LIVE: ๐Ÿ”ŽForenSICK! | Cybersecurity | TryHackme | AMA

The Cyber Mentor ยท Beginner ยท๐Ÿ” Cybersecurity ยท1y ago

Key Takeaways

The video covers a live blue team challenge using TryHackMe, with a focus on cybersecurity and digital forensics, and provides resources for learning and training in the field.

Full Transcript

What's up everyone? Welcome back. Happy Wednesday. Welcome back to another uh TCM live stream. How's everyone doing today? Hoping you can hear me. Okay, let me know if there are any audio problems, but I think I managed to get this going uh for yet another Wednesday stream. Good morning, good afternoon everybody. Hamza is the first in chat today. finally, as you put it. Congrats. Yeah, it's always a race to get to first. AD Penguin, hello. Hello. Welcome. Hope you're doing well. Now, does that AD stand for Active Directory? Because I noticed your uh your Penguin logo there. It's giving me some Linux vibes, too. So, I like it. I like the name. Uh will you show us live hacking? Uh, no, not this week. Uh, I'm going to be doing some uh I guess it's a forensics challenge uh on Try HackMe. It's one of the the recent uh challenges from the other the other Friday ago that it came out. So, that's what we're going to try today. Um, but uh maybe catch us next week. Uh maybe if Alex or Andrew Bellini will be on uh they'll do some maybe some web hacking or exploit development. Who knows? Uh we have such a wide variety of uh uh fun content on our team here. Uh, but I like to do uh some of the blue team stuff on these lives. Hello, Griffin. How's it going? Lapstation, welcome. Welcome. So many people in chat. So, as we usually do these things, uh, we're going to do a bit of a I don't know, just a bit of a a funnel in Q&A, welcome everyone, uh, kind of thing. And then we'll get into the try hackme box for the week that we're going to do. Um, and then, uh, if we have time at the end, uh, hopefully we can get through it, uh, we'll have some more Q&A. Um, I just realized, uh, like very recently because I got a text reminder, I have a dentist appointment in about an hour from now. So, or I have to leave in about an hour from now. So, it's going to be uh not a short stream, but I'm going to try to wrap it up before the top of the hour uh just so I can get to that. Uh how's everyone doing? I'm just scrolling through the chat now. Hello. Yeah, Brit is having some some trouble, but she's still here with us today. Discard packet stone block. They still see you. Sure. Yep. I'm not sure uh what exactly we're referring to there, but sure. I concur. I'm just watching one of your courses now. Awesome. Which course is it? Is it uh on the TCM Academy or is it on YouTube? Uh let us know. Sir Kit, welcome. one of our regulars. Another one of our regulars. Nice to see you all in chat today. So many people. Uh good question here from Emirit. Uh how much should a sock analyst or how much should a sock analyst know or be familiar with active directory? Um yeah, I think it's very important. I think uh active directory is still going to be among us in many enterprise environments uh for even for a long time uh even we're seeing you know this lift and shift approach where we're putting active directory in the cloud. So you know it's not really going anywhere uh at least not uh maybe in the near future. So I definitely think uh having a good understanding uh of active directory is uh uh crucial for for many uh medium even small uh and and particularly large enterprise uh environments these days. Uh which is actually kind of a good segue for one of the announcements that uh uh I was asked to make here uh for good reason. Uh let me pull this up. So uh speaking of uh your question here uh some good resources to get familiar with Active Directory. Uh specifically, we have uh next week, next Friday, uh Heath is doing his um uh defend and attacking or attacking and defending Active Directory live training. Um this is a a fantastic uh event if you were able to to take it. I think we have only a few spots left. Like I said, it's next week uh on May 30th. So uh the the clock is kind of ticking. If you want to uh join the live training, you know, if you have that uh uh you know uh organizational budget, if you want to do some more learning uh as we go out through the year, uh we run this class a few times a year, I would say. Um and I've taken it last year. Uh and you know, I'm not just shilling it. I can genuinely say this is a fantastic uh uh live training or live class. uh whether you're again on the penetration testing side, you want to figure out, you know, hey, what are the common uh misconfigurations or vulnerabilities in in Windows authentication for example uh and how can we take advantage of that in more penetration testing environment or how can we detect and and you know hunt for these things and and ultimately harden and defend against them. Uh so that's where I really found uh value from this training is from the defensive aspect as well because it's really um you know you're introduced to attacks and then you're sort of introduced on how to hunt and defend them. So uh thought I would mention that uh again it's going to be next week. So kind of a good segue there uh for the training. Also the other announcement uh to make is that uh keep your eyes open on Friday. Uh we are coming into the Memorial Day weekend. Uh, and historically we typically do uh we run a sale over over that weekend. So I'm not confirming or denying anything, but I think uh there might be something happening this weekend in regards to that. Uh so stay tuned. Uh I missed the last couple of streams. Glad to see you. Yeah, welcome back. It's been a little bit. Um yeah, I haven't been on for for a little bit either. So, it's mostly been Alex and Bellini in the past few weeks anyways. So, good to be reunited. All right. We'll jump into the box shortly again. Uh hopefully uh we're able to wrap it up before the the top of the hour and I got to got to hop off, but uh we'll still do some more um some more Q&A before we jump in. uh which will you cover today? We are going to do uh we'll get we'll get it started uh shortly, but let me just introduce the room if anyone wants to follow along. Uh we're going to do one of the recent room uh challenges from try hackme here uh just a few days ago uh called security footage. And so the link uh should be going around in chat. I will uh drop it in in a moment if need be, but it's just called security footage. It's a free room, free challenge. Uh and it appears to involve some kind of digital forensics on a pcap or a network capture. Uh so I'm looking forward to digging into that. Brit should stop sending me fishing links. Yeah, same here. Let me see if I can drop that in chat. There we go. What is your opinion on threat hunting? Get that word out of my chat. I swear. Um, I have a great opinion on threat hunting. Uh, but not threat hunting. I don't like that word. It's like the word moist, you know? uh just makes me feel certain ways. I'm new here and I love your content. Well, thank you so much. Yeah. Uh we love putting a variety of different