All language subtitles for Day 1 - Security Boot camp _ CompTIA Security (SY0-601) Exam Preparation - English (auto

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal) Download
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

hello everyone

this is ayam nigi and i am a part of

infosec train

i am one of the trainers uh in

infrastream talking about my experience

uh i have like five

plus years of experience earlier talking

about the days i was into web

development

later down the line i switched to your

cyber security field because i like have

a

keen interest over this field right so i

rather than

going with them and continuing with the

web development i try to grow myself

into cyber security

because i like have a future plans

regarding your dev setups

which is inclusion of your development

part your security part and your

operation part as well right so already

i have a like a bit of an experience

regarding

your development field so i'm more into

now uh cyber security so

covering this field of area and rather

than like

later then i will be going for the

operations as well right so you can say

i like a future

or goal of mine it can be like devsecops

right

moreover we are dealing with other

regarding cyber security right now

right so these are the domains of my

experience like the security testing

cloud security and devops

right so uh talking about the

training and experiences i have

delivered plenty of the batches with

inclusive training

right and talking about the course for

now right the security plus

so security please are it's a defensive

course

right as you guys know uh you guys know

about the teamings right

the red team and the blue team correct

so talking about the teams red teams are

totally guys for your

attacking phase right so regarding the

security plus right

uh and this whole course so basically

guys uh

as i was mentioning we have two teams

right the red

team and the blue team right so that

team

morally focus on your offensive side

right you can see in an attacking site

where they

they exploits the thing they they enter

into the system

right they found all those

vulnerabilities in your network and try

to

exploit them and get an access control

over the system right

and uh it's targeting 601 basically

right but moreover

we'll be covering the topics right since

you know

six hours or three hours of a day it's

not sufficient to cover the whole

topics of the 60 601 right or the whole

security

uh course so we will be covering the

broad areas

right and so we'll be covering broad

areas we'll be covering bits of

of all of them right so yeah and more

specifically

if you're asking about a five zero one

and six zero one will be targeting the

cardinal

security plus six zero one which is the

latest version going on you know

comp shia right the vendor which is

providing security places your comms

here

so your latest version is when your 601

okay so as i was saying security plus

it's your

blue teaming uh blue team course right

which is totally a defensive one it's

not basically

based off your attacking one right here

you loan regarding the defensive side of

the

whole cyber security right so the low

the skills you will be learning in your

cyber

or security place would be like

regarding the terminologies

regarding your attacks threats

vulnerabilities

right architecture and design the

implementation of the policies

right all those about the compliances

your incident deploy

response and operational response if

there is any sort of an attack happen

or your mitigation techniques right so

these are the skills which you learn in

this whole security

plus course right which is provided up

by a conscience

correct so but today we'll be covering

the broader areas so for today's session

right we'll be discussing regarding your

threat actors and threat intelligence

and your malwares and your social

engineering attacks

all right so these are our today's

agenda and that are

topics which we'll be covering

so basically if you talk about uh the

agenda of the

security plus right so like there are

plenty of job roles you will be getting

in it right like your security

administrator right your system

administrator

like your help desk manager your endless

your network engineer your security

engineer

right you can even go for the profiles

of your

devops software developer your i.t

auditors right and your id project

manager as well

so basically uh what you can say

security players are it's a

base level which will be covering each

and every ground of your

other high level techniques right so you

will be setting up your ground level

with this security plus course right so

you will be

getting a much more insight in this

cyber security

specifically talking about the blue team

side

right you will get to know about the red

team as well

right uh like not as an attacking phase

like how to attack and how to code and

how to write scripts

but you will get a few bits of an idea

regarding these things

okay like what sort of a scripts

look like how you launch an attack right

what are the uh like steps to do that

right how do you do the information

gathering because it can be like useful

from the security purpose as well right

and like

how do you attack and particular port

how do you scan them and all these

scenarios

you can cover with the security plus

side as well so you will get a

like you can say an overlook of an

attacking

uh area just to know how things

look around from that side right but

moreover it focus on your

defensive side all right so

uh talking about the examination as well

right talking about the examination you

will be having if you go for the

examination of security please like

accomplish the vendor as i

already mentioned over there so if you

talk about the number of questions in

your examination guys that will be

90 questions over there okay in an

examination it will be of

90 questions it will be if you talk

about the

pattern of the type of questions over

there it will be a multiple choice

examination over there or uh security

plus

and the length of this test would be of

90 minutes guys okay the length of the

test would be 90 minutes

there will be 90 questions over there

and that two will be of

multiple choice so if you talk about the

passing score

uh it would be like if the question will

be like a thousand you can say of

750 right and these sort of things so

750 of a margin

it will be of on a scale of 100 to 900

it will

750 without passing scenarios over there

okay so that was a bit regarding your

whole certificate scenario if you want

to offer the certification

you have to opt for this right

so if you can see uh com she is the

vendor of this and

the code which is latency being for like

followed by x601

right sy-0601 which is of a security

601 so these are the skills which we'll

be covering over here

in this whole courses these are the jobs

and opportunities out there regarding

this course

and you can always found the exam

details over here right the maximum

number of questions are 90

your 750 will be passing score length

the test is 90 and you will be the

multiple choice

questions over there all right so these

are the

bits regarding your certification part

all right

it can be like very efficient to have

this certification or

moreover if you have the knowledge for

this particular

field right as per your job purpose and

like if you're entering into cyber

security field it can be really very

helpful and insightful

to stand out from rest of the public in

this particular

domain all right so proceeding further

with the course lies

right just to mention regarding about

infosect train

we are established in 2016 we are one of

the finest security and technology

training and consulting company

right we provide a wide range of

professional training programs

certifications and consulting services

in the

itn cyber security domain and we have

high quality technical services

certifications or customized training

programs created with

professionals of over 15 years of

combined experience in the domain in

their respective domains

all right and if you talk about our

endorsements

we have like four plus years of services

right and we have a 70-plus school of

trainers

we are already offering 150 plus of

courses right

and we have 100 plus corporate

deliveries we have

valuable partners which has a number of

10 plus and we have 15 000 because of

profession train all right and these are

our trusted clients

you can have a look on them right

samsung microsoft vmware deloitte hcl

and many more and if we talk about why

infosec train

because we have already have certified

and experienced instructors

right and we have these flexible modes

of training

according to our requirements according

to you participants like

whenever you guys are comfortable

regarding the trainings and all those

scenarios and periods

uh any time of the day so we provide

these of flexibilities

for you participants right and like

you can always have the access to the

recorded sessions right we

go through this go to meeting platform

only and whatever the training you will

be having for each and every day

all those session and all those recorded

uh these session will be get recorded

and these recording will be passed on to

you guys via email

and everything right so moreover we also

provide this

uh tailor-made training right for any

particular course

and according to customers or like

participants like you if you have any

you can say any specific requirement

regarding any particular

certification or any particular course

we can always go through all your

requirements and we provide you like

tailor-made training right we can

customize it

according to your needs and we can

provide you that

right all right so basically guys first

of all

talking regarding this cyber security

right

okay so guys what do you understand by

the term security

all right so there's security like you

can say uh

gets you uh in short you can say a

freedom from all those potential harms

right

as you mentioned it gives you the

protection you see it gives you the

safety it gives you securing your and

your environment right so it protects

you from all those

external attacks you can see or any

internal direction attacks we'll talk

about that

later on as well right so these will be

providing what uh your security is

a protection of your own network or

organization

regarding in general terminology as well

it's a protection from

each and everything right which can harm

us which can affect us in a

uh more negative way correct so security

is to provide you with a

protection from them isn't it so guys

when we talk about

uh security right so information

security or you can refer it as your

infosec as well right it refers to the

protection of

data resources from any unauthorized

access right isn't it like from any sort

of an attack

theft or a damage right so these data

are talking about this data right uh

which your organization holds so this

data may be vulnerable right because of

the way it is stored

the way it is transferred over the

network or the way it is processed

correct so the system the systems of

yours they use to store

or transmit and process these data must

demonstrate the properties of security

guys

okay and you can also say this cia right

these like since your secure information

has three properties

which are referred to as your cia trade

cia stands for confidentiality

integrity right and the availability

okay so basically you can also mention

them as a three pillars

of your security all right so

confidentiality basically right that's

what you understand by the term

confidentiality

so confidentiality means that certain

information should only be known to

certain people isn't it

exactly no one can access right yeah

data to be accessed by

authorized people correct so you can

maintain guys this confidentiality by

encryption isn't it

like you can use encryption for

maintaining the confidence

confidentiality

right then talking about the integrity

it means in short that the data is

stored and transferred

as intended right correct

as it was like sent from one user to

