Commute Plan - Back to InfoSec!
So, to get back into infosec I am going with the following plan, in loop
Do:
For:
Do:
- Find and read a thing on the topic (Blog, book, etc)
- Hands on (local gear, VM, cloud, demo web thing)
- Class, test or cert
For:
- Python
- Powershell
- Windows server security options
- Windows desktop security options
- Windows Active Directory management
- VLANs
- Firewall settings
- Port controls
- Web-testing basics: SQL injections, XSS
- Server testing basics: ports, connections
- network scan / port scan
- automation of patching, WSUS
- patch scan
- SQL
- MS-SQL
- DNS management in windows
- DNS settings on registrar
- Windows IIS
- Windows S/FTP
- RAID / SAN shenanigans
- SMTP
- SSL
- Load Balancing
- Database balancing
- VMware (hyperV)
- Physical lock down (disable usb etc)
- Policy Groups
- VPN
- nmap
- metasploit
- splunk
- github
- LAMP (apache)
- Add WMI, AppLocker, Credential Guard, Device Guard, and EMET/Windows Defender Exploit Guard to the list (recent developments or becoming more pertinent)
Suggestions:
ReplyDeleteGrab a copy of @georgiaweidman’s pentesting book?
Try some CTFs? http://captf.com/practice-ctf/
Set up some VMs and poke at them?
Suggestion:
ReplyDeleteroom362.com/start
Suggestion:
ReplyDeletehttps://tisiphone.net/2016/08/26/starting-an-infosec-career-the-megamix-chapter-7/
Suggestion:
ReplyDeletesetting up a Linux mail server including configuring DNS, STARTTLS, etc. (AWS free tier for that?)
Reading: https://github.com/alex/what-happens-when/blob/master/README.rst
ReplyDeleteSuggestion:
ReplyDeletehttps://blog.zsec.uk/101-web-testing-1/
resources:
ReplyDeletehttps://github.com/ForgottenSec/Transitioning_Into_InfoSec/blob/master/index.md
Netacad has some free classes.
ReplyDeleteSeriously - looked at your resume. Beef up on a CI/CD tool now like Ansible or Chef. Tutorials are online for free. If you want to do real DevSecOps work, DM me.
ReplyDeleteI will be honest though nobody will give you week on then week off telework. Doesn’t work that way in DC area.
Jonathan Katz
ReplyDelete
@katzmandu
Dec 20
More
Replying to @amazonv
Download some free @splunk & learn that, too :D