• 10. ThreatGen Again

    •  

      Intro

      In this lesson you are going to:

      continue learning about attacking or defending networks and systems using strategies and techniques that companies employ.

    • Threatgen Red vs Blue

       

      A Cybersecurity Simulation Game

      In the previous lesson, you learned about ThreatGen Red vs Blue. You either played on the red team or the blue team. In this lesson swap teams and see if you are just as good.

    • Go to Steam and start ThreatGen Red vs Blue

      ThreatGEN Red vs. Blue is an educational game-based cybersecurity simulator. The game allows players to assume the roles of either the red team (hackers) or the blue team (defenders). Players can engage in the game either as a single player or in online matches against colleagues. By playing it, you learn and practice hacking and defending techniques and terminology.

      Red Team - Attack

      Blue Team - Defend

      1. Gather Information
        • OPEN-SOURCE INTELLIGENCE (OSINT) - Get information about the network
      2. Search for Targets
        • HOST SCANNING - Find computers in the area
      3. Identify Weaknesses (Attack Vectors)
        • PORT SCANNING - Find what kind of computer it is
        • SERVICE ENUMERATION - Find out what the computer can do
        • FINDING VULNERABILITIES - Find out if the computer has issues
        • SOCIAL ENGINEERING
      4. Formulate the Attack
      5. Execute the Attack
        • Password Attack
        • Pilfering
        • Malware
        • Ransomware
      6. Gain a Foothold
      • Cybersecurity Program Governance - Who is looking after the system
      • Cybersecurity Architecture and Controls - How are they looking after the system
      • Vulnerability Management - How do you manage any issues
        • Vulnerability Identification - What are the issues?
        • Risk Analysis - How bad are the issues?
        • Vulnerability Remediation - How can you fix the issues?
      • Threat Monitoring - Who is trying to get in?
      • Incident Response - What do you do when they are in?