Back close

Course Detail

Course Name Cyber Security Lab
Course Code 26CY682
Program M. Tech. in Cyber Security
Semester 2
Credits 2
Campus Coimbatore

Syllabus

Experiment No. 1: Introduction to Linux Tools

Familiarize with the Linux operating system and commonly used networking and security tools.

  1. Practice basic Linux commands for file handling and system administration.
  2. Familiarize with networking tools such as: ping, traceroute, netstat, ss, tcpdump, curl, wget
  3. Practice process monitoring and service management commands.
  4. Familiarize with file permissions and user management.
  5. Practice basic shell scripting and package management.

Experiment No. 2: Centralized Log Monitoring using Splunk

Install and configure Splunk Enterprise in a centralized server environment.

  1. Install Splunk server in a dedicated machine.
  2. Install Splunk Universal Forwarder in all client systems.
  3. Configure log forwarding from Linux and Windows systems.
  4. Capture and analyze: System logs, Authentication logs, Firewall logs, Web server logs.
  5. Familiarize with: Indexing, Searching, Dashboards, Alerts, SPL Queries.

Experiment No. 3: LAN-Based Attacks and Analysis

Perform LAN-based attacks and analyze the generated logs and network traffic.

  1. Perform ARP spoofing and ARP cache poisoning attacks.
  2. Perform DNS spoofing attacks.
  3. Perform MAC flooding attacks.
  4. Perform Man-in-the-Middle (MITM) attacks.
  5. Observe the ARP table and CAM table before and after the attacks.
  6. Capture packets using Wireshark.
  7. Forward attack logs to Splunk Enterprise and analyze the events. Tools used: Ettercap, Bettercap, Wireshark.

Experiment No. 4: Web-Based Attacks and Analysis

Perform Web application attacks and analyze the logs and captured traffic.

  1. Perform SQL Injection attacks.
  2. Perform Cross-Site Scripting (XSS) attacks.
  3. Perform Brute force login attacks.
  4. Perform Directory Traversal attacks.
  5. Capture HTTP/HTTPS traffic using Wireshark.
  6. Capture web server logs and analyze them using Splunk Enterprise. Tools used: Burp Suite and OWASP ZAP

Experiment No. 5: Network Scanning using Nmap

Use Nmap to perform different types of network scanning.

  1. Perform a Ping Sweep to identify live hosts.
  2. Perform TCP Connect Scan.
  3. Perform SYN Scan.
  4. Perform FIN Scan.
  5. Perform Xmas Scan.
  6. Perform UDP Scan.
  7. Perform OS Fingerprinting.
  8. Perform Service Version Detection.
  9. Analyze the generated traffic using Wireshark.
  10. Capture and analyze scan logs using Splunk Enterprise.

Experiment No. 6: Nmap Scripting and Enumeration

Perform enumeration and vulnerability detection using Nmap NSE scripts.

  1. Perform SMB enumeration.
  2. Perform HTTP enumeration.
  3. Perform FTP anonymous login detection.
  4. Perform SSH brute force testing.
  5. Perform vulnerability scanning using NSE scripts.
  6. Analyze the generated logs and packets using: Splunk Enterprise, Wireshark

Experiment No. 7: Vulnerability Assessment using Nessus

Perform vulnerability assessment using Nessus.

  1. Install and configure Nessus.
  2. Perform Host Discovery scan.
  3. Perform Basic Network Scan.
  4. Perform Web Vulnerability Scan.
  5. Analyze the identified vulnerabilities.
  6. Generate vulnerability reports.
  7. Correlate the scan logs using Splunk Enterprise.

Experiment No. 8: Traffic and Log Analysis using Splunk and Wireshark

Analyze all the attacks and scans performed in previous experiments.

  1. Capture packets using Wireshark.
  2. Correlate logs using Splunk Enterprise.
  3. Analyze: Attack signatures, Network anomalies, Suspicious traffic, and authentication failures.
  4. Create dashboards and alerts in Splunk.

Experiment No. 9: Setup and Configuration of Wazuh

Install and configure Wazuh for monitoring and threat detection.

  1. Install Wazuh Manager.
  2. Configure Wazuh agents in Linux and Windows systems.
  3. Configure log monitoring and alerting.
  4. Familiarize with: File Integrity Monitoring, Rootkit Detection, Vulnerability Detection, Active Response
  5. Analyze alerts generated by Wazuh.

Experiment No. 10: LAN and Web Attack Detection using Wazuh

Perform LAN and web-based attacks again and monitor the generated alerts using Wazuh.

