This section focuses on protecting sensitive data and system assets through access controls, encryption, and risk-based security measures.
Identifies active hosts, open ports, and exposed services to establish baseline network visibility and detect potential attack paths.
Step-By-Step
Target Scope:Identified IP address of lab machine(s)
Ip a
Basic Discovery Scans
Ping Sweep: nmap -sn 192.168.1.0/24
Finds hosts that are on netowrk
List Scan (No Ping)nmap -sL 192.168.1.0/24
Shows what would be scanned without touching targets
Port Scanning
Top 1000 TCP Ports:
nmap 192.168.1.10
Aggressive Scan: nmap –A 192.168.1.10
OS detection, version detection, script scanning, traceroute
.Service Version Detection
nmap -sV 192.168.1.10
All ports
nmap -p- 192.168.1.10
OS Dection
Operating System Fingerprint: sudo nmap -O 192.168.1.10
HTTP Enumeration:nmap -p 80,443 --script=http-enum 192.168.1.10
SMB Enumeration:nmap --script=smb-enum-shares -p 445 192.168.1.10
Implements and validates firewall rules to control inbound and outbound traffic based on security policy and least-privilege access.
Step-By-Step
Open Windows Security (search in Start menu) Search for "Windows Security" in the taskbar and open it.
Click Firewall & network protection
Select active network (Domain, Private, or Public)
Toggle Microsoft Defender Firewall On or Off
Allow an App Through Firewall
Open Windows Security
Click Firewall & network protection
Click Allow an app through firewall
Click Change settings
Check app boxes for Private/Public
Click OK to save
Create a New Firewall Rule
Open Windows Security
Click Firewall & network protection
Click Advanced settings
Allow Changes to be made to device
Select Inbound or Outbound Rules and click New Rule...
Choose rule type: Program, Port, Predefined, or Custom
Click Next, type 80 for port specific location
Define action: Allow or Block
Click next, select allow or block, allow selected, next
Select network profiles: Domain, Private, Public
Name the rule and click Finish
Allowed for port 80, Denied for port 22
Demonstrates perimeter defense configuration using pfSense to enforce segmentation, filtering, and threat containment at the network edge.
Step-By-Step
Go to the following link: pfSense CE Download
As of writing the latest version of pfSense is 2.7.2
Download the amd64 version ISO of the latest version available
I located a file on https://archive.org/details/pfsense-ce-2.7.2-release-amd64_20250728 that allowed me to download the disk file and mount it.
Named Virtual Machine
Specified Hardware
Final Settings
Went to pfsense settings>sytem, changed the boot order: Hard disk, Optical, and uncheck floppy
Went to network configuration>adapter 1> Adapter Type: Paravirtualized Network virtio-net. > Adapter 2>enable network>internal network>named it. Repeat for adapters 3 and 4. *Allow All VMS
Started pfsense from Virtual box Menu Bar
On boot, a banner will show followed by text. Wait for the screen below to appear then press enter to accept the agreement.
Press Enter to start the installation
Press Enter to select the Auto (ZFS) partition option
Press Enter to proceed with installation
Press Enter to select Stripe- No redundancy
Use the Spacebar key to select the Hard Drive (ada0)
then press Enter to continue.
Use the left arrow to select Yes and then press Enter to continue.
Wait for the installation to complete.
Press Enter to Reboot the VM.
Separates network zones to limit lateral movement and reduce blast radius in the event of a compromise.
Step-By-Step
Configure pfSense Interfaces
Used pfSense GUI to assign virtual machines to the correct rooms for their role.
Set IPs for Each VLAN
Go to Interfaces > LAN
Enable interface ✅
Static IPv4: 192.168.10.1/24 (example)
Do the same for:
DMZ → 192.168.20.1/24 (example)
LAB → 192.168.30.1/24(example)
Save + Apply changes
Enable DHCP Servers
Go to Services > DHCP Server
Select LAN
Enable DHCP
Range: 192.168.10.100 – 192.168.10.200
Repeat for
DMZ → 192.168.20.100 – 192.168.20.200
LAB → 192.168.30.100 – 192.168.30.200
Save all.
Apply firewalls Rules
By default, new VLANs are blocked.
Go to Firewall > Rules > LAN
Add Rule: Allow Any → Any (so your LAN can reach Internet)
Do the same for DMZ and LAB, but more controlled:
DMZ → allow outbound to WAN only
LAB → allow to LAN (management) and WAN
Secures wireless access through authentication, encryption, and rogue access point detection to prevent unauthorized connectivity.
