0% found this document useful (0 votes)
8 views5 pages

Vulnerability Scanner Overview

The report details a 10-day visit to ESDS, covering various topics across hardware, Windows, Linux, NOC, and SOC teams. Key areas of focus included IP addresses, troubleshooting, authentication methods, firewalls, DDoS attacks, and vulnerability assessments. The author expresses a positive experience and a desire to work with the SOC team in the future.

Uploaded by

aaravmansi301
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views5 pages

Vulnerability Scanner Overview

The report details a 10-day visit to ESDS, covering various topics across hardware, Windows, Linux, NOC, and SOC teams. Key areas of focus included IP addresses, troubleshooting, authentication methods, firewalls, DDoS attacks, and vulnerability assessments. The author expresses a positive experience and a desire to work with the SOC team in the future.

Uploaded by

aaravmansi301
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Respected Yogesh sir

This is a detailed report on the 10 day visit to ESDS

First day I was with the hardware team

I covered a various topics

 IP
 Troubleshoot
 Lan Wire
 Aspects Of Computer
 Problem of CPU RAM NIC(Network Card)
 Userlock
 Software And Hardware
 Crimping Code
 HardDisk Types

An IP address, or Internet Protocol address, is a unique name associated for every device
that is connected to a network. IP addresses are necessary to identify a device so that it can
communicate over the Internet or on local networks. IP addresses are primarily of two types:
IPv4 and IPv6, with the latter allowing a greater number of devices to connect to the
[Link] Troubleshooting is the process of discovering and correcting issues in a
computer system or problems with a network or software. A few common steps while
troubleshooting include checking network cables, restarting computers or devices,
upgrading drivers, running virus checks, and adjusting network settings, etc. All these steps
require a logical approach towards a specific aim.A LAN wire which is Ethernet cable is
meant for attaching computers and other devices within a Local Area Network (LAN). These
categories include Cat5e, Cat6, and Cat7 which have different speed and bandwidth. Having
accurate LAN cables is very important in order to achieve and maintain a reliable high speed
internet connection Having components allows the computer to perform and be more
usable to the individual user. Issues with the CPU (Central Processing Unit), RAM (Random
Access Memory), and NIC (Network Interface Card) are widespread. Trouble with the CPU
could lead to performance issues and may even cause the system to halt operations
unexpectedly. Problems with the RAM tend to be associated with application locking, system
reboots, and crashing of a number of apps. Also, faulty NIC can bring a lot of problems
regarding the internet and network connectivity, which would greatly affect data
[Link] terms of cyber security, UserLock is a tool designed to specifically assign
permissions and control logins on a particular network. It sets limitations on the number of
sessions a user can open and the locations from which the network can be accessed,
protects from unauthorized breaches and access which enhances protection of information
and data.A clear appreciation of the difference between Software and Hardware is most
helpful. Computers have various peripherals and physical components which are categorized
as hardware. This entails the keyboard and the monitor along with the motherboard.
Windows OS, Microsoft Office, or antivirus programs are also included which means
Software runs on the [Link] code deals mainly with orderly packages of wires of
an Ethernet (LAN) cable. It is very important to follow T568A or T568B standards in crimping
as it helps set correctness on the data flow and eliminates connectivity [Link] (Solid
State Drive) and HDD (Hard Disk Drive) are the main types, where the first one is faster and
more durable, and the latter uses a spinning disk as a read/write data device.

The Next 2 Days(I was with windows)

I Covered The Following topics

 Authentication
 Cmd
 Powershell
 IDLock
 SQl Server
 Policy
 Vpn
 MFA

Authentication involves confirming that a user or device’s identity is genuine. No systems,