content out. Um again, whether you like the web app stuff or, you know, network pentesting or exploit development, even things like low-level assembly, uh you know, it's been awesome to see how we have different people on the team uh that can provide uh uh you know, information in different areas. Uh, can I enroll in PJBT even if I'm new to this field? Yeah, I mean that's that's kind of the the purpose of um the PJBT and you know the accompanying course is it's kind of this like uh start from zero kind of approach, right? um even if you don't uh jump right into the the course on the academy, you know, uh we have some some uh long form kind of lessons and uh courses uh even on the YouTube channel itself, right? And so um you can definitely start there if you'd like and then as you get sort of more comfortable, more experienced, you can jump straight into the course where you're really going to be learning and picking up everything you need uh in order to ace that exam, right? Everything you need is covered in the course. And so um it's it's really uh purpose-built for that. All of our courses are really. Um so you can't really go wrong uh and and in the fact that it being a junior penetration tester uh is is right up your alley, right? kind of the best way to learn in my opinion is again uh to to take any kind of junior oriented course if you're just getting started in the field where it will really sort of guide you through uh you know all the prerequisites and and everything you would need uh in order to get a you know a good grasp on whatever it may be you're learning doesn't have to be PJPT but any kind of beginner oriented course I would say it's hard to go wrong unless it's just bad quality Right. Hello. I just finished my cyber security masters program. Congrats. That's awesome. I'm sure that was no easy feat. So, uh, congrats on that. Uh any sneak peeks on the sock 200 course? Uh maybe I could pull something up. I'm just afraid I'm going to show too much. So maybe not, but it is coming. Um we have some uh some other stuff a a lot of stuff actually at the moment going on kind of in the background or um uh you know just other things happening. So, it is pretty pretty much a crunch time here. Trying to get a lot of stuff done at the moment. And so, it is coming soon. Uh, I know people hate that word soon, but rest assured. Um, I think it's going to be really cool. All right. I fear as if if I wait too long, I'm not I'm going to run out of time for for the challenge. So, let's get into that. Let me try to take one more question before we jump in. Um yeah, when is sock tool one dropping? Soon. Soon, I promise. Um it's a big course and so there's still a lot uh you know to go through uh and to sort of QA and make sure it is polished and nicely put together. You know, there's still some modules and sections uh and labs uh to be put together for that. So, it is coming um really focusing on uh you know making it super complete and and in and quality over uh uh time and again there's there's other stuff going on at the moment but it is coming soon and it's uh turning out to be really cool in my opinion so far. All right, let us jump into this forensics challenge. assuming it's a forensics challenge. Uh based on the description here, uh medium box here says it'll take 45 minutes, which uh might be perfect. It's 12:15 right now. So, let's see if we can get it done in that time. So, uh we just have one flag to answer, which is interesting. Uh we're not sort of guided through in this case. And the story goes, uh someone broke into our office last night, but they destroyed the hard drives with the security footage. That's cool. Uh, can we recover the footage? No. Diffusing the attack box. No, we won't use the attack box. Uh, so I've downloaded the task files um already and we can take a look at what they give us. All right. uh should be in downloads and it's just a pcap. Okay. All right. So, we're given a packet capture file of this security footage uh which apparently has been deleted uh by the attacker. Um so, we'll see what we have. So, I'm going to open this up in Wireshark. All right, let me try to zoom in and see what we're working with here. Just over a thousand packets. So, that's not too bad. Hopefully. I always like to look at the capture file properties, see um what we're working with, right? Uh so, looks like these were captured back in 2022. The room just came out so I guess it took a little bit uh to publish this challenge. Uh so again, yeah, we have just over a thousand packets to go through. Uh but what protocols are we looking for? So I'll go under uh I always like to use the statistics when I'm first sort of introduced to a pcap because again, you know, the there's no point in trying to like scroll through packet by packet trying to figure out what's going on. So I like to see, you know, hey, what protocols are being used in this pcap, right? Um, and so in this case, uh, IPv4 mostly, well, pretty much all, uh, just TCP packets. Looks like one of those is an HTTP packet. That's interesting. So, we'll definitely take a look at that, especially just because it's unencrypted, right? Um, and see if that can help us out. But I'm assuming there's some kind of security footage in this uh, packet capture, right? Uh, it's kind of the point of the challenge. Um, and so I'm assuming that's what all these TCP packets are. Um, that hopefully we'll be able to I guess uh take a look at, right? What we could do is is maybe just for that low hanging fruit if we look at uh to export objects if we can get the footage directly from uh some of these packets. I don't think we'll be able to because again there's only that one HTTP packet and there's no file contained in it. Uh it looks like it's this one right here. And so what I could do uh is just use the HTTP filter there just to uh pull back that single packet. Uh and then I like to rightclick follow HTB stream and see what the actual uh packet contents are. So it looks like it's just making that request or a get request to this IP address on port 8081. Have the user agent here. Uh nothing particularly interesting about this, right? It's just making a request. But where's the response? I'll look at the conversations, too. Yeah. So, we just have this IP talking to this IP address. Um, but where's the response? I guess it's it just moved over to this TCP conversation. So, if we follow the TCP stream, uh, there we go. Now, we're getting something. Okay. So again, we're making this request and it looks like the server or whatever this is is responding uh with some content. Appears to be an image. So we have some uh a JPEG and we have sort of that uh you know a bunch of gibberish that I'm assuming this is a photo uh some kind of JPEG image that was transferred uh in response. Uh but it looks like quite a few packets are in the stream here. So if we keep going. Yeah, it looks like it's just a bunch of images. Yeah. So each of these packets, right? 