#advanced-endpoint-investigations-path

1 messages Β· Page 1 of 1 (latest)

chrome ridge
frigid scaffold
#

πŸ₯³

finite rune
#

It's a paid add-on?

scarlet comet
#

Is this beginner-friendly?

slender tendon
#

I have feedback to send to the admin, but I don't know who to tag, so I'll leave it here.. I think this new learning path logo design looks like BTL2 when the shield has wings.

frigid scaffold
dawn mist
#

This looks good.

amber raven
#

Done 😍😍😍

fossil heron
obtuse coveBOT
#

Gave +1 Rep to @slender tendon (current: #2978 - 1)

finite rune
fossil heron
#

Ahh, that doesn’t seem right. Thanks for reporting it, I’ll get it fixed.

frigid scaffold
amber raven
obtuse coveBOT
#

Gave +1 Rep to @frigid scaffold (current: #1 - 5413)

broken kernel
#

On my way to becoming a cyber security analyst 4 year goal

frigid scaffold
broken kernel
#

@frigid scaffold thanks

obtuse coveBOT
#

Gave +1 Rep to @frigid scaffold (current: #1 - 5451)

cinder scroll
#

Hey I am facing an issue. On the dashboard it is showing 54 % completed. But when I am in the room. It is showing 0% and even the progress bar is not increasing.

frigid scaffold
tribal cliff
#

Is anybody else having any issues with the macOS Forensics: Artefacts room and the VM not connecting? I was working this room and the VM just quit connecting.

ocean roostBOT
#

Done!

strange holly
hushed obsidian
worthy furnace
#

NTFS Analysis. I having problem to start the machine in this room. help needed.

frigid scaffold
worthy furnace
#

ok thanks.

frigid scaffold
shrewd linden
#

these rooms are really good tipsfedora

deep valve
#

Is it just me, or is this question worded incorrectly? How can the cluster chain start at F and end at 10? Shouldn't this be the other way around?

We have a hypothetical file B and its cluster chain starts at cluster F and ends at cluster 10 . What would be the value of the FAT entry at cluster F? Provide the value as you would read it in the HxD editor (e.g. 00001111). Note: File B is not a file on the image. 
formal prism
#

Hello guys, should we take the modules in order?

#

or we can jump through modules?

frigid scaffold
deep valve
finite rune
#

In hexadecimal base notation F < 10 which is 15 < 16 in decimal base notation.

deep valve
obtuse coveBOT
#

Gave +1 Rep to @finite rune (current: #2015 - 2)

pale light
#

d

wide verge
#

on MBR Tampering Case, save corrupting files is always save that long?
edit: smth went wrong with thm machine, tried another one and went smooth

crystal raft
#

Should I start this path when i want to become a digital forensics guy

#

?

frigid scaffold
crystal raft
#

Okay

rare phoenix
#

guys

#

why amcache.hve on my windows VM appears empty?

#

"Index was out of range"

#

The same thing forr every registry hive

#

YES

#

sfc /scannow helped

#

weird VM ig

#

cant check other hives like SOFTWARE, SYSTEM etc. because my system (VM) is using them?

golden spire
#

What is the name of the service that lists Systems Internals as the manufacturer?

#

how can i find it?

rare phoenix
golden spire
#

2

rare phoenix
#

U want the answer?

rare phoenix
#

i already did this

golden spire
#

i found it

rare phoenix
#

oh

#

okay

#

PsShutdown

golden spire
#

check in hide all microsoft services , then it will shows up !

golden spire
uncut robin
#

this path looks really good!

ocean roostBOT
#
Pong!
API Latency

140ms

Client Latency

380ms

ocean roostBOT
#
Pong!
API Latency

115ms

Client Latency

343ms

severe shale
#

yo im new

#

can someone teach me how to hack?

honest hazel
untold cradle
zenith steppe
#

Anybody having issues with the VM for β€œDiskrupt”? It’s so slow!

scarlet depot
#

In https://tryhackme.com/room/expregistryforensics Task 4 : "What is the Computer Name of the computer we are analysing?" is not accepting answer or not the correct format. It asks for 3 letter but in SYSTEM data it shows 5 letter ComputerName "James".

TryHackMe

This room explores different tools used to expedite analysis of registry data during investigation.

toxic herald
#

Hi am new here

junior glacier
#

Wc

ocean roostBOT
#

Done!

gusty flume
#

No shit 😸

fossil heron
#

πŸ˜…πŸ˜€

gusty flume
#

Calling out one of the *many * nonsensical acronyms in the tech industry! πŸ™Œ ❀️‍πŸ”₯

gusty flume
#

Nice. Finishing this path just got me under rank 4K!

wind parcelBOT
#
Pong!
API Latency

117ms

Client Ping

208ms

wind parcelBOT
#
Pong!
API Latency

114ms

Client Ping

236ms

fossil heron
#

Hey All, The CTF we ran in June - HoneyNet Collapse which was build based on this path is now released and part of the module https://tryhackme.com/module/honeynet-collapse. We will be adding this module to the end of this path and it can act as a capstone module where you can test your skills. If you missed it the first time around here is your chance to test your skills again!

shut parcel
#

Hello, I am working on "Windows Incident Surface" Task 8 and i cannot see any ssh connection attempts, anyone can help me?

warm nest
#

anybody getting this error in Windows Incident Surface Room?

#

im unable to use the terminal

#

i need to use the powershell not the cmd

#

its working fine now

marsh cobalt
warm nest
#

there are no logs for event ID 4624 in Blizzard first task lab

#

@crystal zinc can someone help?

#
TryHackMe

A critical alert was triggered from a sensitive server. You are tasked to perform a live investigation on multiple machines to determine the root cause of the incident.

#

room link

warm nest
#

nvm its working after restartingthe vm

teal temple
#

silly acronyms send tweet xD

tulip spire
weary flame
#

Please I need a mentor in cyber security

#

Some should help me please

#

I need mentorship

wraith fox
#

I also

calm summit
#

same here

paper folio
#

I think all of us need a mentor, kkk, but it's really hard someone want to teach us, not for free ! Maybe if you call somone from this chat to resolve some puzzles together from THM. Both will learn. Sorry about my English, still learning !

upper iris
#

If ya all will ask help like this no'one aint going do that

#

If youre focused or either have hunger of knowledge those people dont wait for other's

paper folio
umbral cave
#

Interesting discussion. What would you expect of a mentor?

upper iris
plucky kraken
#

Hello. Discord newb here. Can someone give me a hint. Task 5 of windows user activity analysis... I can't for the life of me find a second sub-folder within the documents folder.

finite rune
obtuse coveBOT
#

Gave +1 Rep to @finite rune (current: #276 - 39)