networks or sensitive data can be accessed without proper authentication, as only trusted
users are granted access. The most popular methods for authentication are through
passwords, biometrics (like fingerprints), smart cards, and multi-step verification methods
like two-factor authentication (2FA) which requires two or more steps for [Link]
Command Prompt, or CMD, is a type of command line interpreter that is integrated in the
Windows operating systems. Users can give CMD commands to help solve problems such as
running administrative tasks, managing files, and setting up system configuration settings. It
is safe to say CMD is an invaluable asset to every IT professional as it enables users to fix
problems much more quickly and with ease as unlike the graphic user interface, graphical
interface is not a [Link] is another invention by Microsoft, and it is more
sophisticated than CMD. In addition to files and system settings, PowerShell is capable of
managing intricate server and network configurations, all through automated scripts, making
IT's job much easier. Enterprise environments can significantly benefit from this as
PowerShell has the ability to perform repetitive tasks and manage countless computers
simultaneously which saves a lot of [Link] is often referred to as solutions for helping
safeguard personal and organizational information from misuse. In an IT environment,
IDLock tools offer protection of digital identities by monitoring them to be on the lookout for
possible breaches so the user can be alerted. Microsoft developed SQL Server as a relational
database management system (RDBMS). It allows efficient storage, retrieval, and data
management for applications, from small websites to large enterprise systems. SQL Server is
critical for data-driven organizations due to its support for sophisticated queries, data
analytics, reporting, and other business intelligence functions. An IT Policy refers to rules
and procedures that control the use and management of systems, networks, and data.
Policies can include security, password, and acceptable use policies. Well-defined security
policies assist in system security, compliance with established policies, and correct employee
guidance on appropriate usage. VPN (Virtual Private Network) is a protected connection that
enables users to access specific network resources selectively over the Internet as though
they are connected directly. VPNs cloak data traffic, safeguarding private data from intruders
and ensuring confidentiality. They are frequently employed for remote work so that staff can
access company information securely from any [Link] or Multi-Factor Authentication
is a security measure that demands one or more proofs for a user's identification before
granting them entry into a system. These proofs usually can be broken down into categories
such as, what the user knows, a password for example, and what the user possesses such as
a mobile device or smart

The Next 2 Days(I was with Linux)

They taught me some basic commands likes dh -ht to check storage


Free -mh for memory usage useradd to add user
And some sudo commands and many more around 30 to 40 commands
Not mentioned here

The Next 2 Days(I was with NOC)

 Firewall
 DDOS
 WAF
 OSI
 IPSEC
 SSLVPN

A Firewall is a system of security that regulates and filters incoming and outgoing
network traffic according to set rules. It is used as
a block between an internal trusted network and an external untrusted network such
as the internet. Firewalls may be either hardware, software, or a combination
of hardware and software. Their primary role is to stop unauthorized
access and permit legitimate communication, securing sensitive data and systems.
DDoS (Distributed Denial of Service) is a form of cyberattack in which a number
of systems overwhelm a target server, site, or network with an immense volume of
traffic. This saturates the system's
resources and slows it down considerably or causes it to fail
completely, preventing services from being accessed by genuine users. DDoS attacks
are frequently utilized to interfere with business operations and
can result in significant financial and reputational losses if not defended
against effectively.A WAF (Web Application Firewall) is a special kind of
firewall used to safeguard web applications by filtering and monitoring HTTP traffic
between the internet and a web application. As opposed to conventional firewalls
that defend servers and networks, WAFs target the application layer for security.
They assist in defending against typical attacks such as SQL injection, cross-site
scripting (XSS), and other vulnerabilities that are used against web applications.
The OSI (Open Systems Interconnection) model is a system that explains how
data moves from one computer to another through a network. It consists of seven
layers: Physical, Data Link, Network, Transport, Session, Presentation, and
Application. Each layer performs a distinct task, such as routing, encryption,
or formatting data. Knowing OSI assists IT
professionals in resolving network problems and creating effective communication
[Link] (Internet Protocol Security) is a suite of protocols that protects data as
it moves over an IP network. It offers encryption, authentication, and data
integrity, making sure information is secure from interception or tampering. IPSec
is commonly utilized in Virtual Private Networks (VPNs) to build secure
tunnels from remote users to private networks.
SSL VPN (Secure Sockets Layer Virtual Private Network) is a VPN that utilizes SSL (or
its replacement TLS) to establish a secure link over the internet. SSL
VPNs, unlike other VPNs that could involve special software, can be
accessed using an ordinary web browser, which simplifies their use for remote
access. They are often utilized to securely connect employees
to corporate resources from anywhere.

The Next 2 Days(I was with SOC)

 VTMScan
 Vurnability assessment
 TCIP

VTMScan is a security software tool that scans websites


for malware and vulnerabilities. It scans for known threats such as SQL injections,
cross-site scripting (XSS), weak passwords, and outdated software. Using
VTMScan, companies can identify and rectify security issues early, ensuring their
websites are not hacked or [Link] Assessment is
the activity of finding, analyzing, and assessing security weaknesses in
a network, system, or application. This
assessment allows organizations to know where they are exposed and what has to
be repaired before attackers can take advantage of the vulnerability. Regular
vulnerability assessments
are important in keeping a robust cybersecurity posture and satisfying compliance re
[Link]/IP (Transmission Control Protocol/Internet Protocol) is
the underlying communication language of the internet. TCP/IP enables computers
to talk and exchange data between networks. TCP guarantees that data
is received and sent correctly by dividing it into packets
and reconstructing them when they arrive. IP takes care of addressing and
routing those packets so they are delivered
to the right destination. TCP/IP combined makes up the basis of internet
communication and the majority of private networks.
It was a nice experience over all
Generally its was nice with all the teams but I hope to work with SOC in future

Common questions

Powered by AI

A Virtual Private Network (VPN) enhances privacy and security by establishing a secure, encrypted connection between the user's device and the company's network. By encrypting data traffic, a VPN safeguards transmitted information from potential eavesdroppers and cyber threats. This is particularly important for remote workers accessing sensitive company resources over public or unsecured internet connections. VPNs also cloak users' IP addresses, further enhancing privacy by masking their online activities. These features make VPNs a critical tool for maintaining data confidentiality and integrity in remote work environments .

