Introduction to Cybersecurity
Cyber threats, attacks and vulnerabilities. Analyze and mitigate threats.
Networking Basics
Types of networks, network communication, Routing, wireless connectivity. IPv4 - IPv6.
Networking Devices
Virtualization and Cloud Services, TCP, UDP, Sockets, ARP, ND, DNS DHCP, Cisco IOS, Cisco Devices.
Endpoint Security
Network security, analyze network traffic, network threats, operating systems, Firewalls, IPS, IDS, ACLs, EDR.
Network Defense
Security architecture, Firewalls-Rules, Firewals-ZPF, Routers-ACLs, Cloud Security, cryptography, alert analysis.
Cyber Threat Management
Governance, ISO 27000, Penetration Tests, Threat Intelligence, CVE, Mitre ATTACK & CK, Risk Management, CSIRT.
Junior Cybersecurity Analyst Career Path Exam
Exam grade: 92%
Dynamic malware analysis under Windows
Process Monitor, Process Explorer, AutoRuns, Fakenet-ng, Eset SysInspector, Registry Explorer, Regshot, Hyper-Analysis, VirusTotal.
Static malware analysis under Windows
Detect It Easy (DIE), Dependency Walker, PeStudio, pdfStreamDumper, OleTools, Ghidra, Malcat.
Osint y Ciberdelincuencia - Ivan Castañeda
1.Foros, Telegram, Deep Web, 2.OSINT en redes sociales: perfilamiento, IMINT, metadatos, 3.Infostealers: Combolists y ULP, 4.Bots maliciosos: phishing, scraping, c2, 5.Campañas de phishing: URLs, redirect, hash, dominios, 6.Scripting en Python: Scripts en Python para OSINT, Sistema de seguimiento en Telegram, Sistema iplogger o grabify, Scripts para detección de bots, Sistema de geolocalización en X
Técnicas avanzadas en Ciberinteligencia (TACINT)
1.Fuentes de inteligencia, 2.Fuentes OSINT, 3.Entorno OPSEC, 4.TTPs Agentes de Amenaza, 5.Monitoreo de amenazas digitales, 6.Técnicas de Desanonimización, 7.Fingerprint, 8.Cyberprofiling, 9.IMINT, 10.SOCMINT, 11.Metadatos Exif, 12.Big Data OSINT, 13.Monitoreo Telegram, Redes Deep Web, Foros Ciberdelincuencia, 14.Análisis de Blockchain, 15.Análisis de tráfico marítimo y aéreo
HACK THE BOX
Resolución de 20 laboratorios de dificultad fácil y nivel medio donde se practico habilidades técnicas de: IDORs, API Enumeration, Command Injection, File Upload Bypass, SSRF, SSTI, XSS Stored, WPA Pin brute force, SQL Injection, LFI, Auth Bypass, Broken Parser Logic, API Explotation, SUID Capability, CVE-2023-0386, CVE-2022-37706, Crack id_rsa hash, Forency device USB, CVE-2022-24439, CVE-2023-2640, Docker Breakouts, LXD Abuse, Sysytemctl misconfig.