another user it was

going as intended nothing sort of a

alteration or modification

is there correct and you can maintain

this integrity by

hashing isn't it right you can put up

integrity by using

hashing then guys we have availability

as well

availability means that information is

accessible to

those authorized to view or modified

right or you can say like

it is available like if we talk in terms

of here like

uh your this ecommerce website or anyone

so like it is

uh available for the users right

to their authorized users or their

genuine users isn't it

so we can maintain these availability by

using the load balances

isn't it or the backup plans right so

uh as we are talking about uh the cia

tried right

so guys what happens some security

models and resources

identify other properties that secure

systems

or like should exhibit right they should

opt for them there as well

because these are not enough to maintain

the security so the most important of

these is you have

non-reputation have you heard about

non-reputation guys what do you

understand by non-reputation

non-reputation means that the subject

right he cannot deny doing something

right

such as creating or like modifying or

sending a resource

right for example if we talk about a

legal document

uh such as a will or like it must

usually be witnessed when it is signed

right

so if there is a dispute about whether

the document was correctly

executed the witness can provide

evidence that

it was right so moreover you can if you

talk about a simply example regarding

this noun repetition you can always talk

about a system camera isn't it

right it's a very common example for

that and a very strong one

so something you do is caught in your

sweet smoothie cam or cctv camera and

you cannot deny about it isn't it you

maintain

non reputation by digital signatures as

well guys uh

there is also authentication as well

right what do you understand about

authentication

okay so guys uh actually what happens

when we

talk about security alright so when we

talk about security

your information security and cyber

security task can be classified in

like five functions right uh

it can be classified in five function

like they what they do they follow the

framework which is developed by our

nest right next stands for national

institute of standards and technology

right so nest it is a set of best

practices

the standards and recommendations that

help an organization

to improve its cyber security measures

right so it is focusing

exclusively on iit security so the next

cyber security framework seeks to

address

the lack of standards right when it

comes to security

so there are currently like major

differences in the way

companies are using technologies

actually right

and the languages and the rules to fight

hackers you can say or the malicious

actors

right and those i can call them as a

data pirates and the

ransomware as well so cyber attacks

right are becoming more widespread and

complex isn't it

becoming very very complex and they are

getting advanced with the time right

so fighting these attacks are becoming

much more difficult

right time is going on or the hackers or

the malicious actors are also upgrading

themselves

they are making their strategies more

and more complex right

so fighting them going against them as a

security person

is also becoming difficult this is

compounded by the lack of

unified strategy among organization so

that's why your nest

it provides a uniform set of rules

guidelines and standards which makes it

easier to share information between two

companies

and easier to get everybody on the same

page

on the same note right so

as i mentioned uh it is classified into

five functions

right so they are your first is

is identify all right

so what do you understand the term

identify guys so what you do you develop

security policies and capabilities over

here guys

you evaluate the risk threads and

vulnerabilities

and recommend your security controls to

mitigate them or to resolve them

right that's your identity part over

here right the function

of your identity then is there your

protect

right so protect what it does it

determine

how your current cyber security policies

protect your organization right and

where they

fell or fall short right where they are

like

having those uh loopholes or the you can

say

the shortage right so this function

supports the ability to

limit and contain any impact resulting

from your cyber security right

so you can categorize uh like which fall

under protection like

like in your access control data

security

information protection and procedure in

your maintenance so

you can like categorize them into

these shortings right in your

organization so that falls under your

protect then you have your detect as

well

all right so what do you understand by

detecting what might be in this function

so what you will be doing you will be

performing ongoing

you can say proactive monitoring to

ensure that

controls are effective and capable of

protecting against new types of threats

absolutely money right then we have guys

respond as well

all right so what you doing respond uh

in this category you identify you

analyze you contain and eradicate

threads to systems and data

security all right you identify you

analyze the contain and eradicate

threats to systems

and data security all right

perfect then you have recover

what do you understand about the term

recover guys yeah you recover from the

incident you have plans

right you moreover you implement cyber

security resilience

to restore your systems and data if

other controls are unable to

prevent your attacks perfect you can

call them a backup strategy as well

all right perfect so when we talk about

security

control category side so your

implementation implementation of cyber

security function is often

the responsibility of the iit department

isn't it so we have like few

security controls so security control is

to provide the system

or the data asset the property is like

your confidentiality

integrity availability and your

non-reputation isn't it

that's the main agent of our to provide

all these

properties to the system of the data

asset correct so control these controls

guys they uh can be divided into three

pro

categories right so these are like

representing how the

control is implemented right so if you

talk about technical

right in the technical it is the control

the control is implemented as a

system like you can say hardware or

software like for example

in your or like firewalls antivirus

software eyes

and your operating system access control

modules and are your

technical controls okay yeah exactly

so technical controls may be or like may

also be described as

logical controls over right then we have

operational

so the control is implemented primarily

by people rather than

systems over here for example you can

say the security guard

right and the training programs are

operation controls rather than

technical controls correct then you have

managerial

so the control gives you oversight of

the information system right

example could be like including risk

identity identification

or a tool that is allowing the

evaluation and selection of other

security controls absolutely perfect

so security controls guys can also be

classified like in types of

types according to the goal or function

they perform actually

okay so it can be your preventive

it can be a preventive exactly right

what do you understand about the

preventive so this control acts to

eliminate or reduce the

likelihood that an attack can succeed

isn't it so a preventive

or you can say the preventative control

operates before an

attack can take place right you can like

like your access control list right

configured on your firewalls isn't it

and i like your file systems objects of

your preventative type controls

right and there is a detective or sorry

detective as you mentioned what do you

understand about the term detective

so this control may not prevent access

okay but it will identify and record

any attempted or successful intrusion

right so a detective control operates

during the progress of an attack okay

so pretty much good example for that

would be on logs isn't it

logs provide one of the best example for

your

detective type controls right

then guys we have one more which is your

corrective so what do you understand

with the term corrective

so this control acts to eliminate or

reduce the impact

of an inclusion event so a corrective

control is used

after an attack right a good example is

a

backup system isn't it that can restore

data that was damaged during an

intrusion right and there are like few

other types

also guys like that can be used to

define other cases over here

regarding the security control one is

your pretty much

physically right the physical one

in physical what you can put over here

like controls regarding your

like physical inclusion but ccd camera

perfect

anything else guys barrier doors all

right

fences perfect locks

great security guard awesome

perfect swipe card all right okay so

controls as you already have mentioned a

lot of examples right there are the

pretty

good ones so a control such as your

alarms your gateways

locks lighting right your security

cameras

and your guards right that deter and

detect

accesses to premises right and hardware

so that's a physical security control

then you have

i believe one of you have mentioned the

deterrent before

right so what is in your data right guys

perfect so in detroit to discourage

people from doing things

all right okay like cctv camera

system camera as we mentioned so it

would be like in your physical one right

like the control like you can say may

not physically or logically prevent the

access but

it controls psychologically isn't it it

discourages

an attacker from attempting any

intrusion

right as you mentioned perfect the sign

boos it includes sign boards and

warnings of legal penalties correct

uh if you're like trust uh trust uh

trespassing any or trying to

make an intrusion into an organization

or in the premises they're like science

uh or like science uh like taking a very

basic example is as you mentioned

be aware of dogs right so it

psychologically

uh discourages that particular threat

actor

protector as in the hacker or any any

malicious person

going on over there right who is trying

to do any sort of a

activity which can harm us right so we

put out these

signs which can like play around with

them

mentally right so these are not

physically or logically they are like

more of your

psychological right so it

psychologically discourages an attacker

from

attempting an intrusion correct

then we have compensating

so what do you understand by the term

compensating eyes so

the control this control right it serve

as a

substitute for a like main control or

the principal control right

and efforts like the same or better even

the better level of protection

but it uses a different methodology or

technology you can see

isn't it so a single employee has the

duties of accepting cash payments

let's say right for example a single

employee has the duties of accepting

cash payments

recording the deposit and like

reconciling the monthly financial report

or like

making the settlement of all those

reports so to prevent

arrows and or like all those sort of

frauds

additional oversight is required right

this means we need a compensating

control such as the leader we can put up

over there

right up like who can perform a review

of those settlements or

another unit who is performing the

settlement instead of like of that

single employer

correct so we can put up an alternate or

you can say the substitute which

might be giving the same or the better

level of a

protections right and might be using

different methodology or

methodology or technology or those

technique but

it will be just like a compensating

which can give you the better control

out there

right so since we are talking about

these things guys

right so security control and uh

everything

so they are always we are dealing with

vulnerabilities

threat and risk isn't it

