Ethical Hacking: Evading IDS, Firewalls, and Honeypots
2h 13mIntermediate2021-02-10
Authors

Malcolm Shore
Cybersecurity Expert, Former Director of GCSB
Course details
Ethical hacking—testing to see if an organization's network is vulnerable to outside attacks—is a desired skill for many IT security professionals. In this course, cybersecurity expert Malcolm Shore prepares you to take your first steps into testing client defenses. Malcolm provides you with an overview of firewall technology, detailing how firewalls work in both Windows and Linux, as well as how to set up a firewall simulation in a GNS3 network. Next, he goes over web application firewalls, API gateway threat mitigation solutions, and how to use honeypots to detect intruders. Finally, he covers the main ways to manage a suspected intrusion, including how to use the Security Onion intrusion detection system (IDS).
Note: The topics covered in this course are drawn from the Evading IDS, Firewalls, and Honeypots competency in the Certified Ethical Hacker (CEH) body of knowledge.
Topics include:
Applying the basics of the Windows Firewall
Using advanced features in the Windows Firewall
Reviewing firewall logs
Linux iptables
Setting up an iptables firewall
Managing rules with Firewall Builder
Setting up a Cisco PIX firewall
Installing GNS3
How web application firewalls protect web servers
Protecting API services with the WSO2 gateway
Running the Cowrie honeypot
Detecting intrusions with Security Onion
Note: The topics covered in this course are drawn from the Evading IDS, Firewalls, and Honeypots competency in the Certified Ethical Hacker (CEH) body of knowledge.
Topics include:
Applying the basics of the Windows Firewall
Using advanced features in the Windows Firewall
Reviewing firewall logs
Linux iptables
Setting up an iptables firewall
Managing rules with Firewall Builder
Setting up a Cisco PIX firewall
Installing GNS3
How web application firewalls protect web servers
Protecting API services with the WSO2 gateway
Running the Cowrie honeypot
Detecting intrusions with Security Onion
Skills covered
Security TestingCybersecurityCert Prep
Concepts
0. Introduction
- 01 - Finding weaknesses in the perimeter
- 02 - What you should know
- 03 - Course disclaimer
1. Firewalls
- 04 - Understanding Firewalls
- 05 - Apply the basics of the Windows firewall
- 06 - Use advanced features in the Windows Firewall
- 07 - Review firewall logs
- 08 - Understand Linux IPTables
- 09 - Set up an IPTables firewall
- 10 - Manage rules with Firewall Builder
- 11 - Port testing
2. Hardware Firewalls
- 12 - Set up a Cisco PIX firewall
- 13 - Create a secure enclave
3. Network Simulation Using GNS3
- 14 - Install GNS3
- 15 - Obtain network device images
- 16 - Set up a network
- 17 - Simulate the ASA firewall
- 18 - Integrate Kali into GNS3
4. Special Purpose Perimeter Devices
- 19 - Understand Web Application Firewalls
- 20 - Protect API services with the WSO2 gateway
- 21 - Understand honeypots
- 22 - Run the Cowrie honeypot
5. Protection from Intrusion
- 23 - Intrusion response techniques
- 24 - xListing sites
- 25 - Snort rules
- 26 - Detect intrusions with Security Onion
- 27 - Extend IDS with reputation
- 28 - EINSTEIN
6. Evasion Techniques
- 29 - Evading antivirus detection
- 30 - Obfuscating payloads with msfvenom
- 31 - Hiding payloads in benign files
- 32 - Custom packaging of software
- 33 - Fileless attacks with PowerShell
- 34 - Hiding with the cloak of invisibility
- 35 - Embedding malware in an alternate data stream
- 36 - Checking for oversight
Conclusion
- 37 - Next steps