Posts

How to Handle a Cyber Attack: The Complete PICERL Incident Response Guide

Image
  HELLO FRIENDS WLCOME TO MY CYPHER LOG INCIDENT RESPONSE LIFECYCLE     Hello guys, today I came up with the most important topic which is the Incident response life cycle, actually we have already seen the overview in our past blog which is incident response forensic basics,  And today we are going to deep dive into that. And there is one more day to finish the fundamentals of cyber security, then I would like to start linux and get into the technical side to strengthen my cyber career if you're also interested in that you can follow that too. I hope we can achieve more in our career. LET'S GET INTO THE TOPIC INCIDENT RESPONCE LIFECYCLE   The  Incident response lifecycle is nothing but the playbook of how investigators would and must handle a crime during and after the period. It has 6 phases of handling an incident. So let's see what are the 6 phases and how investigators follow the 6 phases. THE 6 PHASES OF PICERL     Don't overthink about the ...

What is a SOC Analyst? Understanding SOC Tiers and SIEM Tools

Image
  HELLO FRIENDS WELCOME TO MY CYPHER LOG SECURITY OPERATION CENTRES [SOC] & SIEM BASICS       Hello guys, today I'm going to share what I have learned today. When I started this cybersecurity learning journey I always heard about the common job role which is SOC analyst, I always wondered what it could be and what the analyst will do and today I got the answer. Yeah you guessed right that's the main topic we are going to see here and also the software they are using in the job, which is security operations center [SOC] and SIEM. Ok let's see more about that role and that software, actually it's really interesting. WHAT IS SOC        SOC is nothing but a security operations centre to monitor, detect and analyze every incident in cybersecurity. Actually it has a centralized facility and people are working as a team to detect any incidents. The centres were open 24/7 the whole year. Here people were working in person and also have a virtual team...

The 5 Factors of MFA and How Hackers Bypass Multi Factor Authentication

Image
HELLO FRIENDS WELCOME TO MY CYPHER LOG    Hello guys, Today I have learned an important topic which is Multi factor authentication and Biometrics. I seriously thought that MFA can be 100% safe to prevent us being a victim of cyber attacks, yeah actually it's safe but attackers find their own way to get what they want, so let's see more about those attacks in this blog. MULTI FACTOR AUTHENTICATION      When we buy our phone there is an option to keep our data much more safe which is Multi factor authentication. Actually multi factor authentication is keeping two or more factors to get logged into our account. There is another one too which is two step verification like typing passwords in two different types. Multi factor authentication is different from that here we need to have two security types like having a password and fingerprint. So don't confuse between these two. Ok let's see the 5 factors of multi factor authentication. THE 5 FACTORS OF AUTHENTICATION ...

Identity and Access Management (IAM) & Least Privilege Explained

Image
  HELLO FRIENDS WELCOME TO MY CYPHERLOG      Hello guys, we have learned a lot of  things in our past blogs and actually it's been 3 weeks and in this week we are going to see more about the topics we have already learned and today it's all about Identity and access management and also least privilege, let's dive into the topic. IAM - IDENTITY AND ACCESS MANAGEMENT       Actually IAM is a framework which is used to ensure that the right people have the right access to the right resources at the right time.  It revolves around 4 core pillars, We have seen about the AAA framework in our day 2 blog It has Authorization, Authentication, Accounting and it has another one too which is Identification. IDENTIFICATION   Identification is which I claiming myself using an username to identify. AUTHENTICATION    Authentication is nothing but, I have already claimed my identity using an username now I need to enter into the system using my ...

PKI & Digital Certificates Explained: Solving the "Trust" Problem in Cryptography

Image
  HELLO FRIENDS WELCOME TO MY CYPHER LOG     Guys today we are going to see about the public key infrastructure and digital certificates. It plays the main role in keeping people away from fake organisations. LET'S DIVE INTO THE TOPIC PUBLIC KEY INFRASTRUCTURE    We have already seen the public key in cryptography, actually it is a system that combines both public key and real world identity and it acts like a backbone of secure internet browsing. THE DIGITAL CERTIFICATE      We all have physical documents like our birth certificate and national Id cards there is a sign of a higher authority and we use those certificates to prove our identity right that's how this digital certificate works for websites and organisations. If we receive any email or SMS we would like to see the header like we have already seen about that in our past blogs, actually we see that to know is that the real message from the real organisation. Organisation would have ...

Cryptography Basics: Encryption Types & Hashing Explained

Image
 HELLO FRIENDS WELCOME TO MY CYPHER LOG         Today I came up with a topic which I wondered about what it will be from the first year of my studies in cybersecurity, The cryptography.  In this blog we are going to un-wrap this topic and learn more about it. LETS GET INTO THE TOPIC CRYPTOGRAPHY     You may think that it can be difficult to learn but actually there's nothing like that because I too thought like that about this, if you still think it's difficult I will explain it Like you want.    Cryptography is encrypting data from a readable plain text to unreadable cipher text format. Cryptography is like a knife It has both advantages and disadvantages. Its purpose varies based on who uses it, if you want to use it to protect data it can keep it secure, On the other hand if an attacker uses it he can create a massive bad impact like implement the attack the ransomware. THE TWO MAIN TYPES OF CRYPTOGRAPHY     As I have mentio...

Firewalls, IDS & IPS Explained: Network Security Devices Fundamentals

Image
  HELLO FRIENDS WELCOME TO MY CYPHER LOG    We all hear a lot about Firewall in our field and we also know the overview of it but in this blog we are going to know little more than we already knew. In today's blog we are going to see about the Firewall, IDS and IPS. Let's dive into it FIREWALLS          As we know firewalls work like security guards who monitor the incoming and outgoing network traffic and devices in our systems and whether to block or allow based on the set of security rules. It had three types they are PACKET FILTERING FIREWALL     It will look only at the header of the packet, like IP addresses. It acts like a security guard who stands in front of our college main gate who would permit us if we have a proper ID card, they won't ask many questions to let us in right because we have an ID card otherwise they won't let us in. It had a biggest drawback that if an attacker hides a malware inside a legitimate looking packet...