cybersecurity.txt (473B)
1 Tools: 2 3 - Open Snitch (stop attacks from connection to outside networks) 4 - Bandwhich/Nethogs (netwok requests monitoring) 5 - WireShark (packet inspection) 6 - nftables (setup firewall rules to block all incoming connection) 7 - nmap (port scan to confirm/validate firewall rules setup by nftables) 8 9 Normally you'd want to use both tcpdump and wireshark: 10 11 # on the remote box, no GUI needed 12 sudo tcpdump -i eth0 -s 0 -w /tmp/cap.pcap 'port 443' 13 14 # locally 15 wireshark /tmp/cap.pcap