How to Build a Home Lab for Infosec with Ralph May | 1 Hour

How to Build a Home Lab for Infosec with Ralph May | 1 Hour

Black Hills Information Security

2 года назад

134,251 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

@1xtra299
@1xtra299 - 02.12.2022 05:49

THANK YOU RECORDING AND UPLOADING THIS! Got stuck in a work meeting :(

Ответить
@tbard
@tbard - 02.12.2022 12:18

Some options I use/have used in the past that I wanted to add:

Firewall: installed on bare metal or VMs there is also Sophos XG Home that is also free, it's less lightweight than something like pfsense/opnsense so you WILL lose performance if you don't throw fast single core CPUs (not an issue if you have <=1Gb internet), but it's more similar in functionality to an enterprise firewall. Main bonus for a learning environment in my opinion is being able to set user-based rules using Active Directory users and being able to check who is logged on domain joined computers in the network automatically (using Sophos STAS).

Virtualization: two things here. First of all a really good and free type 1 hypervisor is Xen, it often gets overlooked but while it might be not as popular as it once was it's still an enterprise hypervisor that is being offered basically full featured as open source. It needs to be compiled to have the full features, but there are people doing it and sharing the compiled version.
Second, it's more if you want to learn sysadmin skills than security skills, but VMWare offers for about 180€ bucks/year a VMUG Advandage package that has the highest existing level of license for ALL vmware products for homelab use. (not just the hypervisor esxi, but also vcenter, horizon, tianzu, vsan and much much more). For people with a homelab wanting to learn sysadmin skills that are really useful.

Backups: no matter what you're doing backups are really essentials always, if you're trying to learn stuff you don't know you have a high chance of messing it up, so it's even more important. No matter what you plan to use, take them. Veeam has a free version for up to 10 VMs if you use virtualization on esxi/hyper-v, if you work in IT and contact them you can ask for a NFR license for one year for free to double that up to 20 VMs. It's not a guarantee but they almost always give them out. There is Proxmox Backup Server for proxmox and Xen should be able to do it by itself. If you use VMWare Workstation or Virtualbox it's not ideal but you can just backup the whole drive with some desktop solution. Not sure what to go for there, so I'm sure there's better solutions, but Veeam Agent is free and can be used standalone.

Ответить
@sweetlulu4306
@sweetlulu4306 - 02.12.2022 19:36

I noticed the firewall chart didn't include firewalla

Ответить
@egan555
@egan555 - 04.12.2022 18:22

what’s the best way to get official windows licenses for testing (i.e. AD Lab) these days? msdn use to do subscriptions way back in the day…

Ответить
@AdHdEntertainmentLLC
@AdHdEntertainmentLLC - 05.12.2022 18:00

gr8 video was on the live stream but had to leave so finishing up. Been working on my homelab which seems like forever

Ответить
@devohnmitchell
@devohnmitchell - 05.12.2022 19:08

I'm IT and looking to get into CyberSecurity. A question that was asked on a Job Interview was, "Tell Me about Your Home Network". From that question I realized that I needed to invest in HomeLab and hadn't put in time and money into developing my Home Network and segmenting my network more. Thanks for the Video.

Ответить
@Headh0t549
@Headh0t549 - 06.12.2022 10:59

I don't think this should be called a "how to setup", it's more or less just an introduction/presentation.

Ответить
@SavageScientist
@SavageScientist - 07.12.2022 17:40

Man this is great information my home lab has a mix of things from different companies, i have a ubiquity router, netgear switch, motorola modem lol.

Ответить
@danielstellmon5330
@danielstellmon5330 - 09.12.2022 05:29

the "best way" is the way that does what you need, you can use, and WILL use. The reset is opinion.

Ответить
@fision8090
@fision8090 - 10.12.2022 22:36

I'm here to prove the minefield point and ask why you didn't mention the glorious kvm virtualization method? /s

Ответить
@mridontclickbaitftw4366
@mridontclickbaitftw4366 - 11.12.2022 03:16

How to build a full-sized spider web

Ответить
@MygenteTV
@MygenteTV - 12.12.2022 16:45

Im only 5 seconds into your video and I already subscribed to your channel. You can tell when a person knows his stuff. Im always open to learn new stuff from others. I had been doing bug bounty for a decent time and now for job requiring doing the oscp, hope to learn new stuff from you

Ответить
@rationalbushcraft
@rationalbushcraft - 14.12.2022 03:44

I looks to me like you can heat your house with that equipment. jk I have access to all the enterprise equipment I could ever use. But my philosophy is I don't want to use that much electricity. For me I use a Lenovo mini with a large SSD drive that I run ESXi on. That really does most all I need for a home lab. Rarely do I need more than two or three vms at a time for testing.

Ответить
@Lowest_Levels
@Lowest_Levels - 14.12.2022 09:15

Not sure why I was shared this in recommendations but interesting. The best I can tell, a home lab is a hardware sandbox for hardware testing at an infrastructure/network level and the software that accompanies or aligns with it. The ability to throw various relevant things at it in regards to what could be considered attacks or vulnerabilities security wise to discover weaknesses. Network testing. Would be curious for feedback on this extremely limited understanding.