so we are always dealing with the

vulnerability threat

and risk correct so talking about them

one by one guys what do you understand

by the term vulnerability

perfect like a flaw isn't it if you talk

about the vulnerability it can be a

flaw am i right right all right

so any flaw or any sort of a weaknesses

we know or we call them as a

vulnerability right any sort of a

weakness or flow in your network

right uh that could be like triggered

accidentally or which can be

exploited right by or any

attacker like it can be intentionally to

cause a

security breach right that's your

vulnerability for you

isn't it correct so those are

vulnerabilities what do you understand

by the term guys uh

next one is risk

so basically in general way we can put

out your risk

as like the possibility of occurring of

an

incident it may happen or it may not

isn't it

but let's say if i'm holding a glass of

water over my laptop guys

right it may spill it may not isn't it

correct so going with the terminology

like if like proper definition it's like

the likelihood and impact

or you can say the consequence of a

threat actor

exploiting a vulnerability right

so to assess risk you identify a

vulnerability and then evaluate the

likelihood of it right of it being

exploited by a threat

and the impact that is successful

exploit

you could have over there isn't it so

moreover when we talk about

a risk guys this this can be positive or

negative isn't it

if i take an example bug bounties by

companies role how can it be like a

risk like how can be outcome of positive

or negative

okay we'll discuss later on but moreover

just let me take you the example which i

have

it can be like you put up something in

the share market right

if the share goes up you you are doing

in the rest basis right the share goes

up

correct all right you have a positive

outcome if it goes down you have a

negative outcome of that isn't it so

that's a risk we are playing over there

right perfect so then we have

which brings us to our next one which is

your thread

so what do you understand with the term

thread guys so threat is something

that can harm your asset in a manner

right

so these threat is the potential

for someone or something to exploit a

vulnerability isn't it a threat maybe

you're

intentional or unintentional right the

person

or the thing that poses the threat it is

called your

threat actor or you can say a threat

agent

right okay the person

or thing that poses the threat

is called as your

threat actor

or your threat agent people call it with

various name like a malicious actor you

can say

right and all those things correct

so i and the path right a path or the

tool

used by your malicious threat actor

can be referred as your

attack

vector right that's a thread for you

so since we are talking about threat and

threat actors right

which brings us to our next thing our

next slide which is your

threat actors right isn't it

so if you talk about trajectories you

can say uh you can see pretty much of a

good list out here right so your nation

states cyber criminals

activists terrorist groups thrill

seekers

incited threats isn't it so national

states are like a jeopard political one

the

government provided one right you can

say them as a state

based also isn't it like state sponsored

you can say that

right cyber criminal uh criminals they

have a motivation of a profit

right they go for the profit scenarios

and they

do this cyber attacks over there right

then we have this

hacktivist what do you understand by the

hacktivist guys

as it says motivation is ideological

right

so we can say them like they are like

anonymous

like other common you can say set up by

example for that the activist

right it's a group of attackers or these

activists you can say

so they they hack you can say they have

for an agenda right you can divide this

or terminology into two words like hack

plus activist

correct so they hack for an agenda it

can be like

any any for any purpose right it can be

ideological in terms of like

uh to support the humans out there like

turning like against the government and

all those things so they have this

agenda political gender you can say

and they perform those attacks regarding

that only so if you take an

example of an anonymous group you guys

might have remember this

paris attack was there right so they

help in finding a few

much of details regarding the other isis

party you can say right

and this also happened a big one this

black lives matter

right so anonymous group were also there

as a part of it

right there what they did they got into

the whole organization system that they

uh leaked out few much useful

information which they were hiding from

the people

right and they they like leaked all

those footages which can be like

seen by people out there and they can

like see what the government are

planning against

right and all this sort of weight so

anonymous you can take a very good

example over there

right so terrorist groups you can say uh

always there are cyber uh this threat

which is doing what

it is like having a motivation of uh

violence over there isn't it

so they always deal with the loss of

human life or say

right so if i take an example for that

if you guys have known about the

stuxx net right so a malware was

implemented

almost compromised a nuclear power plant

in iran

so you can put up in the category of

cipher terrorists right so insider

threats any these things real secrets

these sequels they always do for the

exactly shaman attack perfect

so thrill seekers they are always going

for the satisfaction inside the threads

we'll be talking about it later on so

continuing this thing right we have some

other types of it as well so we can look

over here

hackers script kitties and hack device

activities we have already discussed

right

so if you talk about these hackers right

so we have these three type of hackers

right and if you talk about a hacker you

know hacker is someone who has a sound

knowledge of computer and system

administration

right so he has a good knowledge

regarding the hardwares as well as the

networking part

right and like he's sufficient

having sufficient amount of knowledge

regarding all those tools so requires to

do those attacks right perfect bro d3

categories in hackers blackhead

greyhead and whitehead so what do you

understand by the term

blackhead hackers guys so we can

collectively say

a guy is having malicious intent and

those who hack for personal benefits

right guys having malicious intent and

those who hack for the person's benefits

we can like put them into the category

of black hat hacker

isn't it so guys these black hat gray

hat white head i as we have mentioned

right

they have a pretty much good sound

knowledge regarding the

whole computer and system right and the

whole network

so this gray hat as well what do you

understand by the gray hat guys

so you can see the moment they see an

opportunity right they shift towards it

you can see in that way

uh basically let's take an example

regarding greyhead hacker let's say

there is a hacker

was just going through a let's say an

organization their server

right and and he was able to find a

vulnerability or you can see a bug in

that

okay so what he did he went to that uh

organization or to the person

who is like taking uh who's in charge of

all these reporting and everything

he went there he mentioned over there

okay i was able to find out a bug in

your server or in your network

now uh i will tell you about the bug if

you

pay me for that right you can let's say

uh like not a bug boundary program but

he needs some

some amount regarding that telling about

those bugs and all those things so

basically he has a very

good intention not to exploit it not not

to take up the control of all those

organization and try to

make any a negative effect out of it

right

so person what he's doing uh like he

went to the organization of the person

who is in charge of it he reported over

there okay i found a bug in here

on the server in your network so i want

to like a repair like a price money for

that right a small amount

but but the person over there he he

denied for it he said okay

we won't be paying for you or we won't

be paying you for that

particular thing so now what he did he

went to the

yeah dark net right the dark night here

dark web and he

released all those information all those

bugs over there and you know

everything over the dark knight has a

price right for a for each and

everything

it has a price correct so he sell out

things over there so it can be like an

opportunity over there like he found

about him he can sell over there he was

getting a like good amount from there so

he gave all those

details over the dark way that's what's

your gray hair hacker

then what's up white hat hacker guys the

one who performs

uh all these activity with permission of

pen tester

perfect sample right so what they do

they go by the rules or the books

isn't it right so as we are talking

about the fantastic right so you might

have seen this

fantast programs or over there all those

certifications if anyone is interested

since we brought it up

it's a pretty much good feel to go out

if you're more

inclined towards this attacking

situation or

all these sides right so what they do

like if you talk about the fantasy and

everything so first of all they they

found all those vulnerabilities all

those

loopholes which are they are signed for

they go by the book right so organize

the organization they hire a pen test

fantastic so you can say right they hire

a fantastic

they set up some rules you can say or

like a scoping thing right uh

planning and scoping is in the very

initial stage

for this your pen testing right the very

first phase planning and scoping

so you go with the organization you come

up in a deal you plan and scope all

those scenarios

right when you can do the pen testing

which sort of a server is allowed to do

pen testing

at what time i can do the pen testing

right and

like what all techniques i can use like

it will will it be the black box

white box gray box right and like huh

can i perform social engineering attacks

or not right what are the key cards of

your organization so that i can like

like i cannot do fantastic at that time

or even

what day like i should do the pen test

right

which should it be monday at use or if

any any sort of specific days mentioned

for up and tester to do the pen testing

on the day

so planning and scoping is like defined

in such a way right

all those things are mentioned and all

your scopes and all those permissions

are mentioned over there

and then the new you perform you and

test right then you do

rest of the stuff that you're scanning

like enumeration

and taking advantage of uneven

vulnerabilities or exploits which are

found out

right so these are the jobs of a pen

tester right

but he goes by the rules right he

organization is up has appointed a pen

tester

he make a planning and scoping as i

mentioned

right so in that planning and scoping

everything

is clearly mentioned like all your

limits all your boundaries

are mentioned over there and you cannot

go around or go beyond those limitations

which are set up by the organization for

you

right so that's your white hat hacker

pen tester which go by the books and

they too are the

authorized one isn't it i hope that's

clear

so uh talking about these guys uh there

are few more as you have mentioned

just the script kitties

what do you understand about the term

guys script kiddies

so moreover we can classy them or

classify them up into a person who have

no knowledge but are like you can say a

curious mind

right under skilled one perfect but

those who are like a curious minds and

don't do have

much of a knowledge regarding these

things right like they don't or they

don't have

like specific knowledge regarding the

tools what tools and what sort of a

scripts

but to write and how to use the tools

they do just what they go through the

youtube

and they will just randomly like they

pick that script and try to run it that

doesn't know what

might be the outcome of it like they