58 56. It looks like all of these are part of different images and they sort of span multiple packets. Um I'm assuming that's everything in the list, right? If we go to the last one here. Yeah, that's like the last packet we have. Uh, so looks like our answer is going to be contained in that stream. And so we need to figure out how to I guess uh extract uh those images from that stream, which uh I can think of a few uh probably easy ways to do that. Uh but I'll also leave it up to chat if anyone has any ideas that we can take a look at. But just to confirm uh that I'm not crazy here. Um let me zoom back up. I want to find um where that conversation started. Yeah. So it's this one. If I follow that stream again um and zoom in, we can see that we have this JFIF uh header here for this file. And if I were to do uh just a lookup, I have Firefox file signatures. If I just search for JPEG, right? So looking for these uh sort of magic bytes or like the file signatures or file headers that are appended to each image. Um again, we could see that from the stream itself. I can figure out where that is. We notice that uh in the response uh the content type is set to a JPEG image, right? Uh and we can also see this file header here as JFIF. And if we take a look at our table here, uh very handy uh table on Wikipedia that maps the different like image file types to what their file headers look like. In this case, it looks like we have that JFI if or in hex, we can see FF A FF0. Uh, and this sort of header goes on and on. Um, and if we find this again, this sort of refers to a JPEG image, right? If we if a a image interpreter program sees that file header, it knows, hey, I'm dealing with a JPEG image here. How can I render that to the screen? Right? So what we might be able to do here uh is copy this stream because I want to verify uh if we can actually make an image from this. So how do you do this? Uh, if I go to copy hex dump or hex stream, I think that's gonna So, what I could could do also, I think if I follow the TC stream again, I can change the format here to uh something like raw. And now we're just getting sort of the the the hex stream uh of that request and then the subsequent responses that should in theory contain those images, right? Uh so a bunch of gibberish here. Uh but we should be able to find that uh file signature header somewhere in here. So what I'll do is just copy this first stream here and I'll copy as a hex stream. And then what I can do is head over to Cyershift and just paste in uh that stream that we copied. Uh I'm not getting the command. So how can I analyze it through Wireshark? Well, if you have Wireshark installed, uh you can like just open it from your app drawer. Uh and then from here you can go file and then open and find that pcap or uh you can just run if I go back up here, you can just run wire and then provide the name of the pcap that you want to open up. So there's multiple ways you can start up wire uh and open up the uh the packet capture. All right, head back over to Cyersha. I'm going to paste in that stream that I copied. Right, so we have this long list here. And then what I think I can do is go from hex. And then we're basically getting the same uh information that we got. Uh but what I want to do is sort of chop off this front bit here. And so I'm going to look for the start of that. So we have that weird ya. Let me zoom in here. So, I'm going to look for the start uh like bytes of this string here. So, that's going to be FFD8 FFB. And I'll try to find that in this uh input here. Uh FFD8, FF DB. Nope. Uh FFD8. There's multiple different kind of headers. Ah, this is the one we were looking at. Yeah. So, FFD8 FF0. And I think we already have that highlighted. Yeah. So this is the start of that image, right? This is the uh very first sort of bytes in that header uh that are telling us that hey this is a a JPEG image. And so what I should be able to do is chop off all of this beginning part here, right? Like that was part of the response uh which is not part of displaying that image. So if I take that out now we're just starting off with that header, right? So, what I should be able to do through uh Cybersh is to click on this magic button here to actually render out that image. And there we go. All right. So, yeah. So, if I render out the image and zoom out, uh it looks like we have half of an image, right? And I'm assuming that's because the uh image is also carried over to some of these other packets, right? So, if I I guess we're to grab this next one for 10, right? That was the next sort of uh response there. Uh if I do the same thing and copy as a hex stream, I can just paste that in and then clean it up again. So, let me find me zoom back in. I'm going to find where that next uh sort of header starts. Actually, no, it won't do that. We just need to paste in the remainder of this stream. Uh I think we're getting a little bit more. Right. So now we have flag and so we could keep going on and on. Right. So if I try to grab the next uh packet here, do the same thing. Copy the hex stream. We're slowly building out this image, right? And it looks like it says flag. Uh so I'm assuming once we can reconstruct this image, uh we'll have the flag, right? And so obviously we won't we don't want to be doing this uh in Cybersh manually, right? Like like packet by packet. That's going to take forever. Uh there's like over a thousand packets in here, right? But I just wanted to sort of as a proof of concept see if we can actually make that that happen. Right? So it looks like we're on the right track here. uh we're able to identify that hey this this packet capture contains um the uh JPEG headers uh in some of the packets and so can we extract those out right uh and again there are different ways we can do that there's quite a few tools actually uh forensic kind of file carving tools that we can use or different uh file recovery tools um so that's going to make our lives a a ton easier and I don't even think we're going to need cyershe for anything so go back to the packet capture and grab a drink hex header. Yeah, you got it. So that's what we're basically doing. We're just grabbing out those hex streams from that conversation and then um you know saying hey where are all the images? And so that's exactly what we can do now. So uh let me find the entire conversation here. It started with that get request as you recall. So, if I follow the whole TCP stream, we're going to have basically all of the packets now in this one conversation. And so, from here, I'll change it to display from ASI. And then we can go back to RAW where again we're getting uh Whoops. We're getting all of those uh hex decimal values, right? And what I can do, there should be a way to save this. Crl S. Oh, it's down here. Yeah. So, I can click save as. and just save out this entire uh conversation again between these these two systems uh over this TCP connection. Just save that entire thing as a raw kind of file. Right? So just call this raw.txt. And now back in the terminal, I'll open up a new tab with control shift and t and make sure we have that raw text file. Right. So there we go. Uh if we run a file on it, we just get uh data. If I make sure we copied