all modules module 07 · intermediate

Defensive Security

Attackers only need to win once. Defenders win by knowing their estate better than the people attacking it. This module is the blue-team brain.

01Logs that actually matter~5 min

You can’t detect what you don’t record. The non-negotiables:

  • Authentication events — successes AND failures (4624/4625 on Windows, ssh/auth logs on Linux). Lateral movement is visible here.
  • Web server access logs — SQLi/XSS attempts show up as weird encoded requests.
  • Process creation & command lines (Sysmon/EDR) — PowerShell with encoded flags, whoami right after a web request = classic.
  • DNS queries — malware beacons and data exfil love DNS.

Ship logs off-box immediately (attackers delete local ones), sync clocks via NTP so timelines make sense, and retain long enough to investigate last month’s breach this month.

02SIEM & detection engineering~5 min

A SIEM aggregates logs and turns them into alerts through correlation rules:

5+ failed logins then 1 success on the same account in 10 min
Service account using interactive login
Office IP logging in from two countries simultaneously

The enemy is alert fatigue: 500 untriaged alerts = no security. Good detections are behavioral (MITRE ATT&CK techniques like T1110 brute force) rather than signature-only. Every rule needs tuning, an owner, and a documented response.

Hacker crossover: the best pentesters write findings as detection gaps — “this attack chain generated no alert” is executive gold. Try spotting your own patterns: the arcade’s Phish or Fish game is literally detection training.

03Incident response: the six phases~5 min

NIST’s lifecycle — memorize as PICERL:

  1. Preparation — playbooks, contacts, tooling ready BEFORE the fire.
  2. Identification — triage the alert, scope it: how many hosts, what accounts, what data?
  3. Containment — stop spread: isolate hosts, disable accounts, block C2 IPs (short-term vs long-term containment decisions).
  4. Eradication — remove footholds: kill persistence, patch the entry hole, hunt for siblings.
  5. Recovery — restore from clean backups, monitor heavily during return-to-production.
  6. Lessons learned — blameless postmortem feeding back into Preparation.

Classic exam trap: containment before eradication (don’t clean a machine that’s still connected). Real-world trap: skipping lessons learned and getting re-breached identically.

04Hardening that survives contact~5 min

Boring beats clever. The controls that actually stop breaches:

  • MFA everywhere, especially remote access — kills most credential attacks dead.
  • Patching discipline — internet-facing first; most mass-exploitation hits known, patched CVEs.
  • Least privilege — users and services get exactly enough permission, no standing admin.
  • Backups: 3-2-1 — three copies, two media, one offline/offsite. Tested restores or they don’t count. Ransomware’s true kryptonite.
  • Network segmentation — flat networks turn one phish into domain compromise.
  • Email security stack — SPF/DKIM/DMARC plus user training with simulated phishing.

If you remember one line: attackers automate everything common, so uncommon configurations are free defense. Now flip perspectives again with the AD module if you skipped it — blue team needs both sides.