BTLO REPLAY presents GHOSTED | Retired Blue Team Lab Walkthrough
Автор: Security Blue Team
Загружено: 2023-11-17
Просмотров: 409
Описание:
Welcome to BTLO Replay, a video series that will take you through retired BTLO labs. Videos posted every Friday at 6pm GMT.
This week’s lab is GHOSTED, a hard incident response lab that utilizes OSINT skills.
Difficulty: Hard
The GHOSTED scenario:
WeLoveDogz LLC does not have enough funds for a testing environment and their one-man IT department, John, set up a new server straight into production while it was still being configured. Unfortunately, the server got compromised and John does not have a clue how it happened. Luckily, he was able to obtain a packet capture, a log from Suricata IDS/IPS, and a TTY report from auditd running on the system. Help John understand how his system got compromised!
0:00 – Introduction
0:38 – Scenario and questions
5:08 – Investigation files
6:38 – auditd log
7:00 – Question 15
9:05 – Question 14
9:53 – Question 1
11:47 – Question 2
14:24 – Question 3
18:01 – Question 4
20:29 – Question 5
21:36 – Question 4 continued
28:26 – Question 6
30:21 – Question 7
32:46 – Question 8
33:07 – Question 9
36:19 – Question 10
37:01 – Question 11
43:14 – Question 12
48:26 – Question 13
49:12 – Summary
--
Powered by global blue team training provider, Security Blue Team, BTLO is a gamified platform for defenders to sharpen their skills during engaging security investigation and challenge scenarios.
The BTLO Replay series takes viewers through walkthroughs of retired labs. Visit the BTLO website to take on these challenges for yourself and discover new labs launching regularly.
SUBSCRIBE: / @blueteamlabsonline
WEBSITE: https://blueteamlabs.online
DISCORD: / discord
TWITTER: / bluelabsonline
LINKEDIN: / blue-team-labs-online
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: