> For the complete documentation index, see [llms.txt](https://purplebyteone.gitbook.io/index/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://purplebyteone.gitbook.io/index/notes/education/base/purple-team/ibm/courses/cybersecurity-analyst-professional/introduction-to-cybersecurity-tools-and-cyber-attacks/week-1.md).

# Week 1

History of Cybersecurity

* Threats continue to increase and it won't change
* 1.8 mil. unfilled csec jobs + 200k layoff in IT. #layoff2023
* Not enough skilled cybersec people
* Skilled people go to find cool job in DarkWeb due
  * to better salary
  * WFH remote
  * No dumb ass management
  * No weird colleagues
* SOC analyst reviews security incidents in SIEMs
  * Pivot data and triage it in different ways to understand is this an issue or not
  * Create IOC's
  * Find other internal Ip's that are potentially infected with same malware
  * Use
    * Thread feed
    * Search Engines
    * Virus Total
    * Favorite tools
  * Be curious to learn, research and investigate
  * Search more IOC's information for malware from the internet
* Skills in cybersecurity are in high demand.
* Kenneth Gonzalez, a penetration tester in Costa Rica from IBM's Explores Red Team
  * LinkedIn
* IBM is a global company with subject matter experts in a range of job roles.

{% hint style="info" %}
Interesting, is it possible to get hired by IBM for the Red or Blue team role?
{% endhint %}

* IBM [guys](https://d3c33hcgiwev3.cloudfront.net/deHBQ5nPEem6SAq8ilBGGg_741bbdfe17884efb88e59dfe71281303_Your-IBM-Subject-Matter-Experts--Intro-to-Cybersecurity-tools.pdf?Expires=1675814400\&Signature=UaR-ioZ4Id2FUtStZz2hoJcbfty--S5fWS1Ane8ZSlITOhDf7YJM8j2iQBnpqndKaCGWBH0zHg1NUFoHmFmWTdFO8nGmyKIy4BEYx5aPKcB8Uv-~XQoK6eEC31-BtMEEkjmbrfK-OREsaykuY-1OuhM0gJMJUxg4GmoaJUHzYR4_\&Key-Pair-Id=APKAJLTNE6QMUY6HBC5A)
* CIA triad - protection of information systems from unauthorized activities in order to provide confidentiality, integrity and availability
* Confidentiality - data must be restricted to only authorized subjects or entities
  * Data encryption is a common method of ensuring confidentiality
* Integrity - maintaining the consistency and accuracy of data over its entire life cycle.
  * use hash values for data integrity verification as they must match to make sure that the integrity is accurate.
* Availability - it is about keeping the business operations up and running, firewalls, proxies, computers everything has to be up and running 24 by 7, 365 days
  * business continuity plans
  * disaster recovery
  * redundancy

{% hint style="info" %}
Key Terms
{% endhint %}

* Vulnerability - is a flaw, loophole, oversight, or error that can be exploited to violate system security policy.&#x20;
  * For example, a software or an application that has code vulnerable to a buffer or flow exploit.
* Threat - is an event, natural or man-made, able to cause negative impact to an organization.&#x20;
  * It could be a storm or a hurricane or a hacker, for instance.
* Exploit - a way to breach the security of an IT system through a vulnerability.&#x20;
  * Like the buffer overflow example.

{% hint style="warning" %}
Learn how to "buffer overflow" on practice via HTB and TCM
{% endhint %}

* Risk - is the probability of an event or that an event could actually happen.&#x20;
  * Likelihood of a vulnerability to be exploited.

{% hint style="info" %}
Security Threats
{% endhint %}

* We have internal factors and external threats.
* Internal factors
  * former employees
  * current employees
* External factors
  * Malicious events
* Natural factors
  * Lightning
  * Hurricane
  * Tsunami

{% hint style="info" %}
Vulnerability Assessments
{% endhint %}

* Vulnerability assessment - is the process of identifying, analyzing, and ranking vulnerabilities in the specific environment
* Many systems are shipped with known and unknown security holes and bugs

{% hint style="info" %}
Roles in Security
{% endhint %}

* Chief Information Security Officer - a head in charge of the Information Security Division to supervise, manage, and be the leader of the Information Security Tower.
* Digital Forensic Analyst
* SEM Engineer
* Information security analyst - analyzing events, alerts, alarms, and any information that could be useful to identify any threats.
* Information Security Auditor - in charge of testing the effectiveness of computer information systems to make sure that they follow best practices, they follow standards as specific regulations like the ISO27001 or 002 for instance.

{% hint style="info" %}
From Ronald Reagan
{% endhint %}

* US President Ronald Reagan to create the first national policy on cybersecurity
* first policy for a cybersecurity field in United States that is called the National policy of telecommunication and automated Information Systems Security NSDD155.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://purplebyteone.gitbook.io/index/notes/education/base/purple-team/ibm/courses/cybersecurity-analyst-professional/introduction-to-cybersecurity-tools-and-cyber-attacks/week-1.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
