“An easy one to change…” HackMyVM machine covering cookie manipulation, insecure upload file portal, credential stealing, and password cracking with a custom wordlist.
“This CTF gives a clear analogy how hacking strategies can be performed on a network to compromise it in a safe environment. This vm is very similar to labs I faced in OSCP. The objective being to compromise the network/machine and gain Administrative/root privileges on them.”
“Enjoy it!! ;)” HackMyVM machine containing WordPress plugin abuse, credential stealing, and SUID privesc to root.
“An easy little machine for beginners.” HackMyVM machine containing abuse of IPMI service, password cracking to SSH brute force, and credential stealing to access the superuser account.
“The server administrator assigned you to hack this server .So don't disappoint him.This server is easy , just do not give up.” HackMyVM machine covering web directory enumeration, hidden information through stenography, SSH brute forcing with a custom wordlist, credential stealing, and SUID privsec.
In this Sherlock, Players will investigate an incident inspired by rise of malicious google ads for softwares mostly used by individuals like streaming, productivity or note taking applications. Players will analyze windows artifacts to uncover all stages of cyber kill chain.
“Alonzo Spire is fascinated by AI after noticing the recent uptick in usage of AI tools to help aid in daily tasks. […] Without any second thought, he downloaded [an AI] tool. […] A DFIR analyst was notified of a possible incident on Forela's sysadmin machine. You are tasked to help the analyst in analysis to find the true source of this odd incident.”
“Jinkies is a medium difficulty Sherlock where you'll investigate the theft of intellectual property from an organisation called Cloud-guru. Find the source of the leak and answer the questions for senior management!”
“In this Sherlock, you must analyze the tools used by a developer and understand how they may have been the victim of a security breach.”
“A junior SOC analyst on duty has reported multiple alerts indicating the presence of PsExec on a workstation. ”
“You will be given a set of artefacts relating to a workstation that has been compromised by a malware Trojan. You need to analyse the different pieces of evidence to extract IOCs and reconstruct the phases of the infection.”
“The consultancy Forela-Security would like to gauge your knowledge of Windows Event Log Analysis.”
“In this scenario, the Security Information and Event Management (SIEM) system at Forela has detected a series of alerts in a brief period, signaling potential Command and Control (C2) communication originating from an employee, Simon Stark's, workstation. Despite Simon not observing any anomalies, the IT team conducted a preliminary investigation by reviewing screenshots of his task manager for any unusual processes, but found nothing out of the ordinary.”
“Recollection is an easy difficulty Sherlock where you are tasked with carrying out analysis of a memory dump to understand the actions of an attacker and what else within the environment may have been affected.”
“In this Very Easy Sherlock, players will go through artefacts and logs from the Domain controller as well as endpoint artefacts from where Kerberoast attack activity was sourced. Players will work through what to look for to identify kerberoasting attack activity and to avoid false positives due to the complexity of Active Directory.”
“In this very easy Sherlock, you will familiarize yourself with Sysmon logs and various useful EventIDs for identifying and analyzing malicious activities on a Windows system. Palo Alto's Unit42 recently conducted research on an UltraVNC campaign, wherein attackers utilized a backdoored version of UltraVNC to maintain access to systems. This lab is inspired by that campaign and guides participants through the initial access stage of the campaign.”
Collection of Sherlock writeups inside the HTB CDSA Preparation path
“This machine is an easy machine. It should not be difficult gaining the root.”
“This is a small boot2root VM I created for my university’s cyber security group. It contains multiple remote vulnerabilities and multiple privilege escalation vectors.” VulnHub machine containing web directory enumeration, WordPress abuse to RCE, and privesc through common credentials/FTP backdoor.
“A small VM made for a Dutch informal hacker meetup called Fristileaks. Meant to be broken in a few hours without requiring debuggers, reverse engineering, etc..”
