Building the Ultimate Cybersecurity Lab - Episode 3

preview_player
Показать описание
Part 3 of my Ultimate Cybersecurity Lab Project! If you want to get hands on across networking, firewalls, cybersecurity, docker and containers then this is the perfect project for you! In this episode we build our SIEM and XRD tool, Wazuh. We then install the Wazuh agent on our Kali virtual machine, our Docker server and our pfSense firewall. We then move onto our vulnerability scanner, Nessus.

Support the channel, buy me a beer :)

WAZUH Documentation.

WAZUH install agent

WAZUH docker monitoring

WAZUH - firewall agent instructions

Nessus Download

SERVER USED IN LAB:
Lenovo ThinkSystem SE350
Intel(R) Xeon(R) D-2183IT CPU @ 2.20GHz
256GB RAM
2 x NVMe mirrored drives - proxmox installed here
4 x 2TB Disks

RECOMMENDED SPECS
Id recommend at least 64GB RAM, 32GB would work but you might need to power on and off resources when not used.
1TB storage, 2TB would be beneficial for logs
** you can buy a used server on ebay **

LINKS:

TIMECODES:

0:00 -intro
0:35 - build wazuh vm
5:01 - wazuh kali agent
7:04 - wazuh docker agent
11:20 - wazuh pfsense agent
19:58 - nessus
25:50 - outro

GEAR I USE:

Password manager : Got your data stolen during the LastPass hack?? I switched to NordPass and so should you!! I now use Nordpass and it's way better - use my code at checkout to get 3 months free! - N7O4$5

Learn how to record, edit and post YouTube videos, I use Skillshare and its amazing!

WHAT I USE TO MAKE VIDEOS

FOLLOW ME:

#cybersecurity #lab #untimatecybersecuritylab #homelab #pfsense #docker #ubuntu #container #containersecurity #comptiasecurity+ #proxmox #dvwa #webgoat #bwapp #metasploitable2 #metasploite #hacking #wazuh #nessus
Рекомендации по теме
Комментарии
Автор

In this episode we build our SIEM and XRD tool, Wazuh. It's amazing!! We then install the Wazuh agent on our Kali virtual machine, our Docker server and our pfSense firewall. We then move onto our vulnerability scanner, Nessus.

gerardobrien
Автор

I'm a huge of Wazuh. Deployed it myself and got it proxied behind my cloudflare tunnel so I can access it anywhere. I get blown away on how much one can do with that. Awesome product and I'm glad to be able to watch you on your cyber homelab journey.

itlackie
Автор

Building Cybersecurity lab based on your tutorials in my home server. Feeling happy that i have found your profile. 😊

NaveenKumar-tyry
Автор

If anyone has issues getting pfSense to send any data to the wazuh server, check the /var/ossec/etc/ossec.conf file and look at the <server> section where you set the IP. Mine (agent version 4.7.5) had a <protocol>UDP</protocol> line in it which caused the agent to fail the connection due to the wazuh server expecting TCP. Comment out the line, restart the agent and it should spring into life.

RobGirdler
Автор

Began the same project with friends and your videos are absolutely awesome

Jelam
Автор

I've deployed the Nessus and Wazuh servers in LXC containers. A bit less pain to deploy than full blown VMs and it's there by default in ProxMox. Works fine so far.

MichelStumpf
Автор

Fantastic series, looking forward to episode 4!

lawrenceneo
Автор

Thank you for uplaoding this kind of content and going to into details about every steps. Can't wait to see what you do next!

xavierholzendorf
Автор

thoroughly enjoying this project !! looking forward to the next video !! cheers

tristanhoughton
Автор

Hey Gerard can't wait to see your next episode. I have been following you.

SumanAryal-efhb
Автор

Hello Gerard, thanks for this tutorials. the new version of Wazuh does not have the GUI to enable the Docker listener. How do we enable that from the Wazur server?

akamdasi
Автор

Hi, I've been following along pretty smoothly up until the wazuh docker containers. My Wuzuh version is 4.8. I was wondering if you, Gerard, or anyone else have found a solution to docker listener not listening lol. I think the pip install is a bit funky but I can't seem to find any solutions online.

leo
Автор

Wazuh can do security scan and provide all detected vulnarabilities on your machine. Not sure if you need Nesus after you configure Wazuh properly.

sergeygr
Автор

Wazuh 4.8 has a different dashboard than 4.7. I can't seem to locate the place to toggle on the Docker Listener. Is there something I'm missing?

i_am_vengeance_
Автор

Hi Gerard, I was wondering how many CPU or CPU cores you would expect the server to be using at any one time for this Cybersecurity Lab you're building.

lauriemcloughlin
Автор

A 10:07 what keyboard short cut do you use to align the xml you added to the file conf file? Great Video!

Daysis
Автор

awesome awesome awesome! My only question is are you going to be simulating attacks so we can put this to awesome tools to effect

alexeyiah
Автор

getting an error when trying to install wazuh. it says the OS is not one of the recommended OS. i downloaded the same image in your first video. keeps getting stuck "an external processing is using APT" and then keeps retrying. any advice?

edgarvalenzuela
Автор

built the prod-wazuh but gets to the same point and reboots and then stuck on 'booting from Hard Disk'

luomo
Автор

Hey Gerard my pfSense is not connecting on wazuh after following your steps from 11:21 through 16:41.

jameslouis