know like what it be doing by watching

youtube but they don't know like

what each script what each particular

code

does over there right so he doesn't uh

give a thought regarding these scripts

but uh but he just use them you

utilize them so like you can say

scripted these are those who don't

have a much of a knowledge but they are

the curious mind right

like you can put up all those categories

those who want to like hack their

like girlfriend's instagram or all those

things how to do that they just go to

the youtube and try to

exploit it in that way right so you can

put it into

that particular section for your kitties

right

perfect then guys there is the one more

which goes

by the name suicide hackles

like how can you define a suicide hacker

guys

the one who knows what is the outcome of

it right

they know that there will be the bad

consequences

isn't it but still they make that call

isn't it they know let's say if someone

is hacking a facebook or something like

that they know okay

they'll be like a lifetime imprisonment

or something like that if you're trying

to steal a lot of

money from a bank account or something

like that they know the outcome right

they know everything

but still they are going for that thing

right they are

making that call so that's your suicide

hacker all right i hope that's clear to

everyone

so these are the bits regarding our fed

actors

right a few more which brings us to

attributes of threat actors

so we are talking about the attributes

of threat actors

they are internal external intent and

motivation so guys first of all what do

you understand by this term

internal threat actor so or you can say

an internal or

insider threat actor is one that has

been

granted permissions on the system isn't

it

so as you mentioned the example of it

it's a employee of the company

right perfect so uh we can like uh have

this malicious

insider threat as well right here like

your employees your contractors your

partners

you can classify them as well into your

internal threat

actors exactly yeah perfect exactly guys

then uh like we can also put above like

your internal

these threads can be like your

unintentional as well isn't it guys

intentional like you can put employees

and everything over there but

intentionals are also over there right

your unintentional

insider threat right so like weak

policies you can put it over there

like weak policies and procedures like

or even the lack of training

or to the employees or the security

awareness to them isn't it

like uh if i take a very good example of

that like if you are trying to

trying a phishing attack doesn't it so

obviously organization what they do they

they

give the training to their employees

regarding the fishing and everything to

make their awareness

right so if they're not providing a

sufficient

training or like not training their

employees regarding and making them

aware regarding all these sort of an

attacks

an attacker like can take an advantage

of that

am i right so these were like regarding

internal ones right then there is your

so external threat can be someone not

from

inside the organization but from the

outside right

that can enter to the security system of

the company

using malwares or any social engineering

attack right

exactly perfect so an external thread

actor has no account or he's not having

any authorized

access to the target system right that's

why he uses techniques

like malwares or social engineering

attacks to enter the

security system an external actor if you

talk about it right

he may get hands-on like security system

by

like doing an attack on like remotely or

either on the

premises right of like breaking up into

the headquarters by

bypassing all those fences and all those

things right so he cannot

attack either remotely or click on

premises

so it's make it very clear right so it

is a threat actor

that is defined as external not the

attacking

method he is using doesn't it that's a

actual thread actor for you right then

guys they have

intent and motivation what do you

understand by the intent guys

so intent means what the hacker is

hoping to get from the attack right

doesn't it

intent means what the attacker is hoping

to get from the

attack doesn't it and what's the

motivation guys

these are the attackers reason to

perform the attack isn't it

a malicious threat actor like

he can be motivated by greed

curiosity or some sort of grievances you

can say right

for instance exactly to gain money you

can say right

exactly right so like if you talk about

intention like

it would be like regarding to disrupt a

system or to steal some sort of

information out of it correct so

since we are talking about the threat

actors right we always have this

threat intelligence as an outcome of it

isn't it

so threat intelligence basically of

cyber threat intelligence is

information an organization

uses to understand the threats that have

like bill or are currently targeting the

organization right so this information

is used to prepare

prevent and identify cyber threats

right to like counter them or i'll

control all those adverse effects

isn't it so so these these are used to

prepare prevent and identify

cyber threats looking to take advantage

of valuable resources out there right

so over here as it is defined as we all

know the world of technology is growing

day by day

and so as the cyber attacks right so

threat intelligence

is the knowledge by which we can prevent

or

mitigate those attacks right

so guys if i say like if you are talking

about the intelligence right what's an

intelligence just define it so if i

write if i'm writing let's say

twenty three slash zero

zero five slash twenty twenty one

right twenty five slash zero five slash

twenty twenty one 20

8 0 5 20 21

let's say 2 0 6 slash 2021

and so on right first of all if i

mention these things

what are they for you they are just

dates isn't it right they're just dates

over here

not information yet not information yet

for now these are just a

data for us am i right they are just a

data yeah i am mentioning dates

which which are like a data for us for

now right but

if i write something like this

list of

holidays at the heading you can say or

the

title of it then you can say

exactly it's like an information right

correct it's a information exactly

perfect right so these are your

information isn't it

like it is giving now some sort of

information to us okay these days

are like your list of holidays for us

right

so these these are your list of holidays

it can be like a list of holidays over

here

but okay if i specify this

right and like if i specify this date

and like i'm planning to go to

somewhere out there not now since the

covert is over there

right but later on if there is a date

right and i'm planning to

like since the list of qualities are

mentioned i'm planning to go at a

particular location or any place

right on these mentioned dates right

that can be a

intelligence reason being

we are doing what we are making the

decisions out here we are making the

decisions out here

so when it's decision making it's your

intelligence isn't it

like when you're planning out to do

something out of those deeds right

so these are your intelligence correct

all right so which brings us closer

threat intelligence which i've already

told right

so that intelligence or cyber threat

intelligence is information

an organization used to understand the

threats that have

will or are currently targeting the

organization right which can be helpful

for us to prepare and like prevent the

organization from all those cyber

threats right which can be taking an

advantage of

our valuable resources out there isn't

it so when we talk about

these things there are always some

resources for the threats

search right so we have threat research

sources as well so threat research is a

counter intelligence right

it's a counter intelligence gathering

effort in which like your security

companies and researchers

the attempt to discover the

tactics techniques

and procedures right

tend to discover tactics

right techniques

and the procedures

right so we'll talk about it right

like they are they fall in the category

of your threat intelligence providers

okay moreover when we talk about your

threat research

sources right we can go get from the

firewalls regarding your logs and all

those bits

and like we have these honey nets as

well right

so moreover like in short what you are

trying to do is like you

provide them few areas right to attack

right you can say

uh you have a dummy server you pull it

up

over there right and you are luring or

like you

you are like giving those server the

dummy ones right

to the attackers okay you have your main

server

right which like can be a similar of

functionality you can say right

and all those network architecture out

there but moreover main is on another

one

and you you put out those or that dummy

one out there right for an attacker

so attacker will do what he will try to

exploit it right he will try to

figure out the vulnerabilities and he

will try to take an advantage of that

but you are the smart people are around

here right the security one so what he

did

so what all techniques what all

procedures

you can say right what all are tactics

techniques and procedures he's

trying to put it over there right into

your dummy one

doesn't it so whatever his all the

strategies

tactics techniques and procedures trying

to put up over that dummy one

you are observing them right you are

thinking you can say you can you are

taking the note out of them

so now what happened like after okay

that dummy one will be like you gave

some sort of a

privileges you can say like you gave uh

basically this honey one is like

or divided into three categories low

level or medium level and

high level right so that defines like

how much of a portion of a server or

network you are allowing an attacker to

exploit

right so these are defined on those

bases so whatsoever you have put it in

your dummy network or in a dummy server

right so attacker will try to exploit it

and from those exploits

you will take the information out of

them right so what all ports he might

have uh

like exploit or like what all

vulnerabilities he attacked over there

right and all the logs and all those

ips and everything you will try to

observe over there and through that you

will be patching up into your

real or you can see the main server

right so this is like a

threat resource regarding your honey

nets or honeypots right

then we have dark web and dark knight i

guess it's pretty clear to each and

every one right

so if you talk about a dark net it's

like a network infrastructure which is

established to

overlay your internet right and can be

used by using some softwares like your

tor you might have heard about it isn't

it or your i2p or freenet

right so this darknet is most often used

for

illegal activities right like your black

markets

your illegal file sharing over there and

exchanging of illegal goods or services

presented like regarding a stolen

financial or any sort of private data

so it basically prevent a third party

from knowing about the existence of the

network right or analyzing any activity

taking place over the network

so you can take an advantage over there

right so you can like it basically

provides you multiple layers of

encryption

right uh which is put up between the

nodes to achieve this

anonymity that's why you've become

anonymous with that so use this

uh you use this dark web right which is

not visible to search engines right it

can only be accessed over the dark

not only this dark web so like

you can use them into investigating this

dark web

websites and message boards like which

are which can be a valuable source

of counter intelligence over there right

so this the anonymity of dark web

services has made it easy for

investigator to infiltrate the forums

and web stores

that have been set up to exchange any

sort of a stolen data and

hacking tools so you can just put up

like use of this

dark web for the account intelligence

you can see all those data and all those

information out there

and you can put it as like a counter

