Skip to content

Boss of the SOC Demo Part 1 | Version 1 Data Set | Splunk Cyber Security

Introduction and walkthrough of the Boss of the SOC cybersecurity competition using Splunk data sets, with insights on CTFs and cybersecurity careers.

Key Takeaways

  • Boss of the SOC is a practical way to engage with real cybersecurity data and improve skills.
  • Splunk is a versatile tool for data analytics beyond just security information and event management.
  • Governance, Risk, and Compliance (GRC) is a viable and accessible entry point into cybersecurity careers.
  • Effective cybersecurity training requires consistent practice and structured learning pipelines.
  • CTF competitions provide hands-on experience and are valuable for sharpening cybersecurity skills.

What the video covers

  • Introduction to the Boss of the SOC competition, a yearly event hosted by Splunk for cybersecurity enthusiasts.
  • Explanation of Splunk as an information management tool, often mistaken as a SIEM but used for various analytics.
  • Overview of the Boss of the SOC data sets, including different versions and scenarios like ransomware and website defacement.
  • Discussion about participating in the upcoming competition and forming a team for collaborative learning.
  • Walkthrough of the easy-level challenges (50 pointers) in Scenario One focused on website defacement.
  • Explanation of CTF (Capture The Flag) style competitions and how to approach them.
  • Q&A session addressing breaking into cybersecurity via Governance, Risk, and Compliance (GRC).
  • Advice on handling web vulnerabilities in internally built vs third-party web applications.
  • Insights into how nation-state hackers train, emphasizing practice and structured training pipelines.
  • Demonstration of using Splunk queries and tools to analyze security data and identify threats.

Answers

Questions about this video

What is the Boss of the SOC competition?

Boss of the SOC is an annual cybersecurity competition hosted by Splunk that allows participants to engage with realistic data sets and solve security challenges.

Is Splunk a SIEM tool?

Splunk is often called a SIEM, but it is technically an information management tool used for various analytics including business and IT, not exclusively security.

How difficult is it to break into cybersecurity through Governance, Risk, and Compliance (GRC)?

GRC is considered one of the easier areas to enter in cybersecurity, especially for those with a business or IT background, as it involves auditing and compliance aspects.

