SECTION 9 Cyber Security

Follow SECTION 9 Cyber Security
Share on
Copy link to clipboard

Information Security is the name of the game. Don't let the hackers win!

SECTION 9


    • Apr 3, 2023 LATEST EPISODE
    • infrequent NEW EPISODES
    • 23m AVG DURATION
    • 193 EPISODES


    Search for episodes from SECTION 9 Cyber Security with a specific topic:

    Latest episodes from SECTION 9 Cyber Security

    The NIST Cyber Security Framework

    Play Episode Listen Later Apr 3, 2023 30:31


    Time to start looking into cyber security frameworks. For this episode we're looking at the the NIST Cyber Security Framework. We're also explaining what a cyber security framework is and how they can help. LINKS1. NIST Cyber Security Framework (CSF)FIND US ON1. Twitter - DamienHull2. YouTube

    Time For a Maintenance Review - 259

    Play Episode Listen Later Mar 6, 2023 23:44


    Time for another maintenance episode where we review our systems and management process. This time were looking at our Digital Ocean servers, Automox patch management, Fortinet Firewalls, and the password manager Bitwarden. FIND US ON1. Twitter - DamienHull2. YouTube

    How do you roast a server to death? - 258

    Play Episode Listen Later Jan 16, 2023 11:20


    Almost roasted our VMware server to death. Don't do what I did. Enjoy!LINKS1. VMware Server: Super Micro SYS-E300-9D-8CN8TP2. Fans: Noctua NF-A4x20 PWMFIND US ON1. Twitter - DamienHull2. YouTube

    How do we evaluate the LastPass hack for Section 9? - 257

    Play Episode Listen Later Jan 9, 2023 36:14


    LastPass was hacked last year. As LastPass customers we need to evaluate the impact that has on Section 9. Should we continue to use the product? Should we migrate to a different password manager? How do we evaluate a password manager? Consider this the start of a longer conversation about LastPass and password managers. FIND US ON1. Twitter - DamienHull2. YouTube

    SANS and BHIS Videos for Hacking - 256

    Play Episode Listen Later Dec 12, 2022 25:02


    Found some really interesting and helpful videos. One walks you through an Active Directory hacking lab. Another talks about default configurations and bad passwords as a way to hack into systems. The last one is about building a home lab. These are just what I needed. LINKS1. SANS Workshop – NTLM Relaying 101: How Internal Pentesters Compromise Domains2. The Top $ num Reasons You Got Hacked in 2022 with Kent & Jordan | 1 Hour3. How to Build a Home Lab for Infosec with Ralph May | 1 HourFIND US ON1. Twitter - DamienHull2. YouTube

    The Active Directory Lab - 255

    Play Episode Listen Later Nov 21, 2022 20:57


    Found a video that walks you through the process of setting up an Active Directory Lab for hacking. I wouldn't be able to do this without a starting point. LINKS1. Mitre ATT&CK Matrix 2. How to Build an Active Directory Hacking LabFIND US ON1. Twitter - DamienHull2. YouTube

    Using the MITRE ATT&CK Matrix in a lab - 254

    Play Episode Listen Later Nov 7, 2022 21:35


    Last episode was about my crazy study plan, or lack of one. Time to put together a proper study plan. One that works. FIND US ON1. Twitter - DamienHull2. YouTube

    A Better Study Plan - 253

    Play Episode Listen Later Oct 10, 2022 17:20


    Last episode was about my crazy study plan, or lack of one. Time to put together a proper study plan. One that works. FIND US ON1. Twitter - DamienHull2. YouTube

    Learning All At Once - 252

    Play Episode Listen Later Oct 3, 2022 27:01


    Time to jump into my crazy, unorganized study process. Trying to study or learn the CISSP, pentesting, risk assessments, and keep up with my current certification requirements. I've also signed up for two Antisyphon classes. Beginner Classes1. SOC Core Skills2. Getting Started In Security With BHIS and Mitre Att&ck3. Active Defense & Cyber DeceptionAdvanced Classes1. Introduction to Pentesting2. Red Team: Getting Access3. Professionally Evil CISSP Mentorship ProgramFIND US ON1. Twitter - DamienHull2. YouTube

