So, to get back into infosec I am going with the following plan, in loop Do: Find and read a thing on the topic (Blog, book, etc) Hands on (local gear, VM, cloud, demo web thing) Class, test or cert For: Python Powershell Windows server security options Windows desktop security options Windows Active Directory management VLANs Firewall settings Port controls Web-testing basics: SQL injections, XSS Server testing basics: ports, connections network scan / port scan automation of patching, WSUS patch scan SQL MS-SQL DNS management in windows DNS settings on registrar Windows IIS Windows S/FTP RAID / SAN shenanigans SMTP SSL Load Balancing Database balancing VMware (hyperV) Physical lock down (disable usb etc) Policy Groups VPN nmap metasploit splunk github LAMP (apache) Add WMI, AppLocker, Credential Guard, Device Guard, and EMET/Windows Defender Exploit Guard to the list (recent developments or becoming more pertinent)
Comments
Post a Comment