Full Transcript — Download SRT & Markdown

00:00
Speaker A
Cheers, cheers, cheers to you guys. Um, he who goes to bed and goes to bed mellow lives as he ought to and leaves an honest fellow. So, let's talk about what it is that we're going to be doing today specifically. I posted this up previously in chat earlier, and I'm going to post it up again so you guys can follow along if you would like. So, if you're unfamiliar with this, this is called the Boss of the Sock competition.
00:43
Speaker A
today specifically i posted this up previously in chat earlier if you and i'm going to post it up again so you guys can follow along if you would like so if you're unfamiliar with this this is called the boss of the sock
01:10
Speaker A
It is a yearly competition that is hosted by Splunk. If you're unfamiliar with Splunk, welcome to the channel. We talk about it quite a bit. It is an information management tool. A lot of people would call it a SIEM. It is technically not a SIEM because I've also seen it utilized for business analytics and IT analytics and everything else like that. So, it is not security specific. It is just an information management toolset. It will take in logs of whatever type you have, and that can be logistics, it can be literally anything, and it will help you make meaningful use of the data.
01:24
Speaker A
technically not a sim because i've also seen it utilized for business analytics and it analytics and everything else like that so it is not security specific it is just an information management tool set it will take in logs of whatever type
01:40
Speaker A
Now, in that, what I've been providing over there is something called—I don't normally stream on this one with the screen share. Let's make sure I get this right. Ah, yes, I got it right. Okay, wonderful. So, in this, it's called Boss of the Sock, and it allows you to engage and play around with their data set. Now, previously, what I've been doing over on my other stuff on Monday called Jack of All Trades over on Twitch is I have been slowly working through this and trying to build the data set myself to get—I'm getting more back into the hands-on type of stuff, um, just to keep the wit sharp.
01:59
Speaker A
the screen share let's make sure i get this right ah yes i got it right okay wonderful so in this it's called boss of the sock and it allows you to engage and play around with their data set now previously what
02:17
Speaker A
Having said that, I found out that they have the—so they have, right now, they have released up to version three on the, um, that you can download and engage with as far as data sets go. Come June, there is an actual competition again this year for .com 22. I fully intend on participating in that, and also I can have a team of up to four, so I have spots for three other people. We can do a live—well, we can't technically stream the CTF live, but we can do some stuff and have some good times.
02:29
Speaker A
type of stuff um just to keep the width sharp um having said that i found out that they have the so they have right now they have released up to version three on the um that you can download and engage with
02:47
Speaker A
Um, yeah, so it's going to be interesting. Having said that, I'm definitely going to practice a little bit with the older, um, older items, and tonight I wanted to start working through with you guys at the 50 level. Okay, what is that? Or not the 50 level, but the 50 pointers, the easy ones, the slow balls, the slow curves. Um, so there is a lot of content when you go into this Boss of the Sock, and this is telling me I have two hours left because they give you a four-hour time limit every time you start it up.
02:56
Speaker A
i fully intend on participating in that and also i can have a team of up to four so i have spots for three other people we can do a live well we can't technically stream the ctf live but we can do some stuff and have some
03:10
Speaker A
So, in that, when you click here, load up Pause the Sock version one, and then you're given two scenarios: Scenario one, Scenario two. Scenario two is ransomware. Scenario one is website defacement. Okay, I'm going to start tonight. We're going to go over the lower-end questions in Scenario one.
03:31
Speaker A
the 50 level but the 50 pointers the easy ones the slow balls the slow curves um so there is a lot of content when you go into the this boss of the sock and this is telling me i have two hours left because they give
03:44
Speaker A
Now, if you're not familiar with CTF style, okay, so let's hit a couple questions real quick because you guys are asking a bunch tonight, and I want to make sure I get to them. I don't know how to phrase the question, just wondering on thoughts since I am taking class on GRC, which is Governance, Risk, and Compliance. How hard is that to break into cybersecurity with this?
04:05
Speaker A
scenario one is website defacement okay i'm gonna start tonight we're gonna go over the lower end questions in scenario one now if you're not familiar with ctf style okay so let's let's hit a couple questions real quick because you guys are you're
04:25
Speaker A
Not hard at all. Governance, Risk, and Compliance, if anything, is actually one of the easier, um, easier areas to break into, uh, because it's considered more—not to say that it's not cyber because it is, it's cyber—but you can transition laterally into it from a business perspective as somebody that's, you know, just kind of like really into IT, and then you come at it from an auditing perspective. Um, a good person to talk to is Alexandra, Alexandria San Miguel. She's going to kill me messing up her name. Um, friend of mine, she's been on the channel before. Talk to me after this. I can get you her info. She is director of, um, GRC over at Walk the Runway right now, and she's been on our I&E show as well.
04:35
Speaker A
security with this not hard at all governance risk and compliance if anything is actually one of the easier um easier areas to break into uh because it's it's considered more not to say that it's not cyber because it is it's cyber
04:51
Speaker A
Jordan McGee, how would you handle an internally built web app versus a web app created by a third party in terms of finding web vulnerabilities? Bug bounty programs, plenty of scanners out there. You know, would be great to talk to for that one in particular our mod tonight, Mr. Net Frazier. I would suggest hitting him up. Definitely a good person to talk to on the specifics there.
05:08
Speaker A
alexandra alexandria san miguel miguel she's going to kill me messing up her name um friend of mine she's been on the channel before talk to me after this i can get you her info she is director of um
05:24
Speaker A
Tae Kwon Gong, how do nation-state hackers train and build skills? Practice, practice, practice. It's kind of a, um, it's kind of unfortunate in cybersecurity because all the times you see, like, everyone just seems to get it right. They're on the computer, and what Hollywood makes look easy all the time is for two reasons: one, just because it's Hollywood, they make everything intentionally look so much easier than it actually is just to move stories along. In reality, um, you know, they don't show the 10,000 hours worth of work that it took to get to that understanding.
