WEBVTT

00:01.160 --> 00:09.410
So we have talked about hacking and we've talked about how hacking in the cybersecurity sense is a bad

00:09.410 --> 00:09.890
thing.

00:10.310 --> 00:15.410
But thankfully, there is a discipline and we we love it.

00:15.770 --> 00:17.330
We're all about this discipline.

00:17.540 --> 00:19.010
It's ethical hacking.

00:19.250 --> 00:21.890
It's using hacking skills.

00:22.250 --> 00:25.070
But for good, how is this possible?

00:25.250 --> 00:35.510
Well, we are a white hat hacker, and we are going to be hired by an organization to be constantly

00:35.510 --> 00:44.840
seeking out vulnerabilities, to be constantly keeping up with how black cats are attacking us, what

00:44.840 --> 00:47.420
are the vulnerabilities they're looking for?

00:47.600 --> 00:51.140
What are the types of attacks they are performing?

00:51.440 --> 01:00.500
We're going to be constantly applying our networking and our systems skills, and this means that we'll

01:00.500 --> 01:10.340
really be students of the communications between systems and those systems themselves.

01:10.580 --> 01:17.810
And we're going to be giving you in this ultimate guide a lot of the information that you would need

01:17.930 --> 01:23.510
about networking in systems to give you a huge head start in this environment.

01:23.780 --> 01:30.740
This is one of the reasons why this ultimate guide is such a huge seller here at Udemy.

01:31.540 --> 01:40.690
Now we're going to be taking a look at the exact same tools and using the same tools as black cats do.

01:41.050 --> 01:43.690
And you'll hear me mention it more than once.

01:43.930 --> 01:54.250
We always need to stay ethical, and this means we can't violate any of the guidelines our organization

01:54.250 --> 01:57.940
may have put forth against using these tools.

01:58.240 --> 01:58.900
Think about it.

01:59.230 --> 02:07.450
Maybe you're in the headquarters of your enterprise where you're hired as a white hat hacker, and that's

02:07.450 --> 02:08.590
not your job title.

02:08.710 --> 02:12.940
It's more like cyber security analysts level one.

02:13.300 --> 02:19.990
So you're a cyber security analyst, level one, and you are working for the organization and you're

02:19.990 --> 02:28.030
at the headquarters location and you trigger a whole bunch of security alarms because you're experimenting

02:28.030 --> 02:29.770
with one of the black hat tools.

02:30.040 --> 02:38.380
And this would be unethical for you to do because it violates the security policy in place at your organization.

02:38.680 --> 02:48.040
So we're going to be very careful as white hat hackers to make sure that we are performing our responsibilities

02:48.280 --> 02:56.560
but within a defined scope, and that will be adhering to the limitations of what we can do.

02:56.740 --> 02:59.500
And in fact, we'll be elaborating on that coming up.

03:00.430 --> 03:08.020
Ethical hacking is so great because it allows us to understand the attackers.

03:08.410 --> 03:11.560
We have to know thy enemy.

03:11.680 --> 03:18.250
If we are to properly protect ourselves, we need to know who they are, what their motivations are,

03:18.370 --> 03:23.740
what their techniques are going to be, what their tactics, what their procedures will be like.

03:24.220 --> 03:32.920
So we need to really study them and know their tools and know their procedures so that we can make it

03:32.920 --> 03:41.590
well worth our salary for an organization to help protect their systems by using the very best and most

03:41.590 --> 03:44.290
appropriate security controls.

03:44.920 --> 03:52.390
Now, as a white hat hacker, you're constantly answering questions for your organization, like what

03:52.390 --> 03:55.030
can potential adversaries see?

03:55.420 --> 03:59.680
What can they do against visible resources?

03:59.980 --> 04:04.570
And when they do attack, are they visible?

04:04.810 --> 04:09.010
Can we actually see and trace their attacks?

04:09.550 --> 04:18.370
It is also critical that we be able to explain to the organization how they are going to be able to

04:18.370 --> 04:21.130
see attackers when they do show up.

04:21.400 --> 04:28.960
So we're going to be helping them set up sophisticated systems, maybe even Sims, and that is spelled

04:28.960 --> 04:39.730
S I e m, which is going to be a very sophisticated management platform for correlating and being able

04:39.730 --> 04:45.190
to analyze security events that have happened in our environment.

04:45.490 --> 04:50.680
So SIM is a great, great concept that you need to be aware of.

04:51.040 --> 04:57.220
This may be how we're helping the organization see attackers as they show up.

04:57.940 --> 05:05.890
Notice this is an incredibly exciting field, and notice that this is a field that's going to challenge

05:05.890 --> 05:14.470
us because we are going to be consistently and constantly studying the attacks that are now possible

05:14.620 --> 05:18.550
in an ever changing technological landscape.