    Asset Management Policy - 251

    Play Episode Listen Later Sep 5, 2022 13:30


    Time to create a policy for asset inventory. This will help us define what we need in our asset inventory. It will also help us define what we need in our procedures. The process we use to manage the inventory. LINKS1. Enterprise Asset Management Policy TemplateFIND US ON1. Twitter - DamienHull2. YouTube

    Discovering Devices With runZero - 250

    Play Episode Listen Later Aug 29, 2022 18:15


    We're scanning our network with runZero to get an inventory of devices. What did it find? What can we learn from this inventory? How well does it work? LINKS1. runZero - Active discovery tool for asset inventoryFIND US ON1. Twitter - DamienHull2. YouTube

    Do we have adequate security controls in place? - 249

    Play Episode Listen Later Aug 22, 2022 22:19


    We're in the process of implementing the CIS controls. This will take time. We're also very busy. Are there any gaping security holes that we need to fix? Do we have any security controls in place? Can we wait to implement the CIS controls?LINKS1. runZero - Active discovery tool for asset inventory2. Enterprise Asset Management Policy TemplateFIND US ON1. Twitter - DamienHull2. YouTube

    cis security controls
    CIS Controls: Hardware Inventory Part 1 - 248

    Play Episode Listen Later Aug 15, 2022 13:07


    Time to get an accurate inventory of the devices on our network. Once we have an inventory, we can move on to policies and procedures. LINKS1. runZero - Active discovery tool for asset inventory2. Enterprise Asset Management Policy TemplateFIND US ON1. Twitter - DamienHull2. YouTube

    Going Back to the CIS Controls - 247

    Play Episode Listen Later Aug 1, 2022 17:17


    Time for another maintenance episode. This time were going back to the CIS Controls. This time were using version 8. Hoping to implement the first 7. FIND US ON1. Twitter - DamienHull2. YouTube

    Azure Testing - 246

    Play Episode Listen Later Jul 11, 2022 14:17


    Time to start learning Azure. We've had Azure AD and Microsoft 365 for years. Just added Azure to the mix. Lots to learn. LINKSFree Azure AccountFIND US ON1. Twitter - DamienHull2. YouTube

    The OSINT Rabbit Hole: Part 1 - 245

    Play Episode Listen Later Jun 20, 2022 26:33


    Time to go down the OSINT rabbit hole. What is it? What are we looking for? What are some of the tools we can use? LINKS1. Kali Linux2. Shodan2. Spiderfoot4. theHarvester5. OSINT FrameworkFIND US ON1. Twitter - DamienHull2. YouTube

    Kali Linux, Nmap, Shodan, Gophish, Zap and Burp Suite - 244

    Play Episode Listen Later Jun 13, 2022 19:09


    Time to dig in and start learning the tools. LINKS1. Kali Linux2. Nmap3. Shodan4. Gophish5. Zap6. Burp SuiteFIND US ON1. Twitter - DamienHull2. YouTube

    New Job, VMWare Server, Tools - 243

    Play Episode Listen Later May 30, 2022 19:40


    Got a new job. This makes our lab environment more important than ever. Some labs will be for me. Others will be for work. We need to make sure everything is working. We also need good documentation. No more messing around. FIND US ON1. Twitter - DamienHull2. YouTube

    Organizing IT Before New Job - 242

    Play Episode Listen Later May 9, 2022 10:06


    There could be a new job in my future. Before that happens, we need to organize our IT. We're looking at patching, Microsoft Defender for Business, and data recovery. FIND US ON1. Twitter - DamienHull2. YouTube

    New Projects: SIGMA, Python, Cloud - 241

    Play Episode Listen Later May 2, 2022 23:22


    Time for some new projects. Still have a few things to do with Wazuh. Once that's done, I'll need something new to work on. Python is the big one. Seems everyone is asking for Python skills these days. LINKS1. The Azure Sandbox – Purple EditionFIND US ON1. Twitter - DamienHull2. YouTube

