0% found this document useful (0 votes)
4 views4 pages

Hack

The document outlines a process for adding funds to a bank account on a fake banking website and provides an overview of defensive cybersecurity practices. It details the roles of a Security Operations Centre (SOC) in monitoring for threats, managing security policies, and responding to incidents. Additionally, it discusses digital forensics and incident response processes to handle security breaches and unauthorized activities.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views4 pages

Hack

The document outlines a process for adding funds to a bank account on a fake banking website and provides an overview of defensive cybersecurity practices. It details the roles of a Security Operations Centre (SOC) in monitoring for threats, managing security policies, and responding to incidents. Additionally, it discusses digital forensics and incident response processes to handle security breaches and unauthorized activities.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

ou should have found a secret page that allows you to add funds to a bank account

([Link] Type the hidden page into the FakeBank


website using the browser's address bar.

From this page, you should be able to add funds to your bank account (remember
your bank account number is 8881). Let's add $2000 to it:

If you managed to add $2000 or more to your account, you should be able to see
your new balance reflected on your account page. Press the Return to Your
Account button at the end of the deposit receipt to go there now and confirm you got
the money!
CyberSecurity

Defensive security, known as the blue team, is used to prepare and proactively
protect an organisation's IT infrastructure. It is concerned with two main tasks:

1. Preventing intrusions from occurring


2. Detecting intrusions when they occur and responding properly

Some of the tasks that are involved in defensive security include:

Cyber Security Awareness


Training users about cyber security attacks, such as phishing and social engineering.

Documenting & Managing Assets


We must know the systems within the organisation to adequately protect them.

Preventative Security
Firewalls and Intrusion Prevention Systems are the first line of defence. These devices control
what traffic is allowed to enter and leave the network and prevents malicious traffic from entering
the network.

Logging & Monitoring


Comprehensive logging of the network and system activity is essential in detecting a threat or
unauthorised activity.

Frameworks, Policies & Procedures


Creating robust security policies helps ensure that the organisation's devices are used
appropriately.

Security Operations Centre (SOC)

A Security Operations Centre (SOC) is a team of cyber security professionals that


monitors the network and its systems to detect malicious cyber security events.
Some of the main areas of interest for a SOC are:

Trends & Vulnerability Awareness


Keeping up to date with the latest trends and vulnerabilities in the industry is an essential skill to
help understand the risks an organisation faces.

Policy Violations
A security policy is a set of rules that outline ho Digital Forensics

Digital forensics is the application of traditional forensic science processes to digital


devices. Digital forensics is used to preserve and analyse digital evidence to aide in
the investigation of incidents, such as a breach. This may involve looking at
information from:

Log files provide plenty of information about what happened on a system. Even if the
attacker tries to clear their traces, some traces will remain.w an organisation's
assets are to be used and protected. The SOC team monitors for adherence to these
policies.

Unauthorised & Illegal Activity


The SOC team establishes a baseline of acceptable behaviour and activity. Any deviation from
this baseline is investigated. IllegIncident Response is how organisations manage
security events such as breaches, data leaks and cyber attacks. An incident
response process is a defined set of stages to minimise damage, contain the threat
and recover fast. The process will look like so:

Let's explore these in a bit further detail:

There are many open-source databases out there, like AbuseIPDB, and Cisco Talos
Intelligence, where you can perform a reputation and location check for the IP
address. Most security analysts use these tools to aid them with alert investigations.
You can also make the Internet safer by reporting the malicious IPs, for example, on
AbuseIPDB.
Now that we know the IP address is malicious, we need to escalate it to a staff
member!

Preparation
Creating the necessary resources and frameworks to handle an incident. This includes creating
incident response teams, infrastructure to support in the incident response process, as well
anything to help prevent the incidents, such as providing phishing awareness training.

Detection & Analysis


Using tooling and processes to detect incidents and assess their scope (reach) and severity.
Logs can be analysed for suspicious events.

Containment, Eradication, and Recovery


Limiting the impact of the incident, such as preventing a virus from spreading and eliminate the
cause and restore affected systems.
al activity exposes the organisation to higher risk.

Intrusion & Breach Detection


No matter how well protected an organisation is, there is always a risk of a breach.
The SOC team is responsible for detecting and responding to these breaches.

You might also like