Vulnerability Assessment Lab

Tools & Technologies: Nessus, Oracle VirtualBox, Windows 10, TCP/IP Networking, Vulnerability Assessment

Project Overview

Conducted a hands-on vulnerability assessment lab using Oracle VirtualBox, Windows 10, and Nessus to simulate the process of identifying, analyzing, and remediating security vulnerabilities within a computer system.

Lab Setup & Configuration

  • Created and configured a Windows 10 virtual machine using Oracle VirtualBox.
  • Configured the virtual machine's networking to establish connectivity within the lab environment.
  • Installed and configured Nessus as the vulnerability scanning platform.
  • Verified network connectivity between the scanning environment and the target Windows system.
  • Configured scan settings and targets to perform vulnerability assessments against the virtual machine.

Vulnerability Assessment

  • Conducted comprehensive vulnerability scans against the Windows 10 system using Nessus.
  • Reviewed scan results to identify vulnerabilities, misconfigurations, outdated software, and potential security weaknesses.
  • Analyzed Nessus findings based on severity and potential security impact.
  • Researched identified vulnerabilities to better understand their causes, potential exploitation risks, and recommended remediation methods.
  • Installed intentionally vulnerable and outdated software within the isolated lab environment to create additional vulnerabilities for testing and analysis.
  • Compared scan results before and after introducing vulnerable software to observe how Nessus identified newly introduced security issues.

Remediation & Verification

  • Implemented remediation strategies based on Nessus recommendations.
  • Updated or removed vulnerable software and addressed identified system weaknesses.
  • Re-ran vulnerability scans after remediation to verify that vulnerabilities had been resolved or reduced.
  • Compared initial and subsequent scan results to evaluate the effectiveness of the remediation process.
  • Documented findings and used the results to develop a better understanding of the vulnerability management lifecycle.

Skills Demonstrated

  • Vulnerability assessment and scanning
  • Nessus vulnerability scanner
  • Windows system administration
  • Virtual machine deployment and configuration
  • TCP/IP networking
  • Security vulnerability analysis
  • Risk assessment
  • Vulnerability remediation
  • Security documentation and reporting
  • Hands-on cybersecurity lab experience