Threat Analysis and Vulnerability Assessment Demo
-
The objective of this project was to work with a blue team and conduct a simulated investigation into suspicious activity on a network that may be indicative of an insider threat. It was implemented in phases with Parrot OS as the attach machine and Ubuntu as the victim machine:
In the Network Configuration and Reconnaissance phase, scanning and traffic capture were done
In the Log Analysis for Threat Detection phase, directory enumeration and log analysis using dirb and parsing tools were deployed
In the Vulnerability Assessment phase, I illuminated the ramifications of data exposure and recommended remediation
-
The following tools were used in this project:
Wireshark
Nmap
Nikto
Dirb
Parsing Tools (grep, head, tail, and awk)
-
Following the analysis and assessment, several concerns were uncovered:
Firstly, performing scans and utilizing parsing tools unearthed a worrying backup folder and signs of external scanning of the network
Secondly, the folder led to the discovery of sensitive credit card information accessible over the Internet
Thirdly, the use of Wireshark reinforced the occurrence of a data breach and exposure through the filtering
-
This project fortifies the importance of implementing access controls and employee training to mitigate insider threats.
It also highlights the need for incident response professionals, as they work to monitor and contain data breaches and protect the interests of those involved.