Step
Start virtual lab and open terminal
Type:
ip a
This will show the ip address on the etho0 interface.
Open Wireshark from the Kali application menu
Open terminal and Ping Target
Type: ping 8.8.8.8 -c 4
This pings google DNS 4 Times, here you can see ICMP packets (type 8=request,type0=reply)
Filter for ICMP in Wireshark
In the top filter bar, type:
Icmp
Press Enter: This filters all non-ICMP packets
Enter: This filters all non-ICMP packets
Click on one Echo (ping) request, expand the details, note the source destination, and packet type.
Source IP: 10.0.2.15, Destination IP: 8.8.8.8, Packet type: request. TTL(Time to Live) 1.092786352
Open packet details.
ICMP ping to 8.8.8.8 was successful. Packet analysis confirmed Echo Request and Reply were visible, with no anomalies in TTL or Route.
Click on one Echo (ping) request, expand the details, note the source destination, and packet type.
Source IP: 10.0.2.15, Destination IP: 8.8.8.8, Packet type: request. TTL(Time to Live) 1.092786352
Open packet details.
ICMP ping to 8.8.8.8 was successful. Packet analysis confirmed Echo Request and Reply were visible, with no anomalies in TTL or Route.
Create fake Wi-Fi antennas
sudo modprobe -r mac80211_hwsim || true
sudo modprobe mac80211_hwsim radios=4
Command: iw dev (to view 4 virtual Wi-Fi radios)
You should see wlan0,wlan1,wlan2,wlan3
Create your "Good Wifi" (WPA 3 network)
(Type this carefully):
Command: sudo nano /etc/hostpd/hostapd-goodwifi.conf
Type this inside the file:
When you are done, press:Ctrl+O>Enter>CTRL+X to save and exit.
Better Option for Me
Command:
Type this carefully):
sudo tee /etc/hostapd/hostapd-goodwifi.conf <<'EOF'
Now type theses one by one and press enter after each line:
interface=wlan0
driver=nl80211
ssid=MySafeWiFi
hw_mode=g
channel=6
wpa=2
wpa_key_mgmt=SAE
rsn_pairwise=CCMP
wpa_passphrase=MyStrongPassword123
ieee80211w=2
Note: ieee80211w=1 enables WPA3-style management frame protection simulation.
At the end of typing this, type EOF on a new line and press Enter
This will save the file
To check if it's saved Type:cat /etc/hostapd/hostapd-goodwifi.conf
Create Fake rouge AP file
Type this on a new line and press enter:EOF
Create your "Imposter Wifi"
sudo tee /etc/hostapd/hostapd-badwifi.conf <<'EOF'
Types these into the command lines:
interface=wlan1
driver=nl80211
ssid=MySafeWiFi
hw_mode=g
channel=11
wpa=2
wpa_key_mgmt=WPA-PSK
rsn_pairwise=CCMP
wpa_passphrase=FakePassword123
ieee80211w=0
Type this on a new line and press enter:EOF
Create Client
Create the "Client file"
sudo tee /etc/wpa_supplicant/client.conf <<'EOF'
Now type this:
ctrl_interface=/var/run/wpa_supplicant
update_config=1
network={
ssid="MySafeWiFi"
psk="MyStrongPassword123"
key_mgmt=SAE
proto=RSN
}
Type this on a new line and press enter:EOF
Start the Simulation
Load the virtual wifi module.
sudo modprobe mac80211_hwsim radios=4
Start hostapd
Command: sudo /usr/sbin/hostapd /etc/hostapd/hostapd-badwifi.conf
If it's correct you'll see:
wlan1: interface state UNINITIALIZED->ENABLED
wlan1: AP-ENABLED
Start the Good AP
Command: sudo /usr/sbin/hostapd /etc/hostapd/hostapd-goodwifi.conf
Client connecting to Rouge AP connected to fake wifi
sudo wpa_supplicant -i wlan2 -c <(echo -e 'network={\nssid="Free_Coffee_WiFi"\npsk="badwifi123"\n}') -d
Connect to good wifi
sudo wpa_supplicant -i wlan3 -c <(echo -e 'network={\nssid="LakeTown_WPA3_Secure"\npsk="secure1234"\n}') -d
While the simulation runs, you can view traffic logs from hostapd (rouge AP)
Open a new terminal and monitor with
Command:
Stop the Simulation:
Locate folder with wpa_supplicant
Command:
sudo ip link set wlan0 down
sudo ip link set wlan1 down
sudo ip link set wlan2 down
sudo ip link set wlan3 down