Complete Guide to Open Source Security

Complete Guide to Open Source Security

6h 48mIntermediate2025-01-27

Authors

Malcolm Shore

Malcolm Shore

Cybersecurity Expert, Former Director of GCSB

Course details

The course covers a selection of open-source tools for each major area of cybersecurity. These include governance and risk tools, firewalls, identity systems, vulnerability scanners, SIEM and incident response systems, threat hunting and security analytics tools, and security assurance and threat intelligence systems. For each tool or system, the course describes how to install and configure them, and provides a demonstration of their use. Instructor Malcolm Shore also includes a number of community versions of commercial security tools as well as a number of useful open source tools which, while not themselves cybersecurity tools, are useful in support of cybersecurity activities.

Learning objectives
Analyze the key features and functionalities of various open-source cybersecurity tools across major security domains.
Implement the installation and configuration processes for selected open-source security tools and community versions of commercial security tools.
Demonstrate proficiency in using open-source tools for governance, risk management, network security, identity management, vulnerability assessment, and threat intelligence.
Evaluate the effectiveness and applicability of different open-source security tools in addressing specific cybersecurity challenges.
Create a comprehensive security strategy incorporating appropriate open-source tools for an organization's specific needs and risk profile.

Skills covered

Cross-Platform DevelopmentMobile DevelopmentNetwork SecurityCybersecurityOne-Off

Concepts

Introduction

  • Introduction to complete open source security
  • What you should know
  • Disclaimer

Open Source Software

  • Open source security software
  • Open source software licensing
  • Installing and testing open source security tools
  • The Proxmox virtualization system
  • Installing Kali Linux
  • Using the application menu
  • Installing additional tools
  • Introduction to the Kali Purple workstation
  • Introduction to the Kali Purple server
  • Creating a Kali Purple server template
  • Software component security
  • Scanning with an automated SCA tool

Governance and Risk Tools

  • Introduction to GRC
  • Architecting with ArchiMate
  • Modelling security with Archi
  • Adding security to the model
  • Security risk management with SimpleRisk
  • Taking SimpleRisk for a spin
  • Using eramba for GRC
  • Configuring the eramba system
  • Preparing your risk context
  • Setting up your assets
  • Entering risks into eramba

Identity Solutions

  • Introduction to identities
  • Installing ZITADEL
  • Setting up the ZITADEL directory
  • Authorizing access with ZITADEL

Firewalls

  • A survey of open source firewalls
  • The basics of firewall operation
  • Installing pfSense
  • Accessing the DMZ via pfSense
  • Installing the IPFire firewall
  • Up and running with IPFire
  • Installing NethSecurity
  • Configuring the zones
  • Configuring the NethSecurity lab
  • Opening up the file server
  • Activating the LAN DHCP

Proxy, IDS, and Web Services

  • Setting up Nginx as a proxy server
  • Adding Suricata IDS to the proxy
  • Setting up a public web server
  • Testing the efficacy of web protection

Vulnerability Scanning

  • Installing GVM
  • Running a vulnerability scan with GVM

Security Assurance

  • Installing the Wazuh SIEM
  • Installing a Wazuh Linux agent
  • Installing a Wazuh Windows agent
  • Collecting Nginx logs in Wazuh
  • Monitoring an attack with Wazuh
  • Detecting web shells with Wazuh
  • Activating vulnerability scanning

Security Log Monitoring

  • Installing the ELK Stack SIEM
  • Upgrading Kibana to HTTPS
  • Configuring log integrations
  • Installing the Fleet server
  • Enrolling hosts into the Fleet server
  • Enhancing your logs
  • Detecting reconnaissance with the ELK Stack
  • Detecting exploitation with the ELK Stack
  • Monitoring alerts with the ELK Stack

Security Analytics

  • Installing Sirius CE
  • Solving the Unit 42 quiz with SELKS
  • Installing NetWitness
  • Taking NetWitness for a spin

Threat Intelligence

  • Exchanging threat intelligence
  • Installing OpenTAXII
  • Working with the Cabby client library
  • Installing the OpenCTI threat intelligence system
  • Connecting threat intelligence sources to OpenCTI

Managing Incidents

  • Installing the IRIS incident management system
  • Managing incidents with IRIS
  • Installing Velociraptor
  • Connecting Linux hosts to Velociraptor
  • Connecting Windows hosts to Velociraptor
  • Running commands remotely from Velociraptor
  • Accessing client files with VFS
  • Hunting with Velociraptor

Threat Hunting

  • Understanding Malcolm for threat hunting
  • Installing Malcolm
  • A tour of Cyberville with Malcolm
  • Threat hunting with Malcolm
  • Deep diving with Malcolm's Arkime

Dev and Support Tools

  • Installing the Kiwi TCMS test management system
  • Security testing with Kiwi TCMS
  • Installing the osTicket web app
  • Managing trouble tickets
  • Mind mapping with Freeplane
  • Introducing the Valkey datastore
  • Scripting with Valkey

Conclusion

  • Next steps
120,000 Toman