    Wazuh, Detection, and VMware Management - 240

    Play Episode Listen Later Apr 25, 2022 28:27


    Wazuh! It works! Not only does it work, but it's awesome. We're also covering detection as part of a security program. You can't have good security without detection. We're also throwing in a bit of VMware management. Can't manage labs in VMware without some management know how. LINKS1. Wazuh · The Open Source Security Platform2. Lab Instructions - Emulation of ATT&CK techniques and detection with Wazuh3. Sysmon config from SwiftOnSecurity4. Wazuh Server Rules5. Video: Installing The EDR Solution WazuhFIND US ON1. Twitter - DamienHull2. YouTube

    Wazuh, Sysmon and Atomic Red Team - 239

    Play Episode Listen Later Apr 11, 2022 27:57


    Time for more Wazuh and Sysmon. This time we're adding Atomic Red Team for testing. This is starting to look really good. Unfortunately we're missing something. LINKS1. Wazuh · The Open Source Security Platform2. Lab Instructions - Emulation of ATT&CK techniques and detection with Wazuh3. Sysmon config from SwiftOnSecurity4. Wazuh Server Rules5. Video: 163. Use Sysinternals Sysmon with Wazuh: The Swiss Army Knife for Windows MonitoringFIND US ON1. Twitter - DamienHull2. YouTube

    Labs, Wazuh & Sysmon, Microsoft 365 - 238

    Play Episode Listen Later Apr 4, 2022 22:15


    We've packed a lot into one episode. We're reviewing Dorothy's lab, Wazuh & Sysmon and Microsoft 365. We do have some good news. Got Sysmon installed. We also have access to good Microsoft 365 instructions and a book. We're moving in the right direction. LINKS1. Sysmon Installation2. Microsoft 365 Business Premium Partner Playbook and Readiness Series3. Office 365 for IT Pros4. ITProMentor: The Microsoft 365 Consultant's BundleFIND US ON1. Twitter - DamienHull2. YouTube

    How does one get into IT? - 237

    Play Episode Listen Later Mar 28, 2022 29:10


    There are many ways to answer this question. First, you need some skills. For this ongoing project we've decided to focus on Windows. Server 2019, Windows 10 and 11, and a bit of networking for good measure. One has to start somewhere. FIND US ON1. Twitter - DamienHull2. YouTube

    What is Microsoft Defender for Business? - 236

    Play Episode Listen Later Mar 21, 2022 13:41


    We're in the process of testing Microsoft Defender for Business. This includes vulnerability management, endpoint detection and response and a lot more. This could be the security solution we've been looking for. LINKS1. Overview of Microsoft Defender for Business 2. Video: Onboarding Windows 10 devices to Defender for BusinessFIND US ON1. Twitter - DamienHull2. YouTube

    Are Security Solutions 100% Perfect? - 235

    Play Episode Listen Later Mar 14, 2022 18:15


    Of course security solutions aren't 100% perfect. So, why are people building security programs around perfect solutions? LINKS1. YouTube Video: "Prevention First": An Approach to Cybersecurity w/ Minerva Labs!FIND US ON1. Twitter - DamienHull2. YouTube

    How do we deploy Sysmon? Part 2 - 234

    Play Episode Listen Later Mar 7, 2022 28:18


    Time to go deeper down the Sysmon rabbit hole. Looks like Wazuh does a lot more than we thought. LINKS1. Sysmon2. WazuhFIND US ON1. Twitter - DamienHull2. YouTube

    How do we deploy Sysmon? Part 1 - 233

    Play Episode Listen Later Feb 28, 2022 13:30


    Time to start thinking about our Sysmon deployment. There are a lot of moving parts to this project. It won't be a simple install on Windows 10. That's just a small part of the project. LINKS1. Security Onion2. Getting started with Elastic Stack3. Sysmon4. WazuhFIND US ON1. Twitter - DamienHull2. YouTube

    Mini Security Audit - 232

    Play Episode Listen Later Feb 21, 2022 31:22


    We're conducting a mini security audit. We've got our short list of things we're doing for security. Are they working for us? Are there things we need to change? How are we doing?LINKS1. Security Onion2. Getting started with Elastic Stack3. Sysmon4. AppLocker FIND US ON1. Twitter - DamienHull2. YouTube

    security audit
    Application Allow List with AppLocker and Intune - Part 1

    Play Episode Listen Later Feb 14, 2022 17:15


    It works! We have application allow listing with AppLocker. Pushed out the settings from Intune. This is awesome!NOTE: No links to instructions for Intune and AppLocker. I need to find good documentation or write my own. LINKS1. Security Onion2. Getting started with Elastic Stack3. Sysmon4. AppLocker FIND US ON1. Twitter - DamienHull2. YouTube

