Hook

Their other posts in the index, biggest breakout first.
ONE LAB. This one Linux lab could actually get you hired. And that's not clickbait. Y'all commented on the last video asking for labs, and I'm here to deliver. So, here's the first lab that we're gonna do in our cyber security series. If you're new here, my name is Nate. I work in Information Systems and Cyber Security. I have an ISSE engineer. And I help people break into the industry. If that interests you, make sure you drop a follow. Today we're going to be digging STIG, a Red Hat Linux VM. Now, we are going to need a couple things before we get started. You're going to need some type of hypervisor, somewhere to run the VM, whether that's Proxmox or Virtual Box, anything of that nature, to run. And this Linux VM. There's plenty of tutorials online that are super simple to set up. Once you have that set up, you are going to need to download a RHEL 9 or RHEL 10 image from Red Hat themselves for free. You can do that by setting up a developer account. And before we get started, we're actually going to need to install the OpenSCAP scanner onto our Red Hat VM. The scanner is the OSCAP binary, security guide is the content it scans. Once you have that, ready to get going. Now, the first step before we even get into STIGging the Red Hat VM, you're going to want a backup, okay? Because we're going to be changing a lot of settings that could actually break the image itself. So you're gonna want an undo. I'm going to show you how to do it on screen right here. Now, Rule One of compliance is you actually want to scan whatever VM or box you're operating on to get a whole picture. You don't know what's been installed or if it is a fresh install. You need to know what you need to harden. So by typing this command on your virtual machine. Baseline. This is the starting point. Now, the result is not gonna look pretty. This is our baseline, this is our starting point. And what we do next is actually what separates practitioners that know what they're doing versus ones who don't. Pick one, Red finding. Pick direct root login over SSH. Watch how a single checkbox directly connects all the way up to what you see is not just a Linux setting. It's actually a DISA STIG which directly satisfies a NIST 853 catalog which systems get directly authorized against. And if you can walk that chain up, you sound like someone who can do this for a living. Now, we're gonna directly change this one rule and then rescan. And watch what happens. As you can see, based off the scan, it is now a green setting, which means we have satisfied at least one control. Now with SCAP scanning, you can actually fix multiple controls at once. That way you're not going one by one. And if you're hardening a whole fleet, you can use tools like Ansible to actually accomplish this for you. With this command right here. As you can see, after our scan, we have our before and after appear on screen, and your ARF.xml is actually pull directly into the DISA STIG viewer. That's the evidence. Evidence the auditor would actually want. Now, that may sound like a lot, but it's literally something that people do everyday at a small scale and a large scale. So if you do this lab, you provide a write-up, well, you write up that you stand out exponentially. I cannot even tell you how rare it is. The scan is the easy part. I have not seen anybody talk about this before. Now, something to point out that DoD baselines also want FIPS mode enabled, so make sure you do that upon install. But other than that, you just hardened a Linux system. Love you guys, like always, I'll see you in the next one. Peace.