Москва
+7-929-527-81-33
Вологда
+7-921-234-45-78
Вопрос юристу онлайн Юридическая компания ЛЕГАС Вконтакте

Why "defense and attack".

Обновлено 02.08.2025 08:01

 

Telegram channel: https://t.me/protectioninformation

Telegram Group: https://t.me/informationprotection1

Website: https://legascom.ru

Email: online@legascom.ru

 

I don't think anyone will have any questions about the concept of "protection". The information security administrator must protect corporate IT resources. But what does the attack have to do with it? In order to effectively defend something, it is necessary to know well the methods of attack in order to be able to anticipate the actions of attackers and prevent them.

And now let's talk about how all this is related to the topic of this channel. Who is it intended for? This channel is intended primarily for system administrators and information security specialists who would like to understand the practical aspects of protecting corporate resources from various threats. When interpreting information for the channel, I focused on practical aspects, that is, there will be no "reflections on the topic". Instead of lengthy reflections, I tried to focus on practical ways to solve information security problems, that is, various scenarios and settings of applications and network equipment, working with vulnerability detection tools, and much more will be described here. We will also talk about how to write instructions and information security policies, and touch on the legislative framework for ensuring information security in the context of regulatory legal acts.

So, we have decided that this channel is, to a certain extent, a practical guide. But many may have a question: what about hackers? Is this channel a guide for computer hackers? My answer is this: in general, for a novice hacker, this book may be useful in terms of learning the basics of information security, means of penetration and protection of networks and applications. However, it is unlikely that the exploits and utilities listed in the book will be used in practice to hack specific systems, since patches and updates have been released to close these vulnerabilities while the information for the channel was being prepared. In addition, many of the examples of vulnerabilities and incorrect settings have been deliberately simplified by me in order to give the reader an idea of the general type of such vulnerabilities and the means to combat them, rather than to teach them how to penetrate other people's networks. So, young computer system researchers, if you want to learn how things work in computer systems, then this channel is for you, but if you want to learn how to hack the Pentagon, then it is unlikely that it will be able to help you.

So we have come to the main issue that is being discussed on my channel - the search and elimination of threats to the security of the information system. The task of detecting and even more so eliminating threats to the security of an information system is not trivial. As mentioned above, modern corporate networks consist of many different devices and applications, and to detect threats, you need to have a clear understanding of how these systems work, the protocols used, security tools, and more.

On my channel, I will try to pay as much attention as possible to the practical aspects of information security in relation to the technical aspects of the functioning of various systems. That is, when considering issues related to the protection of a local network, I will also talk about the general principles of the functioning of various network protocols and devices. Perhaps this will seem like an unnecessary reminder of the basic truths to some readers and they will skip these sections, but I would still like the practical material provided in this book to be understandable even to novice specialists.

Yes, speaking of practice, I note that to perform many of the examples described on this channel, you will need the Kali Linux distribution. You can learn more about this distribution yourself.

I hope I have managed to attract the reader's attention. Now let's move on to discussing a number of theoretical foundations of information security, without which it will be difficult for you to understand my further posts.