05:38
Speaker A
finding web vulnerabilities bug bounty programs plenty of scanners out there you know would be great to talk to for that one in particular our mod tonight mr net frazier i would suggest hitting him up definitely a good person to talk to on the
05:56
Speaker A
Also, you have what's called a training pipeline. So, when you are in a military or government organization, you generally start by planning your personnel as personal management. You're planning per job functionality and need, and then you create a massive repeatable process full of checks and balances that you can run a hundred people through. Okay, so it's not easy to just go, yeah, I'm going to, you know, create this job role or whatever else in the military.
06:16
Speaker A
they're on the computer and what you're what hollywood makes look easy all the time is for two reasons one just just because it's hollywood they make everything intentionally look so much easier than it actually is just to move stories along in reality
06:33
Speaker A
Very explicitly though, when it comes to hacking or, um, whatever else you have, if they are military-based or government, you know, based or provided or whatever else, then they've been through that whole training pipeline. Now, if you're talking about nation-state as in third-party contractors that are popularized through China, Russia, and Iran specifically, um, you just—it's one of those, you just gotta train, you gotta train, you gotta understand, you gotta live in it and do it.
06:49
Speaker A
start by planning your personnel as personal management you're planning per job functionality and need and then you create a massive repeatable process full of checks and balances that you can run a hundred people through okay so it's not easy to just go yeah i'm
07:17
Speaker A
Um, yeah, it would not surprise me to find out some of the, like, whenever they catch these individuals, if you look at their background, you know, sometimes they might have, uh, background from an actual college education in computer science. Sometimes they, you know, sometimes they don't. They just learned everything that they can, and, you know, they're savants at it. You know, everyone's got a story, but what you will find for all of them is that they do it all the time. It's like breathing for them.
07:33
Speaker A
whatever else then they've been through that whole training pipeline now if you're talking about nation state as in third-party contractors that are popularized through china russia and iran specifically um you just it's one of those you just gotta train
08:00
Speaker A
Um, and they generally don't have to look things up. Well, I won't say they don't have to look things up because there's definitely been instances that we've seen they do. They have to look things up. They have to go and find things. They make things work. But once you get the anonymity portion down right, once you're actually able to get the anonymity portion together, then you can work in on the problem for as long until you get caught. And a lot of times, we're seeing also a lot of security postures and not monitoring appropriately.
08:14
Speaker A
have uh background from an actual college education and computer science sometimes they you know sometimes they don't they just learned everything that they can and you know their savants at it you know it's everyone's got a story but what you will
08:28
Speaker A
So, ah, Danielle Marquez, how would you deal with the stress on instant response tasks, especially on these wartimes and cyber threats that are coming? Um, step one, I only worry about—I do my best to only think and worry about the things that I can control. Um, that's half the game. If I have no control over it and there is nothing I can do to change it, there's no point in thinking or fretting or worrying about it, you know what I mean?
08:40
Speaker A
been instances that we've seen they do they have to look things up they have to go and find things they make things work but once you get the anonymity portion down right once you're actually able to get the
08:52
Speaker A
Um, yeah, it's something kind of insane. Um, for the rest of it, you know, I have good work-family balance. I try to anyway. Um, and, you know, I really need to go and get more exercise, but I try and I try and go take walks and things like that. And then I do this. Realistically though, I'm not doing a good job. My insomnia has been kicking up recently, so I need to find something else too.
09:09
Speaker A
with the stress on instant response tasks especially on these wartimes and cyber threats that are coming um step one i only worry about i do my best to only think and worry about the things that i can control
09:21
Speaker A
Um, Brian Godfrey, how do you think 14 UK parents feel now, especially when one child allegedly has 14 million Bitcoin? Oh my gosh. If you guys are not familiar with what's going on over the Nvidia, Microsoft, oh, what else? There's a couple companies in there. I'm having trouble remembering them all.
09:44
Speaker A
kind of insane um for the rest of it you know i have good work family balance i try to anyway um and you know i i really need to go and get more exercise but i try and i try
10:04
Speaker A
Um, turns out though that the child apparently was on—
10:20
Speaker A
parents feel now especially when one child allegedly has 14 million bitcoin oh my gosh if you guys are not familiar with what's going on over the nvidia microsoft oh what else there's a couple companies in there i'm i'm having trouble remembering them all
10:42
Speaker A
um turns out though that the child apparently was on it's a child they believe it's 17 years old was able to hack these big big companies and um according to uk resources they identified who the individual was a very long time ago or not a very long
11:03
Speaker A
time ago with a while ago and they've been just keeping tabs on all the work that they've been doing so they fully expect to yeah that's just unfortunately that that is childish hubris um it's also a great example of why i am
11:23
Speaker A
very hesitant to teach somebody how to hack that's under 16 years old i'm very hesitant so rodnett if you were to hire a penetration tester with no experience how would you identify if he has enough skills to do the job
11:40
Speaker A
i don't care if he's got the skills i can teach him skills i care if he hasn't i care if he has a work history that shows that he's been to work on time accomplished the work roles that he
11:52
Speaker A
needs to he's able to work with others um you know and they've got a fire in the belly as well and so i what i want to see is i want to see them doing you know top one percent on try hack me
12:04
Speaker A
or hack the box i want to see um you know ejpt and ptp or oscp certification i want to see um research reports breaking down the new vulnerabilities or demonstrating them videos demonstrating them that's the stuff i want to see
