Showing posts with label CyberDefenders. Show all posts
Showing posts with label CyberDefenders. Show all posts

Thursday, January 2, 2025

Digital Forensics:DumpMe Lab—Memory Forensics Writeup— Cyber Defenders

Digital Forensics:DumpMe Lab—Memory Forensics Writeup— Cyber Defenders


Cyberdefenders: DumpMe

Description

One of the SOC analysts took a memory dump from a machine infected with a meterpreter malware. As a Digital Forensicators, your job is to analyze the dump, extract the available indicators of compromise (IOCs) and answer the provided questions.


Digital Forensics:DumpMe Lab—Memory Forensics Writeup— Cyber Defenders


Q1 What is the SHA1 hash of Triage-Memory.mem (memory dump)?

Digital Forensics:DumpMe Lab—Memory Forensics Writeup— Cyber Defenders

Ans: c95e8cc8c946f95a109ea8e47a6800de10a27abd 


Q2: What volatility profile is the most appropriate for this machine? (ex: Win10x86_14393)
We can use the imageinfo  plugins to determine the proper profile of Triage-Memory.mem.

vol.py -f Triage-Memory.mem imageinfo
Digital Forensics:DumpMe Lab—Memory Forensics Writeup— Cyber Defenders


Q9 What is the LM hash of Bob's account?

#vol.py -f Triage-Memory.mem --profile=Win7SP1x64 procdump hashdump | grep "Bob"

Digital Forensics:DumpMe Lab—Memory Forensics Writeup— Cyber Defenders

Bob:1000:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
User: Bob
LM:aad3b435b51404eeaad3b435b51404ee

Make a file on your computer and copy/paste Bob_account’s hash in there. 

We will use Hashcat to crack it. Look through Hashcat’s mode LIST and you’ll see that NTLM is mode 1000:
Make sure you have the rockyou.txt list saved on your system before we start.
#hashcat -m 1000 <hash file location> <wordlist file location>

Digital Forensics:DumpMe Lab—Memory Forensics Writeup— Cyber Defenders


In a few seconds we will have our password (up top after the hash).

Digital Forensics:DumpMe Lab—Memory Forensics Writeup— Cyber Defenders


If you’d like an easier alternative, use CrackStation.

Digital Forensics:DumpMe Lab—Memory Forensics Writeup— Cyber Defenders



*ขออภัยที่ทำไม่เสรฺ็จ ค่อยกลับมาทำใหม่ครับ


ที่มา:   cyberdefenders.org 



หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูล  เผยแพร่ความรู้และให้โอกาสในการค้นคว้าหาข้อมูลเพื่อการศึกษา   บุคคลที่สนใจโดยทั่วไป รวมถึงนักเรียน นิสิต นักศึกษา  ในการเรียนรู้เท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ


#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD

Friday, January 21, 2022

BlueTeam CTF Challenges - CyberDefenders

 BlueTeam CTF Challenges - CyberDefenders with Paraben's E3

CyberDefenders is a training platform focused on the defensive side of cybersecurity, aiming to provide a place for blue teams to practice, validate the skills they have, and acquire the ones they need.

Download Challenge 

DIGITAL FORENSICS: CTF 

SHA1SUM 88a22f6ad6d140c9151e6983b894c6eb6c64735d


1  What is the computer name of the suspect machine?


3 What was the DHCP LeaseObtainedTime?


4 What is the computer SID?


5 What is the Operating System(OS) version?





6 What was the computer timezone?




17 It looks like the suspect user deleted an important diagram after his conversation with the external attacker. What is the file name of the deleted diagram?


20 What are the serial numbers of the two identified USB storage?


24 Using prefetch, determine when was the last time ZENMAP.EXE-56B17C4C.pf was executed?

25 A JAR file for an offensive traffic manipulation tool was executed. What is the absolute path of the file?

27 Shellbags shows that the employee created a folder to include all the data he will exfiltrate. What is the full path of that folder?


29. Provide the name of the directory where information about jump lists items (created automatically by the system) is stored?


30 Using JUMP LIST analysis, provide the full path of the application with the AppID of "aa28770954eaeaaa" used to bypass network security monitoring controls.



อ่านเพิ่มเติม Cloud Forensics:Google Drive forensics with Paraben's E3
                      Digital forensics:P2CO-P2C Certified Operator

ที่มา:   cyberdefenders.org 
           


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ


#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...