🔄 Topic

Finishing Course 3 by studying hardening techniques that reduce network and system compromise risk.


🎯 Goal

Understand how OS hardening, network hardening, cloud controls, and NIST CSF thinking reduce attacker opportunity.


🛠 What I Did

Today I finished Course 3 — Connect and Protect: Networks and Network Security by focusing on security hardening.

The material covered OS hardening, network hardening, cloud security, brute force attacks, network security applications, cryptography in cloud security, and using the NIST Cybersecurity Framework to respond to an incident.

Hardening means reducing unnecessary attack surface before an attacker abuses it.


🔗 Key Cybersecurity Connections

Hardening is prevention, but it also helps SOC work.

If hardening is weak, alerts become more likely:

  • exposed SSH or RDP
  • weak passwords
  • no MFA
  • default accounts
  • unnecessary services
  • poor firewall rules
  • missing patches
  • weak cloud permissions
  • public storage exposure
  • missing logging

A good analyst should not only identify suspicious activity. They should also recognize the control weakness that made it possible.


🔍 Investigation Questions

  • Which service is exposed?
  • Is the service required?
  • Is authentication strong?
  • Is MFA enabled?
  • Are default accounts disabled?
  • Are patches current?
  • Is logging enabled?
  • Are firewall rules restrictive?
  • Are cloud permissions least privilege?
  • Are backups protected?
  • Which NIST CSF function applies: Identify, Protect, Detect, Respond, or Recover?

🚨 Detection Opportunities

Detection and hardening checks:

  • brute force against SSH, RDP, or VPN
  • successful login after many failures
  • exposed admin port from internet
  • endpoint missing security updates
  • cloud storage made public
  • firewall rule allowing broad inbound access
  • logging disabled on critical system

Example:

service=SSH
exposure=internet_facing
failed_logins=350
mfa=false
hardening_gap=remote_access_exposed_with_weak_controls

🧭 MITRE ATT&CK Techniques

Possible mappings:

  • T1110 — Brute Force
  • T1078 — Valid Accounts
  • T1133 — External Remote Services
  • T1562 — Impair Defenses
  • T1490 — Inhibit System Recovery

🗺 Visual Investigation Diagram

Asset
    ↓
Exposed service or weak control
    ↓
Attacker opportunity
    ↓
Detection / alert
    ↓
Hardening recommendation
    ↓
Reduced risk

⚠ Challenges

The challenge is not treating hardening as boring checklist work. In reality, many incidents happen because basic hardening was weak or missing.

The hard part is prioritization: fix the controls that reduce the biggest realistic risks first.


📚 What I Learned

I learned that hardening is attack-path reduction. Every disabled unnecessary service, restricted firewall rule, patched system, and monitored log source removes or reduces an attacker opportunity.


➡ Next Steps

  • Create a basic hardening checklist for Linux and Windows systems
  • Map hardening controls to attacks they reduce
  • Write a NIST CSF-style incident response summary
  • Review exposed services in my lab environment
  • Create one detection idea for brute force against remote access

🧠 Reflection

Finishing Course 3 felt like a strong checkpoint. Networking concepts are no longer just theory; they now connect to logs, protocols, attacks, and controls.


🧩 Lessons Learned

What worked

Viewing hardening as attack-path reduction.

What broke

Thinking of hardening as only prevention and not SOC-relevant.

Why it broke

Weak hardening creates the conditions that alerts reveal later.

Fix / takeaway

For every alert, ask which hardening control would have reduced the opportunity.


📈 Skill Progression Context

This supports my SOC analyst and detection engineering progression because it turns course material into investigation habits: identifying assets, reading evidence, asking better questions, and explaining security risk clearly.

Instead of treating the certificate as passive study, I am using each topic to build practical analyst thinking that can later become lab notes, detections, diagrams, or portfolio writeups.


😄 TL;DR

Hardening is not glamorous, but attackers love unhardened systems.