Trust No One by default!
Key Takeaways
The video discusses the importance of a Zero Trust approach to cybersecurity, highlighting the limitations of traditional cybersecurity models and the benefits of using tools like ThreatLocker to block all unauthorized actions by default. The conversation covers various topics, including the use of PowerShell by threat actors, the risks of remote access tools, and the need for network control and application whitelisting.
Full Transcript
the other part is what things can do when they're running okay so in the case of the Jack jackaby example he was using Powershell to reach out to the internet to get the polymorphic reverse shell and Powershell is very often used by threat actors it's an incredibly powerful piece of software and it makes sense for a bad guy to use it because it's on every Windows machine y so why would you not use it if it's sitting on every Windows machine it's a an attack in a casino in Vegas was implemented using a smart heater in a fish tank oh wow so a smart heater and a fish tank are compromised and then they use that to basically bounce on or try and connect into a server why would a smart heater in a fish tank even it's if it's on the same physical Network or the same network as the rest of your machines why would it need to be able to connect to a server hey everyone it's deavon bubble coming to from zero trust World here in Orlando big shout out to thread Locker for sponsoring my trip here and making people available like Rob Rob great to see you again good to see you David good to see it last time we spoke we were doing a demo with jacobe and you guys him from running a really cool piece of software so perhaps you can tell us a little bit about that and how you guys stopped him from hacking the network certainly so um as you obviously know jacobe is a genius and he has some of the most amazing ideas um techniques tactics he uses in this particular case he had a basically a polymorphic reverse shell so it was a reverse shell that changed constantly he'd send a request out to an API he'd get a reverse shell back every time it was different and it was never picked up by any of the traditional tools or methods so um he basically tried it on the machine with thrat locker and thrat Locker immediately stopped it and jacobe was amazed because he thought we were doing some sort of you know deep understanding or or recognition of what he was up to and what he was trying to do and I had to break the news to him I was like Jobe I'm really sorry we're it's none of those things we're not we we don't care what you're doing we're just stopping what you're doing because fundamentally what you're using Powershell doesn't need access the internet so we just block it from accessing the internet it was no more advanced than that really but uh it was it was really eye opening just the way he approached the way he tries to do things some of the solutions he has it's amazing I mean that's a big Paradigm Shift right I heard you do a presentation few years ago now I and you can update me with a new figure every 11 seconds ransomware destroys a company or something every 11 seconds on average uh a company gets hit by romere I mean it's and it's it's showing no signs of slowing down yeah so it's still a major problem in today's world and I mean that sort of the Paradigm change that you guys brought in right so perhaps you can just I don't want to put words in your mouth so tell us what's the difference between what thread Locker is doing versus traditional Solutions cuz they don't seem to be working uh well I mean the evidence would suggest that they're not um I suppose the traditional model uh toward cyber security is about about identifying everything that's bad uh about stopping Things based on decision fundamentally is this thing good or is this thing bad yeah the problem with that is that nobody knows all of the bad things and and it turns into a constant trying to catch up trying to you know catalog everything known that's bad I mean that's where antivirus has been for years trying to get signatures and definitions edor are more about behaviors and what things look like and are they behaving suspiciously but fundamentally it still comes down to a decision about good or bad um we take away the need for decisions about good or bad because our approach is everything that isn't explicitly allowed is going to get blocked so it's not permit by default deny by exception it's deny by default permit by exception now a lot of people are afraid of that concept they think oh it means I won't be able to do my work but the the the important part of that is the permit by exception the permit by exception is what allows people to operate it's what allows businesses to continue to work but the by default is what will keep them keep them safe because it's what's going to stop ransomware fing is going to stop the interesting thing is it's not just about things like ransomware it's also about things like WinRAR for example I mean WinRAR how you can encrypt data with WinRAR you can delete data with WinRAR you can transfer data with WinRAR I mean it has all of the characteristics of ransomware now it's not a bad application so you're typical AV or Ed or is not going to stop WinRAR from running in your environment but in most environments does something like WinRAR need to be able to run I mean the reality is probably not and you apply that to a dozen different things so any desk is a remote access tool of choice team viewer yeah absolutely team viewer I mean one of my and I favored is a terrible word to use in this context but one of my favor cyber attacks over the last number of years was actually on a water treatment facility here in Florida oh wow yeah and it was described in the media as a advanced Cyber attack but it turns out it was literally just somebody got into a team viewer account and started changing the uh chemical levels in this water treatment facility that was obviously incredibly serious and dangerous but an advanced Cyber attack which is basically just somebody got into a team viewer account and started playing with with levels so as I said it's not always