Table of Contents

Lab 01 - Security Foundations & The CIA Triad

The Pitch: Theory Meets Practice

Welcome to the Introduction to Cybersecurity (ISC) labs!

In Lecture 1, we discussed security at a high level: the CIA Triad (Confidentiality, Integrity, Availability), Attack Surfaces, Threat Actors, and Security Policies. But how do we apply these theoretical concepts in practice?

In the real world, defenders and attackers do not rely on clicking buttons in graphical interfaces; they rely on automation and a deep understanding of operating systems. Throughout this course, we will use three core pillars to bridge the gap between theory and practice:

Every task in this lab is a direct application of the theoretical concepts discussed in Lecture 1.

Objectives

Preparation

You may use the UPB's OpenStack cloud to spawn a Virtual Machine to be used for this lab! Read this guide.

Download the task archive for this section. Unzip it. Each exercise will have a corresponding folder.

Part 1: Confidentiality & Evasion

Lecture Concept: Confidentiality & Attacker Evasion. Developers sometimes mistakenly use codifications (like Base64) to hide sensitive data, confusing obfuscation with cryptography. Alternatively, attackers encode their payloads to evade intrusion detection systems.

01. The Illusion of Security

Part 2: Integrity & Indicators of Compromise

Lecture Concept: Integrity, Baselines, and IoCs. Integrity ensures data hasn't been maliciously modified. Defenders use cryptographic hashes to create a “baseline” of a healthy system. If a file's hash changes, it serves as an Indicator of Compromise (IoC) pointing to a malware infection.

02. The Tampered Asset

Part 3: Availability & Auditing

Lecture Concept: Availability, Denial of Service (DoS), and Auditing. To protect Availability, we must monitor (audit) user events. When a DoS attack occurs, the logs hold the key to identifying the attacker's TTPs and blocking them.

03. Hunting the Threat Actor

Part 4: Attack Surface & Least Privilege

Lecture Concept: Internal Attack Surface & Least Privilege. Complex systems are difficult to secure. Sometimes the biggest threat isn't external, but an internal mistake where an administrator violates the principle of Least Privilege.

04. The Internal Attack Surface

Part 5: Python Automation

Lecture Concept: External Attack Surface & Automated Attackers (Script Kiddies). Attackers don't map external attack surfaces by clicking links in a browser; they automate the process to find forgotten administrative panels, backups, or API endpoints.

05. Mapping the External Attack Surface (Web Fuzzer)

docker run -d -p 8080:80 ghcr.io/cs-pub-ro/isc-lab-intro-web

Feedback

Please take a minute to fill in the feedback form for this lab.