Kali Purple Essential Training

Kali Purple Essential Training

4h 32mIntermediate2023-12-12

Authors

Malcolm Shore

Malcolm Shore

Cybersecurity Expert, Former Director of GCSB

Course details

Kali Purple is the latest addition to the Kali Linux ecosystem. Designed specifically for cybersecurity professionals and ethical hackers tasked with implementing defensive security strategies, the innovative extension to the renowned Kali Linux platform helps to address the needs of a diverse user audience by leveraging the principles of the NIST Cybersecurity Framework.

In this course, join instructor Malcolm Shore as he provides an introduction to the range of open-source tools supported on the Kali Purple cyber defense platform. Explore the tools provided in the application menu aligning to the five NIST Cybersecurity Framework categories: Identify, Protect, Detect, Respond, and Recover. Malcolm shows you how to install and use some of the additional tools, and covers the deployment of the Kali Purple software as a cyber range tool on a mini-PC (NUC).

Skills covered

PurpleKaliPenetration TestingEssential TrainingCybersecurity

Concepts

Introduction

  • Learning how to use Kali Purple
  • What you should know
  • Disclaimer

Building a Cyber Range

  • Introduction to Kali Purple
  • Introduction to virtualization
  • Virtualization using Proxmox
  • A first look at Proxmox
  • Installing Kali Linux
  • A quick tour of Kali Linux
  • Installing the Kali Purple workstation
  • A quick tour of Kali Purple
  • A first look at the Kali Purple servers
  • Creating a Kali Purple server template

Proxy IDS

  • Setting up NGINX as a proxy server
  • Adding Suricata IDS to the proxy
  • Setting up a public web server
  • Creating a Linux application server
  • Creating a Windows application server
  • Installing the juice shop
  • Installing virtual machines in the lab
  • Using kali-autopilot to generate attack scripts
  • Running an attack on autopilot

Vulnerabilty Scanning

  • Web scanning with ZAP
  • Installing GVM
  • Running a vulnerabilitty scan with GVM

Security Monitoring with ELK

  • Installing the ELKStack SIEM
  • Upgrading Kibana to HTTPS
  • Configuring log integrations
  • Installing the Fleet server
  • Enrolling hosts into the Fleet server
  • Enhancing our logs
  • Detecting reconnaissance with ELKStack
  • Detecting exploitation with ELKStack
  • Monitoring alerts with ELKStack

Security Monitoring with Wazuh

  • Installing the Wazuh SIEM
  • Installing a Wazuh Linux agent
  • Installing a Wazuh Windows agent
  • Collecting NGINX logs in Wazuh
  • Monitoring an attack with Wazuh
  • Detecting webshells with Wazuh
  • Activating vulnerability scanning

Threat Hunting

  • Understanding Malcolm for threat hunting
  • Installing Malcolm
  • A tour of Cyberville with Malcolm
  • Threat hunting with Malcolm
  • Deep diving with Malcolm's Arkime

Threat Intelligence

  • Exchanging threat intelligence
  • Installing OpenTaxii
  • Working with the cabby client library
  • Installing the OpenCTI threat intelligence system
  • Working with the OpenCTI threat intelligence system

Incident Response

  • Installing Velociraptor
  • Connecting Linux hosts to Velociraptor
  • Connecting Windows hosts to Velociraptor
  • Running commands remotely from Velociraptor
  • Accessing client files with VFS
  • Hunting with Velociraptor

Conclusion

  • Next steps
100,000 Toman