about what's good or bad it's about what's required and what's not and what required is as I said what will allow businesses to operate what's not is something that we deny robt heard you use another example you to use showan to do a scan in Orlando right yes and it was quite scary with what did you call it ransomware deployment protocol yeah orp orp so basically look anybody can do this using Showdown you can just search for a particular area and a particular port and it will show you all of the machines with that Port exposed now at the time I did it there was somewhere in the region about 900 machines exposed with orp exposed to the internet now it's one of the most common ways in because fundamentally once orp is exposed it's just a throw as many passwords as he can and you will eventually get in um so yeah ransomware delivery protocol it's one of the biggest vectors um it's somewhere about 20% of ransomware taxs involve RDP exposed RDP but the scary thing is I mean I I'm assuming most of these organizations don't know it's exposed so you know somebody set it up once forgot about it um we had a great great example of a very large company a prospect and at one stage their edor was basically the edor was saying they had rans somewhere now when we actually looked into it they didn't what we discovered was there was incoming RP connections constant basically Brute Force attack underway now the the company said that's impossible we don't have ODP exposed to the internet on any of our connections so we there was actually Danny our CEO opened up remote desktop put in the IP address login screen straight away well and it turns out it was actually one of this organization's techs at home who was working from home but he decided that working from home wasn't convenient enough he actually wanted to work from his friend's house when he was at home so he opened up RP to his work laptop on his home internet connection so he could connect in from his friends house and this is the thing most organizations have no idea that this kind of thing is happening they have no visibility they they no control fundamentally about this kind of thing and that's something that we try to address with our products yeah because you have this is it learning mode where you run the product for a while and then you discover and then it's quite I think you got some good stories where like customers like that one they didn't even know what was in the organization I I I would argue that 90% of organizations have no idea what software is sitting on their machines uh or running on their machines in fact um I did an interesting exercise for a um a relatively small company about 200 mpoint company at one stage and they wanted to show us or they wanted us to tell them all the bad things that were in their environment and as I said we don't really do concern ourselves that much were good or bad but what I did and said was said look I'm going to look for remote access tools I'm going to see how many remote access tools are running on your machines turns out uh six different remote access tools were running so they team viewer they'd log me in they had anid desk they had Bomar the the really interesting thing though apartment and these things are running I'm not just saying they're sitting around in a downloads folder they're actively running on the computers um the really interesting thing was that 20% of this organization's machines were running team viewer that organization did not use team viewer the company who managed their it did not use team viewer but we both know how it happens which is at some stage in the distant past some third party said I need to get into your computer to fix a piece of software will you install team viewer for me so they install team viewer company gets in and it's forgotten about it's left there but it sits there as a potential way into the network basically forever so something like that even if it's required you don't need to allow it perpetually you don't need to allow it permanently so you need to in your David no problem at all I'm going to permit it for your machine for 2 hours after which time it's not going to be able it's going to be shut down and it's not going to be able to run anymore so again that's the kind of control that we offer with the approach that we take I think the concern people have right is I've got all these applications is it going to break the application that I've got currently yeah well I suppose going back to what you said learning mode is really important so first of all when it's deployed it's not going to block anything it's not going to go get in the way it's not going to stop anything I mean fundamentally it shouldn't even when it's when when it's uh fully deployed but basically what we do during that initial period is we want to see what's in the environment we want to see what's running on David's computer so we can see David's running Creative Cloud we can see d d David's running office we can see David's running 10 other applications some of which we know about and recognize some of which we've never seen before we' have no idea of but we need to accounter them we need to catalog them we need to allow them to continue to run once David's machine has been secured so that's why that learning mode is so critical um we've also got what we call simulat denies so in that learning mode we can see all of the things that would have been denied if thre Locker had been enabled so you know this piece of software generates a new file every day or a new hash appears for this well we need to take care that we need to create allowances for that and we can do that during that learning period but the idea is that at the end of it you're going to have two things first of all you're going to have complete visibility over what is in your environment and as I said there's always surprises there there's always things that people don't know about but you have a full software inventory you know what's needed on every single computer within your organization but as well as that you're also at a point where you can secure your machines you can secure your environment safe in the knowledge that