intelligence now you can just patch up

things over there

regarding all those threat researchers

right

so these were regarding your threat

resource sources

right then we have your guys your threat

intelligence provider

right so we have this behavioral

we have reputation we have threat data

right so basically our primary research

which we did like you had your

ips and logs and all this dark web and

your

honeypot or your honey nets right so all

these primary research

you can say dark web on the second

resource okay so basically all these

researches by threat research uh sources

they are categorized in broad forms

right first is your behavioral threat

research right so what does your

behavioral threat research does

as i mentioned those ttp right so it

describes the examples of

attacks and the ttps which are gathered

out there ttp as in your

tactics techniques

and the procedures isn't it

so what do you understand about the term

tactics guys so basically as your ttp

that refers to the pattern

of activities and methods associated

with specific

like you can say threat actor or group

of threat or group of actors right we

analyze from their patterns

and we try to strategize the liking to

say put up as a

threat intelligence over there right so

you analyze all those uh

tactics tactics as in like it is a

guideline that describes the way

an attacker performs the attack from

beginning to the end isn't it

so it consists various tactics of

information gathering to perform

initial exploitation perform cleveland

escalation

perform the lateral movement right and

etcetera

that's your tactics then it comes your

techniques

techniques it is a like technical method

used by an attacker

to achieve like an intermediate resource

right

exactly so uh use an attacker to achieve

intermediate results during the

attack so it includes like your initial

exploitation

setting up right and maintaining command

and control channels out there

right so all those techniques are being

mentioned at this

phase then you have this procedure

proceduralizing like organization

approach

like they followed by the threat actors

to launch an attack right so they

set up a whole procedure which has to be

take place

to attack an organization isn't it so

like procedure of information gathering

you can say step type steps instructions

right so like what like an attacker

collects information about the target

organization

right he identified key targets over

there the employees and they

collect their contact details and on the

rest of the things right

so all those step-by-step processes are

being done in your

procedure that was your behavioral part

okay behavioral threat research then

your then is your reputational

reputational threat intelligence it's

like list of ip addresses and domains

which are associated with malicious

behavior which might have gone through

your

honeypot you can say right and like

identifying all those

signatures of file based malware and

those things right so that falls under

the

reputation category then you have thread

data as well

thread data like the data that can

relate

like events observed by looking

like your customer logs okay that's your

thread data

then we have also these platforms and

feed guys like closed property

so your threat research and like your

these cti data it's

it's made available as a like paid

subscription basis right

you have seen this fire i and this ibm

x4 so like you

put up a price for that and they'll be

doing these strategies for you

right then obviously this academic as

well academy journals you can see their

papers and all those things

right other like platforms from there

you can use get these threat

intelligence right

these are the providers for all those

threat intelligence you can go for the

academic journals all these papers and

all those things they might have put an

article about it

social media pretty obvious right like

they they companies and like uh

individual researchers and practitioners

what they do

they write informative blogs or like on

the social media feeds

isn't it so you can always get those

sort of

intelligence from that particular area

from social media it's a pretty big

thing right

so you might have like even as of now

you guys might go through various

blogs and all those articles which might

help you

uh like gain all those threat

intelligence it is it

yeah perfect around the year ioc system

so

uh then there is conferences right so

like security conferences are always

being

hosted right and it's sponsored by

various institutes

isn't it and they they provide an

opportunity for presenting

presentation on the latest threats and

technologies right

these are your conferences from which

your like area from where you can go and

get all those

threat intelligence right then there is

a last one which is percent

open source intelligence right so some

companies

operate like intelligence services on an

open source basis as well

right so we'll show you that as well and

we'll also try a few tasks

on the basis of ocean as well okay guys

since you are asking about the

reputation guys reputations are elected

intelligence like regarding ip addresses

and all those domains

associated with your malicious behavior

okay and like even

regarding the signatures of your

malwares

so they falls under the reputation

threat intelligence

all right okay as always you mentioned

uh like as i mentioned uh

some companies they operate through

intelligence services on an open source

basis as well right so if i take you to

an

website ocean framework i guess everyone

knows knows about it

right for those who don't let me just

show you

okay if you go with the social framework

over here

right you can uh like search on the

respect of various things over here

right

this framework provide you lots of

options right lots of uh

crazy options you can go regarding these

things you can search out regarding any

any particular thing right so if i like

if you even

giving details about a person over here

right so if i click let's say if i'm

going with the email address

and respect email addre list of options

like email search common email formats

email verification bridge data

mail blacklist all those things so even

if i click on email search

right it will be giving throughout more

tools over here

right that's the one to email to address

pip pl right regarding people's right

the harvester in foga male db

and very small right so if i even go

with the hunter it'll be just hoping

that

letting a particular platform for you so

in respect to domain names you can just

find out the

email address over here right so that's

how your osint framework

can be utilized to gather more and more

intel in this regarding the thread

right so you can get that information

over here right

perfect so just giving a task over here

guys

a small task for now so task is

gather the email ids okay gather email

ids

and respect to domain

intersect

pain dot com

okay all right let's do one thing let's

put it on a hole uh let me show you one

more thing since we brought up hosting

and all those

techniques so even like ocean framework

we have been using over here

even guys your google is more than

enough to

like pretty much good utility to give

you a lot of information out there

right so basically what you do with the

ocean you narrow down all your search

over here right

so with the help of google you can do

that as well

correct so uh you can search in various

respects or in various aspects over here

all right

like uh for say if you want to find any

uh

pdf formats only like if you want to

search the let's say if

i'm let's say

all right okay let's say i click on

security plus right

the things you can see guys uh it's the

black thing which is mentioned over here

it's a url isn't it

correct these are the you are the black

one at the top one

right and if you see the blue one which

is being highlighted these are known as

your

titles right these are your titles

and if you can see over here the below

format which is it establishes the core

knowledge required by the file any cyber

security role and provides a site

springboard and also these are your text

isn't it so you can search in respect to

that and you can just narrow down your

results over here right

you can see 38 uh like lacks of results

are over here like you can do what

you can refine your search in respect to

url right if i hit this

oh this one is required

perfect so what it will be doing

the megan spelling stick over here

okay don't worry so basically it will be

uh searching out all those things

respect to your

url base right so if you can notice like

if i

iron in url security so it will be just

searching for this particular word in

your url part right

so you can see it narrowed down the

results from 38 lakh to like

seven eight seven lakh eighty five

thousand right so we just

cut it down the whole uh search scenario

over here

if you can like uh closely the url is

having security so each and every like

in your first page at least uh you will

be having all those

url which will be having each security

as a word in there

right so you can always play around with

it you can even mention the in title

so now in title what will be happening

it will be searching respect to a title

having security word in it right

so you can see security security will be

or the word

present in your title out there so it

will be reflecting all those results for

you

in which security is mentioned over the

title part

right so you can see it narrowed down

your results so similarly you can do

with the text

as well

so you will find this security part in

the

text one okay

so you can see you you are getting a lot

of results out here

but initially we were having 38 lakhs

format right

like our research or the results out

here 38 lakh but what we did we narrowed

down each and everything over here

so we we reduced our this labor work you

can say

right and we are like doing what we are

uh doing it very in a

smart way around right this whole google

thing this is also known as a google

docs you can say

do rks right google docs so there is

whole data feed or the database

regarding people what they do they

mention all their techniques and all

these

fancy way you can say or the smart way

around to play around your google and

get you the desired results out here

right so that's a whole different

database of the

google doc so you can also put it around

like if you want to file uh

only the pdf files over here so file

type is the option

right you can just mention it and giving

out the results

regarding your pdfs only

okay

oh boy

all right so you can see pdf pdf pdf is

mentioned over here so if i click on any

one

it will be prompting up an option to

download these

all those files so you'll be just

getting the results as an outcome over

here which are the

pdf ones right you can see

it's a pdf for you isn't it so this is

like the way you play around with all

those techniques

in your google right so you do what you

search for a particular thing in these

ways rather than just typing whole

portion or whole thing over here

you just make it more smartly you play

around with it and try to

gather information over here all right

okay

so uh i hope this is clear to everyone

okay so that brings us to back to the

challenge guys

all right so if you can look over here

how i use it

so i want you to find email ids

about like of infosect train with

respect to this domain name

okay perfect so

just to mention i what i prefer to go

with

is something okay i have to pause the

screen for a minute because i have to

enter my credentials

right so just give me okay so as you can

see over here uh

this is one of those utility or tool you

can say right

snug dot io you can go with it okay all

it need is

your this registration okay so you can

just log in over here

so if i can if i can show you this if

you are able to see find emails you can

go with the domain search

right and if i type the domain name over

here let's say infosec train for now

it's already already giving you this a

drop down option and you can see the

prospects are 29.

so if you click on this you can see all

domain emails if i click over here guys

can you see how we are getting a pretty

big list out here regarding the emails

and i can just assure you these are the

valid ones

right so there are various ways uh you

might have gone to the google

like or searching for the social media

platforms

right even this uh webinar one you got

my email id

right of the mails and all those bits

from all those promotions out there so

that's a pretty good way right that's

the technical you are doing over here

this

you are strategizing your things over

here right

you are gathering as much as the

information you can like you are then

you are

doing what you are narrowing it down you

are playing now uh smart around here

right

so typically uh if you talk about these

tools they are locked

out out there like as you mentioned the

hunter dot io it's one of them

right so you can use this ocean

framework as well

right you may be for the subscription

base but it's generally free

so it may not always give you the

results okay that depends on

organizational organization but

uh it's like i would say a good

promising website not all time but

it gives you all those things okay

so this task we got a pretty good hit

over here isn't it

we got like 28 emails out there and

these are the valid ones i can

assure you okay i guess this was a

pretty much interesting task

okay so for now i guess this thing is

clear right

so after this we'll be moving on to the

next one which is your

malwares so uh guys what do you

understand by the term malware

so basically guys uh malware take this

term

mal and the

where right you can just divide into two

portions

right so mal is in

malicious right

the malicious whereas in

software isn't it so any software which

is there with an intent to harm

is known as your malware right guys

so malware is a like you can say a

catch-all term for any type of malicious

software

which is designed to harm or exploit any

programmable device your service

or network right so these cyber

criminals you can say they typically use

it to

extract data that can like help them

to that they can leverage over victims

for financial gain right and any other

personal benefit out of it right so

it can like damage the financial data

your healthcare records

your personal emails and passwords they

can get all those pi

out of it right so they compromise all

your information right you can say

in short right all those they take all

those leverages and

gain any in terms of financially like

they will be asking for the monies

and many more isn't it so typically uh

like there are

plenty more like malwares out there

various type of malwares

so few bits of them are like your

virus isn't it so if we talk about them

the types of malwares are like a virus

worms trojan right here root kits

and your keylogger right so if we talk

about

virus right what is a virus guys so

basically guys

your virus stands for

vital

information

right vital information resources

under

c's right

exactly bjn i mean perfect great so

it is a type of malware right so it

stands for vital information resource

underseas

so i guess this full form is

self-explanatory as well right

so what it does it seizes all the

information resources that are in your

system right so it works in multiple

ways

like whenever you feel like your system

is low

like do you see your system might be

infected by virus

isn't it so your information are seized

basically which makes it slow isn't it

so effect about

virus sees

okay so a fact about virus the very

first virus

was with the name brain it was created

by these two pakistani brothers

okay so like remember virus like

moreover it will be like a comparison

between virus and voms okay so virus can

replicate themselves

but they can only replicate themselves

within a

system right that means virus won't be

able to travel in a

network so let's say if all of us are

sitting

on a same room guys and even we are like

connected to the same

wi-fi person and if one of our system is

infected with a virus

that won't mean that all of us will get

infected with that

virus okay that won't

mean that all of us will get infected

with that virus that means it will

replicate

like it will replicate within a system

but not in the

network all right that's your perfect

so then we have your warm which brings

us to the warmth what do you understand

by warms guys

so these are like you can differentiate

with this basis only with the virus and

warm right

so like thing is like with virus like it

can replicate itself but in a

particular system right but when we talk

about warm it can replicate

itself in the network that means

like taking the same example right if we

are considering we all are sitting on a

same network right attached to uh

connected to the same wi-fi so if one

system is infected with a warm

taking the same consideration of the

example right it means everyone like

or like those who are currently in the

same network like the odds are very high

over here

that others can get infected through a

bomb so that's a basic difference

between your worms and

while it's right it propagates copies of

itself through one network from one

computer to

another right then we have guys uh your

trojan right so you know trojan what are

trojan

so these are general looking files which

tend to give you a backdoor

access right so it's a type of malicious

code or software that looks legitimately

made but

can take control of your system right

with uh putting up a trojan horse or not

trojan malware

attackers can control like whole

system of yours right that gives your

back door on your computer

and it lets an attacker access your

computer and

control it right then you have guys

another one which is your

key logger what do you understand about

the term keylogger like keylogger tools

can either be hardware or software meant

to automate the process of keystroke

login absolutely so whatever keystrokes

you are making in your system

it locks those keystrokes and sent to

the

remote location isn't it so like it can

be helpful like

like it can be like a spyware tool which

are used by your cyber criminals

so they can steal your pii pii is in

your

personally identifiable or viable

information right like your

email ids mobile numbers like if you're

like based out of u.s

social security number you talk about

india it's like your aadhaar card and

all those bits right so those are your

pia personally identifiable information

right

these tools record the data sent by

every key stroke

like into a text file to be retrieved at

the late time

that's your keylogger right then you

have

talking about the trojans right like

they similarly work like a

root kit regarding root kit you know

like these root kits are like put up in

your

hard drives or in your mbr you can say

right when they give you the backdrop

access over there right so

rootkits are not generally looking files

but you can put it on the

hardware on your operating system the

mbr must boot record right in your hard

disk

which holds all those boot loader

your this partition table you know the

partition tables

right when you you might have seen this

thing whenever you try to

uh set up a new window in your machine

in your system right

it always asks like uh regarding the

partitions of those

spaces right the c drive d drive and

everything isn't it you might have seen

that thing

right so basically attract that

particular portion for you

okay so you can do what like someone is

oh okay you

like you know you would give the

bootable pen drive and all those bits to

uh install the windows and every bit so

you what if like

i'm an attacker and like i'm putting up

all those things and all those

bootable files right and so if anyone's

trying to

put up a windows through that one dive

or the usb drive which i've given

yeah perfect jonathan so it can just

this

rotate will be given to uh through that

as well and it can just

give me the control so very good example

regarding this would be

like lenovo if you remember lenovo they

had to withdraw your

around like you can say 65 000 computer

or so

from the market have you read anything

regarding this thing

uh lenin will be drawing okay so back

somewhere a couple of years

they had to withdraw those let's say 65

000 computers from the market and the

whole reason they had to withdraw those

systems from the market was

uh because they found that root kits in

the lenovo based system

right and then what happened lenovo had

to pull up like pull them up from the

market

okay so like if you talk about the

lenovo guys

they did this uh on a good intention

actually right

because you know they put up a back door

in their firmware and the reason they

put up a back door is like you know

there are a lot of people who call

customer care and who are

arguing about things like this system is

not working properly

right and these pop the and these people

are not the techy people

to be specially mentioned about that

right so we can say any example

or like any other person from any other

department who's not a techy one

right so taking any department which is

not of a techie

one right any like you say sales or or

say any

customization all those ones right so

what they do they

like they are rushing to the system

admin saying okay my keyboard is not

working it is typing differently and all

the system admin tells you that your

keyword has been changed from

the us to uk one isn't it so

that sort of like people i'm talking

about who don't know anything about this

technology right so these people what

they do they have complaints but they

don't know what exactly it is happening

in the back end

so what can be done in these sort of

cases is like lenovo they added a

rootkit

and whenever anyone use to complain

regarding anything in lenovo

what they do they used to take remote

access

of their system and they used to solve

their problem right people were happy

but think of it when attackers they came

to know about it but

this particular route get right would

they leave it

would they leave this advantage after

knowing okay root kit is installed in

this

uh system then like you can take the

back door excel out of that

so they started exploited it and then

lenovo just had to

take back all those laptops on the

market right so this was regarding your

route yet

okay there are many more as you guys are

constantly