everything. Yeah. So, it looks like it's uh rendering out as the the actual ASKI content. Uh which is fine. So, a few different tools, like I said, uh can really speed up this process here. Uh and actually carve out those images from now that we have everything in a file, we can carve it out directly, uh from this. We might even be able to run it against the pcap itself and save us some some steps there. But um just sort of doing it step by step here. And now I'm in Kali Linux. So there should actually be some forensic tools in here that we can use. Uh if I run the appropost command, uh we can actually just search for something that we want to do and it can uh tell us on our machine uh by reading sort of the man pages or the uh uh help pages um if any tools match our search terms. Right? So if I search for recover or carve for example, uh looks like we get nothing. Uh but again, if I search for recovery, uh we have some results. Recover. There we Oh, there we go. That's what I'm looking for. So the scalpel tool is a I think a perfect uh use case for this. Uh why you didn't remove the header for the second packet? Uh the second packet actually didn't have that header. It was only at the start of that image, right? So where was it? I think it was eight. So if I follow this stream, I'll change it back to ASKI. [Music] um there. Uh so we're going to have the file header at the beginning of the image. But if I scroll down to that next packet, so packet 10 in this case, it's just a continuation of that image, right? So we're not actually going to specify the header again because it's just part of the same image. It's just split up into multiple packets due to like size, right? Uh so we didn't need to remove anything from the subsequent packets as we sort of built out that image because they were all tied to the same sort of image. Um, and that's what this scalpel tool is going to help us do. Uh, so if I just look up scalpel Kelly Linux. And so, uh, again, it's a nice file carver for us. Uh, if you're not running Keali and it's not pre-installed, you can just run a pseudo app to install Scalpel. Uh, but it's a a file carver, right? So it can actually look through uh it has sort of an internal database of those file signatures or those file headers and it can extract matching files from whatever we give it right. So it's going to be perfect I think in this case. Yeah, it was all in this uh unencrypted TCP stream. I don't know what like specific uh tool or software was used to to transmit that image. Uh but whatever it was, it was in sort of this this unencrypted stream here, which is why we were able to grab those uh bytes bytes from it. All right. So, let's try to use scalpel. Um Let's figure out how we can actually use it. I think it uses a config file. Yeah, scalpel.com. But where is that? Trying to find out where it is saved by default. I guess I could search for it. Uh Etsy scalpel scalpel.com. There we go. Okay. So, pseudo nano etsy scalpel. There you go. So, this configuration file controls the types and sizes of files uh that are carved by scalpel. Oh, for most that's the other tool that we could use. Maybe we'll try that later. Yeah, I remember that from another CTF. I think the uh something in Nomicon from the other year. You use this tool to do the pretty much this exact same thing. So, that's why it felt familiar. Uh and I think with scalpel. Yeah, there we go. So we just need to uncomment what we want to extract, right? So we can it's a very powerful tool, right? It can it can grab PGs, bit maps, I think like PDFs and stuff too. Um, anything really. And it's really good for these packet capture scenarios where again we have these sort of raw bites of an image. And then so I'll just uh uncomment those JPEGs there and then save the config. And now I think we can run uh scalpel here. by providing it the I or if we just run it on its own. Yeah. What's the syntax here? Oh, set an output directory for car files. How do I specify raw.txt? Uh output. We'll just call it output. Whoa, that did not work. What did I do? Okay. No such file or directory. Maybe I don't put the I there. Okay. There we go. Looks like that might be working. Uh can we extract the image from ASI? Why do we have to convert it? Yeah, I think you can. Like like I said, I think you can even run the scalpel against the pcap file itself. Um, but I just saved out in that raw format just so we don't potentially miss anything or if like you know some special characters don't mess anything up. I don't know. It's kind of like using base 64 encoding to make sure nothing when you transfer a file or something it doesn't mess anything up. But I think yeah, it would be worth trying and you know maybe not doing that step. Save some save yourself some time. Uh but the main purpose of using Cyberche at the beginning was just to sort of demonstrate or um you know figure out as a proof of concept if we're on the right track here. And it looks like we were. Uh so uh yes, we uncommented both of those different JPEG headers. It looks like one of them had zero files. The other one had 541 files. And it looks like it was able to carve those out. Sweet. So, let me jump into that output directory. Uh, audit.txt. Oh, cool. Yeah. So, it grabbed all of these different files in sequential order, which is nice. So, we have 500 and something of them. Cool. I'm assuming they're in this JPEG folder. Yes, there we go. So, that really saved us some time, right? So, you know, we could go ahead and and paste that whole stream into uh Cybersha. And there's probably an operation we can do to, you know, grab a uh grab a file signature or something. Uh I'm sure there's a way uh to basically strip out that other TCP information. So, we we're just left with the images. And again, maybe we could print them all out in Cybersh, but having them as a file on disk makes our lives a lot easier. Um, so let's try to take a look at them. Right. So they're all saved in this output folder. Um, let me navigate over there. There we go. Perfect. Let me zoom in there. Look at that. So we were starting to get one the flag. And now we have them all. And I get it now. It's security footage. And so this is like each frame that was sent over, right? You can see it's kind of moving as we go frame by frame. So we could I mean that's the flag, right? So we could I guess scroll down and copy each character. Uh but let's try to have some fun with this uh and make a movie out of each of these frames. I've done this kind of thing before, like not for any CTF related things, but I know you can I know there's sites out there you can paste in a bunch of frames and it'll make like an animated gift for you. Let's try that. uh image uh JPEG frame to animated GIF. I'll see if this will work. Um yeah, any of these should work. And then images to GIF. Let's try that. Let's just select all these. And again, uh I don't know if I'm assuming, yeah, it's uh scalpel that's doing this and putting them in sequential order for us, which is really nice. It makes that process so much easier. So, if I select all of them, you should be able to just generate a GIF. Come on. This would be so funny if it worked. Well, I'll take a look at some some pin questions while we wait. uh without knowledge in blue team stuff is sock 101 in TCM good start I mean yeah I'm obviously pretty biased there but I think it's like the perfect start uh for that scenario as well um uh again kind of like the other question earlier about the PJPT um you know the the TCM courses like are really meant to walk you through from sort of uh that starting point uh until uh having all the knowledge you need to uh you know maybe pass the exam or just uh you know um approach whatever role uh you might be going for. Right? So um obviously we have more advanced certifications as well but or courses uh but the sock 101 in particular is really meant for uh again those sort of tier one analyst roles and and picking up those blue team sort of uh analyst sock analyst fundamentals and so I think that would be a great start. Um we also have the um on the free tier like the free course we have for um help desk. So I think that's a good prerequisite uh if you really just have no kind of like uh system related knowledge or or um you know operating system knowledge as well. Um it would be a good uh uh sort of starting point if you're like really starting from nothing in IT or cyber security. Um and then you can sort of take that free course and then go into uh you know sock 101 or if you want to go sort of the penetration testing route, you can take the pract practical ethical hacking course as well. So uh that's where it can kind of split off depending on uh what you want to get into. I don't know if this is going to work for us. Let me try a different site. Oh, shoot. I think my VM's frozen. Whoops. Okay, let me try to close this tab while we wait. Uh, will bin work in this case? Yeah, I think it will. I think in the same sense I think it might actually be easier. I think it can automatically detect the file headers and we'll we'll grab those out so we don't actually have to mess with any configuration files. So that's might be another way to do it. All right, I'm hoping I can get some response back on this VM. I don't want have to restart it, but I might have to. All right, let me restart that. Last time I tried to be slick and start it back up again. Uh what if there is a text raw file and I have to find the flag from it as a memory file. What should I use for that? Uh not sure exactly what you mean. Uh if you mean like a memory capture um I mean you can use something like volatility. Um you know there's a bunch of different tools for memory forensics. Um but in in this case like we're dealing with a a packet capture, right? So it's already written to disk. Um, if you're working with memory, yeah, again, I would recommend something like volatility or uh some other kind of memory forensic specific or like memory image analyzing tools. So, it would really just depend on what the flag is that you're uh trying to find, right? Like is it in like a process command line or is it in the registry value? Uh, again, it would just depend on what specifically you're looking for. And volatility has plugins for uh any kind of uh any kind of uh uh analysis you want to perform pretty much on the endpoint level. All right, let me pop this back up. We're restarting after we bricked our machine and we'll have to look for an alternative way to uh create that uh thing. Hopefully we still have it. Output. There we go. We still have all those images. Okay, let's try to find a proper way to do this. Um, Linux make gift from images. This is literally what I do. I just, you know, I guess you could ask chat GPT. It'll give you some advice on tools or whatever to use. Um, image magic. I've used that before. But I hate that tool. Uh FMPEG. Yeah, let's try FME fmpg. Perfect. Create animated gift from a set of JPEG images. That's exactly what we're looking for from 14 years ago. I need something that can be scripted on Windows 7. Well, this should still work for us. FMPEG uh file uh input for images. Is that going to work? Yeah, let's try it. Do we have it? All right, we can install it. Uh J uh JPEG sequence. Yeah, that's what I'm trying to do. I think you can do that. I'm guessing through uh these commands here. So, let's try it. Uh we've installed ffmpeg. Um I'm just going to copy one of these first. Convert the images to a video. Okay, let's just grab this one. This will convert images from the current directory named image one image 2 to a video named video.avi. Okay, so we're in the current directory. Uh, let me paste this in. What do we want to do? Um, well, let's try to do an MP4. Image percent D. What does F do though? If that's okay, maybe we just read the help page. F format. Okay. Uh, air opening input file image percent d.jp. Is that like a wild card? Yeah. Image_01. Okay. So, how are these named? They're just numbers. Okay. So, if I just put percent d.jpeg. Nope. Oh, you need to have Why is this so confusing? This has been surprisingly fun. I'll have to look into more blue team stuff. Yeah, I'm glad you found it fun. Um, it is kind of a a cheeky challenge, but it does use some genuine like uh uh you know, techniques, right? Like file carving and and stuff like that and working with pcaps. So, I do actually enjoy it. Hopefully we can figure out how to make this get this flag. I know the key is in specifying the name so I don't have to rename everything. image dash percent. We're already on this one. Oh, there we go. Yeah. Okay. Frame rate doesn't really matter in this case. Um, this determines the file name sequence. It looks for image dash meaning. Yeah. D indicates decimal integers. Five is the number of digits. Okay. So, we just need to specify the number of digits. Okay. Let me grab this entire thing and then just change what we need to. So we have how many digits per image? One, two, three, four, six, seven, eight. So we just need to put percent 08 I think. And then the rest of it is all gibberish. I guess it doesn't matter. There we go. It's working. Okay. Uh, it's not red, so it doesn't look like there are any errors. Do we have Yeah, we have output.mpp4. Drum roll, please. Hopefully this works. Um, it's at the bottom. There we go. Output.mpp4. Let's play it. Yes. Yes. That's so cool. There's our flag. Okay, let me get this typed in to try hackme. Oh, that's that's actually one of the most unique flags I've seen on the platform. That's cool. So, someone literally had to sit down with a camera. It looks like a web camera and record that. That's cool. Okay, let's try to get these side by side. uh flag. I guess we'll go frame by frame here 5 E B F 5 7 E A 6 B 2 8 7 7 F D B C Oh my gosh, the long flag. I got it. I got it first try. There we go. I think I had an extra parenthesis there, but I guess it didn't matter. There we go. Well, that was pretty magic. Yeah, that was cool. That was a cool uh CTF there. Uh, no, this is all new. Haven't done a try hackme room in a while. Yeah, there we go. So, just as a recap, we had a P uh packet capture file. Within that packet capture, there was a TCP stream uh where uh you know, a host