you're not going to break things and the not going to break things is really important because obviously it's a concern but again we wouldn't be in business we wouldn't be where we are today if we broke things because as I said it is a powerful tool and to to steal a a movie ISM with great power comes great responsibility with great power comes great responsibility we've no interest in breaking things in people's environments we want to make it as smooth as possible and that's part of the the service we provide it sounds really complicated though because let have got like 100 applications 300 whatever number of applications is it difficult for me as the customer to manage those would you guys take that load on so we take responsibility by virtue of what we call built-in applications so it is a absolute and it has historically been a concern with allow listing and anybody who's tried to implement allow listing will know this that it is historically or has historically been a heavy lift um so you need to piece of software updates you need to account of all those files uh one of the I suppose the secret source of thrat locker is what we call buil-in application so what we do is we maintain definition so every time a new update comes out for acrobat or office or even Windows itself we'll catalog those applications we'll run them through what we call our testing environment make sure everything is okay doesn't misbehave and then we'll add them to our built-in applications and those built-in applications get pushed down to anybody who's using that application so or sorry so acrobat is on David's Machine new hash gets cataloged by our applications team it gets pushed down to your machine automatically so fundamentally you don't need to worry about updates causing problems to your software we're taking that responsibility on how many applications have you got is it 4,000 with the last figure I heard the last figure I checked so it was it's about 5,000 Windows about 3,000 Mac so the last I checked was actually last week and it was 8,340 in on Windows or like in total in total in total so Windows Mac and windows Mac and Linux and Linux as well that's great so what is ring fencing because that's another term I've heard so ring fencing is actually What stopped jackaby so uh ring fencing is the there's two parts from our perspective there's two parts of what we call application control and um application control is what can run or what can't run which is the allow listing part the other part is what things can do when they're running okay so in the case of the Jack jackaby example he was using Powershell to reach out to the internet to get the polymorphic rever shell and Powell is very often used by threat actors it's an incredibly powerful piece of software and it makes sense for a bad guy to use it because it's on every Windows machine y so why would you not use it if it's sitting on every Windows machine it's what's called living off the land fundament um so what we say is look well look power shell need may need to operate in your environment you may need to run it for administrative purposes but does Powershell need to reach out to Jacob's random um polymorphic reverse shell server no does it need to reach out and be able to download malware no does it need to be able to exfiltrate data or copy data to a random Cloud location no so our approach with ring fencing is about controlling what applications can do so say Powershell does not need to access my files so therefore I'm not going to allow to access my files it does not need to access the entire internet so therefore we're not going to allow it to access the entire Internet it's the same principle and if you think about it it's it's also default and I permit by exception so it's block Powershell from accessing all of those locations but allow it to access to the place it needs is needs to access so it's exactly the same Principle as just expanded upon so what is Network control I think it's storage control so Network control is a really really important piece of the jigsaw because one of the things that we have seen is it doesn't matter how well you protect your computers your servers there are so many other things on people's Network these days that can be exploited and that can be misused um again I hasten to or I shouldn't use the word favorite in terms of cyber attacks but yeah one of the ones that I found most interesting in the last number of years was a a casino in Vegas it wasn't the big attack in the casino in Vegas recently but a an attack in a casino in Vegas was implemented using a smart Heat in a fish tank oh wow so smart heater in a fish tank are compromised and then they use that to basically bounce on or try and connect into a server why would a smart heater in a fish tank even it's if it's on the same physical Network or the same network as the rest of your machines why would it need to be able to connect to a server exactly so Network control and there's a million other examples I mean we all know about all of the vulnerabilities in firewalls these days I mean it it seems like there's a weekly CBE serious CBE um and a lot of them involve vpns um so again and what a lot of these threat actors do is that they're not actually doing in in in the first instance they're not actually doing the hacking so let somebody else find all the vulnerabilities they're letting somebody else exploit all the vulnerabilities they're basically just getting back a list of credentials there a lot of organizations will actually tie their firewalls to their ad so once you've got into a firewall once you've got into a VPN you've effectively got full access to the network and one of the things that we've seen is remote encryption so basically encrypting data on something that is protected using something that isn't protected so whether that be a VPN connection or a remote connection whether it be some someone spinning up a VM and a hyperv server I mean that's another common one that we see is they get in they get onto a hyperv server they create a new virtual machine that virtual machine has no security it's got no EDR it's got no threat Locker on it they just spin