    What should we do for security? - 230

    Play Episode Listen Later Feb 7, 2022 21:34


    We've come up with a short list of things we should do for security. These are industry recommended solutions. They make it extremely hard for an attacker to get in. LINKS1. Security Onion2. Getting started with Elastic Stack3. Sysmon4. AppLocker FIND US ON1. Twitter - DamienHull2. YouTube

    Security in The Real World - 229

    Play Episode Listen Later Jan 31, 2022 19:43


    Security in a lab is one thing. Security in the real world is something else. Time to start thinking of real world solutions. LINKS1. Pay What You Can Training - List of Antisyphon training that includes John Strands classes. FIND US ON1. Twitter - DamienHull2. YouTube

    What's on your network? - 228

    Play Episode Listen Later Jan 24, 2022 30:03


    Do you know what devices are on your network? Do you have an accurate inventory? Discover what's really connected to your network with Rumble.run. This is an awesome network discovery tool.LINKS1. Rumble.run2. Nmap - Nice but not as cool as RumbleFIND US ON1. Twitter - DamienHull2. YouTube

    Security Training and Job Hunting - 227

    Play Episode Listen Later Jan 17, 2022 18:13


    Time for another round of security training. This time it's John Strands Cyber Deception class. We're also talking about job hunting Jason Blanchard style. LINKS1. Active Defense & Cyber Deception w/ John Strand - Starts 1-24-222. Jason Blanchard: Twitter Account3. Jason Blanchard: Twitch AccountFIND US ON1. Twitter - DamienHull2. YouTube

    Fortinet Firewall Licensing Update - 226

    Play Episode Listen Later Jan 10, 2022 24:14


    A proper explanation of our Fortinet firewall licensing. Goals, tasks, and lessons learned. LINKS1. FortiGate 60F - We have two of these.2. Overlay Controller VPN (OCVPN)FIND US ON1. Twitter - DamienHull

    Fortinet Firewall Licensing - 225

    Play Episode Listen Later Dec 20, 2021 27:52


    Time to get licenses for our Fortinet firewalls. They expire next month. We're also planning for next year. LINKS1. Free Python Class - Focused on network automation. 2. FortiGate 60F - We have two of these.FIND US ON1. Twitter - DamienHull

    My Python Class - 224

    Play Episode Listen Later Dec 13, 2021 19:02


    We're talking Python classes, Wi-Fi issues, security training and more. We're also beginning to plan for next year. Yup, the new year is right around the corner. LINKS1. Free Python Class - I'm not ready for this class. Might go back to it when I've learned the basics. FIND US ON1. Twitter - DamienHull

    What's next for the new lab? - 223

    Play Episode Listen Later Nov 22, 2021 11:46


    What's next for our lab? What should we focus on? What kinds of things can we add to it?FIND US ON1. Twitter - DamienHull

    new lab
    How long does it take to build a basic lab? - 222

    Play Episode Listen Later Nov 15, 2021 20:32


    It use to take us forever to build a lab. Lots of documentation, testing and planning has changed that. Big step in the right direction. FIND US ON1. Twitter - DamienHull

    We Need a Network - 221

    Play Episode Listen Later Nov 8, 2021 14:51


    We need to build a new network. One that includes a Firewall, Windows Domain Controller, Windows 10 and Windows 11 workstations. This will be our starting lab. One we can add to in the future. FIND US ON1. Twitter - DamienHull

    We're Analyzing Logs With Logwatch - 220

    Play Episode Listen Later Nov 1, 2021 16:00


    As the title says, we're analyzing logs with Logwatch. Big step in the right direction. Started this back in episode 218. Couldn't get email to work. It works! Not only does it work, but we can catch evil. LINKS1. Logwatch2. Postfix3. How To Install and Configure Postfix on Ubuntu 20.04 4. Rsyslog TLS configuration : Ubuntu simple step-by-stepFIND US ON1. Twitter - DamienHull

