Ravindra BagaleCourses & study guides

36. More Essential Kali Tools

36.6 Defence Checklist for These Tools

Aata tools shikle – pan tumhi trainer/defender pan aahaat. Raja ani Rani chya Pune chya fictional shop chya website sathi short checklist:

Threat from this chapter Defence
FFUF / directory fuzz Rate-limit, WAF, no backup files public, auth on admin paths
Amass / subdomain enum CT monitoring, kill dead subdomains, inventory
WhatWeb fingerprint Strip version headers, harden banners, patch stack
Netcat shells Egress filter, host firewall, watch ss/netstat, EDR
Bettercap MITM HTTPS+HSTS, segmentation, static ARP/DAI, user awareness

Rozcha habit: lab madhe attack try kara, mag tyachya against control implement kara – techi real learning. Aata pudhe jaauya.

Ravindra Bagale's Tip

Memorising tool names helps a little in exams, but on the job they ask: "How would you detect FFUF?" Write the checklist table in your own words – then you'll be able to say it the same way in the interview. Learn attack and defence together, not separately.

Practice task

Varcha table copy karun aaplya notes madhe expand kara: pratyek row sathi ek concrete command kiwa config step liha (example: fail2ban / nginx limit_req for fuzzing; ss -tulnp cron for shells). Shraddha Bagale la (fictional junior) samjavnyasarkha ek paragraph liha: "Why HTTPS alone is not enough against lab MITM."