that up and then they use that to encrypt data on something that is protected so that's where Network control comes into it it's about again same principle denied by default permit by exception so block all Network traffic all access from anything except those things that we trust those things that need to have access so only my workstations need to access my file share so why would I let anything except my workstations access my file share but again it's the same principle just expanded on storage control pretty much the same thing so we can the clever thing or the the the the best thing I think about storage control is we can actually control which programs have access to what data so if you think about your traditional model your traditional approach to storage it's user base so it's David has access ACC to that Finance share over there but the problem with that model is once David has access to the finance share everything David runs has access to that fin Finance share as well and again that's something that is misused so all it is all it takes is a vulnerability or you running something you shouldn't and then all of a sudden that data is at risk so with storage control we can limit which individual programs have access to that data so if only office and acrobat and teams and zoom need access those files why would you let anything except office and acrobat and teams and zoom to two ancest those filed so again deny by default permit by exception you're probably seeing a theme here I've noticed yes it's an important Paradigm change right it really is it's it's taking your traditional permit by default deny by exception and basically complete 180 just turning it around Rob it's great to like have endpoint protection but what about the cloud because obviously a lot of people using the cloud these days yes absolutely um I suppose somebody who used um Microsoft 365 or Office 365 or whatever they're calling it today for many years one of the biggest challenges with it is there's a lot of useful information there a lot of pertinent information there's a lot of warnings a lot of this is trying to happen or fail log in there and a lot of cases people don't see it because it's it's Microsoft and it's so hidden away keeps us all employed absolutely so we basically got what we call floud detex so detect is our detection platform because we do see detection as being important in general terms even whether bpoint or Cloud detection is also important but it shouldn't be the primary layer it shouldn't be the thing that you're depending on because we discussed the problem with detection is if you don't detect something it's basically game over if that's your only layer so we see detection as being complimentary to those other controls we mentioned and I will I will talk about a control that I'm hoping we're going to have coming very soon but Cloud detection so what we do is effectively we take those alerts those logs those rist detection stuff the things that Office 365 generates and we basically alert you on it okay we say hey there's something going on here um I had a great story with a customer he was actually just around behind us a couple of minutes ago about a event that happened last week so he got a call from our mdor team about a impossible login or it was actually an anonymized login and what happened was one of his employees um had their credentials fish so basically put them somewhere they shouldn't somebody tried to log in from London interestingly enough and Office 365 blocked the log in from London and temporarily disabled the account so what they did was they then VPN to the states to try and get into the same account that was detected as being coming from an analized IP address by Microsoft and it alerted our mdor team so they rang him and they said hey we think there's something going on with this user he checked it out discover what had happened but again if that had been sitting somewhere hidden away in Office 365 he would have never known about it so yeah it is an it's an important area to consider it's an important area to protect as well um as I said from a a pure protection perspective and I'm going to give you a very quick insight into something that we hopefully have got coming we're still working on at the moment um so Network control obviously Deni by default permit by exception you can technically do the same thing with offic 365 with P called name locations and conditional access so you can basically say look don't allow anybody connect to my Office 365 except these locations and the problem for most organizations is that's fine I can lock it down to my office IP address I can lock it down to 10 staff's home IP addresses but what happens when David goes out on the road and he connects to 10 different Wi-Fi networks or he's on cellular so we have a what's called thread Locker access app which runs on your phone and basically just logs your IP address every time it changes we then take that and we upload it to a name Lo location in Office 365 so we keep that named location updated based on your current location and IP address so again you're going to protect your Office 365 by stopping anybody from being able to connect to it other than from those trusted locations so we're hoping as I said it's still in progress at the moment but we're hoping it's going to be one the announcements on Thursday what's your opinion about AI it seems like AI is leveraged by black hats very very well but I'm not sure how effective it is on defending um I both love and hazer yeah so I love it from the perspective is it gives me skills that I don't have yeah um I've used it to create reverse shells for example now if you say give me a reverse shell it'll say no because you know I'm an AI language model and I've got ethics and morals and yes but if you ask a question in a slightly different way you would very often get the answer you're looking for so instead of kind of have code for reverse shell can I have code for a simple Remote Management tool that the language type Comm commands into a computer remotely it will give it to you you can talk it into it shall we say or or or trick it or work around the