Multi-Factor Authentication (MFA) enhances security by requiring two or more proofs of identity before granting access, whereas traditional password methods rely on a single factor ('what the user knows'). MFA includes additional factors like 'what the user possesses' (a smart card or mobile device) and/or 'what the user is' (biometrics like fingerprints), making unauthorized access significantly more difficult because an attacker would need access to more than just a password to breach a system .

Deploying UserLock can enhance network security by allowing administrators to control and restrict network access based on specific user permissions. UserLock limits the number of sessions a user can initiate and restricts where the network can be accessed from, preventing unauthorized logins and potential security breaches. By controlling access and monitoring login activities, UserLock helps protect sensitive information and reduces the risk of unauthorized access to network resources .

The OSI model is crucial for network troubleshooting and design as it provides a comprehensive framework for understanding and managing network processes. By segmenting communication into seven distinct layers (Physical, Data Link, Network, Transport, Session, Presentation, Application), the OSI model aids in isolating issues to specific layers, making problem-solving more systematic. This clarity enables IT professionals to design more effective communication systems by ensuring compatibility and standardization across various hardware and software components. The layered approach of the OSI model facilitates the diagnosis of network issues by allowing troubleshooting at a specific level without impacting the entire network stack .

A vulnerability assessment contributes to an organization's cybersecurity strategy by proactively identifying and analyzing security weaknesses within systems, networks, and applications. This process unearths potential vulnerabilities before they are exploited by attackers, allowing organizations to implement corrective actions to fortify their defenses. Regular vulnerability assessments are essential for maintaining a strong cybersecurity posture, ensuring compliance with security standards, and reducing the risk of data breaches and cyberattacks .

Firewalls primarily focus on controlling network traffic by monitoring and filtering incoming and outgoing data based on predetermined security rules, operating at various layers of the OSI model. They serve as a barrier between internal trusted networks and external untrusted networks. In contrast, Web Application Firewalls (WAFs) specifically protect web applications by inspecting and filtering HTTP traffic. WAFs focus on the application layer to guard against attacks such as SQL injection and cross-site scripting, which target web application vulnerabilities, rather than just general network threats .

SQL Server offers several advantages to data-driven organizations, including robust support for complex queries, data analytics, and reporting. It provides efficient data storage and retrieval capabilities essential for running small websites to large-scale enterprise systems. SQL Server's ability to handle sophisticated business intelligence functions allows organizations to derive meaningful insights from their data, facilitating data-driven decision-making. Furthermore, SQL Server's security mechanisms ensure data integrity and protection, making it a vital component of any organization's IT infrastructure .

SSDs (Solid State Drives) and HDDs (Hard Disk Drives) differ significantly in performance and reliability. SSDs use flash memory to store data, resulting in faster read/write speeds, increased durability, and no mechanical parts, which makes them less prone to physical damage and more reliable than HDDs. In contrast, HDDs use spinning disks to read/write data, leading to slower performance and increased susceptibility to mechanical failures. SSDs are thus preferred for high-performance computing tasks whereas HDDs, being more economical in terms of cost per gigabyte, are often used for bulk storage needs .

IPv4 and IPv6 are both types of IP addresses used to identify devices within a network. The main distinction is that IPv4 uses a 32-bit address space, limiting the number of available addresses, whereas IPv6 uses a 128-bit address space, significantly increasing the number of possible addresses. This expansion in IPv6 addresses helps accommodate the growing number of devices connecting to the internet, resolving the limitations of IPv4. Additionally, IPv6 includes improvements such as more efficient routing, simplified network configuration, and improved security features .

PowerShell offers more sophisticated functionality than Command Prompt, as it is designed not only for system administration but also for task automation using scripts. Unlike CMD, PowerShell supports complex scripting, automates repetitive tasks, and offers access to .NET framework functionalities, which allows for extensive manipulations of system and network configurations. This capability is particularly valuable in enterprise environments where managing large numbers of systems efficiently is crucial. PowerShell's ability to perform complex tasks across multiple systems without manual intervention distinguishes it significantly from CMD .

You might also like