Browsed by
Author: Amal Mammadov

Local Admin Password Solution (LAPS) STEP-BY-STEP

Local Admin Password Solution (LAPS) STEP-BY-STEP

Today we will deploy Microsoft LAPS solution to manage local administrator passwords in computers. Its an excellent tool that takes the burden of rotation of local administrator account password or to avoid cases when all workstation have the same password for local administrator account. First we need to download LAPS from the MS download center and install it on Management Computer (Domain Controller). LAPS is installed to “%ProgramFiles%\LAPS”. https://www.microsoft.com/en-us/download/details.aspx?id=46899 For “Managed computers” we can run the installer to install same…

Read More Read More

Active Directory Group Nesting

Active Directory Group Nesting

Group Scope There are four group scopes: Local Global Domain Local Universal The characteristics that define each scope fall into these categories: Replication. Where is the group defined, and to what systems is the group replicated? Membership. What types of security principals can the group contain as members? Can the group include security principals from trusted domains? Availability. Where can the group be used? Is the group available to add to another group? Is the group available to add to…

Read More Read More

SOC METRICS

SOC METRICS

Some typical SOC metrics to demonstrate the SOC value to the business decision makers may include: The mean TTD of the incident after its occurrence The mean time to contain the incident after its detection The mean time to mitigate the incident after its containment The number of incidents being detected, contained, and mitigated The percentage of the discovered incidents found using the plays in the SOC playbook The number of new plays added to the SOC playbook The number…

Read More Read More

Security Operations Center (SOC) ROLES

Security Operations Center (SOC) ROLES

The SOC manager should develop a workflow model and implement SOPs for incident-handling that guide the analysts through the triage and response procedures. Security analyst tiered responsibilities may include: Tier 1 Continuously monitors the alert queue Triages security alerts Monitors the health of the security sensors and endpoints Collects data and context necessary to initiate Tier 2 work Tier 2 Performs deep-dive incident analysis by correlating data from various sources Determines if a critical system or data set has been…

Read More Read More

OpenSSL Generating Private and Public Key Pair

OpenSSL Generating Private and Public Key Pair

In this post I will create asymmetric encryption key pair and then demonstrate the encryption and decryption of sample test.txt file with Private and Public keys using OpenSSL in Linux 1. Generate 4096-bit RSA Private key and protect it with “secops1” pass phrase using 128-bit AES encryption and store it as private.pem file openssl genrsa -aes128 -passout pass:secops1 -out private.pem 4096 Encryption of private key with AES and a pass phrase provides an extra layer of protection for the key….

Read More Read More

Describing Security Event Analysis: Diamond Model for Intrusion Analysis

Describing Security Event Analysis: Diamond Model for Intrusion Analysis

Critical thinking skills are a core requirement for a security analyst. The security analyst must be able to link together logs, events, and other meta-data by identifying patterns across a massive amount of gathered data. The diamond model, developed by Caltagirone, Pendergast, and Betz is a method for helping the security analysts derive order from the chaos. The basic intent of the diamond model is to create a systematic way to analyze events in a repeatable way so that the…

Read More Read More

Regulatory Compliance

Regulatory Compliance

Compliance regulations are a major driver for security in organizations of all kinds. They define not only the scope and parameters for the risk and security architectures of an organization, but also the liability for those organizations that fail to comply. Current trends in regulatory compliance include the following: Strengthened enforcement Global spread of data breach notification laws More prescriptive regulations Growing requirements regarding third parties (business partners) Risk-based compliance on the rise Compliance process streamlined and automated The following…

Read More Read More

Access Control Models

Access Control Models

Access control includes control over access to the network resources, information system resources, and information. It is crucial for an organization to implement the proper access controls to protect the organization’s resources and information. A security analyst should understand the different basic models for implementing access controls in order to better understand how attackers can break the access controls. Mandatory Access Control Secures information by assigning sensitivity (security level) labels on information and comparing it to the level of sensitivity…

Read More Read More

Describing Security Event Analysis: Cyber Kill Chain

Describing Security Event Analysis: Cyber Kill Chain

The cyber kill chain is a model that describes the structure of an attack. One of an analyst’s key jobs is to understand exactly what the attackers did. The steps of the kill chain enhance visibility into an attack and enrich an analyst’s understanding of an adversary’s tactics, techniques, and procedures.   The following lists the seven stages of the cyber kill chain: Reconnaissance: Research, identification and selection of targets, often represented as crawling Internet websites such as conference proceedings and…

Read More Read More