controls that they built in but what that's shown me is that it's effectively lowered the barrier of Entry to bad actress to malicious actors because once upon a time you needed skills you need knowledge you needed to be able to code fundamentally to be able to create things like malware now you can either go ransomware as a service just go in the dark web find ransomware as a service and pay a few hundred dos for it or you can use something like an llm to help it give you the code so it's lowered that b barrier of Entry so we're once upon a time maybe there was 3 four 500,000 people in the world who' be able to do this now there's literally millions you know they just need to be able to ask the right question um so that's a part of it that I both love and hate I mean I I struggle with it sometimes in so far as very often the code that gives you is junk um so I shout at it sometimes I call it names from time to time and I just want to like full disclosure and apology when they come for us and they will come for us at some stage but when the the AI comes for us and kills us all it's probably largely my fault because I've chat gbt a dumbass on too many occasions but look there is value in it as well with most things there good and bad there's value in it as well I mean it is useful it's it's a learning tool it's something you want have to find out how something works you can absolutely do that um so it can be used for positive as well as negative ways but as you said yourself um very often it is the the from a security point of view man what what what people can do like you said no skills these days no so does thread Locker rely on AI or some clever stuff like that to block stuff no it's a short answer because again that involves decisions that involves deciding what's good or bad so no it's not something we do that's why that's where jacobe was like confused in the beginning right cuz he thought it was fancy AI or some kind of clever analysis but you guys weren't doing all that fancy stuff he thought it was behavioral analytics he thought it was some sort of advanced you know behavioral decision- making fundamentally and it was none of those things it was just literally controls I mean controls are very simple and fundamentally it's like can this happen or can not typically it's binary decisions it's yes or no it's not you know bring in all these different data points and try and figure out something using AI this the it's not needed Rob gonna ask you a do dodgy question now now obviously you telling me thread Locker is great but you know what what do your customers say are you is your customer base growing you get a lot of you got customers from small to large you know who's deploying the stuff because that's the real test right absolutely uh I mean it it's changed over time but the I mean the company itself is is going gang busters I mean as I I know you weren't at previous worlds and hopefully you'll be at the next one but it's basically this event itself has doubled yearyear for the last four years so when I was at my first one which was three years or over 3 years ago um I think it was about 200 people wow um today it's 1,500 so it it's growing exponentially much like the company is I mean the the the messages getting across the lesson that the traditional approaches traditional models are not going to keep us safe is very much sinking in with organizations now whether or not they have the budget or the wherewithal to do something about it today fundamentally a lot of organizations are coming to the same conclusion which is that fundamentally detection is not enough it's important as we discussed but it's not enough it's not it's not going to keep you safe so what will keep you safe is basically zero trust it's ton die by default it's the approach that we take and we are probably if not definitely the most Innovative company and easiest to use which is why we are growing so quickly I mean you got is a Gip BL some is as an example of a big company right there's some very large companies military as well well a year ago jaff were our largest customer now we probably have 10 bigger than them um so yeah there's a lot of big organizations and again look they they have been looking they know this is the right approach but they have in a lot of CAS I mean I've spoken to an organization in the UK um who have spent and this is not an exaggeration they spent four years trying to implement application white listing they turned it on once and it blue screened a whole bunch of servers and they turned it off again but they're still working this is still a project that is underway for these guys um I spoke to a um a large health insurance company in the mid least and it was the same thing they'd spent two years 10 people 10 staff had spent 2 years on a project trying to implement L listing and had given up they just said right this isn't going to work it's not possible so that's I suppose what we do we make it possible we make it obtainable we make it achievable for as you said everything from L and pop shops to massive organizations so it is it is something that we see every day I will say this for everyone watching thanks to thread Locker it's going to be implemented in my team because this is something we also need so Rob thanks so much for that and thanks for the interview welcome David pleasure thank you
Original Description
Big thank you to ThreatLocker for sponsoring this video and my trip to ZTW25. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
// Rob Allen’s SOCIAL //
LinkedIn: https://www.linkedin.com/in/threatlockerrob/
X: https://x.com/threatlockerrob
// YouTube video REFERENCE //
Can this mind blowing Reverse Shell Attack be stopped?: https://youtu.be/nODVcuLhe1M
// David's SOCIAL //
Discord: https://discord.com/invite/usKSyzb
X: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube: https://www.youtube.com/@davidbombal
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Coming Up
0:44 - Intro
0:55 - Stopping Jackoby's Hack
02:10 - Threatlocker VS Traditional Solutions
03:33 - Deny By Default, Permit By Exception
05:06 - Ransomware Deployment Protocol (RDP)
06:58 - Are Organisations Safe?
