help & support
314 TopicsDFIR CTF: PCAP Challenge - Question 7
For the question What is the XOR key used to encrypt the malware payload? I am wondering about what I should be looking for in the WireShark, as I can't seem to find any indications of a specific key being used in the pcap file. From the files extracted, I also did not notice any indications from the XML file as well. Summary: I am basically super lost in where I should be digging deeper from.33Views0likes2CommentsCVE-2022-33891 (Apache Spark) – Defensive Question 8
I am wondering about what I am missing in terms of: Analyze the log files. At what time does the attacker first discover that the Apache Spark engine is accessible? (Provide your answer in the format HH:MM:SS) I cant seem to get the time right. unless if I am looking at the wrong area.19Views0likes1CommentTrick or Treat on Specter Street: Ghost of the SOC
Hi there, Am I right as obvious that it may seem that for me to login to Kibana, I need to access this through the Elastic IP address that I have entered in my browser? If so I'm getting the error message on my screenshot. I tried this a few days ago as well and the problem persisted then as well.556Views0likes18CommentsIncident Response: Application Shimming
I'm working through the Incident Response: Application Shimming lab and I'm stuck on the final question (but have correctly answered all previous questions). Without giving away any answers to those reading this, I'm hoping someone can tell me whether I'm following the correct investigation path or if I'm overlooking an artifact. So far I've: - Followed the registry keys mentioned in the briefing. - Identified the affected application and the installed shim database. - Examined the SDB file with the provided analysis tool. - Followed the breadcrumb trail from the previous questions. - Examined the DLL identified in the previous question for URLs, HTTP-related strings, and other obvious indicators. - Searched the SDB and related files for URLs and network indicators. - Checked the application's installation directory for additional relevant artifacts. At this point I can't find anything that appears to answer the final question, and I'm wondering if I'm expected to analyze a different file or use a different tool than the ones provided in the VM. Could someone give me a nudge in the right direction? Specifically, I'd like to know: Am I investigating the correct artifact? Is there another file or artifact that should be analyzed? Or is there another technique/tool that the lab expects me to use? Thanks!37Views0likes0CommentsPowershell Deobsfuscation Ep.7
I first collected the .ps1 script and noticed that it is from hex after decoding from hex I noticed that it converts from decimals This led me to use the from the from decimal recipe from Cyberchef However, this led me towards only the decoded eding of the script itself. with the main obfuscated payload being empty. I am wondering about where I am going wrong in my thought process.Solved55Views0likes1CommentCTI First Principles: Threat actors and attribution Q9
In doing all of these questions most of them are fine. Q9 isn't accepting any form of answer I input. There is nothing definitive on the PDF that gives an exact quote-able answer and anything that would logically be the answer comes up as incorrect, even asking the AI tool and all the advice it gives is no good as still returns as incorrect, ironically the tool even admitted to the questions being unfortunately specific in the answers and couldnt get it correct itself. Is this a bug or just really poor question design that expects an open ended answer that you just have to guess is the correct variation of the truth? I feel the same focus on a lot of questions in other modules isn't on getting the correct answer, but answering correctly which leads to a lot of frustration and a massive waste of time.224Views0likes1CommentAPT29 Threat Hunting with Splunk: Demonstrate Your Skills - Question 10
In relation towards the question : A PowerShell script was initially executed to extract encoded data from an image file. What is the full ParentCommandLine field value used to execute this? I am pretty lost and where I should be looking for, as searching for the zipped file activities did not bring up any notable powershell scripts I also tried inputting: C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.Archive\Microsoft.PowerShell.Archive.psm1 as well which did not workSolved51Views0likes1Comment