Hunting Attacks As They Happen // SOC Level 2 Ep.21 TryHackMe Threat Hunting: Foothold

preview_player
Показать описание
In this video, we will learn to hunt malicious activity indicating a potential initial compromise of a workstation or a machine. Time stamps below.

**************************
Hackaholics Anonymous
**************************
By joining the Hackaholics Anonymous community, you'll get direct access to me, a community of supportive likeminded individuals, and exclusive perks like:
- Bug Bounties
- Python Automations for CySec, PenTesting, SysAdmin
- Exclusive Content
- Live Chats / Q&A's / AMA's
- And much, much more!
**********
*******
*****
***
*
**************************
Protect Yourself
**************************
Want an all-in-one AntiVirus/VPN $0.07 per day?
- SurfShark Link (VPN & AntiVirus For Unlimited Devices For $2.20/mo):
**************************
Join TryHackMe
**************************
Wanna practice hacking without getting caught?
- TryHackMe Discount Link:

Threat Hunting Foothold Timestamps:
00:00 Intro
02:40 1. Initial Access
08:10 1a. Hunting Initial Access
17:34 1b. Remote Code Execution on Web01
31:23 1c. Phishing Links & Attachments
41:17 2. Execution
46:10 2a. Use of Command-Line Tools
56:23 2b. Built-In System Tools
01:08:24 2c. Scripting and Programming Tools
01:13:53 3. Defense Evasion
01:39:15 4. Persistence
01:45:08 4a. Scheduled Task Creation
01:50:23 4b. Registry Key Modification
01:56:02 5. Command and Control
02:02:26 5a. Command and Control Over DNS
02:11:39 5b. Command and Control Over CloudApps
02:18:00 5c. Command and Control Over Encrypted HTTP Traffic
02:24:19 Conclusion / Review
Рекомендации по теме
Комментарии
Автор

Hi Hank, really enjoyed this room. Lots to take in and absorb but well worth it. For me you explained it very well and I was able to follow along quite well. I certainly know much more than I did so many thanks.

davidpickering
Автор

Hi Hank, looking forward to this room. Looks like you've put a lot of work into it. In order to follow along within THM, i've done the necessary to log in via the THM Attackbox and waited more than a sufficient amount of time before inputting the IP address into the browser only for it to say 'Kibana server is not ready yet' I have logged out and back in several times and even tried openvpn but always states the same. I'm pinging okay. Not sure if you have any ideas on what cound be wrong. I will still go through your tutorial to absorb the knowledge and look at the process but I cannot replicate whilst following along. Not had this issue before with THM but it won't stop me.

davidpickering