  1. Perform LAN-based attacks.
  2. Perform Web-based attacks.
  3. Monitor generated alerts in the Wazuh dashboard.
  4. Analyze attack logs and rule matching.
  5. Compare the detection capability of Splunk and Wazuh.

Experiment No. 11: Exploiting Vulnerabilities using Metasploit

Use Metasploit and Meterpreter to exploit Windows and Linux vulnerabilities.

  1. Set up vulnerable Windows and Linux virtual machines.
  2. Perform vulnerability scanning.
  3. Exploit vulnerabilities using Metasploit modules.
  4. Establish Meterpreter sessions.
  5. Perform: Privilege Escalation, File Access, Command Execution.
  6. Capture logs and analyze the attacks using Splunk Enterprise, Wazuh, and Wireshark.

Experiment No. 12: Wireless Security Lab

Perform wireless network attacks and wireless traffic analysis.

  1. Perform wireless network reconnaissance.
  2. Capture WPA/WPA2 handshake packets.
  3. Perform deauthentication attacks.
  4. Perform wireless packet sniffing.
  5. Analyze wireless traffic using Wireshark.
  6. Perform wireless auditing using Aircrack-ng and Kismet.

Experiment No. 13: Active Directory Security Lab

Understand Active Directory architecture and perform Active Directory security analysis.

  1. Set up Windows Server as a Domain Controller.
  2. Configure users, groups, and policies.
  3. Perform Active Directory enumeration.
  4. Analyze authentication logs and Kerberos events.
  5. Perform privilege escalation and lateral movement analysis.
  6. Monitor and analyze Active Directory logs using: Splunk Enterprise, Wazuh

Objectives and Outcomes

Prerequisite

Basic network troubleshooting, OSI layers, Basic usage of Linux utilities and networking tools.

Objectives
  1. To familiarize with Linux tools and networking utilities.
  2. To configure centralized log monitoring using Splunk Enterprise.
  3. To perform LAN-based attacks and analyze the generated logs and traffic.
  4. To perform web-based attacks and analyze the generated logs and traffic.
  5. To perform network scanning using Nmap with different scanning techniques.
  6. To perform scripting and enumeration using Nmap NSE scripts.
  7. To perform vulnerability assessment using Nessus.
  8. To analyze attacks, scans, and network traffic using Wireshark and Splunk Enterprise.
  9. To configure and monitor systems using Wazuh.
  10. To exploit Windows and Linux vulnerabilities using Metasploit and Meterpreter.
  11. To perform wireless network attacks and wireless traffic analysis.
  12. To understand Active Directory architecture and perform Active Directory security analysis.

The experiments make use of Kali Linux and other open source security tools.

Course Outcome
Course Outcome(CO) Bloom’s Taxonomy Level
CO 1 Analyze network traffic, system logs, and security events using Linux tools, Wireshark, Splunk Enterprise, and Wazuh. L2
CO 2 Perform network reconnaissance, enumeration, and vulnerability assessment using Nmap, NSE scripts, and Nessus. L4
CO 3 Implement and analyze network, web application, and wireless attacks in controlled environments and evaluate their security implications. L4
CO 4 Exploit and investigate Windows, Linux, and Active Directory security vulnerabilities using penetration testing and security monitoring frameworks. L4
CO-PO Mapping

CO-PO Mapping(3-High, 2-Medium, 1-Low)

CO/PO PO 1 PO 2 PO 3 PO 4 PO 5 PO 6 PO 7 PO 8 PO 9 PO 10 PSO1 PSO2 PSO3
CO 1 2 3 2 3 3 2 1 3 3 3
CO 2 2 3 3 3 3 2 1 3 3 3
CO 3 3 3 3 3 3 2 1 3 3 3
CO 4 3 3 3 3 3 2 1 3 3 3

Text Book / References

  1. The Web Application Hacker’s Handbook, Dafydd Stuttard and Marcus Pinto, Wiley Publishing, 2nd Edition.
  2. Nmap Network Scanning, Gordon “Fyodor” Lyon, Insecure.Org LLC.
  3. Metasploit: The Penetration Tester’s Guide, David Kennedy, Jim O’Gorman, Devon Kearns, and Mati Aharoni, No Starch Press.
  4. Practical Malware Analysis, Michael Sikorski and Andrew Honig, No Starch Press.
  5. The Practice of Network Security Monitoring, Richard Bejtlich, No Starch Press.

DISCLAIMER: The appearance of external links on this web site does not constitute endorsement by the School of Biotechnology/Amrita Vishwa Vidyapeetham or the information, products or services contained therein. For other than authorized activities, the Amrita Vishwa Vidyapeetham does not exercise any editorial control over the information you may find at these locations. These links are provided consistent with the stated purpose of this web site.

Admissions Apply Now