was sending a bunch of JPEG images as frames to the other host. Uh we were able to sort of dig into that packet capture uh take out the individual uh you know hex bytes from it uh from the the packets themselves um and basically use uh file carving tools to to grab all of those images. We saved them out to individual frames and then we used u a neat little trick to uh put all those frames together in a video format which we didn't have to do. I guess we could have just copied it frame by frame but that was much more fun. Um so yeah, there we go. I hope you guys enjoyed that. That was Yeah, that was a cool one. Uh do have a little bit of time now for to wrap up with some Q&A before I have to run. So, let me jump back over here. Yeah, that was a cool one. I agree. That was clean AF. Thank you. Appreciate it. Yeah. Good job, everybody. Uh, do you have any try hackme room or labs by you? Yeah, I mean I used to work for try hackme. So if you do the um like the the sock level one and the sock level two pass. Um I have a I have a few rooms uh in those paths. Um there's like some threat hunting rooms. There's some log analysis and elastic uh rooms as well. Um I saw that they repurposed one of my uh rooms for their sock simulator I think. So, there's like one scenario you can do, which is I I I think based on uh some uh artifacts I put together for one of the rooms. So, um it's cool that they're I still see my stuff from time to time. Uh how do we know which frame to start in at the pecap? Uh let me see if I can pull it up again. Basically, it was like the first um part of the conversation. So, uh, wire sharkark just pulling it back up for you. So, basically, the conversation kind of starts with this get request, uh, which is the fourth packet in, right? There's some, uh, uh, sort of the three-way handshake going on here. Um but if we follow this the entire stream uh we can see we have the request and then this is the first packet in that response which contains uh that uh uh file header right for the the JPEG file there. And so the rest of it just immediately follows this entire stream. And so we just save this entire thing out to a file and then we were able to carve based off of that. Hope that makes sense. Do one insane level room in try hackme. Yeah, maybe maybe next stream again. I haven't done a try hackme room in a while, so it was nice to to find a fun challenge to do. Um because we kind of ran out of the blue team Labs online stuff. Uh there's still some Sherlocks we can do on Hack the Box, which uh I enjoy more. So maybe we'll do some more of those, too. Uh, you arrived late. Can we have the video? Yeah, if you just check the uh TCM YouTube channel uh after the live stream, it'll be in the the recent lives tab that you can go to and rewatch. Look out for more hot dog fishes. Uh, does TCM have modules for uh who want to learn cyber from zero knowledge? Yeah. Um, so I would start off with the free tier. Uh, there's like some some really good core uh skills and core courses you can take completely for free. uh like the practical help desk, uh you know, the Linux 100, uh the programming course. So, there's a ton that you can just start out, you know, for completely free. Uh and then work your way up to um whatever you want to take, right? So, if it's on the blue team side, I would recommend the Sock 101, uh which again really kind of starts you from zero to uh uh you know, being a you know, having those those core sock analysis skills. Uh there's also the practical ethical hacking course, right? If you want to do the penetration testing side. So, um really just depends which direction you want to go. Um there's there's uh some great courses all around from uh you know specifically from TCM but also you know many different vendors or Try Hackme has some free pass as well. So you can't really go wrong these days. Uh what do you think about Cyber Defenders Labs? Um I don't know if I've ever done one and I' I've taken their uh I've done the CCD like I have the C um and I've never done any of the labs. So uh I just haven't had time I guess. Uh maybe we'll try to do some on stream uh if they have free tier ones. Um but yeah, like I I took the certification course and you know, you're supposed to do labs and I think you get extra points if you do labs, but I just didn't have time and and just took the exam. Um but they they seem to be good. Like uh so hopefully if they're if they have like some free uh labs you can do outside of the certification, we can do some of those. Uh if I want to join for to get more practice, what can I do? Um uh yeah, a bunch of different things like we just said. There's um Try Hackme has some free challenge rooms and and lesson rooms. Um you know, Hack the Box, uh Blue Team Labs online with security blue team um or um Let's Defend as well. There's there's so many different uh ranges out there and a lot of them have free rooms that you can do. Uh if you didn't have a GUI, could you also do this with TCB dump? Yeah, I think you can if you um yeah, you definitely can. Uh if you filter out um you can use some of the uh uh display filters to to filter out just that conversation. Uh and then I think you can use the capital X argument with TCB dump to print out those hexodimal bytes. Uh so you can do that the same kind of way um and save it out to a file or you can probably just run scalpel against again the pcap itself. like you might not even need to do that intermediary step because it is kind of smart enough to dig into a pcap. I think there's a bunch you can do. Um all right, this is going to be the last question because top of the hour and uh as I mentioned earlier, I have a dentist appointment that I need to go to um uh really soon. So, I need to uh get ready to leave for that. I will just say before I take the last question though um just a reminder we have the active directory hacking and defending class uh next week which I encourage you to take uh if you if you're interested uh it's a fantastic course um taught by Heath Adams um next Friday I believe it is on the 30th and so uh just a reminder if you if you do want to take that the the spots or the seats are running out I think we have like two or three left so just thought I'd mention that but what do you think about labs versus real life uh labs can be fun uh they can be tailored to whatever kind of learning environment you want. So I think they they're a very useful tool. Um but it is really hard to replicate real life and real life kind of enterprise environments in in labs alone, right? Um that was one of the the struggles I've always had um being someone that built uh CTFs and different lab machines and cyber ranges, right? So um it is always hard building something realistic uh and also applicable um to specific uh learning objectives, right? Because in real life it's not always simple, right? Uh for threat hunting for example, um someone should build a threat hunting room where you don't find anything, right? To make it really realistic, right? You start out with a hypothesis, but there's just nothing in the data and so you just waste your time. So um that you know the realities of of real life can be um sometimes in contrast with uh learning objectives from a cyber range for example or labs. Um so there is a balance there I think but um labs are like the best way you can sort of prepare for uh the real life experience in my opinion. Thanks so much. Loving the sock 101 course. Appreciate that. Um and so with that, thank you everyone. Sorry I didn't get to everyone's question today. Uh I just uh again completely forgot I have a dentist appointment in like 20 minutes. So uh I have to run, but thank you all. Uh be sure to tune in next Wednesday. Uh we'll have another stream. We do this every Wednesday. Um, if you do have any uh lingering questions, you can head over to the TCM Discord uh and we'll uh do what we can to get those answered. Uh, feel free to hop in anytime and and just chat. And so with that, have a great rest of your week, everyone. Uh, and I will see you uh another time, maybe next week.

