4. บจก.สยามถนัดแฮก
Responsible / Version: Pichaya Morimoto / 1.0 (2023-09-26)
Confidentiality class: Public
Overview
4
1. ศักยภาพของทีม IT Security องคกร
- BAD (Build, Attack, Defend)
- IT Security Certification
- Learning Pyramid
2. Online Learning Platform
- SecPlayGround
- DropCTF
- BlueTeamLabOnline (BTLO)
- HackTheBox (HTB)
- TryHackMe (THM)
3. TryHackMe Platform
- Room
- Learning Path
- AttackBox & VPN
- Blue Team Rooms
- Intro to Endpoint Security
- Incident Handling with Splunk
- Linux System Hardening
- Sigma
- Yara
- Phishing Prevention
5. บจก.สยามถนัดแฮก
Responsible / Version: Pichaya Morimoto / 1.0 (2023-09-26)
Confidentiality class: Public
5
BAD (Build, Attack, Defend)
ที่มา: https://danielmiessler.com/study/red-blue-purple-teams/
Red Teams (Offensive Security)
- Penetration Tester
- Red Teamer (Adversary Simulation)
Blue Teams (Defensive Security)
- IT Security Compliance
- Internal Security Team
- IT Security Engineer (SI)
- IT Security Consultant
- Incident Responder
- Security Analyst (SOC)
- Cyber Threat Hunter
- Digital Forensics Examiner
Purple Teams
- Red + Blue
7. บจก.สยามถนัดแฮก
Responsible / Version: Pichaya Morimoto / 1.0 (2023-09-26)
Confidentiality class: Public
Challenges in Cybersecurity Talent Acquisition
7
- Everyone is looking for senior IT security staff
- Less open positions for junior IT security staff
- Hire junior IT security staff to do mid-level cybersecurity tasks
e.g.
- 0-year experience
- Penetration Tester
- SOC Tier-1 Analyst
- …
คนที่ไมรู คนที่รู
8. บจก.สยามถนัดแฮก
Responsible / Version: Pichaya Morimoto / 1.0 (2023-09-26)
Confidentiality class: Public
8
IT Security
Certifications
Common Misconceptions:
- Certification equals expertise
- All certifications are equally valuable
- One-size-fits-all certification
- Certifications guarantee job security
- Certifications are only for beginners
- Recertification is not necessary
9. บจก.สยามถนัดแฮก
Responsible / Version: Pichaya Morimoto / 1.0 (2023-09-26)
Confidentiality class: Public
Dunning
Kruger
Effect
9
Source: BrandThink
https://www.facebook.com/brandthi
nk.me/posts/2471666556492215/
- Individuals with low ability at a
task tend to overestimate
their ability
- While those with high ability
underestimate their own
competence.
58. บจก.สยามถนัดแฮก
Responsible / Version: Pichaya Morimoto / 1.0 (2023-09-26)
Confidentiality class: Public
แนะนําห้อง TryHackMe ที่น่าสนใจ
58
Red Team
- Red Team Fundamentals (ฟรี)
- Red Team Recon (ฟรี)
- Bypassing UAC (ฟรี)
- Lateral Movement and Pivoting (Premium)
- Active Directory Basics (ฟรี)
- Credentials Harvesting (Premium)
Blue Team
- Incident handling with Splunk (Premium)
- Linux System Hardening (Premium)
- Sigma (Premium)
- Yara (Premium)
- Intro to Endpoint Security (ฟรี)
- Phishing Prevention (Premium)
59. บจก.สยามถนัดแฮก
Responsible / Version: Pichaya Morimoto / 1.0 (2023-09-26)
Confidentiality class: Public
Linux System Hardening
59
ที่มา: https://tryhackme.com/room/linuxsystemhardening (Premium)
60. บจก.สยามถนัดแฮก
Responsible / Version: Pichaya Morimoto / 1.0 (2023-09-26)
Confidentiality class: Public
Linux System Hardening
60
การทํา Hardening คือการตั้งคาหรือติดตั้งการปองกันตาง ๆ บนระบบเพื่อ
ลด Attack Surface และความเสี่ยงที่จะถูกโจมตี
- Physical Security
- Filesystem Encryption
- Firewall
- Remote Access
- User Accounts
- Software and Services
- Update and Upgrade Policies
- Audit and Log Configuration
ที่มา: https://tryhackme.com/room/linuxsystemhardening (Premium)