Ответить
@prettyboylatino7324
@prettyboylatino7324 - 15.12.2022 04:31

Bro love the video. Appreciate your time and excellent concept. Just subbed

Ответить
@bbqworld2103
@bbqworld2103 - 15.12.2022 19:33

Great video, thanks!

Ответить
@jdkingsley6543
@jdkingsley6543 - 17.12.2022 09:17

What a gem of a video, I was fortunate enough to build my home label with some older stuff, I just wanted to learn the basics. I one tip I tell folks is you dont have to break the bank.

My lab consists of 5 machines, two of which are mac and the rest a combo of windows, windows server and Linux. An assort of switches, and a few watch dog firewalls. Most of my money went into software like burpsuite and virtual machine licenses.

Ответить
@Bargemanos
@Bargemanos - 24.12.2022 00:43

Just a typo i guess, but its OPNsense, without the E in open as shown in the video in the firewall part.

Ответить
@rashondricevans6282
@rashondricevans6282 - 26.12.2022 21:37

Where is the link to the Tiny Lab you mentioned?

Ответить
@markh3684
@markh3684 - 29.12.2022 11:04

Once you start hearing the um's, it's hard to hear anything else

Ответить
@TinkerTech
@TinkerTech - 29.12.2022 16:40

Not trying to be nasty. I really liked the video. But you got carried away with "um". You have a great cadence, clear voice and the content in general was informative. Just try to work on that 1 thing

Ответить
@coloradopatrick
@coloradopatrick - 08.01.2023 19:32

Watching this in Jan '23. Great video! Thanks for recording and uploading. You've given a lot of content to think about as I go down the home lab path!

Ответить
@barry3792
@barry3792 - 26.01.2023 20:48

Great work! Veteran to veteran, hey no disrespect but I'm having a hard time getting past your ascending inflection at the end of most sentences which seems to be mainstream these days 😖. But I'm sub'n anyway, thanks.

Ответить
@ripits_62
@ripits_62 - 25.02.2023 11:42

Network topology diagrams?

Ответить
@YukisomeVideo
@YukisomeVideo - 05.04.2023 21:52

Can i follow this tutorial using an linux / window instance on aws ?

Ответить
@Random-ch9my
@Random-ch9my - 12.05.2023 18:13

Just wanted to mention that Mikrotik (not Microtik) routeros is open-source, not closed source.

Ответить
@thatguyinelnorte
@thatguyinelnorte - 20.06.2023 03:57

Even though there is a huge range of products, it would be nice to have a low-end list of items and estimated pricing... What I've seen looks like > $5,000 for all "recommended" parts... so I either missed something, or I'm not the intended audience...

Ответить
@tigerscott2966
@tigerscott2966 - 26.08.2023 20:59

Nice Lab...

Let me get my pen and paper...

Class is in session...

thanks...

Ответить
@keybordeur8308
@keybordeur8308 - 20.11.2023 19:08

Very good video. Lots of info in an hour. Great presentation. Thank you!

Ответить
@scottt5570
@scottt5570 - 13.01.2024 10:00

Umm, ugh, umm, uhh, umm, ugh, umm, uhh, umm 😳 got half way, cant listen to you saying umm anymore

Ответить
@nixrohan
@nixrohan - 26.01.2024 20:45

Are you motherred from hf?

Ответить
@imsethtwo
@imsethtwo - 15.03.2024 01:33

loved the video but the uhms and uhs were unbearable at some points lol

Ответить
@possumwizard
@possumwizard - 22.05.2024 16:24

This is super cool, thanks so much for sharing. I'm trying to break into the field and this will help me cobble all my project ideas together!

Ответить
@hkondres
@hkondres - 29.07.2024 07:00

Addiction... Right on the money... I read an article - homelab for $0 on old laptop - and that is what/how I started but things can go quickly out of hands... Even with small things like HDDs, or switches or Raspberry Pi-szszsss... It's hundred here, hundred there, 20 becomes change, then 50 bucks is sooo cheap - at the end... nothing is cheap if you don't need or use it.

Ответить
@abuuahmad3238
@abuuahmad3238 - 08.08.2024 02:27

I just got my sec+ exam passed...now I want to stack some labs experiences...and this video was perfect... impeccable content
Keep on good work brother..
Allahuma baarik

Ответить
@deveau145
@deveau145 - 05.09.2024 19:55

Thanks for the overview!

Ответить
@slimsediq
@slimsediq - 02.10.2024 01:54

please more video of this like Sir.
I love it, Thank you!

Ответить
@BlackHillsInformationSecurity
@BlackHillsInformationSecurity - 04.01.2023 18:56

Help us share the knowledge with the infosec community! Give us your Likes to help others find our videos. Share this video with your friends. We want to grow big for 2023, so tell us in the comments which topics you want to see from BHIS this coming year! Thank you, we appreciate you all!

Ответить