Original Description

https://www.tcm.rocks/soc101-y - Start your blue teaming roadmap with SOC 101, the comprehensive course created by Andrew Prince himself. SOC 201 is coming soon! Watch as we take on a blue team challenge today with Andrew Prince. Follow along here: https://tryhackme.com/room/securityfootage There's still a few spots left for the May 2025 Hacking & Defending Active Directory Live. Grab yours before they are gone: https://www.tcm.rocks/adli-y The room starts around the 07:15 mark. #livestream #blueteam #dfir #cybersecurity #tryhackme Sponsor a Video: https://www.tcm.rocks/Sponsors Pentests & Security Consulting: https://tcm-sec.com Get Trained: https://academy.tcm-sec.com Get Certified: https://certifications.tcm-sec.com Merch: https://merch.tcm-sec.com ๐Ÿ“ฑSocial Media๐Ÿ“ฑ ___________________________________________ X: https://x.com/TCMSecurity Twitch: https://www.twitch.tv/thecybermentor Instagram: https://www.instagram.com/tcmsecurity/ LinkedIn: https://www.linkedin.com/company/tcm-security-inc/ TikTok: https://www.tiktok.com/@tcmsecurity Discord: https://discord.gg/tcm Facebook: https://www.facebook.com/tcmsecure ๐Ÿ’ธDonate๐Ÿ’ธ ___________________________________________ Like the channel? Please consider supporting me on Patreon: https://www.patreon.com/thecybermentor Support the stream (one-time): https://streamlabs.com/thecybermentor Hacker Books: Penetration Testing: A Hands-On Introduction to Hacking: https://amzn.to/31GN7iX The Hacker Playbook 3: https://amzn.to/34XkIY2 Hacking: The Art of Exploitation: https://amzn.to/2VchDyL The Web Application Hacker's Handbook: https://amzn.to/30Fj21S Real-World Bug Hunting: A Field Guide to Web Hacking: https://amzn.to/2V9srOe Linux Basics for Hackers: https://amzn.to/34WvcXP Python Crash Course, 2nd Edition: https://amzn.to/30gINu0 Violent Python: https://amzn.to/2QoGoJn Black Hat Python: https://amzn.to/2V9GpQk My Build: lg 32gk850g-b 32" Gaming Monitor:https://amzn.to/30C0qzV darkFlash Phantom Black ATX Mid-Tower
Watch on YouTube โ†— (saves to browser)
Sign in to unlock AI tutor explanation ยท โšก30

Playlist

Uploads from The Cyber Mentor ยท The Cyber Mentor ยท 0 of 60

โ† Previous Next โ†’
1 Buffer Overflows Made Easy - Part 1: Introduction
Buffer Overflows Made Easy - Part 1: Introduction
The Cyber Mentor
2 Buffer Overflows Made Easy - Part 2: Spiking
Buffer Overflows Made Easy - Part 2: Spiking
The Cyber Mentor
3 Buffer Overflows Made Easy - Part 3: Fuzzing
Buffer Overflows Made Easy - Part 3: Fuzzing
The Cyber Mentor
4 Buffer Overflows Made Easy - Part 4: Finding the Offset
Buffer Overflows Made Easy - Part 4: Finding the Offset
The Cyber Mentor
5 Buffer Overflows Made Easy - Part 5: Overwriting the EIP
Buffer Overflows Made Easy - Part 5: Overwriting the EIP
The Cyber Mentor
6 Buffer Overflows Made Easy - Part 6: Finding Bad Characters
Buffer Overflows Made Easy - Part 6: Finding Bad Characters
The Cyber Mentor
7 Buffer Overflows Made Easy - Part 7: Finding the Right Module
Buffer Overflows Made Easy - Part 7: Finding the Right Module
The Cyber Mentor
8 Buffer Overflows Made Easy - Part 8: Generating Shellcode and Gaining Shells
Buffer Overflows Made Easy - Part 8: Generating Shellcode and Gaining Shells
The Cyber Mentor
9 HackTheBox - Sunday Walkthrough (Re-Up)
HackTheBox - Sunday Walkthrough (Re-Up)
The Cyber Mentor
10 Networking for Ethical Hackers - TCP, UDP, and the Three-Way Handshake (Re-Up)
Networking for Ethical Hackers - TCP, UDP, and the Three-Way Handshake (Re-Up)
The Cyber Mentor
11 Networking for Ethical Hackers - Network Subnetting (Re-Up)
Networking for Ethical Hackers - Network Subnetting (Re-Up)
The Cyber Mentor
12 Networking for Ethical Hackers - Network Subnetting Part 2: The Challenge (Re-Up)
Networking for Ethical Hackers - Network Subnetting Part 2: The Challenge (Re-Up)
The Cyber Mentor
13 Networking for Ethical Hackers - Building A Basic Network with Cisco Packet Tracer (Re-Up)
Networking for Ethical Hackers - Building A Basic Network with Cisco Packet Tracer (Re-Up)
The Cyber Mentor
14 HackTheBox - Fighter Walkthrough (Re-Up)
HackTheBox - Fighter Walkthrough (Re-Up)
The Cyber Mentor
15 Beginner Linux for Ethical Hackers - Navigating the File System
Beginner Linux for Ethical Hackers - Navigating the File System
The Cyber Mentor
16 Beginner Linux for Ethical Hackers - Users and Privileges
Beginner Linux for Ethical Hackers - Users and Privileges
The Cyber Mentor
17 Beginner Linux for Ethical Hackers - Common Network Commands
Beginner Linux for Ethical Hackers - Common Network Commands
The Cyber Mentor
18 Beginner Linux for Ethical Hackers - Viewing, Creating, and Editing Files
Beginner Linux for Ethical Hackers - Viewing, Creating, and Editing Files
The Cyber Mentor
19 Beginner Linux for Ethical Hackers - Controlling Kali Services
Beginner Linux for Ethical Hackers - Controlling Kali Services
The Cyber Mentor
20 Beginner Linux for Ethical Hackers - Scripting with Bash
Beginner Linux for Ethical Hackers - Scripting with Bash
The Cyber Mentor
21 Beginner Linux for Ethical Hackers - Installing and Updating Tools
Beginner Linux for Ethical Hackers - Installing and Updating Tools
The Cyber Mentor
22 Cracking Linux Password Hashes with Hashcat
Cracking Linux Password Hashes with Hashcat
The Cyber Mentor
23 Reminder: Twitch Hacking Live Stream Tonight! 2/26/19 at 8PM EST
Reminder: Twitch Hacking Live Stream Tonight! 2/26/19 at 8PM EST
The Cyber Mentor
24 Hacking Live Stream: Episode 1 - Kioptrix Level 1, HackTheBox Jerry, and Career Q&A / AMA
Hacking Live Stream: Episode 1 - Kioptrix Level 1, HackTheBox Jerry, and Career Q&A / AMA
The Cyber Mentor
25 Hacking Live Stream: Episode 2 - HackTheBox Active, Vulnserver Buffer Overflow, and Career Q&A / AMA
Hacking Live Stream: Episode 2 - HackTheBox Active, Vulnserver Buffer Overflow, and Career Q&A / AMA
The Cyber Mentor
26 Hacking Live Stream: Episode 3 - Hack The Box Blue, Devel, and Career Q&A / AMA
Hacking Live Stream: Episode 3 - Hack The Box Blue, Devel, and Career Q&A / AMA
The Cyber Mentor
27 New Zero to Hero Pentest Course, New Website, and 2K Subs?!
New Zero to Hero Pentest Course, New Website, and 2K Subs?!