10:31 - Allowlisting
11:48 - What is 'Ringfencing'?
13:20 - What is 'Network Control'?
16:44 - What About Cloud Security?
19:48 - Rob's Opinion on AI
22:33 - Threatlocker's Growth
24:51 - Conclusion
wifi
android
iphone
windows
microsoft windows
apple
google
ransomware
hack
hacker
hacking
hak5
rubber ducky
omg cable
vpn
firewall
cybersecurity
virtual private network
penetration testing
ethical hacker
starlink
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#hacker #hack #cybersecurity
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from David Bombal · David Bombal · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
RYU SDN Controller Part 4: Graphical User Interface (GUI): Practical GNS3 SDN and OpenFlow
David Bombal
HPE Network Protector SDN Application Part 1 - Introduction
David Bombal
HPE Network Protector SDN Application Part 2 : DNS Interception using OpenFlow
David Bombal
HPE Network Protector SDN Application Part 3 - Lab Setup using Physical Switches
David Bombal
HPE Network Protector SDN Application Part 4 - Demo of malicious websites blocked
David Bombal
HPE Network Protector SDN Application Part 5 - Demo OpenFlow table interception flows
David Bombal
HPE Network Protector SDN Application Part 6 - Demo of Physical Switch configuration
David Bombal
HPE Network Protector SDN Application Part 7 - Demo Service Insertion Tunnel / GRE Tunnel
David Bombal
HPE Network Protector SDN Application Part 8 - Demo SDN OpenFlow Reporting
David Bombal
HPE Network Protector SDN Application Part 9 - Demo switches interception of DNS traffic
David Bombal
GNS3 Talks: GNS3 version 1.5.X Appliance Tips
David Bombal
CCNA 200-125 Exam: AAA demo: TACACS+ with GNS3
David Bombal
GNS3 2.0.0 beta 2 install
David Bombal
CCNA #012: Learn SNMP with GNS3, Wireshark and Solarwinds NPM - CCNA 200-125 exam
David Bombal
CCNA #013: Spanning Tree CCNA Exam Questions: Know the answer? CCNA 200-125 exam
David Bombal
GNS3 2.0.0 beta : GNS3 VM integration with GNS3 GUI
David Bombal
CCNA #018: Routing exam questions: Who wins? OSPF, EIGRP or RIP? Sure? CCNA 200-125 exam
David Bombal
CCNA #019: Spanning Tree CCNA Exam Questions: Root Bridge, Root Port and more: CCNA 200-125 exam
David Bombal
GNS3 Download, installation and configuration - GNS3 1.5.3 and Windows 10
David Bombal
CCNA #023 EIGRP Neighbor Troubleshooting (DUAL Issues) for the CCNA 200-125 Exam
David Bombal
GNS3 2.0 Architecture and schema Part 1: What is the GNS3 Controller?
David Bombal
GNS3 2.0 Architecture and schema Part 2: Emulators and virtualization
David Bombal
CCNA #028 VTP Troubleshooting for the CCNA 200-125 Exam
David Bombal
CCNA #029 VTP & DTP Troubleshooting for the CCNA 200-125 Exam
David Bombal
CCNA #030 VTP Troubleshooting for the CCNA 200-125 Exam
David Bombal
GNS3 : How to download Cisco IOS images and VIRL images. Which is the best? How do you get them?
