#soc-level-1-path

1 messages · Page 1 of 1 (latest)

dull swallow
#

🥳thm SOC Level 1 thm 🥳
In the Junior Security Analyst role, you will be a Triage Specialist. You will spend a significant portion of your time triaging or monitoring the event logs and alerts.

The responsibilities of a Junior Security Analyst or Tier 1 SOC Analyst include the following:

☑️ Monitor and investigate alerts (most of the time, it's a 24x7 SOC operations environment)
☑️ Configure and manage security tools
☑️ Develop and implement IDS signatures
☑️ Escalate the security incidents to the Tier 2 and Team Lead if needed

mortal solar
#

second!

verbal parcel
#

Guess i'l have to pay for another year of tryhackme 😄

celest bronze
#

I think is a proble at this question

#

or maybe im just dumb NotMyBusiness

#

I tried ||virus total||

#

with these ips

trim widget
plush junco
#

Super Excited for this path

tough sequoia
#

Stuck on Pyramid of Pain room, task 9 right now, swear i have these right lol

tough sequoia
#

If anyone completes this task 9 let me know, curious what i did wrong... i have matched all the answers based on the text from the room but still no luck

novel ginkgo
#

I am stuck on task 5 question 2 the ip address it stated no problems from virus total and metadefender

tough sequoia
# novel ginkgo I am stuck on task 5 question 2 the ip address it stated no problems from virus ...

I ended up finding the answer on Any.Run and not one of the tools from Task 2 like it says

https://any.run/report/e2d2ebafc33d7c7819f414031215c3669bccdfb255af3cbe0177b2c601b0e0cd/90b76d7b-8df6-43c5-90ec-d4bbcfb4fa19

hazy kettleBOT
#

Gave +1 Rep to @tough sequoia

novel ginkgo
tough sequoia
#

or i missed something, but i have seen a few people with the question/issue so i think it may be the question yes

novel ginkgo
tough sequoia
#

i found the results when googling the IP, not sure how to view saved reports on any.run otherwise

novel ginkgo
hazy kettleBOT
#

Gave +1 Rep to @tough sequoia

tough sequoia
#

Im still stuck on task9, if there is a guide/answer for that in the youtube i would appreciate the link lol, finished everything else and thought i had this right

#

ah found it

#

LOL the youtube video (https://www.youtube.com/watch?v=q1d61X0TvHc) shows the guy trying task 9, the split view site saying he is wrong, then he just completes the task (since no answer is required)... guess that didnt help me

Learn what is the Pyramid of Pain and how to utilize this model to determine the level of difficulty it will cause for an adversary to change the indicators associated with them, and their campaign.

USE THIS CONTENT FOR EDUCATIONAL PURPOSES !!
----------...

▶ Play video
novel ginkgo
#

Will try again don't believe I can't get past that round

hollow magnet
#

doing the pyramid of pain section task 5, are these not the same question just worded differently or do i need to rest my brain? 😄

tough sequoia
#

one is the source file that the user ran and the other is the "dropped" file that the malware placed, they are different

#

at least from my memory of the room last night

hollow magnet
#

yep, you're right. top one is the dropped file, the bottom is the source file the user interacted with

main bronze
#

Where do I start looking for the source file the user interacted with?

tough sequoia
serene bridge
serene bridge
steady siren
#

Hello very new to cyber security, going through soc 1 and having trouble finding name of ransomware on virus total

steady siren
#

found it its conti

marsh carbon
wraith atlas
#

Hellooo you all. I'm stuck in section 4, question 2. I would really think the answer to the question is simply URL but nope 😃
Question: What term refers to an address used to access websites?

trim widget
tough sequoia
hasty wedge
#

Hello all

#

Hope u r doing well

#

Is someone can help me to understand the following question:
What term refers to an address used to access website

#

In pyramid of pain room please

primal igloo
#

Well, how do you got a website?

hasty wedge
#

By writing the url

primal igloo
#

Ok, and is inside the URL?

#

Before the TLD?

hasty wedge
#

Ok thanks

#

Room completed thanks to u

dim egret
#

@scenic token I'm pretty sure there is an issue with the static site on Pyramid of Pain. Two of the answers apply to Host/Network Artifacts and none of the answers seem to apply to "IP Addresses". I tried many different combinations and none produced a successful result. I know you don't even need to finish it to click the "completed" button but it seems like this task will cause some confusion for people who are trying to learn what each stage of the pyramid involves. Thanks for putting the room together!

hazy kettleBOT
#

Gave +1 Rep to @scenic token

wraith atlas
hazy kettleBOT
#

Gave +1 Rep to @lament scroll

mellow plinth
hollow magnet
#

yeh, was worked out just under my original comment, one is original file the end user interacted with and the other is the 'dropped" file

craggy sorrel
#

Where do I go for the full name of the G_jugk.exe malware

#

Can't find anything that matches the string it's looking for

craggy sorrel
steady siren
#

hello i am new to cyber any tips on getting better at osint so i can answer 5.4

unreal hare
steady siren
unreal hare
#

Apparently the soc learning pathway is only for subscriber
Unfortunately I'm requested to pay 😩😩 it sucks

steady siren
#

its just 90 for unlimitted access for a year and its not gonna take a year for me to finish this pathway

steady siren
hasty wedge
#

Hello, of course

steady siren
#

so i am very knew to cyber

steady siren
hasty wedge
#

Do you answer to the previews question?

steady siren
#

yea i answered the first 3

#

those were in the pics above so i was hoping the 4th one was too

hasty wedge
#

Ok how do you find the name of the malicious doc?

steady siren
#

maybe open the exe file

hasty wedge
#

Try to put the name file on Google

#

You will find some interesting things

#

Did you find something?

steady siren
#

when i put the file name of number 3 in google i don't see anything that points me in the direction of the filename

hasty wedge
#

Click on any.run report

#

You will find the answer there

steady siren
#

any other tips i don't really understand what im looking for

steady siren
#

thanks JIGSAW

steady siren
#

ALL done JIGSAW thanks

heavy brook
#

can someone please help me with this

#

Use the tools introduced in task 2 and provide the name of the malware associated with the IP address

#

when i run the ip address on OPSWAT MetaDefender it says no threat detected

hasty wedge
#

Don't forget that you can use Google can be used as a tools to gathering informations

nocturne cave
#

Threat Intelligence Room: Task 3 UrlScan.io - "The Cisco Umbrella rank of the primary domain is 222829" and "This website contacted 17 IPs in 3 countries across 14 domains to perform 119 HTTP transactions." BUT, those do not give a woop! Instead, one has to look up the old answers in someone elses walkthrough, namely rank 345612 and 13 domains.

main bronze
#

I am working on Threat Intelligence Room task 5 PhishTool. I do not understand how I get the IP from Email1.eml? It says use Cyberchef but how do I do that with no internet on the box? Is there a way to download the file to the attack box?

nocturne cave
trim widget
trim widget
nocturne cave
hazy kettleBOT
#

Gave +1 Rep to @trim widget

brave oar
#

Hi I am doing Splunk 3 and I think I noticed a mistake? I describe it on the forum: https://tryhackme.com/forum/thread/60e4a83036963fcce57b4c0b#last
Q: : What is the name of the text file that was successfully uploaded into the S3 bucket while it was publicly accessible? Answer guidance: Provide just the file name and extension, not the full path.

We know the timestamp from the previous questions. We know bitbucket was publicly available between Timestamp:14:01:46 and 14:57:54 on 20/08/2018 .

If you check this timestamp, you won't find events. If you change it to All time, you will find correct Event.

**It is because the event, that is correct took place at 13:02:44. **

Is that question build incorrectly or I am wrong?

nocturne cave
knotty plover
craggy sorrel
knotty plover
hazy kettleBOT
#

Gave +1 Rep to @craggy sorrel

craggy sorrel
knotty plover
#

completely

knotty plover
rustic tusk
#

.

nocturne cave
#

Hi

golden trench
#

Hi guys, I am stuck on SOC task 3

#

can anyone help?

trim widget
rough iris
#

Excuse me, has anyone here solved Task 9 in the Pyramid of Pain? I think it has some problems. Thanks for reading my question.

haughty frost
#

The second question in Task 5 of the Pyramid of pain has an issue. Virustotal does not associate the IP address to any malware.

spark dagger
haughty frost
#

I have already found it

spark dagger
#

Oh great!

haughty frost
#

I am just reporting an issue 🙂

spark dagger
#

👍

shadow lynx
hazy kettleBOT
#

Gave +1 Rep to @hushed temple

novel ginkgo
rough iris
novel ginkgo
#

Oh my god when you are correct whoops check your answer 🤦and he clicked on completed

swift vessel
#

Is pyramid of pain task 9 bugged?

hushed goblet
verbal parcel
haughty frost
#

In the "Unified Kill Chain" room, Task 6 the first tactic is wrongly named "Lateral Movement". It should be "Pivoting"

hazy kettleBOT
#

Gave +1 Rep to @haughty frost

digital umbra
#

I am doing Pyramid of Pain Task 5, but cant seem to figure out 3rd answer, i did manage to get questions 1,2,4 right though. Not sure if I am just blind or my brain is not working Q,Q

digital umbra
#

okay nvm, the answer has always been right infront of me

languid matrix
#

Is the box in threat intelligence tools intentionally set up so that it can't connect to the internet?
Noticed that yesterday and seems counter intuitive since you are supposed to use PhishTool and analyse the .eml provided.

onyx adder
#

Hello, I want to "export object" .txt file of HTTP2 using Wireshark (traffic is decrypted) but every time I try it refuses to open

#

^ Wireshark: Traffic Analysis > Task 8 > " Investigate the decrypted packets and find the flag! What is the flag?" Packet No. 1578 flag.txt?

jolly prism
#

hello on the page cyberkillchainzmt page you make a reference to persistence but the page is private : normal ??

jade vine
#

Hey guys, I totally hit the wall with "Autopsy" module

#

Task 7: "What MD5 hash value of the binary is listed as an interest file" I Search for "Interesting File under "Keyword search" and nothing came up...

#

What is the "Interesting File" it's referring to?

#

Because there are so many

jade vine
#

Never mind I figured it out! xD

round badger
#

Hello, on Sysinternals room, Task 9. I'm not able to find the answer for the question "Run the Strings tool on ZoomIt.exe. What is the full path to the .pdb file?"

#

I've found 2 paths but not the one which is needed for the question.

#

Please, could someone validate that the answer is there ? Thank you

tropic marlin
#

https://tryhackme.com/room/snortchallenges1 im on task 2 and im stuck on 2 questsions "What is the SEQ number of packet 62" and the TTL of 65 ive noticed that examining the alerts every packet has the same SEQ number and the TTL are all 2 digit numbers and not 3 and cant get either of the questions right ?

vocal ermine
quiet pendant
#

was It normal that I have spend 8 hours solving pyramid of pain room? xDDD

late isle
#

bro im just learning

undone bridge
#

Hi all, I'm a little stumped on OpenCTI, task 4: What kill-chain execution phase is linked with the Command-Line Interface Attack Pattern? I listed all 7 phases of the kill-chain and even more, I don't seem to know what the question is looking for. Isn't command-line used most often in Installation phase? -TIA

undone bridge
elder slate
bitter siren
#

Room: Incident handling with Splunk. The query index=botsv1 does not return anything. Are you supposed to add the data somehow? I cannot find it on the machine.

fleet berry
nocturne cave
#

Path is rockin coolguy 🔥

#

wondering how to get an invite to the Persistence Room since it is private

cobalt forum
#

hello

#

Pyramid Of Pain - Task2: Provide the ransomware name for the hash '63625702e63e333f235b5025078cea1545f29b1ad42b1e46031911321779b6be' using open-source lookup tools

#

i put the hash in the right tool online but the answers i am getting are not correct

cobalt forum
nocturne cave
#

Try using the other tool it will show you right at top

#

The task states to use both of the tools that were mentioned in the task. One may provide more information than the other etc..

#

The other tool is MetaDefender

cobalt forum
#

i found the right answer! thnx

nocturne cave
nocturne cave
#

I might be overthinking the above note there so the answer is yes in my humble opinion

knotty plover
#

hey, for snort intro task 6, how do I find the referrer IP? I've tried a few different parameters with snort -r and I can't find anything that fits the answer

knotty plover
#

nvmd I got it, make sure you check the text portion of the packet you see with -X

#

lol

knotty plover
#

how do I find alerts generated for mx-2.pcap? Nothing I try will work

#

for snort intro task 8?

glacial fox
#

Help me task

#

Pyramid of pain

#

task 4 tinyURl is down

#

tiny is not open

echo geyser
#

Let's not self promote your medium articles here please, especially if your write up contains answers. @brisk sage

hazy kettleBOT
#

Gave +1 Rep to @echo geyser

light crypt
#

Hello all, I don't understand the question 2 in task 3 in the Windows Event logs room, help me please

whole jay
#

Hello All, I have got a question regarding Threat Intelligence Tools - task 5 PhishTool. I am starting machine, there is directory there with email to be anylzed - but cannot launch phishtool through browser - it looks like machine does not have access to internet - cannot launch any page. Do I understand something wrong?

echo geyser
#

You could then just transfer the files for analysis to either the attackbox or your own VM

digital kelp
#

Alright let's see how long would it take me to finish this path

whole jay
#

@echo geyser via SCP?

echo geyser
digital burrow
#

Hello, I'm doing the hive project room. I uploaded the pcap file as an observable.
However I'm unable to get a flag from the provided url

hazy kettleBOT
#

Gave +1 Rep to @echo geyser

mint solar
#

Jesus I hate this path...

echo geyser
mint solar
# echo geyser Don't do it then 😅 ?

well Ive told myself I´ll do every learningpath...
and here we are. I know I will never go into blue teaming or so. Its just like me and math in college I hate but Ive to to it

north viper
#

Ok, got it, needed the attack box to spin up a server and wget the damn thing!

north viper
#

So, final question on threat intel tools asks: What malware family is associated with the attachment on Email3.eml?

#

I've discovered the same answer in my digging but coming up as incorrect everytime, can I get a sanity check please?

sacred umbra
north viper
#

Ha I was so sure it began with a T! I've been on virus total, phihtool, Talos, malware bazaar but see nothing with a D! @sacred umbra

#

Got it!

desert knot
#

Having an issue with task 5, getting the malware of the associated IP address. Virustotal and other queries haven't resulted in a name for the IP

#

Nevermind I found the answer clicking on the tabs

#

Now my google skills are failing miserably

#

All done, whilst google failed me, discord searching worked out in the end

desert knot
#

And damn the pyramid of pain is actually just broken it seems

languid matrix
north viper
#

Every day is a learning day eh @languid matrix

hushed goblet
digital burrow
#

@hushed goblet hello, I got the flag.:)

paper cipher
#

I just finished Pre-Security, and Intro to Security. I plan to start SOC Level 1 after I get off work today! I'm excited!

#

Does anyone who has already completed it have any review/advice?

nocturne cave
#

ok im stuck on pyramid of pain using the AnyRun.

#

@hidden aspen how are you?

#

nevermind got it!!

hidden aspen
#

ok cool, but please dont ping anyone like this for help 😉 haha

nocturne cave
#

oops sorry was just saying hi?

hidden aspen
nocturne cave
#

k sorry

nocturne cave
#

ok so i'm genuinely stuck i'm using the MetaDefender to find the malware associated with URL but it says it's clean? -- Nevermind found it

nocturne cave
#

love my training in the Soc level!

#

So does anyone know in the pyramid of pain how to find the dropped binary's file?

paper cipher
#

I'm stuck on Pyramid of Pain Task 5. It asks "Use the tools introduced in task 2 and provide the name of the malware associated with the IP address." When I look up the IP on Virustotal or OPSWAT, it comes back clean.

Does anyone know the answer? I'm seeing online that this is bugged, but would like the answer so I can continue on through.

oblique flicker
paper cipher
hazy kettleBOT
#

Gave +1 Rep to @oblique flicker

digital burrow
#

Hello, I'm doing the "snort challenge - live attacks" room.
I can't get the flag, despite being able to catch the malicious traffic

#

Can anyone help me please?

rancid crater
#

Hi everyone

#

i have a problem concerning

#

the phishing analysis fundamentals

#

room

#

i tried to decode the base64 encoded email2.txt

#

however terminal sends me a message saying invalide input

#

the command is base64 -d email2.txt > email4.txt

#

maybe my command is wrong

nocturne steeple
#

is anyone else having an issue with the Yara room, task 10, file2?

whole jay
nocturne steeple
whole jay
#

And you copied newly created Yara rule(created by yargen) to appropriate directory ?

nocturne cave
#

Hi guys, when using -A fast mode on Snort, where is the alarm file located?

timber shore
#

Hi, to find the name of the malware in the pyramid of pain - I pasted the hash in virustotal and got many different names. I found the correct answer from the number of asterisks in the answer format. In general, if you paste a hash and get many different names from different providers - how do you know which one is right?

thick jacinth
#

I'm totally new in blue team. Would you say that this path show you the base knowledge for a real job?

shell jackal
paper cipher
timber shore
#

I’m not a soc analyst but a SIEM consultant- got the job with some tryhackme practice and studying for the CySA+ - so go for it

vagrant ledge
blissful ice
timid adder
#

is there any way I can download excersie file from wireshark, zeek, snort rooms? VM is extremely slow for me (prob because I live far away from a data center)

warm forge
#

is there a way to download tools or files from the tryhackme attackbox?

#

for example the wordlist files on the attackbox

nocturne cave
#

Room: Windows Event logs
Task 3:
Question: what event files would be read when using query-event command?
It has , no hint and the question is changed recently. I can’t figure it out, we can read any log file we want. I tried the command by it self and it said the command needs parameters. The question dost make sense at

violet loom
#

Hi, did you guys experienced any issues answering the questions in Snort Challenge - The Basics Task 2?

nocturne steeple
#

seems the answers are wrong

#

doesnt want to take the ACK number of packet 64

#

or

#

the SEQ number of 62

blissful ice
violet loom
nocturne cave
nocturne cave
timber shore
blissful ice
#

@nocturne cave @timber shore Thank you both. I think I'll do fine but I can tell you I've been lacking at some of the stuff, even after 2 months of studies. So take your time.

hazy kettleBOT
#

Gave +1 Rep to @next portal

wicked forum
#

What was the point of the flag in task 9 of pyramid of pain? Didn't need it to prove learning in the task...

delicate pulsar
#

Hello I am stuck on Pyramid of Pain, Task 2, Hash Value. I have tried all the names I can find. Any hints? Thanks

paper cipher
#

I also had success just google searching the hash value and looking through the top results.

delicate pulsar
hazy kettleBOT
#

Gave +1 Rep to @paper cipher

violet loom
nocturne cave
#

Can you pleas just give me then answer? @violet loom

nocturne cave
#

*the

forest halo
#

Pyramid of pain, task 5, question 2. So annoying to find, but finally found it. Tip: use the hash that you can find in the picture + use OPSWAT. It will be easier to figure it out a word with 6 characters.

hoary tusk
hazy kettleBOT
#

Gave +1 Rep to @forest halo

silk pike
nocturne cave
#

Ma brother pleas give me the answer, not even one query left there that i didn’t use, the question dosnt make sense at all, its asking what fill would be read , like we can read any log file with it. Pleas give me the answer

#

@silk pike

silk pike
#

There's several places with the answer, it's even in the screen shots. You're over complicating it, I promise. Read what's it's asking you and then use context clues to find the answer. I did it within minutes of seeing your question.

paper cipher
#

Threat Intelligence Tools task 3 threw me for a loop.

#

I see the correct answer to question 1 in the screenshots, but when you go to URLscan.io, the Cisco umbrella has changed.

nocturne cave
#

Noooo nooooo i don’t believe it, it was this easy nooooooo , i was stuck with for like 3 days . Thank you my brother @silk pike

hazy kettleBOT
#

Gave +1 Rep to @silk pike

silk pike
#

😉 all good, I've done that many times

light crypt
#

Hello everyone. I need help on the ItsyBitsy room. Someone to help me in mp? Thanks you

runic totem
#

Hi all! After some help on SNORT room Task 3 this question I was sure would either be open-source or rule-based but neither are working??

#

Oh can’t upload an image but it’s Task 3 question “According to the official description of the snort, what kind of NIPS is it?”

#

“Real-time” doesn’t work either and there’s nothing else in the official description 🤔

silk pike
# runic totem Oh can’t upload an image but it’s Task 3 question “According to the official des...

Read "Snort can be deployed inline to stop these packets, as well. Snort has three primary uses: As a packet sniffer like tcpdump, as a packet logger — which is useful for network traffic debugging, or it can be used as a full-blown network intrusion prevention system. Snort can be downloaded and configured for personal and business use alike." very carefully, the answer you're looking for is right in front of your eyes.

#

Break down what NIPS stands for, it will make it easier.

unique roost
#

!docs verify

wide mesaBOT
native gate
#

I know this has been asked a few times, now, and yet I still can't find it, can someone point me in the right spot? or better yet is it a word on the page???? or a word I need to come up with????

primal igloo
native gate
primal igloo
#

But it uses the name, not the abbreviation.

native gate
#

thats where I am at right now.... cause I am not seeing it, and if I trace back, to nips, and what it falls under anothing lines up,

native gate
#

how the hell would I, or could of found that/>????

primal igloo
#

Because it's ||full-blown|| 😄

native gate
#

thank you, thank you, @primal igloo now I can get to the fun stuff,

hazy kettleBOT
#

Gave +1 Rep to @primal igloo

primal igloo
#

Happy Hacking.

native gate
abstract sundial
#

This Yara task is whooping me!!! Anyone know of a good walkthrough video that breaks it down barney style?

paper cipher
#

I’m gonna do the Yara room when I get home from work lol then maybe I can help, or vice versa

abstract sundial
#

@paper cipher I PM'd you

still pendant
rancid crater
still pendant
rancid crater
nocturne cave
#

anyone done with snort room?

pine thicket
nocturne cave
pine thicket
#

NBA training period is also known as ...

#

stuck here

nocturne cave
heavy brook
#

hey guys, im doing Windows Event Logs. has anyone ever gotten the answer to task 3.2What event files would be read when using the query-events command?

#

the answer i get is: read events from an event log, log file or using structured query.

but it doesn't match the answer format

heavy brook
#

i got it no

#

now

heavy hawk
pine thicket
heavy hawk
#

no worries, happens sometimes. So you've found it?

pine thicket
#

yes

lyric thistle
#

Hi all, anyone to help me out on task2 of the pyramid of pain, I am kinda stuck on this task though I have completed all the other tasks

heavy hawk
modest flame
pine thicket
#

what's the syntax to use two protocols in snort

pine thicket
modest flame
#

didn't see it ahah, wp bro

modest flame
pine thicket
#

ya sorry...

modest flame
#

What protocols do you want to specify ?

pine thicket
#

tcp and udp

#

all i find is syntax for filtering only one protocol

modest flame
#

Have you tried to only specify ports or others protocols ?

#

i mean i you want to filter tcp+udp on port 53, just write "port 53"

pine thicket
#

no need to filter port but need to filter only protocols

#

is it possible to filer two protocols in one line?or do we have to make it two

modest flame
#

wtf i don't get it imo

#

what do you have in your input file other than tcp and udp ? xD

pine thicket
modest flame
#

Which question is it ? in snort room?

pine thicket
#

task 9 Q4

#

letme try filtering two protocols separately

amber owl
#

Has anyone completed the OOpenCTI room, i have a dumb question that I am stuck on

modest flame
#

regarding structure of rule imo you'll need 2 lines

pine thicket
#

not working either after making it into two lines

pine thicket
#

ya it works if we change the id

modest flame
amber owl
pine thicket
amber owl
modest flame
#

this channel exists only for this :p

modest flame
#

Whhich question ? What have you already done for this ?

amber owl
modest flame
#

ahahah i where stuck on this question when i did it

#

i'll start the lab and i'm coming to help you

#

need to remember how is it ^^

amber owl
#

no worries i appreciate it

#

I took a screenshot but idk how to put it in here

modest flame
#

There is a + button juste at the left of the area where you can write

#

from here you can upload a file

#

or simply drag & drop you pic here

amber owl
#

ill open the app on my phone cuz I'm not seeing it on the web browser

primal igloo
#

You need to verify, to post screenshots.

#

!docs verify

wide mesaBOT
amber owl
primal igloo
amber owl
pine thicket
#

hey @primal igloo are u familiar with snort rules ?

modest flame
#

@amber owl have you tried to go inside "Related entities" tab ? (second on the right column)

amber owl
#

This is what I see

modest flame
#

Really strange

amber owl
#

Yeah it's been like that for me all morning that's why i was so lost

modest flame
#

We should notify ad admin cause you are supposed to be able to see malware linked to this attack on the overview panel

amber owl
#

I'm just not sure if the issue would be on the OpenCTI end, THM, or my personal end for some reason

modest flame
#

i can't find it on my side

amber owl
#

I had to restart my thm instance but once i do I'll try to see if i can find a place to make a report

#

now it won't even let me connect to the attack box instance

pine thicket
#

@modest flame i've figured it out. And yes we have to make it into two lines (one for tcp and UDP) with different id and we have to specify SAMEIP

nocturne cave
#

Hey should i do soc level 1 for blue teaming is it worth ? Or what should I do for blue teaming

verbal parcel
nocturne cave
#

Ok

bleak zinc
#

Good morning, I am on task 3 of ATT&CK Framework question "This group overlaps (slightly) with which other group?" I have the previous question answered but this one got me stumped. Can someone point me the right direction.

verbal parcel
# bleak zinc Good morning, I am on task 3 of ATT&CK Framework question "This group overlaps (...

You kind of have the answer in the information of the first group the task asks you to find.

Focus on these 2 questions:

What groups have used spear-phishing in their campaigns?

Based on the information for the first group, what are their associated groups?

Based on the answers from these questions you will find the answer for the below question also.

This group overlaps (slightly) with which other group?

bleak zinc
#

I am just reading that now and I think I have just found the answer lol, thank you Alek.

verbal parcel
bleak zinc
#

Yea, I do a lot of reading and I somehow missed it. Like you said back to square one and read everything ;).

verbal parcel
bleak zinc
verbal parcel
#

the important part is to understand it, not finish it fast 😄

pine thicket
bleak zinc
hazy kettleBOT
#

Gave +1 Rep to @forest halo

unreal zenith
#

Hey all, anyone here who works as a SOC analyst, trying to make a move into SOC from AppSec and looking for a mentor who can provide some insights 🙏

vagrant ledge
frigid slate
#

I am working on task 7 of the snort section and I keep getting an error after I run snort and try to run traffic through it. S5: Session exceeded configured max segs to queue 2621 using 2621 segs (server queue). 10.100.1.33 44484 --> 10.10.248.173 80 (0) : LWstate 0x40 LWFlags 0x2101 Has anyone else gotten this error?

nocturne cave
#

I'm working through Threat Intelligence Tools, and when downloading the .eml file on task #7 my antivirus is picking it up as a trojan, anyone else had this issue?

pine thicket
#

is there something wrong with WindowsForensics1 Task-9 Q.1 which keeps on saying `incorrect'?

#

ahhh it's B...nevermind instead of B i wrote as 8

pine thicket
nocturne cave
#

Yes.

#

Should I download it onto the attack box? The way it’s laid out I download onto my local machine.

#

@pine thicket

pine thicket
#

Well if you download malicious file to your main machine and got an AV, it's gonna say THIS FILE IS FOUND MALICIOUS and that's what AV is for.Ya you should use your VMware or attack box

nocturne cave
#

lol. Should have known. Thanks.

empty kite
#

room Yara, Task 5. there is no red or green boxes notsure @scenic token

marsh inlet
#

Yo, I'm trying to download the document for analysis from Threat Intelligence Tools Scenario 1 and the system keeps refusing to download on my machine what do i do?

nimble oasis
#

they are meant to be solved on the target machine as that poses no risk

hazy kettleBOT
#

Gave +1 Rep to @nimble oasis

nimble oasis
#

still it will be the minimal amount of malicous file but you never know how your network and antivirus would react

#

or your computer

marsh inlet
#

i have to analysis it so makes no sense reallty

#

*really

#

Never mind.. fixed it\

pastel stump
#

If I wanna study for the Security+ certification exam, should I be doing the SOC Level 1 learning path?? or do I try and do both?

sinful cloud
#

I’d stick to the security+ path. It’s not overly complex but you definitely want to focus and make sure you pass and not have to pay the exam fee twice

fringe quiver
#

@scenic token
pyramid of pain task 4 asks for the first malicious domain per anyrun, but since anyrun gives suspicious/malicious as different categorisations, the expected answer doesn't match with what anyrun would suggest is the best match.

nocturne cave
pastel stump
pastel stump
hazy kettleBOT
#

Gave +1 Rep to @tulip gull

nocturne cave
hard valley
#

Hi all, stuck in Threat intelligence tool taks 5..... how to access the phishtool in the VM? it has no internet connection out

pastel stump
hazy kettleBOT
#

Gave +1 Rep to @tulip gull

nocturne cave
nocturne cave
pastel stump
empty kite
#

Sysinternals Task 9, what is mistake? vm don't have D:\ disc, i try command prompt and PS

lavish sun
#

Hy Everyone! I need help in snort challenge room. I’m on Task 2 - Writing IDS Rule and Task 3 FTP Rule.
What is the SEQ number of packet 62? Write rules to detect "all TCP port 21" traffic in the given pcap.

What is the number of detected packets?

nocturne cave
#

cannot connect machine to internet on Task 5 of Threat Intelligence tool? cannot access any website or even run update to fix the issue. Any solutions?

#

tried creating machine multiple times, but same issue, any mods here?

nimble oasis
indigo dragon
hazy kettleBOT
#

Gave +1 Rep to @undone bridge

jovial tulip
#

Is it better to start with cyber defense path or this one?

nimble oasis
regal relic
#

hey guys i am stuck in opencti room under soc level1 path, my machine browser wont access opencti ??

#

any idea how can i fix that

random blaze
north viper
#

I'm really struggling on the snort section of this path, rules don't seem to give results I need. Can someone help with the initial start of the snort basic challenge?

compact karma
north viper
#

@compact karma I got it eventually, thanks

hazy kettleBOT
#

Gave +1 Rep to @compact karma

vast delta
#

"You can use the "base64" tool. Read the log/alarm files and extract the bas64 command. base64 --decode filename.txt"

Any help what command can I use ?!

I don't want to use the manual way.

#

room Snort Challenge - The Basics

frozen compass
#

@nimble oasis

north viper
#

So, writing IDS rules(PNG) for the snort challenge "basics". In quotes because it's been a slog! I'm trying to find the software name embedded, managed to find a hex signature for PNGs to put in my rule, but I'm not getting a log to search through. Any help please? Am I the only one who has struggled hard with some of this room!

fringe quiver
north viper
primal igloo
#

Free paid games?

#

Oh sure.

#

@hidden aspen can hook you up, she is an iOs guru.

crystal steepleBOT
#

:hammer: HyperTrizzz_#2935 has been banned.

hidden aspen
#

thx @primal igloo 🙂

hazy kettleBOT
#

Gave +1 Rep to @primal igloo

north viper
queen willow
junior viper
#

@scenic token I'm currently in SOC level1 path on task 9 of cyber-kill-chain. I believe you built this. Can you please give me a hint towards solving this? I've researched CKC and attempted different things but I'm still having trouble. Thank you. and Happy New Year. EDIT: I reloaded the page and re-entered everything and it finally worked!

hazy kettleBOT
#

Gave +1 Rep to @scenic token

lavish sun
austere bear
#

could someone plz highlight the error?>

#

why its not working

#

?

fringe quiver
# lavish sun Nope 👎

So if you make a standard alert type rule for tcp 21 (the FTP data port) with a "-l ." (That's lower case L for log, and a dot for current folder)

You can use the -r flag to replay the saved log through your created rule file, but use a -n <number> flag on the end to tell it to stop processing after -n packets.
That way the last packet displayed should be packet <number> and you can read the sequence off that.

#

According to my notes, it's Task 8 of the Snort basics room that explains the flags you need so you can have a little more in depth resources.

glad hinge
#

Hi colleagues, am stuck in snort challenge task 3 (failed FTP login attempts) i wrote the rules and see the log file created but it disappears in in seconds, any idea what am doing wrong?

lavish sun
hazy kettleBOT
#

Gave +1 Rep to @fringe quiver

winged charm
#

Anyone in the Yara room. Im kinda stuck on task 8.6 and task 8.8. When I check the file2 it states it is clean

nimble oasis
#

oh wait never mind that is later

nimble oasis
#

the hints will maybe help too

winged charm
#

Okay thanks. Il try that

winged charm
nimble oasis
winged charm
#

The only file I see is metaslsoft.php that is shown in the result. is that it?

nimble oasis
sharp hare
#

I've done the first machine task, answered all questions correctly but still not able to proceed. Someone help

olive jasper
#

So I am in Pyramid of Pain task 5, and the 2nd question says use the tools introduced in task 2 to be able to name the malware associated with the IP address that the victim system was trying to connect to. I have tried searching in virustotal and OPSWAT utilizing the IP address, those both came up empty. Then I tried using the MD5 hashes of the modified files to do the search, also turning up nothing. Looking for a hint here.

brazen sandal
#

@olive jasper just took a peak, the answer is present but you won't find it jumping out at you. 1. what might the suspicious process execution suggest? 2. did you check for relations to the suspicious IP?

olive jasper
hazy kettleBOT
#

Gave +1 Rep to @brazen sandal

nocturne cave
#

!rank

polar crystal
#

could somebody explain the direction of the flow in the snort rules -> <>, because the official documentation doesn’t help me much. I don’t understand why we need to create two rules in order to catch HTTP traffic ( any any <> any 80 and any 80 <> any any )

#

I thought that bidirectional(<>) means the request and the response, which goes in both directions

#

And I though that alert tcp any any <> any 80 would be enough to catch all HTTP port 80 traffic

fresh karma
#

I'm doing the Phishing Analysis Tools, Phishing Emails 3 "What is the From email Address?" I found the email address, however there is no way to copy that long email address into the regular window and the VM has no internet? Any thoughts?

zenith jackal
#

Hello everyone, I need some help with Task 2 - Writing IDS Rules (HTTP) in SOC Level 1 Snort Challenge - The Basics...... On the first question "What is the number of detected packets?", I get the answer 164. However, the right answer is 328, but I don't understand where they get that from! I would be very grateful if someone had an idea...

polar crystal
#

Are you using bidirectional flow? aka <> for both of your rules

zenith jackal
#

no, I used "any 80 -> any any" in the first one and "any any -> any 80" in the second rule

polar crystal
#

Now try to use<> in botg

zenith jackal
#

It worked! Thank you very much!

polar crystal
#

Yeah, that's weird, I'm still struggling with the direction of the flow, don't get how it works properly

zenith jackal
#

Nor do I, unfortunately... 🙂

desert sky
#

Anyone having issues with rdp to windows machines? I am unable to connect to windows vm from my local machine nor from the attackbox

primal igloo
nocturne cave
desert sky
desert sky
primal igloo
desert sky
#

Ohh no, but is it possible to have a vm on the machine to be on VPN??

primal igloo
desert sky
#

Ok will try that but for the connection, it doesn't work in attack box as well. With remmina, its asking for password for some login key ring. If I cancel it, and it says can't connect to RDP server.

primal igloo
junior viper
#

Can someone help me with task 7-scenario 1 of the threat intelligence room?

nocturne cave
#

sure, are you still there?

junior viper
#

i figured it out. Thanks though

fresh karma
hazy kettleBOT
#

Gave +1 Rep to @olive jasper

nocturne cave
#

Hello, i am at task 5 in Splunk (SIEM). Its about to find the correct password due to a successful connection. My way to it was actually to use the field "SPOILER ALERT" || "connection-type"|| to distinguish successful or unsuccessful connections. Would you reccomend another field or use the same?

heavy barn
#

In Room "Threat Intelligence Tools" in Task 5 "PhisTools" the VM has no connection to the internet, so im not able to analyse email1. I dont have a chance to get this email1... Any Recommendations?

junior viper
languid geyser
#

If you're ever searching for help with the Snort "According to the official description of the snort, what kind of NIPS is it?" You're going to be upset when you find out what it is..

primal igloo
tame ore
#

unable to generate wazuh reports as the two agents are showing disconnected

grand swallow
#

hi guys, did anyone have issues with network service room with the question of "What would be the correct syntax to access an SMB share called "secret" as user "suit" on a machine with the IP 10.10.10.2 on the default port?". My answer is correct according to THM but when putting it into terminal , I keep receiving error of that syslog is deprecated and the host is unavailable

#

Is there anything I can do to fix this?

golden oyster
#

hey

#

why my answer is incorrect?

golden oyster
#

Name room is TI tools

primal igloo
#

Can you link the room?

golden oyster
#

task 5

primal igloo
#

3/4 octets has 4 characters.

#

It's asking you to defang it.

golden oyster
#

lol kek

#

its easy

#

sorry

#

@primal igloo I didn't understand what needed to be done

#

thx

livid cosmos
frank glade
#

Hi, I have some issues with Yara, when I type touch somefile then myfirstrule.yar it say command not found

polar crystal
#

touch somefile them myfirstrule.yar?

#

just do touch myfirstrule.yar

frank glade
#

ok thanks

nimble oasis
#

if you want a response here is one... shadow has not done this path yet so no clue what is wrong or how to answer your question

raven cedar
#

Is anyone having trouble finding the correct answers in Pyramid of Pain (Task 4 and 5)? I'd think the information could be better to find the malicious URL request...

limber cobalt
#

Hi All, I can't start Sysmon on VM : Sysmon.exe -accepteula -i ..\Configuration\swift.xml Any idea ? Thanks !

spiral flame
raven cedar
hazy kettleBOT
#

Gave +1 Rep to @spiral flame

frank glade
hollow cairn
#

I need help with something

spiral flame
dire bridge
#

Hi, currently working on the Snort room, Task 6, I'm not sure as to why I'm not able to run the commands given on the introduction "sudo snort -dev -l" to run the task for answers it keeps telling me that the "-l" requieres an argument, but there is no mention of any of this in the instructions, any help anyone can give me will be greatly appreciated. UPDATE I found a walk through of the lab and I was able to troubleshoot the issue.

spiral flame
# raven cedar Is anyone having trouble finding the correct answers in Pyramid of Pain (Task 4 ...

also, I just finished task 5 for Pyramid of Pain.... for Task 5 questions 2 and 4 (tryhackme says to use google as the hint) I found this link that answers both those questions. The link is a page from app.any.run. From this page you will need to look for: 1) the file name .... and 2) the threat name .... to answer questions 2 and 4 from this task. Hope that helps! https://any.run/report/e2d2ebafc33d7c7819f414031215c3669bccdfb255af3cbe0177b2c601b0e0cd/90b76d7b-8df6-43c5-90ec-d4bbcfb4fa19

raven cedar
raven cedar
hazy kettleBOT
#

Gave +1 Rep to @spiral flame

turbid cypress
#

I'm struggling with understanding Yara, yarGen, in task 9. I had the correct command to compare the generated yara file to 1ndex.php. I leveraged the commands from task 8 to run Loki against 1ndex.php and see the similar results as completed in task 8. I'm curious why this same approach, in the same directory, created the same results as in task 8, or before yarGen was run. Any help would be greatly appreciated. #soc-level-1-path

turbid cypress
#

I revisited the Yara task 9, moving the file2.yar file into the required Loki folder and ran the task 8 command with sudo privileges. @frank glade #soc-level-1-path

frank glade
#

I don't get it

turbid cypress
#

review the spaces in the hint for Yara task 9. there's a command. Then there is a file name. Then a file location. @frank glade #soc-level-1-path

light crypt
#

Hello all! In the room Snort Challenge - The Basic, task 2, question "What is the number of detected packets?", I can'i answer this question. My rules are OK. someone can help me? thanks

junior viper
#

I'm in the sysinternals room. When I click the green Start Machine button, it does not open in a split screen. And there is not a blue Show Split Screen button at the top. How can I access the machine? I am on a mac.

chilly trellis
#

Are you connected to the VPN?

fringe pivot
#

Hello,

I'm doing the redline room and trying to import the analysissession1 to redline after running the script as admin privs. Im getting unknown error and opening it only shows me:
Timeline
Tags and comments
Acquisition history

While creating the script i edited it as the room states. Nevertheless due to the error in importing all the information needed to complete the task. (For example System information) show as not collected?

Anyone got tips or tricks for this. I noticed that the VM Local disck is really full so could that be effecting my issue?

junior viper
# chilly trellis Are you connected to the VPN?

No, I wasn't. I had to open the terminal on the linux attack box and use the command "remmina" to rdp into the windows box. but it was very tiny and I was unable to enlarge it. But PTL I was able to finish the room and progress. Thanks for your response.

hazy kettleBOT
#

Gave +1 Rep to @chilly trellis

chilly trellis
#

Also, sysinternals is a paid room isn’t it? I have to search each time because I’ve been on paid membership for years now, but you’re on paid right?

junior viper
chilly trellis
#

I’m not certain as to why you would have issue, unless something something browser configuration or non-paid attempting to use the attackbox more than 1x/day

#

In retrospect, I don’t think it would be relevant if the VPN were used or not, but I could be incorrect

#

Nonetheless, you’ll have to share your adventure with us and I sincerely hope you succeed!!

#

(In all fashions, but specifically Sec+ in this instance 😊)

native gate
#

Pushing my way through the snort rooms. Lol took longer then I expected.

raven cedar
#

Hello, the section for URL.scan.io doesn't have the correct information such primary domain. The correct answer can be found onder the section "domains" but I also noticed that the main IP of tryhackme.com is changed on urlscan.io keep this in mind! Have great day all

cunning tide
#

I'm really liking this path

royal crest
#

Just got through the Yara room. 🥴 Gonna need to do more research on this lol it was a tough one for me.

nocturne cave
#

hello guys, complete discord noob here. nice to meet y'all

torn marlin
#

starting journey toward cyber security any advise, help.

nocturne cave
#

just start i think

#

if anybody in here wants to learn together cybersecurity hmu

grand mulch
#

Hey all, I think my mind is playing tricks on me. I am currently in the Threat Intelligence Tools > Abuse.ch >Q1 and I cant find the IP in the list on threatfox. I have all of the other questions answered but for some reason searching the IP or cntrl+f the IP brings up nothing. If anyone could point me in the right direction I would really appreciate it. I will check in after I get back from the job I am super late too! Thanks in advance

quiet lintel
royal crest
grand mulch
hazy kettleBOT
#

Gave +1 Rep to @royal crest

quiet pollen
#

Does the Soc 1 path correspond with any certs? BTL1 or Cysa+?

mint breach
#

Hey guys. I am doing the SOC 1 path and I'm at the last task where I have the assign the correct statements to each level of the Pyramid of Pain. I am positive that I added them correctly, but it won't complete it. I googled it and there are statements saying that that part is broken. Is it right?

primal igloo
mint breach
hazy kettleBOT
#

Gave +1 Rep to @primal igloo

agile blaze
narrow totem
#

Hello guys currently doing the SOC level 1 course but have some difficulty on the Pyramid of Pain I don’t clearly understand how it works or how I should understand it
Can anyone explain it simply to me please ? Thank you

elfin flint
#

I'm having a problem with Pyramid of Pain --> Host Artifacts (Annoying): why the question 3 and 4 are exactly the same but won't accept the same answer?

elfin flint
nocturne cave
#

Question 4 is looking for a different file name than question 3. I do agree that the question could've been worded better.

#

There's also a hint button there, that kinda helps.

narrow totem
mint breach
slender fern
slender fern
# narrow totem Hello guys currently doing the SOC level 1 course but have some difficulty on th...

I think the whole point of the Pyramid of Pain is for us to understand (as a Defender) how much it IMPACTS the attacker when we're able to detect the kind of attack they have executed. Like for Hash Values - it's on the lowest level because once it's detected by the defenders, it will only take the attackers a short amount of time to recalibrate/re-strategize their attack, unlike the higher levels were the attackers might need a lot more time to re-strategize and maybe even create a new way/tool to execute their attacks. Something like that.

mint breach
nocturne cave
narrow totem
hazy kettleBOT
#

Gave +1 Rep to @meager dragon

elfin flint
#

I'm stuck in the Pyramid of Pain room, at Task 5 (Host Artifacts).

#

I got questions 3 and 4 exactly the same, but won't accept the same answer.

nocturne cave
nocturne cave
#

For Threat Intelligence Tools, Scenario 1: "From Talos Intelligence, the attached file can also be identified by the Detection Alias that starts with an H..."-
How do I obtain the hash of the email attachment of Email2.msg in the room machine? Is it a bash cmd or smth in Thunderbird?

nocturne cave
hazy kettleBOT
#

Gave +1 Rep to @meager dragon

vast delta
ornate canopy
vivid flicker
scarlet kraken
#

yo

limber anchor
#

hello here i have a question

nocturne cave
#

Hello, I have a question re: Snort Live Attacks Task 2 Question 2 & 3: "What is the name of the service under attack?"
I managed to stop the attack by using Snort in sniffer mode, then writing a rule based on what was observed, and blocking the malicious traffic. (I included the flag.txt in the screenshot below.)
But I don't understand why the answers to Question 2 & 3 are not http or 80, but rather ssh or 22, when all of the traffic I blocked was to port 80 and not 22, and looking through 40+ packets, I don't see any sign of ssh.

lean pilot
#

hi

#

i want some hep about one flag

nocturne cave
#

whats the flag? :D

lean pilot
#

I can't insert an image here

#

May I send the link?

#

they ask me to Execute the command from Example 8. Instead of the string Policy search for PowerShell. What is the name of the 3rd log provider?

wise slate
#

hey

#

can any one teach me cyber hacking

#

?

#

?

terse rain
#

-unmute @wise slate Please do not spam the same characters

hazy kettleBOT
#

🔊 Unmuted Why do i exicet#8195

nocturne cave
# lean pilot they ask me to Execute the command from Example 8. Instead of the string *Policy...

task 4 links to a doc at the top of the page: https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.diagnostics/get-winevent?view=powershell-5.1
scrolling down to example 8 you'll see this. im sure ull be able to figure out what to do from here :D

nocturne cave
#

Hey guys, I am trying to do the "Splunk Basics" room to prepare for a very important interview. The only problem is that I am not able to open Splunk... I am not sure how to do that. I opened the Kali Machine and that's it. I am new here so don't judge me 🙂 Can someone help? 😦

gritty bison
#

im trying to complete the sysinternal how do i connect to the vm?

fierce nest
fierce nest
fierce nest
#

In task 2 Connect with the Lab, click start machine, wait a minute then you'll get an ip address

muted flare
timid adder
#

In the Incident handling with Splunk room, Reconnaissance phase section, I just cannot find any information related to "What is the web scanner, the attacker used to perform the scanning attempts?". ||I know I suppose to find it in user-agent, but after look at http_user_agent list, I don't see any abnormality||

woeful stirrup
#

I'm planning to take the CYSA+ exam. Would taking this path be a good primer for taking the exam? I'm trying to find somewhere that I can get practical hands-on knowledge.

weary lake
#

In the OpenCTI section (OpenCTI Dashboard 1), the URL link does not work.

tame sparrow
#

Hi everyone i have one question for SOC Analyst job. What skill set should one Junior SOC Analyst have in order to land a job as a SOC Analyst?

pale ginkgo
pale ginkgo
tame sparrow
hazy kettleBOT
#

Gave +1 Rep to @pale ginkgo

pale ginkgo
olive mesa
#

Ha

#

😎

nocturne cave
#

You type out your emoji's lol?

olive mesa
#

nooooo...

#

Why would I do that

nocturne cave
#

I saw the 8)

#

B)

#

than you edited

olive mesa
#

definitely not

#

you're seeing things

nocturne cave
#

oh weird.

#

i am

#

it went from "B)" to the emoji

olive mesa
#

weird

#

must be lag

nocturne cave
#

yup

#

must be

olive mesa
#

maybe

#

maybe the whixijoklial widget spun too fast

#

¯_(ツ)_/¯

tame sparrow
orchid pollen
#

im just trying to get into a SOC and stay there

verbal parcel
#

SOC is usually an entry level job in cybersecurity, at least level 1 is, there are a lot of companies who hire only people who have at least some IT background experience but heard stories of some companies hiring without it also, not very often tho...

As for being easier to move over to pentesting after, very possible because you get a lot of knowledge doing SOC operations, you need to learn from both sides, you can't actually defend without knowing how attacks work, but you can also specialize on the defensive side of cyber, to advance and evolve in it also, incident response and so on...

#

They key is to start from somewhere, practice and keep learning and with time you will find out in what direction you will want to go next, or even if cyber is actually for you or not...

orchid pollen
#

please point me in the direction of these socs

verbal parcel
#

direction of getting hired or learning directions?

orchid pollen
#

i guess hired?

verbal parcel
#

well depends as i said of your background experience, certificates, knowledge

#

But if you already have these and feel confident you can start with a linkedin profile

orchid pollen
#

i could show you my resume and linked in

verbal parcel
#

Or other job seeking sites locally in your country

#

Well it's always a good start with a linkedin profile, it mostly is one of the best ways nowadays for IT folks but not only...

#

Start following cyber domain related things and build a network gradually, seek to improve the profile by scouting others and with time opportunities will come also, and most importantly, never stop learning, take breaks, as long as you need them, but never stop...

#

It never ends

orchid pollen
#

currently doing this path to touch on splunk, and snort since all places are recommending SIEm experience

verbal parcel
#

yes it's kind of mandatory

#

and splunk is a great resource since a lot of them are using it

orchid pollen
#

as for work, im in the cyber division but i just apply patches and updates to vmware,linux,windows

#

just trying to level myself up

verbal parcel
#

it's a big advantage to work in the domain, it makes things way easier

olive mesa
#

hello

verbal parcel
#

But keep in mind guys it depends also on the company you are gonna work for, their expectations and SOC architecture, Security architecture as a whole, the first thing you need to see is their job description and after have a talk with them, because there are a lot of companies that offer SOC Analysts jobs and don't actually specify what level of experience they want, some of them want more incident response experience, some just some IT background and experience, some are impressed maybe by a cert or a completions of some sort, so it varies a lot depending of the companies needs, location, culture and so on, just fyi...

#

I mean don't get discouraged if you go through some interviews were you will get rejected or something...

tame sparrow
verbal parcel
# tame sparrow Yea thats normal but in your opinion what are jobs below SOC analyst (the ones t...

hmmm not aware of any cyber jobs under SOC level 1 but saw a lot of people coming from other IT position, like IT Support for example, Operations sides and so on, i myself come from an IT operations side so i guess any prior IT experience could be good, but as i said, depends on the position you are gonna get hired, the companies expectations and security architecture but this is kind of the general consensus, at least from my experience and knowledge...

tame sparrow
verbal parcel
# tame sparrow Tnx Alek for sharing that now i know but i wanted to ask you one more question �...

Well firstly as i already said, some IT background experience would be an advantage, whatever that is, support or operations or whatever...

Related to courses or certs or any other kind of cyber training this would be an advantage also of course but in my opinion some IT background or real experience would be way better.

In the end SOC L1 is an entry level job so besides the companies that falsy promote a SOC analyst job and have different expectations, you shouldn't have any problems in nailing such a job with minimum experience and knowledge in the domain.

tame sparrow
hazy kettleBOT
#

Gave +1 Rep to @verbal parcel

cinder pike
#

hey all, im on pyramid of pain and does anyone explain what is the meaning of "dropped binary"?

muted flare
hazy kettleBOT
#

Gave +1 Rep to @muted flare

compact harness
#

Hey guys not sure if I'm doing something wrong or is it broken, but I'm on the CTI email phishing part and it says I need to use phishtool to scan the email1.eml, but the virtual machine seems to have internet disabled

#

Is there something wrong on my part or am I completely misunderstanding the task?

acoustic spire
fathom saddle
nimble oasis
nimble oasis
acoustic spire
sweet inlet
#

Hello everyone, I've been trying to finish the room Mitre for two days now. in task 5 the engage site does not work correctly for me, the page is displayed, the tabs etc but when for example I click on prepare and plan as requested it does not work? it seems buggy, I tried with different browsers 😟

haughty vine
clear sail
#

hey guys , ive solved the whole room except this question .. i got the answer but i cant tell what is the right format. the question on task 4 Provide the BIOS Version for the workstation.
i got the answer : INTEL - 60440000 PhoenixBIOS 4.0 Release 6.0

#

anyhelp please

#

@pure nova

sweet inlet
hazy kettleBOT
#

Gave +1 Rep to @haughty vine

clear sail
#

like hello

clear sail
#

@oblique locust

pale ginkgo
clear sail
clear sail
clear sail
clear sail
pale ginkgo
clear sail
nocturne cave
#

Snort time ! Currently working on Network Security & Traffic Analysis module

fickle talon
#

I am facing some issues in the redline lab. For IOC Search collector, when i try to generate a report, I get "There is not enough space on the disk". Anyone know a fix for it ?

pliant crag
#

I am stuck in a room for the SOC level one, its the ATT&CK® Emulation Plans section on the sandworm question, it does not like they way I am typing the answer??

nocturne cave
#

Anyone getting this error when launching ICMP traffic script ? Snort Room Task 6

#

[Fixed] added sudo

nocturne cave
pliant crag
#

@nocturne cave thanks I finally got it yesterday 🙂

hazy kettleBOT
#

Gave +1 Rep to @pale plaza

royal crest
#

Sysmon room TASK 6 directions say to open Hunting_LSASS.evtx but it’s not on the Desktop in the Practice folder??

sinful nimbus
glass fog
#

For anyone who was having an issue with the Mitre Engage website to complete task 5 in the Mitre room of the Cyber Defence Frameworks module, the site is now working again so you should be able to complete it

royal crest
hazy kettleBOT
#

Gave +1 Rep to @sinful nimbus

nocturne cave
#

Snort dropping packets

nocturne cave
#

Day 5 of attacking Snort room. I'm definitely putting this on my resume. A newly attained skillset, if you can get through the snort modules and develop your rule writing skills it can be beneficial

paper cipher
#

Has anyone who has completed this path found work in a SOC, or similar role?

I just finished this path, and am going to begin a job hunt soon. Looking for some advice as I am currently not in the tech field (I’m a teacher) 😄.

plush plume
#

Gerald Auger from simply cyber released a video about Soc related interview questions, i can't tell if it's good but i enjoy his content so i'd give it a try

paper cipher
hazy kettleBOT
#

Gave +1 Rep to @plush plume

paper cipher
#

While I'll definitely do some interview question prep, I'm currently more concerned with how to get a SOC or SOC adjacent interview first lol

nocturne cave
nocturne cave
#

Snort is another level of security.

nocturne cave
#

The firefox of the VM of the task 5 PhishTool for the Threat Intelligence Toools does not work

fierce cypress
#

Snort Challenge - Live attacks (brute force). How do you justify it being SSH. It could be port 80 because there is traffic back and forth in port 80 so can it not be brute for on a login page? .There are more packets from port 80 than port 22.

plush plume
#

you can see the traffic on port 80 though

#

actually read it

#

so if it's not a ton of passwords tried in short succession it's most likely not a bruteforce

quaint badge
#

Hello guys anyone having problem with accessing the web when you deploying the machine in Task 5 Phishtool from the room Threat Intelligence Tools

quaint badge
nimble oasis
#

sigh

#

@quaint badge @nocturne cave

#

you are not meant to use phishtool

#

that was just an example of a tool you can use

#

you are meant to use thunderbird that is on the target machine to solve the questions for the remaining tasks

#

and/or copy the hash from the target machine to plug into some of the sites that are given too

#

you are not mean to copy the emails or eml files over

#

as those actually contain malicious files if you check the hash on virustotal

nocturne cave
#

Ok, thanks 👀🫡

nimble oasis
#

no problem

#

this is just the 34th time someone makes this mistake

quaint badge
hazy kettleBOT
#

Gave +1 Rep to @nimble oasis

quaint badge
nimble oasis
quaint badge
hazy kettleBOT
#

Gave +1 Rep to @nimble oasis

nocturne cave
#

woot woot! just finished Snort room

#

great room, great resources! Thanks @radiant knoll

hazy kettleBOT
#

Gave +1 Rep to @radiant knoll

nocturne cave
paper cipher
# nocturne cave

Congrats! It was my favorite room, but also the one that stressed me out the most.

nocturne cave
#

Now i look forward to the Snort-The Basics

#

gonna teach me how to analyze and stop malicious traffic with Snort ! this atta be good !

#

Also the resrouces and Cheat Sheet they provided. This is unmatched

nocturne cave
paper cipher
#

What did you guys put on your resume about Snort?? Shamelessly asking so I can add it to mine 🙂

nocturne cave
#

I'm putting it under my skillset then taking it to Zojja in Careers channel and see what she tells me there

#

But then again, this isn't until I'm done with all the snort modules and I have implemented my own snort rules and detection system on my own internal networks and systems

#

I have one for Ubuntu WSL2 running already as a live feed

#

Also going to add my write ups for this. I finally edited and created one of the many write ups I have from THM

#

Quick sneak peak of my write up for Snort-The Basics

#

Still editing in progress

royal crest
onyx garden
sinful nimbus
sinful nimbus
royal crest
hazy kettleBOT
#

Gave +1 Rep to @sinful nimbus

sinful nimbus
#

Sure, no problem.

nocturne cave
nocturne cave
#

have it running on the background

#

for any ICMP packets

#

THM is unmatched i tell ya

nocturne cave
#

Network Miner let's gooooooooo

#

Very legit

nocturne cave
#

I'm on the network miner room and saw these sneak peak rooms coming soon!

plush plume
#

😍

frank orbit
#

Hey all, can somebody confirm that the pyramid of pain practical is broken?

shy badger
#

Hello. I want to learn a lot.

plush wharf
#

i

sinful nimbus
sinful nimbus
hybrid vector
frank orbit
#

Aight thanks 🙂

nocturne cave
normal anvil
#

I’m repairing eCIR exam dose #soc-level-1-path useful to make me pass in the exam ? Or I need to make another practice ?

nova spade
warped urchin
warped urchin
fossil temple
#

/

nocturne cave
#

Hi all I seem to be stuck on SOC sysinternals task 5

#

I have used who is, but the answer is definitely not what I am getting either microsoft or INAN

dawn wedge
#

Hi i would like to start my career as a SOC analyst level 1 suggest me a roadmap to do it ?

worn dawn
nocturne cave
#

I've been sleeping on Wireshark THM room

#

When i first started on THM I was focused mainly on the basics and web fundamentals stuff but never really dipped into the Blue Team paths of THM

#

Love how this room is showing me how to extract files from captured PCAPs

#

and using my terminal combined

#

SOC Level 1 path is Odin sent

#

I am cyber network bender

#

A question a day keeps the memory at bay

terse rain
#

TryHackMe loves you too @nocturne cave

nocturne cave
#

It's pretty awesome! Cause now i got in the habit of running wireshark everyday in the morning and dropping the made PCAPs into Network Miner, which is another amazing tool that THM introduced.

nocturne cave
#

Check this out

#

Got Snort running on my local WSL2

#

just pinged my machine for icmp packets and my Snort rule picked it up!! 😅

#

Heres' the Snort rule i created for it. Go in the /etc/snort/rules/local.rules

#

alert icmp any any -> $HOME_NET any (msg:"testing ICMP";sid:100001;rev:1;classtype:icmp-event;)

#

should also work for Kali Linux (non wsl2)

tired trail
#

Hello, I am doing the pyramid of pain Task9 and it always says I got the answer wrong....I checked the previous comments about this matter but seems to me it is still buged ? Correct me if I am wrong

Is there any way to find out if I got the answers correct or not?

fresh socket
#

Looks like I am not the only person having issues with Sysinternals - Task 5 - Networking Utilities (https://tryhackme.com/room/btsysinternalssg) with the answer not taking the correct whois org.