mentioning them right one is a

ransomware

isn't it so guys what's a ransomware

so uh it asks for money what it does it

tends to encrypt your file and in return

they ask for money right

you give money and they decrypt the file

for you

isn't it okay then there is your guys uh

spyware as well what does the spyware do

like just a one liner would be enough

over here

so spyware whenever you hear the word

spyware always remember basically guys

your browser yeah browser having

habits yes naveen mentioned browsing

history

right so what they do they are browser

specific it can never affect your system

in a way

that it can take data through files okay

so it specifically attacks your browser

and steal your browser's history browser

caching and that's what your

spyware do yeah perfect

correct okay then there is what more

have you guys heard about adware

what's an adware so now always remember

when we are using the term edward guys

it merely create

hoaxes right although you can see the

false fitnesses

so you can see an ad we are saying a lot

of fancy things for you but it may end

up doing nothing for you right

so like whenever you visit torrent or a

website where you see

flashy pop-ups or all the time those

flashy pop-ups

are dangerous okay so what they do we

like so what we do we simply tend to

ignore like all those flashy pop-up of

times right because we know that they

are simply ads

even though that pop-up is saying that

your system is infected by any xyz virus

also right but something or anything

else but you know it's nothing more than

a flashy ad

okay so it create hoaxes right and like

it flashes or simply throw advertisement

in your in front of you

okay so you have seen those who have

used torrent and all those bits you

might have seen all those flash pop-ups

and all those gaming websites

and various more right so you get these

fleshy poppers over there so it will

just click on that it will be redirected

to another page

and that depends if uh attackers has put

on something inside it or not

right so this was regarding your adware

so

taking you back to the ransomware uh

have you guys heard the recent news

regarding the ransomware group with the

name

our evil so uh there is one more recent

one guys regarding your this

apple one so what they do uh hackers

they were able to get their hands on

these blueprints of the apple

products so yeah so there was this

quanta right the supplier or you can see

the

company right so what they do they were

able to get this

hands-on on the blueprint of the apple

and they were demanding for 50 million

dollar right for not leaking all those

blueprints

out okay so they were asking about this

you can say the ransom of 50 million

dollars for not clicking on all those

blueprints of the apple that's pretty

much latest one it's been like i guess

last month only also so yeah you can go

for that

all right so that was your bit regarding

your guys uh malwares

i hope everything is clear till this

point perfect

which brings to our next thing right

which is your

social engineering right so what do you

guys understand about the social

engineering

perfect so what you do you do malicious

activities out here right

by human interaction process isn't it

right

you manipulate them right you play

around with their trust

right you you gain their trust you

become so

likable that they trust you and like

whatever

you ask for they will like give you out

all those details

isn't it and you can take advantage of

that so basically you are manipulating

people around here you are playing

around with your trust

and all those things to gather the

information which can be very

crucial and very important for you isn't

it that's a social engineering attack

right so talking about this again uh

taking an example and all those things

as i mentioned before if you talk about

a pen tester

right so let's say these are this black

box testing right

so you know black box testing wasn't it

what's the black box testing guys

so the proper definition regarding this

would be like the one who is having

like zero information you can see

regarding the target

right so let's say if i say you

just pen test infosec train would be

able to do that

like you have to go a various way around

right but you have no idea regarding

your target over here

isn't it so that's your black box

testing

then there's gray box testing as well

when you have some information regarding

your target right

so let's say uh i gave you okay this

infosection is written in

like php apache server and all those bit

so you got a

few bits of information right so you can

just

strategize all those techniques and all

your procedures according to

those information right then we have

this white box testing as well

so what's in a white box testing when we

have full knowledge of the target let's

say i share whole source code with you

right now you can take like although

like it will be pretty much of a quick

technique right since you've got all the

information so it will be very easy to

you

uh for you to do the pen testing right

for the white box testing

so these all things are like mentioned

if we talk about okay

like planning and scoping of the pen

test right so you have

seen i have as i discussed right so in

planning and scoping if

they are around to go uh like basically

for a black box testing it will be very

helpful because he don't have any sort

of information rather than gray box in

the white box

they have a few bit of information

regarding their target but black box

testing

they have no information regarding

target right so they have to go around

with social engineering as well

which can lead some sort of a detail to

them as well over there

isn't it so then two is discussed over

the planning scoping for the pen testing

part that's another sort of a story

but yeah i guess you got the idea

regarding social engineering right

so these are the ways to manipulate and

play around with human

you can say mindsets getting theirs and

all those bits and then you try to

take advantage of that by getting

crucial information you can say right of

any information which

which might be very useful and which

might be very helpful for you

for the further base of

when testing or attacking whichever you

go for

right so that's your uh social

engineering

attack for you right so when you talk

about social engineering attacks guys uh

there are plenty of more over there

okay so types of social engineering

attacks are your fishing smishing

fishing waterfall spear fishing

uh whaling right shoulder surfing

dumpster diving

piggy backing tailgating deep stopping

right

let's discuss for these bits for now

right

okay so going with the very first one

which is your

fishing so guys what do you understand

by the term phishing so you fool around

people you send fake links but

moreover you send the emails which might

be like you know

very general one like you genuine one

you can say like if you read the email

and all those bits

you will see okay this is more of a

genuine one and i can like

trust this one let's say i am an

attacker also uh i have sent you this

phishing email

right what i have done i have just taken

let's say i

i can send this phishing email in

respect like i can be as an hr

at that infosection.com i will be send

up with this email id and i can

send this email to any person out there

who's from infrastructure

right i will just draft an email which

will be a very genuine looking email

right

email id i am spoofing over there you

can say right i'm using a fake email id

i can put reply as a char at the

screen.com and i can just

mail with that right so if i'm targeting

any person

or any employee from the infosec train

right and he'll be considering okay this

is from the hr team only

and it's with genuine one right so i can

trust this

and i will be just passing their link

over there which can be very harmful

right and which can be very like if the

user click on that link

i can take advantage of that right as an

attacker

so just to show you that bit just

give me a minute has anyone heard

regarding this old fish

there are many more frameworks out there

but office is one of them provided by

your

ec council as well if you can see our

dashboard over here

right so this is like to uh you can do

various things over here wishing is

missing i can like even do

a calling like uh i can impersonate one

of you guys i can use your numbers you

might have seen in the movies and ever

well you can see their private number is

mentioned over there even i can use

anyone's number and i can try to

call them with the same number but the

person on the other side will be me

right so i can use any i like uh say

naveen over here right so i can use

naming number to call

uh mando and i can call him like uh and

he'll be thinking okay it's naveen but

it will be me over here right so i can

just spoof that number as well

so many more over there smashing credit

harvesting attachment

right so just i will go with the entire

click

okay it will take time oh okay

perfect so i can do what i can just put

up a campaign name over here let's say

testing right

uh i'll be just you can create your own

template either way like but i will go

with accessing template

and i will be selecting the existing

template like your

that's the corona wireless coverage 19

right so over here

ah yeah regarding this one

select country it can be let's say

step in india

right select template let's say

work from home kobe 191 let's say i'm

so you can see it uh drafted a whole

uh email for you right can you see this

one on the right side

it's more of like a genuine one isn't it

this whole email out here

right perfect so what i can do uh

i can select this template right it says

one type it's selected

sender email uh let's pull it up like hr

another infosec train dot com since we

are posting up this work from home

uh this template right so it should be

very genuine looking so let's say send

an email would be your hr

infosectrine.com right

so send the name uh let's put your hr

resource team which will make it more

effective subject is work from home

policy

perfect time zone expired you can show

it later on as well

right what you will do you will import

users over here you will just

select them so there are various files

to go with the various options but i

will just go with a quick add

i'll just name add everything over here

let's say

let's put up my own gmail one

[Music]

all right enter the designation it says

security

department security right company

uh infosec train

branch that's it security again and

country let's say india over here

right so i'll just quickly add it up and

let's create one more one more i will

just go with the 10 minute email id

so it will just it's just a temporary

email id guys right so you can just

always use this one

whenever you're going to any websites

which in which you don't want to

register with your own

uh email id or the genuine one you can

always use this 10 minute email id to

give your temporary access right it can

work like the genuine one

let's put it up over here sorry name

test email id portable here designation

let's say

testo department testing

company let's say train

branch desktop country india

right i can just add up it as well

now quickly import them right so batch

count you have to just

click the batch count should be like

less than the number of users batch

interval you have to mention over here

like one

like send the messaging to breakage one

training type uh

okay it's not giving an option perfect

okay basically if you can see it's it

will be showing you the landing page

right whenever the person is clicked on

this one

link you'll be landing on this

particular page which is your

something like this okay

so uh problem is uh like uh mainly i

know i won't be writing this page

landing page because i have to do what

like the precautions so i put them like

white listing and all those bits

but no ways uh you will get an idea

regarding this simple scenario how this

email

is being sent to you so what will happen

uh

perfect this is the high name name will

be like uh

regarding this uh users which we have

added right at the bottom it will be

showing this link

and a chart team over here right okay

let's let's let's

do one thing let's create it up

right done

show this will take a bit of time

meanwhile let me just open my email id

okay as you can see it says campaign has

been successfully initiated so

let's take it you can see campaign has

been listed out over here campaigning

with the

name testing send two emails right

complex hundreds of ymd that's the

creator so let's

let's check it out okay can you guys see

over here i got an email from human

resource team

if i click on this

listen can you see guys i say my current

concert for that means you know this is

really an ongoing dynamic situation on

behalf of organization

i'm really worried about reaching to the

workplace that is then crowded in all

those bits

right and it says regards hr team though

it's mentioning note the phishing

simulator emails for the lab purposes

right so if you can see we we generated

a genuine email right and i'm

sending them to myself can you see

uh guys can you tell me what's the email

id mentioned over here

what is the email id from which email id

i have sent this mail

hr isn't it so i have used the rainbow

id over here to

send any one of the person one for

organization so he'll be just obviously

if they are not uh well trained well

aware regarding this thing they will

just

read this mail and they will be thinking

it's the genuine one though it's for

this is something mentioned which is for

the lab purpose that's why otherwise you

won't even get this notification as well

so if as soon as the person is clicking

on this link he'll be landing on another

page

so it's won't be opening on this one

right now

oh credit work perfect can you see the

landing page opened over here

so guys uh it says oh you have been

faced right so i can take with that link

i can take the uh

uh this user anywhere i want to right

so this is the one how you can play

around with this thing or else like you

what you can do

uh there are various ways to do social

engineering attacks right you create

a copy you url or whole page of let's

say facebook

login page you can just create a dummy

of that obviously url won't be like the

real ones

but you can put that url over the

phishing email and you can

do what let's say uh i copied the

infosec train whole page or the whole

design for the login

portion or the login portal right so i

copied it

and i copied my url which i have created

for that

taking the username and password from

the users right so what i will do i will

create

full copy of that and i will pass that

link

in my phishing email to that particular

user user will be thinking okay it's the

general one from the organization he

will click on that link

he will go to a login portal he will be

entering his username and password

and as soon as we click on it i will

just redirect him to the

original page and moreover i can get

those credentials of that person with me

the username and the password

this is to just how fool around the

people with these things

the social engineering techniques and

the phishing one all right i hope you

got the point

over here guys so let's get back to the

thing

is fishing right we were talking about a

phishing

so phishing is a cyber crime in which a

target or targets are contacted by email

telephone or text message by someone

posing as a legitimate institution to

load

your individuals into providing

sensitive data such as personally

identifiable information

banking and credit card details and

password right

then guys there is machine what do you

understand by the terms missing

so basically you got an idea right

regarding these things so what you do in

this one is like you would be

doing phishing in respect to sms space

right let's say the lottery one or you

want this particular price

yeah you want this car or something like

that so just faking around and you'll be

passing all those malicious things over

there in this

messages and trying to get the person

and view that person into that link

right

perfect okay then we have guys your

another one

which is wishing what do you understand

by the term

wishing so as you mentioned voice

over fishing right isn't it wishing a

combination of voice and phishing is a

telephone version of phishing this

technique uses a spoof caller id

that can make attacks look like they

originate from a

known number right so

over here like you know you might have

got got a call

right i guess everyone or so you get a

call over your phone

they might be saying okay uh so you have

like they might be like important some

of some of a person from a bank isn't it

and like they will like a fraud call as

you mentioned okay

so they were saying okay sir we are

contacting from this particular bank

it's what's a

yes bank or any sbi bank and uh we need

you to

give your otp and all those bits right

to to

maintain uh the count over there right

so

for say of example of mine they told me

okay so

i was traveling the metro and they gave

me a call so your

card has not been registered so your

account

due to that your account will be like

you can say diminish or like remove from

there

correct and for that uh you just need to

uh

give few bit of details to us right so

they asked and asked

and like account number atm number right

those weights they already have those

things right but moreover they ask for

those

this otp the main part right

that's your multi-factor authentication

so they ask for the otp

and you know obviously i haven't given

the otp

but main agenda is as soon as you

provide the otp there will be like

a transaction of hefty amount from your

account isn't it so these things are

done by the wishing

and the one who was asking the guardian

is uh how to figure out the email

from the valid user so just you have to

check the spf dkm your

demark your message id so that's another

story but these are

these are used to check the

authentication right the authentication

code is mentioned the return path is

over there the sender ip is there

so you can go with these things and

these are helping you to validate that

email id

so since fishing it's a pretty much like

you know

common but it's pretty much of a very

good

attack which can take an advantage right

so as a

security uh guys you should train the

employees you should have this training

around there and

make them aware regarding these things

right all right

so uh then we have this spear fishing

what do you guys understand with the

spear phishing

okay spear phishing is a social

engineering attack in which a

perpetrator disguises a trusted

individual

takes the target into clicking on the

link of spoof email

text message and stand matches so you

basically target specific

people over here right so

it can be any individual over here you

target an individual over here then we

have this

wailing wailing you know guys whaling is

like a cyber attack targeting a high

profile executive

exactly a top management or top high

class people we are targeting over here

right it use this happy email messages

targeting high level

decision makers within our organization

such as your eco cfos

right your cto and all those things

right

so when you're targeting high profile

people that's your

building then you have this shoulder

surfing guys what's the shoulder surfing

shoulder surfing refers to the act of

obtaining personal private information

through

direct observation right so you're

looking from person's

shoulder to get sort of information a

very common example would be like your

atm one right isn't it

so you know atm line you might have seen

these things uh but you do

like your shoulder surfing right you are

just speaking in front of the person

what sort of a password he is or like

what of course he's

entering while doing the transaction

right or moreover

like many people might have done in

their college days or this school days

back those days right so let's say last

11th hour of the exam oh sorry like last

hour the exam right

and you don't know like you you know

like you're gonna get get failed right

so what do you do you try to do shoulder

surfing over there isn't it

and you look over there you look in the

front seat like the person who is

sitting in front of you he will try to

like speak over there and he will try to

see whatever the answer he's writing is

that it

anyone done that because i have done

that in my college days

right so that's a pretty good example

regarding a shoulder surfing

right so we won't call it cheating now

we caught your shoulder surfing

then we have dumpster diving guys

dumpster diving those beans yeah

from the garbage from where you can get

uh like

print outs all those useful information

all those files and lock documents which

can be pretty much useful

for you so that's why organization also

they put up this policy or if

you say the practice to shred all those

documents those are which of no use

because if you dump them over the

dustbin

anyone would be like if there's an

attack or any person who

like anyone if they get there they get

their hands on these particular

documents

the files uh that could be pretty much

like an advantage for them right they

can

get a good hefty and good important

stuff out of it

right so what they do they ask you to

shred all those things because generally

we also practice

the same thing right in our house we

order something from the amazon

we receive it and what we do we

we just take the gift out of it write

the item out of it and we just throw

that package over the document but we

don't

if you notice the delivery thing is or

there'll be address or the billing

address and those statements are printed

over a paper over there on a slip and

which is attached to your

wrapper right so you don't just

shred it off and you just simply throw

it in the description so it can be very

advantageous for other people

right so that's your terms to type in so

always just shred your files and

everything which is of no use

before dumping it to the first pen then

we have piggybacking

right and we have tailgating basic uh

and tailgating

so tailgating guys you know you can see

uh basic difference main difference over

here is

authorization and non-authorized one so

tailgating is like

following somewhere or someone without

their

knowledge right yeah entry without

access

behind someone so let's say in your

office you you swipe your card and like

or you give you punch over there and you

get

an entrance to the organization right so

let's see if person is over there right

or any attacker what he will do he will

just follow you till the time that gate

is open

and you might have seen this in metro as

well people what they do

uh like someone is entering their token

and then they will just

go behind them with them right and they

will just pass that

security area isn't it so that's your

tail getting piggybacking is like when

like someone is opening that door

for you they know you and they are

opening the door for you right

so basically you are using the authority

as well over here

so that's also tailgating and

piggybacking

right then ev's dropping it's pretty

much common you have stopping let's say

two people are working in a

working space right and they are having

sort of a conversation or discussion

regarding their new deal

a new project that is going to get

deployed so what i will do i'll be just

i'm i'm i'm there hearing their

whole conversation and i'm trying to get

the ideas of information which can be

very

useful to me doesn't it that's you keep

stopping over here

you can say man in the middle perfect

great that's it guys

that's it for the whole today's agenda

like your malware threat

and threat intelligence and everything

right so that's it for the days i guess

you got

the whole concept were clear to you

regarding each and every terminology

we have discussed till this point okay

thank you guys that's it for the day

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.