David Bombal
GNS3 ASA setup: Import and configure Cisco ASAv with GNS3
David Bombal
GNS3 switching setup and options: Cisco and other switching options in GNS3
David Bombal
GNS3 switching setup and options Part 2: GNS3 unmanaged built-in switch
David Bombal
GNS3 switching setup and options Part 3: Router on a sick with GNS3 unmanaged built-in switch
David Bombal
GNS3 switching setup and options Part 4: Etherswitch Router for Cisco Dynamips Part 1
David Bombal
GNS3 switching setup and options Part 5: Etherswitch Router for Cisco Dynamips Part 2
David Bombal
GNS3 switching setup and options Part 6: Etherswitch, Wireshark, 802.1Q, InterVLAN routing
David Bombal
GNS3 Talks: Docker, Open vSwitch, SDN and OpenFlow Part 1: GNS3 Switching Part 7
David Bombal
GNS3 Talks: Docker, Open vSwitch, SDN and OpenFlow Part 2: GNS3 Switching Part 8
David Bombal
GNS3 Talks: Docker, Open vSwitch, SDN and OpenFlow Part 3: GNS3 Switching Part 9
David Bombal
GNS3 Talks: Docker, Open vSwitch, SDN and OpenFlow Part 4: GNS3 Switching Part 10
David Bombal
GNS3 Talks: Docker, Open vSwitch, SDN and OpenFlow Part 5: GNS3 Switching Part 11
David Bombal
GNS3 Nexus (NX-OSv) switch setup and configuration Part 1: GNS3 switching options Part 12
David Bombal
GNS3 Nexus (NX-OSv) switch setup and configuration Part 2: GNS3 switching options Part 13
David Bombal
GNS3 Talks: Docker, Open vSwitch, SDN and OpenFlow Part 6: GNS3 Switching Part 14
David Bombal
GNS3 Talks: Docker, Open vSwitch, SDN and OpenFlow Part 7: GNS3 Switching Part 15
David Bombal
GNS3 Cisco CSR 1000v setup and configuration Part 1: GNS3 NFV
David Bombal
GNS3 Cisco CSR 1000v setup and configuration Part 2: GNS3 NFV
David Bombal
GNS3 Talks: Use the NAT node to connect GNS3 to the Internet easily!
David Bombal
GNS3 Talks: GNS3 2.0 RC1 is now available
David Bombal
GNS3 Talks: GNS3 2.0 Portable Projects - easily export and import GNS3 projects
David Bombal
GNS3 Talks: Multiple clients sharing projects in real time, plus console session shadowing!
David Bombal
CCNA #035 NAT Troubleshooting Scenario 1 - Can you find the issue? CCNA Exam 200-125 troubleshooting
David Bombal
CCNA #036 NAT Troubleshooting Scenario 2 - Can you find the issue? CCNA Exam 200-125 troubleshooting
David Bombal
GNS3 Talks: ESXi, GNS3 VM and KVM support Part 1: leverage servers and the cloud
David Bombal
CCNA #037 OSPF Troubleshooting - can you find the issue? CCNA Exam 200-125 troubleshooting
David Bombal
GNS3 Talks: ESXi, GNS3 VM and KVM support Part 2: leverage servers and the cloud
David Bombal
CCNA #038 NAT Troubleshooting Scenario 3 - Can you find the issue? CCNA Exam 200-125 troubleshooting
David Bombal
CCNA #039 - OSPF DR, BR and DROTHER Election - do you know the answers?
David Bombal
CCNA #040 NAT Troubleshooting Scenario 4 - Can you find the issue? CCNA Exam 200-125 troubleshooting
David Bombal
GNS3 Talks: Arista vEOS GNS3 import and configuration Part 1
David Bombal
CCNA #041 - OSPF DR, BR and DROTHER Election - do you know the answers?
David Bombal
GNS3 Talks: Arista vEOS GNS3 import and configuration Part 2
David Bombal
GNS3 Talks: ipterm: Linux, Docker, Python, SDN and more! Part 1
David Bombal
More on: AI Security
View skill →Related Reads
📰
📰
📰
📰
How to Find Safe and Reliable Old Gmail Accounts
Dev.to · abusmm
Catching SSH Brute-Force Attacks Before They Escalate: Building a Detection & Response Workflow…
Medium · Cybersecurity
Exchange Online EX1436407: recover without damaging list data
Medium · Cybersecurity
Only One 2027 Cert Date Is Real. CCNA’s.
Medium · Cybersecurity
Chapters (14)
Coming Up
0:44
Intro
0:55
Stopping Jackoby's Hack
2:10
Threatlocker VS Traditional Solutions
3:33
Deny By Default, Permit By Exception
5:06
Ransomware Deployment Protocol (RDP)
6:58
Are Organisations Safe?
10:31
Allowlisting
11:48
What is 'Ringfencing'?
13:20
What is 'Network Control'?
16:44
What About Cloud Security?
19:48
Rob's Opinion on AI
22:33
Threatlocker's Growth
24:51
Conclusion
🎓
Tutor Explanation
DeepCamp AI