Body of Knowledge: Hands-On Security Lab Journal
What It Is
During my cybersecurity semester at Fontys (September 2023 to January 2024) I kept a Body of Knowledge: a running lab journal, updated 18 times over the semester, that ended up at 88 pages. Every chapter follows the same pattern: explain the concept in my own words, do the assignment in the lab, document each step with screenshots, and close with what I learned, including what didn't work.
The semester was built around a simple loop: attack something, then defend it, then detect the attack. That loop is why this journal matters to me: it's where I first saw both sides of the same attack.
What It Covers
- Web attacks: path traversal, command injection, SQL injection (manual UNION attacks and sqlmap), XSS and CSRF, using Burp Suite, DVWA and PortSwigger labs.
- Network attacks: Nmap scanning, ARP spoofing / man-in-the-middle with Ettercap and Wireshark, and WPA2 cracking with aircrack-ng.
- Password cracking: Hydra and wfuzz against a login form, hashcat against stolen hashes.
- Defense: a ModSecurity web application firewall, a segmented network with two pfSense firewalls, and SSH hardened with two-factor authentication.
- Detection and monitoring: Wazuh (host IDS), Suricata (network IDS/IPS), Nagios XI (availability) and Zeek (network security monitoring).
- Concepts: risk analysis and the CIA triad, responsible disclosure and GDPR, identity and access management, and security incident response.
Highlights
Automating instead of fighting. Installing the ModSecurity WAF by
hand from the course PDF kept failing, so I turned the instructions into a bash
script, using sed to find and replace the lines in each config file.
After a lot of trial and error it installed cleanly on a fresh DVWA machine: I
copied it over with scp, ran it, and the same SQL injection that worked
against plain DVWA now hit a 403 Forbidden page.
Seeing the attack from the defender's side. With a Wazuh manager on its own server and an agent on that WAF-protected machine, Wazuh caught my own SQL injection attempt, mapped to MITRE ATT&CK T1190 (Exploit Public-Facing Application). Being the attacker and then finding myself in the logs is what pulled me toward the SOC side of security.
Chaining one weakness into another. I did SQL injection on DVWA
both with sqlmap and by hand: provoking an error to identify MySQL, using
ORDER BY to count columns, then a UNION SELECT with
CONCAT() to pair each username with its password hash. Weeks later,
in the password-cracking chapter, I fed those same MD5 hashes into hashcat, which
cracked them in 29 seconds.
Designing before building. For the network segmentation assignment I drew the network first, then built it: an outer and an inner pfSense firewall separating two VLANs. One VLAN could reach the other but not the reverse; tracing that down to a missing gateway and static route on the outer router, plus a firewall rule on the inner one, taught me more about routing than any lecture did.
Following the unexpected. While an Nmap scan ran, Wireshark showed
SSH and TCP traffic going to host.docker.internal. Instead of ignoring
it, I traced it: Docker on my laptop had bound to the network interface, so my
laptop's IP resolved to Docker's hostname. A small thing, but it's the habit that
matters in a SOC: when something looks odd, find out why.
What Didn't Work
The journal is honest about failures, because they taught me just as much. I never got the VPN exercise working (the Windows VM ended up isolated from the network, despite checking firewall rules, logs, packet captures and routes); my custom Suricata rule wouldn't fire after an hour of trying; I couldn't get Zeek's logs readable in Elastic; and I cracked three of the six Wi-Fi workshop networks, not the harder ones that needed hashcat or targeted an enterprise network.
Looking Back
Reading this journal now, I can see where my direction came from. The attack chapters were fun, but the moments that stuck were on the detection side: Wazuh catching my own injection, Suricata alerts, Zeek's connection logs. That's the work I want to do: understanding attacks well enough to recognize them in the logs.
References
- Full Body of Knowledge (PDF, 88 pages, 11 MB). Home-network addresses and a third-party server's address are redacted.