Page linking to all of my writeups for the SOC Analyst Tier 2 in CyberDefenders
Reconstruct the 3CX supply chain attack by analyzing compromised MSI and DLL artifacts to identify TTPs and attribute the incident to a threat actor.
Reconstruct a multi-stage attack by analyzing Windows memory dumps using Volatility 3, identifying malicious processes, command lines, and correlating findings with threat intelligence.
Analyze memory images and event logs using MemProcFS, EvtxECmd, and Timeline Explorer to identify Andromeda bot IOCs, reconstruct its infection timeline, and attribute it to an APT group.
Reconstruct attacker methods on a Linux system by analyzing a disk image, recovering deleted files with Photorec, and correlating logs, command history, and configuration files.
Reconstruct Amadey Trojan behavior by analyzing memory dumps with Volatility3 to identify malicious processes, C2 communications, payload delivery, and persistence mechanisms.
Correlate Azure AD, Activity, and Blob Storage logs in Elastic Stack to reconstruct an attack timeline, identifying initial access, lateral movement, persistence, and data exfiltration.
Analyze a memory dump using Volatility to identify malicious processes, persistence mechanisms, defense evasion techniques, and map them to MITRE ATT&CK.
Employ Volatility to analyze a memory dump, identifying suspicious processes, network IOCs, memory protections, and attacker's command-and-control infrastructure.
Analyze a sandbox report using Any.Run to identify Stealc malware behavior, extract configuration details, and map observed tactics to MITRE ATT&CK.
Analyze a suspicious executable using VirusTotal and MalwareBazaar to extract IOCs, identify C2 infrastructure, MITRE ATT&CK techniques, and privilege escalation mechanisms.
Analyze Sysmon logs in Elastic SIEM to investigate REvil ransomware attack behaviors, decode recovery sabotage commands, and identify IOCs including the C2 onion domain.
Analyze network traffic using Wireshark to identify DanaBot initial access, deobfuscate malicious JavaScript, and extract IOCs like IPs, file hashes, and execution processes.
Analyze network traffic using Wireshark to identify DanaBot initial access, deobfuscate malicious JavaScript, and extract IOCs like IPs, file hashes, and execution processes.
Analyze a memory dump using Volatility to identify a malicious process, extract network IOCs, file hash, and compilation timestamp, correlating with external threat intelligence.
Utilize ALEAPP to analyze Android device artifacts, reconstructing a victim's financial details, movements, and communication patterns.
Investigate IcedID malware using VirusTotal and threat intelligence platforms to identify IOCs, associated threat actors, and execution mechanisms.
Analyze malware artifacts using threat intelligence platforms like VirusTotal to identify IOCs, C2 servers, and understand adversary tactics.
Analyze a cryptocurrency phishing kit to identify exfiltration methods, extract critical IOCs, and gather threat actor intelligence using local logs and Telegram APIs.
Analyze network traffic using Wireshark's custom columns, filters, and statistics to identify suspicious web server administration access and potential compromise.
Analyze SMB traffic in a PCAP file using Wireshark to identify PsExec lateral movement, compromised systems, user credentials, and administrative shares.
Analyze network traffic for LLMNR/NBT-NS poisoning attacks using Wireshark to identify the rogue machine, compromised accounts, and affected systems.
Investigate AWS CloudTrail logs using Splunk to identify unauthorized access, analyze configuration changes, and detect persistence mechanisms.
Investigate network traffic with Wireshark to identify attacker TTPs, extract XSS payloads and session tokens, and determine exploited web application vulnerabilities.
Analyze network traffic using Wireshark to identify web server exploitation, extract attacker IOCs and persistence mechanisms, and map attack techniques to MITRE ATT&CK.
Page linking to all of my writeups for the SOC Analyst Tier 1 in CyberDefenders
Writeup for the fourth entry of the Kioptrix series on VulnHub
Writeup for the fifth and final entry of the Kioptrix series on VulnHub
Writeup for the third machine in the Kioptrix series from VulnHub
Writeup for the second entry of the Kioptrix series on VulnHub