auditing with Burp

Part 1: Examine the Juice Shop Application

Part 2: Use Burp to Analyze Juice Shop

Part 3: Use Burp Intercept to Manipulate Traffic

Part 4: Use Burp Repeater to Manipulate Traffic


Lab 5.2: Server Configuration and Static Analysis

Part 1: Using SSLyze to Inventory Protocols and Ciphers

Part 2: Use Nmap to Inventory Certificates and Ciphers

Part 3: Audit Server Configuration

Part 4: Analyzing Components Used in Juice Shop

Part 5: Analyze Juice Shop Source Code


Lab 5.3: Fuzzing with Burp

Part 1: Fuzzing for Injection Flaws

Part 2: Fuzzing for Enumerating Usernames

Part 3: Brute Forcing Authentication


Lab 5.4: Injection Flaws

Part 1: HTML and Script Injection

Part 2: SQL Injection to Bypass Authentication

Part 3: SQL Injection to Extract Data


20 Total Labs 93 Total Sections