@alpine lintel, maybe could shed some light on it?

alpine lintel
fresh socket
hazy kettleBOT
#

Gave +1 Rep to @alpine lintel

nocturne cave
#

Wireshark provides IP Geolocation mapping !!

tired trail
#

Good morning from spain, I have a question, since I am doing this soc-lvl-1 path does anyone recommend me to do the OWASP top10 room? Or is that toooo advance and I should look into it when I am done with this path?

nocturne cave
#

OWASP Top 10 primarily serves as a roadmap for red teamers path

sinful nimbus
#

Hello All,

Did anyone find an issue with the redline report on the Intro to Malware Analysis Room or am I just going to the wrong link lol

empty cradle
#

I am new to this

nocturne cave
empty cradle
#

Sir I have started my journey i have completed my ceh

#

I want to learn soc analyst role and responsibilities

nocturne cave
#

!docs verify <-- to get verified

wide mesaBOT
#
TryHackMe
That topic does not exist!

Use !docs to list all of the available topics.

nocturne cave
#

!docs verify

wide mesaBOT
empty cradle
#

Ok

nocturne cave
#

If you have CEH you can also get a role on here

simple raven
#

Anyone able to access Mitre Engage? Trying to complete the MITRE room but the page is just timing out for me

fresh socket
#

When ive had issues with the room connecting, I terminate it from the split view and restart the machine, sometimes its been 2-3 times

raw sandal
#

anyone done the threat intelligence tools section yet, im confused and not sure if its me or a bug.

#

i got an email address and i need to know the originating IP address of the email address and yet i cant seem to find it anywere

#

the ubuntu OS VM on tryhackme has no internet access by the seems either

terse rain
#

@raw sandal We don’t use the r word here

raw sandal
ember quiver
#

Can the Soc Level 1 path help to get a job in Cyber Security

ember quiver
#

Hello

fiery path
primal igloo
#

For anymore help, ask in #room-help

If I don't help, someone else will. 🙂

#

Or this channel, Ithought I loaded in General.

bold mason
#

Finally got this the a few weeks back after going at it on/off for months! Very solid path! Those Snort cheat sheets, good stuff guys!

ember quiver
zenith oriole
#

Righto onto the next learning path. SOC Level 1 hopefully I get to learn a lot about defence so I can defend myself and beat back attackers. Very excited to start this path. Good luck to anyone also on this path! I'm super happy to be on the same path as you guys!

zenith oriole
#

Do Junior Security Analyst part of a Security Operation Centre really use all the kill chain frameworks, diamond model and MITRE? When do you use them? Are they used for different reports like the diamond model is more for the manager and the Unified Kill Chain is more for ticketting detections to triage them up the chain of command.

#

Or do Security operation centre peps just use one to organise tickets but it's different depending on the company.

lavish mica
slow marsh
#

I'm in the Yara room doing the Valhalla task. I need to donwload contents of file1 and file2. I established connection to network using OpenVPN. I can ping the machine. I used 'tryhackme' as user to ssh and 'tryhackme' for password but getting denied. I used my own creds but also getting denied. What am I missing?

silk carbon
hazy kettleBOT
#

Gave +1 Rep to @silk carbon

zenith oriole
#

In the Threat Intelligence Tools room do I really have to setup and OpenVPN connection to the attack box just to download 3 files?

#

"Use the .eml file you’ve downloaded in the previous task, PhishTool, to answer the following questions." I can't access the Internet through the attack box, so I can't do anything with the .eml files apart from open it in a text editor.

short rivet
#

Anyone herewho have good knowledge of splunk?

#

Need some help

primal igloo
#

Just ask. 🙂

zenith oriole
#

If anyone else is struggling a lot with downloading the email files from room Threat Intelligence Tools. A super scuffed solution is to open them in a notepad tool and carefully copy and paste all the text into your own text editor and save it with the same file name.

half arch
#

Hello!
Can someone just give me a brief comment on what is the difference between these two snort rules sets?
alert tcp any 80 > any any (msg...) alert tcp any any > any 80 (msg...)
and
alert tcp any 80 <> any any (msg...) alert tcp any any <> any 80 (msg...)
These two sets give different results, but I can't really understand why. Seems like two first rules are the analogy to " <> " direction in the second set, but I know I'm wrong

#

Nevermind, I got it, just needed to structure my question I guess

left hedge
#

It's probably been addressed but the URL in https://tryhackme.com/room/itsybitsy for the last 2 flags seems to have expired. I was only able to answer those 2 questions from a walkthrough

slender lichen
# primal igloo Use Thunderbird.

please could you elaborate? if I open Thunderbird it asks me to set up an account, but that cannot be done since the internet cannot be accessed through the attack box.

primal igloo
slender lichen
#

that I can do yes, but I'm unable to use the phishtool to analyse the email as the task describes

#

as in upload the email onto phishtool

primal igloo
#

Which you can't do, as the VM doesn't have an external internet connection.

#

So you need to use Thunderbird.

slender lichen
#

that's something I don't get - how do I use thunderbird other than open the email? if I click to open thunderbird it asks me to create an account which I can't do as there is no network access. there is no other option to use it

primal igloo
#

It shouldn't do.

Maybe @nimble oasis can help, I think she may have done that room

slender lichen
slender lichen
#

that's the one

nimble oasis
#

form there you will have to use the view source

slender lichen
#

okay, I can open it, but I didn't know I had to use view source

#

how do I go about learning to use phishtool?

#

do I download the emails in some way onto my computer?

nimble oasis
nimble oasis
slender lichen
#

got it - I'll give that a go!

#

thanks!

nimble oasis
#

no problem

zenith oriole
#

Spent like 40 minutes on one flag because I did read the instructions......

#

Lesson learnt.

zenith oriole
#

The snort rooms are goated rooms. Thanks ujohn

nocturne cave
#

Yes totally agree with you also coolguy

barren abyss
sinful nimbus
hazy kettleBOT
#

Gave +1 Rep to @barren abyss

barren abyss
white mural
#

hey I have a question, its on the topic on fast fluxing on the soc analyst pyramid of pain box ~ the question is "What IP address does the malicious process (PID 1632) attempt to communicate with?" the answer is the ip that starts with 50. But i dont get why, since the PID has multiple ip addresses, why was that one ip the answer, was it because its the first inbound request? The answer is on page 5 of the given pdf https://assets.tryhackme.com/additional/pyramidofpain/task3-anyrun.pdf

fringe kraken
unkempt lotus
#

hi

primal igloo
#

Hello.

ruby umbra
#

hi can i really learn some hacking tips here

radiant jewel
remote crater
#

hi hackers

#

everybody hear me

zenith oriole
#

Yep

remote crater
#

are you hacker?

woeful stirrup
#

So another path was completed, this was a lot of work. I doubt have any shame in admitting that I had to use walk through on this. I definitely feel the imposter syndrome setting in, but I am determined to not let it get me down. I am sure I will retake the courses within this path because I feel I need to keep practicing. Anyway, I am done with this now and it shows that I have a commitment to learning this alchemy that is cybersecurity. If anyone is looking for a candidate for an entry-level position in a SOC, this boy is indeed your man.

nimble oasis
prime plume
#

This learning path is probably the most in depth I have taken at this point and I am enjoying it.

spring cloak
prime plume
stiff mist
#

Hello all, in the room Threat Intelligence Tools on Task 7 I cannot use the data on the attached VM. Cannot download them as well

primal igloo
stiff mist
#

but cannot use Talos TI or Phishtool

primal igloo
stiff mist
valid marten
#

Snort Challenge-The Basics Task 2 Q1: What is the number of detected packets? I searched through the chat with Albin asking the same question-Why is the answer double what I'm seeing in the summary? Using port 80 and <>. Thanks!

light belfry
#

Would someone be able to help me with SOC L1 IP address? I got the answer but i dont understand how that is the answer - there are other PID 1632

#

@white mural did u ever find out the answer?

#

I think the answer could be related to the ASN? hetzner onling GMBH, Host Europe GmbH and Cloudflare Inc are all known companies but unified layer is not, maybe that is why it is considered more malicious?

nocturne cave
#

What room is this ?

light belfry
#

@nocturne cave Pyramid of Pain