The Cyber Mentor
28 Zero to Hero Pentesting: Episode 1 - Course Introduction, Notekeeping, Introductory Linux, and AMA
Zero to Hero Pentesting: Episode 1 - Course Introduction, Notekeeping, Introductory Linux, and AMA
The Cyber Mentor
29 Zero to Hero Pentesting: Episode 2 - Python 101
Zero to Hero Pentesting: Episode 2 - Python 101
The Cyber Mentor
30 Zero to Hero Pentesting: Episode 3 - Python 102, Building a Terrible Port Scanner, and a Giveaway
Zero to Hero Pentesting: Episode 3 - Python 102, Building a Terrible Port Scanner, and a Giveaway
The Cyber Mentor
31 Zero to Hero Pentesting: Episode 4 - Five Phases of Hacking + Passive OSINT
Zero to Hero Pentesting: Episode 4 - Five Phases of Hacking + Passive OSINT
The Cyber Mentor
32 Zero to Hero Pentesting: Episode 5 - Scanning Tools (Nmap, Nessus, BurpSuite, etc.) & Tactics
Zero to Hero Pentesting: Episode 5 - Scanning Tools (Nmap, Nessus, BurpSuite, etc.) & Tactics
The Cyber Mentor
33 Zero to Hero Pentesting: Episode 6 - Enumeration (Kioptrix & Hack The Box)
Zero to Hero Pentesting: Episode 6 - Enumeration (Kioptrix & Hack The Box)
The Cyber Mentor
34 Zero to Hero Pentesting: Episode 7 - Exploitation, Shells, and Some Credential Stuffing
Zero to Hero Pentesting: Episode 7 - Exploitation, Shells, and Some Credential Stuffing
The Cyber Mentor
35 Installing Windows Server 2016 on VMWare in 5 Minutes
Installing Windows Server 2016 on VMWare in 5 Minutes
The Cyber Mentor
36 Zero to Hero: Week 8 - Building an AD Lab, LLMNR Poisoning, and NTLMv2 Cracking with Hashcat
Zero to Hero: Week 8 - Building an AD Lab, LLMNR Poisoning, and NTLMv2 Cracking with Hashcat
The Cyber Mentor
37 A Day in the Life of an Ethical Hacker / Penetration Tester
A Day in the Life of an Ethical Hacker / Penetration Tester
The Cyber Mentor
38 Active Directory Exploitation - LLMNR/NBT-NS Poisoning
Active Directory Exploitation - LLMNR/NBT-NS Poisoning
The Cyber Mentor
39 Zero to Hero: Week 9 - NTLM Relay, Token Impersonation, Pass the Hash, PsExec, and more
Zero to Hero: Week 9 - NTLM Relay, Token Impersonation, Pass the Hash, PsExec, and more
The Cyber Mentor
40 Zero to Hero: Episode 10 - MS17-010/EternalBlue, GPP/cPasswords, and Kerberoasting
Zero to Hero: Episode 10 - MS17-010/EternalBlue, GPP/cPasswords, and Kerberoasting
The Cyber Mentor
41 Writing a Pentest Report
Writing a Pentest Report
The Cyber Mentor
42 Zero to Hero: Week 11 - File Transfers, Pivoting, and Reporting Writing
Zero to Hero: Week 11 - File Transfers, Pivoting, and Reporting Writing
The Cyber Mentor
43 The Complete Linux for Ethical Hackers Course for 2019
The Complete Linux for Ethical Hackers Course for 2019
The Cyber Mentor
44 Full Ethical Hacking Course - Beginner Network Penetration Testing (2019)
Full Ethical Hacking Course - Beginner Network Penetration Testing (2019)
The Cyber Mentor
45 Popping a Shell with SMB Relay and Empire
Popping a Shell with SMB Relay and Empire
The Cyber Mentor
46 Pentesting for n00bs: Episode 1 - Legacy (hackthebox)
Pentesting for n00bs: Episode 1 - Legacy (hackthebox)
The Cyber Mentor
47 Pentesting for n00bs: Episode 2 - Lame
Pentesting for n00bs: Episode 2 - Lame
The Cyber Mentor
48 Pentesting for n00bs: Episode 3 - Blue
Pentesting for n00bs: Episode 3 - Blue
The Cyber Mentor
49 Web App Testing: Episode 1 - Enumeration
Web App Testing: Episode 1 - Enumeration
The Cyber Mentor
50 Pentesting for n00bs: Episode 4 - Devel
Pentesting for n00bs: Episode 4 - Devel
The Cyber Mentor
51 Pentesting for n00bs: Episode 5 - Jerry
Pentesting for n00bs: Episode 5 - Jerry
The Cyber Mentor
52 Web App Testing: Episode 2 - Enumeration, XSS, and UI Bypassing
Web App Testing: Episode 2 - Enumeration, XSS, and UI Bypassing
The Cyber Mentor
53 Pentesting for n00bs: Episode 6 - Nibbles
Pentesting for n00bs: Episode 6 - Nibbles
The Cyber Mentor
54 Web App Testing: Episode 3 - XSS, SQL Injection, and Broken Access Control
Web App Testing: Episode 3 - XSS, SQL Injection, and Broken Access Control
The Cyber Mentor
55 How NOT to Approach a Cybersecurity Mentor
How NOT to Approach a Cybersecurity Mentor
The Cyber Mentor
56 Web App Testing: Episode 4 - XXE, Input Validation, Broken Access Control, and More XSS
Web App Testing: Episode 4 - XXE, Input Validation, Broken Access Control, and More XSS
The Cyber Mentor
57 Pentesting for n00bs: Episode 7 - Optimum (hackthebox)
Pentesting for n00bs: Episode 7 - Optimum (hackthebox)
The Cyber Mentor
58 Pentesting for n00bs: Episode 8 - Bashed (hackthebox)
Pentesting for n00bs: Episode 8 - Bashed (hackthebox)
The Cyber Mentor
59 Pentesting for n00bs: Episode 9 - Grandpa
Pentesting for n00bs: Episode 9 - Grandpa
The Cyber Mentor
60 Top 5 Internal Pentesting Methods
Top 5 Internal Pentesting Methods
The Cyber Mentor

The video provides a live demonstration of a blue team challenge using TryHackMe, covering cybersecurity and digital forensics concepts, and offers resources for learning and training in the field. Viewers can follow along with the challenge and learn about blue teaming, incident response, and security assessment. The video also provides information on upcoming courses and training programs, including SOC 101 and Hacking & Defending Active Directory.

Key Takeaways
  1. Start with the basics of cybersecurity and digital forensics
  2. Understand the concept of blue teaming and incident response
  3. Use TryHackMe to practice and learn about security assessment and vulnerability identification
  4. Follow along with the live challenge and take notes on key concepts and tools
  5. Explore additional resources and training programs, such as SOC 101 and Hacking & Defending Active Directory
๐Ÿ’ก Blue teaming is a critical component of cybersecurity, and practicing with tools like TryHackMe can help learners develop essential skills in security assessment and incident response.
๐Ÿ”’ Pro feature: Ask AI to explain this lesson โ†’

Related Reads

๐Ÿ“ฐ
My app's anti-theft feature locked every user out
Learn from a real incident where an anti-theft feature locked out all users and understand the importance of testing and validation in security design
Dev.to ยท Ihor Olkhovatyi
๐Ÿ“ฐ
PyPI Supply Chain Hardening, GitHub Bug Bounty Revamp, LG Proxy Ban
Learn about recent security updates in PyPI, GitHub, and LG to protect against supply chain attacks and bugs
Dev.to ยท soy
๐Ÿ“ฐ
Auditing the Surface We Added Since the Last Audit
Learn how to audit new attack surfaces added since the last audit and identify potential issues
Dev.to ยท Rob
๐Ÿ“ฐ
Looking for Testers and Contributors: AWS GuardDuty to Microsoft Sentinel Integration
Integrate AWS GuardDuty with Microsoft Sentinel using an open-source project and contribute to its development
Dev.to ยท Femitek Consulting
Up next
Cerebras CISO Naor Penso on AI Security & The CrowdStrike Partnership
Cerebras
Watch โ†’