Skip to main content

Module 13: Vulnerability management

In lesson 12.6 you scanned your own domain controller, watched the alert arrive, and worked out it was you. The scanner was the noise in that lesson. Here it becomes the tool, and you find out what it was actually trying to tell you.

That word "vulnerability" is about to get less impressive. A vulnerability is a flaw somebody could use to make software do something it should not: read a file it should not read, run a command nobody typed, keep a connection open until the machine falls over. Vulnerability management is the ordinary work of finding out which ones you have, deciding which ones matter, fixing those, and being able to say why you left the rest.

The deciding is the hard part, and it is the part nobody teaches. Scanners are generous. Point one at a single container image and it hands back several hundred findings, which is a number no human can act on. This module is mostly about turning that number into a short list you can defend.

What's in it:

  • 13.1 what a scanner actually measures, and why three tools disagree
  • 13.2 scan a container image, and meet your first pile of findings
  • 13.3 hundreds of findings, and what to do first
  • 13.4 build a real network scanner on UBNT01
  • 13.5 your first network scan, and reading the report
  • 13.6 credentialed scanning, and why it looks like an attack
  • 13.7 patching, properly, including your domain controllers
  • 13.8 the findings you are not going to fix
  • 13.9 journal entry
  • 13.10 checkpoint

What you need, and what you can skip​

Lessons 13.1, 13.2, 13.3 and 13.8 run on any tier, including Tier 1 on a 16 GB laptop. They need UBNT01 from Module 6 and nothing else. They are also, honestly, the most useful lessons in the module: the triage skill in 13.3 is what you would actually be paid for.

Lessons 13.4 to 13.6 install a full network scanner, which is a heavy piece of software. It shares UBNT01 with the monitoring stack you built in Module 12, and lesson 13.4 covers exactly how to make room for it, including the option of running one at a time. If your machine cannot carry both, that lesson tells you so plainly and gives you a working alternative rather than leaving you stuck.

Lesson 13.7 needs the domain from Module 5, both domain controllers, so Tier 2 and up. Tier 1 students should read it anyway; the reasoning is the point and it transfers to any pair of servers you cannot take down together.

Scan only what is yours

Everything in this module points at machines you built. Running a vulnerability scanner against infrastructure you do not own or have written permission to test is, in most countries, a criminal offence rather than a grey area, and "I was learning" is not a defence anybody has successfully used.

Your lab is on 10.10.10.0/24 and it is entirely yours. Keep the scans inside it. Lesson 13.5 covers exactly how to confine a scan to that range, because a scanner pointed at a slightly wrong number will happily cross into your home network and then your internet provider's.

Where this sits​

Module 12 taught you to notice things happening. This module is the other half of the same job: knowing what is wrong before anybody exploits it. Detection tells you somebody is at the door. Vulnerability management is knowing which of your doors do not lock.

Module 14 then takes the list you build here and attacks it, so the findings stop being rows in a report and start being a way into a machine you own.