    Netbox for Network Documentation - 219

    Play Episode Listen Later Oct 25, 2021 15:02


    Found a new tool called Netbox. This tool was designed to document large data centers. We're trying to use it to document our network. Lots of cool features and lots of moving parts to think about.LINKS1. What is NetBox - FREE Network Documentation System?2. i HATE network documentation....but NetBox might help // ft. Jeremy Cioara3. Installing Netbox in 10 Minutes or LessFIND US ON1. Twitter - DamienHull

    Installing Logwatch For Log Analysis - 218

    Play Episode Listen Later Oct 18, 2021 20:59


    Time to analyze our cloud server logs. For that we're going to use Logwatch. This will require the Postfix SMTP server for sending email. We also need the UFW firewall. Once again, lots of moving parts. LINKS1. Logwatch2. Postfix3. How To Install and Configure Postfix on Ubuntu 20.04 FIND US ON1. Twitter - DamienHull

    Installing Windows 11 and VMware Updates - 217

    Play Episode Listen Later Oct 11, 2021 16:24


    We're talking Windows 11 and VMware Updates. Did an Install of Windows 11 in our VMware environment. This required a virtual TPM. Moved on to VMware updates. This included updates to ESXi and VCSA. Lots of moving parts to these projects. LINKS1. Create a Virtual Machine with a Virtual Trusted Platform Module 2. Configuring and Managing vSphere Native Key ProviderFIND US ON1. Twitter - DamienHull

    Learning to Use Microsoft 365 Apps - 216

    Play Episode Listen Later Oct 4, 2021 20:56


    We're trying to get the most out of 365. That includes learning how to use apps like Teams, Planner, OneNote and more. There's a lot of moving parts to this. Installing, configuring, training, standards and more. We're still at the beginning stages of this process. We have a long way to go. FIND US ON1. Twitter - DamienHull

    Planning For a New Wi-Fi Access Point - 215

    Play Episode Listen Later Sep 20, 2021 26:53


    Time to plan for a new Wi-Fi Access Point. We're replacing our old Asus Wi-Fi router with a Fortinet Access Point. What are the risks? How much downtime will there be? What's our backout plan?FIND US ON1. Twitter - DamienHull

    Building an Internal DNS Server - 214

    Play Episode Listen Later Sep 13, 2021 23:25


    Time to add another DNS server to the network. This could be considered a small project. It still has a lot of moving parts. What OS should we use? What hardware should we use? Can we manage another server? FIND US ON1. Twitter - DamienHull

    Can we speed up a Server 2019 Install? - 213

    Play Episode Listen Later Sep 6, 2021 13:22


    Dorothy want's to speed up the installation of Windows Server 2019 in the lab. We're looking into an automated install. We're also looking at all the steps leading up to the install. How do we connect to our VMware server? How do we create a VM? How do we make everything faster?FIND US ON1. Twitter - DamienHull

    Could we manage 1,000 Laptops? - 212

    Play Episode Listen Later Aug 31, 2021 15:47


    Yes we can! We're using Intune, Azure AD and Automox to manage two laptops. The same process we use for two could be applied to 1,000. Settings, applications and updates can all be pushed out with a few mouse clicks. FIND US ON1. Twitter - DamienHull

    Lesions Learned From 3 Job Interviews - 211

    Play Episode Listen Later Aug 16, 2021 23:24


    I've had 3 job interviews this year. Here's what I've learned so far. FIND US ON1. Twitter - DamienHull

    Basic Microsoft 365 Security - 210

    Play Episode Listen Later Aug 9, 2021 15:03


    We're focusing on basic Microsoft 365 security. We're also reviewing our Microsoft 365 Business Premium Licensing. LINKS1. m365maps.com 2. Basic Security Set Up for Microsoft 365FIND US ON1. Twitter - DamienHull

    Claim SECTION 9 Cyber Security

    In order to claim this podcast we'll send an email to with a verification link. Simply click the link and you will be able to edit tags, request a refresh, and other features to take control of your podcast page!

    Claim Cancel