12:28
Speaker A
i i don't i don't like putting people through technical skill interviews um at all because context is really important when you do a job and it's much more important to understand how a person thinks versus do they like
12:55
Speaker A
unless you're going to code for me in python or java or something like that then i don't need to see a snippet of your code unless that's a major part of the day right um more so what i would be focused on is
13:12
Speaker A
i might set them down on the cali box if that's their preferred choice and ask them to you know do like a major um it's very small lab environment like hey send this over here or you know do a quick probe of the network or blah
13:26
Speaker A
blah blah blah like just to see make sure they're comfortable on linux and they're not just bullshitting um a couple things um door mcgee in your opinion what is the best process for pitching new ideas to securing the enterprise such as
13:41
Speaker A
disabling mbns um in r to vps of a company sorry for the multi questions how about we get to that in a bit so we can keep going on this um i don't want to just leave everybody sitting and watching the wrong screen
13:56
Speaker A
cool excellent so we're gonna i'm gonna hold your question there joy mcgee and we're gonna take a look at boss of the sock all right so in this if you're not familiar with ctf events this is a form of ctf as in capture the
14:13
Speaker A
flag the way these work is you go and you answer a question by finding a string element relevant to what's going on tonight we're going to focus on the easier ones because you guys will be able to follow along and play along too
14:25
Speaker A
i'm also going to show you introductory threat hunting techniques as well so with that when we come to boss of the sock and we're talking at scenarios website defacement right um if you read through all of this right
14:47
Speaker A
the website i'm really not batman.com hosting on wayne and prize ips space has been compromised group has multiple objectives but the key aspect of their modus operandi is operandized face websites blah blah blah um and this is alice's first day and then
15:07
Speaker A
there's all this information now i'm really not batman.com oh by the way if you guys are like laughing right now because i'm saying i'm really not batman.com everything else like that um it talks about it in some of the
15:24
Speaker A
references and resources it talks about what the background is and they basically built an entire business case around the idea of this is alice's first day as a sock operator on wayne enterprises networks in you know in the batman
15:41
Speaker A
era of dc comics so it's kind of cool um so poison ivy is the group that we're going after as you can see on the screen right now with that not again you guys can log in you can read this yourself there's also
16:05
Speaker A
excess information this is her journal that's involved there's also an apt a group with any any information things like that this is a splunk reference chart um this is a quick startup oh this is an explanation of what the source types are
16:29
Speaker A
and we'll get to source types in a second okay if you're unfamiliar with splunk this is the splunk interface now let me try and do this as well oh come on well i did have i did have a demo for
16:59
Speaker A
you there you go i diagrammed to show you guys and there it goes okay wonderful all right so with this this is our diagram i know it's crude leave me alone um so this is our firewall where we're
17:15
Speaker A
gonna have some of our logs and the reason why i pulled up the diagram is to show you that here is going to be the fortigate so that's f g t here is going to be our web page which
17:27
Speaker A
is also known as i what do they call it i'm really not batman.com all right so that's our website that's our fortigate firewall that goes in front of it and then we have just um call that machine evil because we don't
18:00
Speaker A
know the infrastructure of the attacker yet but i will start when i'm doing my notes i will literally like draw a line across the middle of the page and go what i know about the attacker what i know about our systems
18:13
Speaker A
that were involved and i'll start like my notebooks look a little um what's it called a little rain man with the flying numbers and stuff all around it's it's kind of all over the place um but yeah so i have that for reference and we'll
18:33
Speaker A
keep filling that little attack map out if you will with that we're going to start here if you're unfamiliar with the way splunk searches go you use two qualifiers off the top and by the way this is called
18:44
Speaker A
spl splunk processing language so you start with what's called an index which is a grouping of records now a group a group of records just means the actual database itself and you can have more a multitude of indexes
19:01
Speaker A
realistically an index can also be clustered together of a couple different databases in physical servers so just because you have one index by name doesn't necessarily mean that it is just one server that's standalone it can be a
19:15
Speaker A
multitude of servers you can like you can architect this in a a lot of different ways and functions one way that i've seen indexes grouped by which worked out pretty well was the form of data or again the collection
19:33
Speaker A
point so in that let's bounce back over here so in that if we have logs that are coming from the fortigate up here where we have the network level i would do an index that's just networking and then if i had stuff that was related
19:52
Speaker A
to my security tools or my agents that's sitting on the system i would call that index security and then for my assets the individual like system logs i would probably call that one like uh just literally system logs i mean i
20:11
Speaker A
kind of already said the name or syslog right so those are three different indexes i could do and then you have the second form i am jumping back back and forth so fast um then you have the second form called
20:25
Speaker A
a source type now a source type is very specifically the type of record that is involved and it's stored on whatever index that is okay in this there is a huge just a whole bunch of different source types available i'm trying to
20:45
Speaker A
keep this relatively quick and short and you can dive into them in the bot stop source types information material that's available here when you go here it'll tell you and give you a description of windows ta this is
21:00
Speaker A
the default windows ta for splunk this is all this is what's being utilized and collected here are all the source types that are available uh which we have registry logs we have event logs we you know those are all
21:13
Speaker A
system based we have meaning fortigate which we have events traffic and utm um iss for the information server uh dhcp hdp so stream usually means pcapp data so it'll be some form of uh or level of packets of data
21:33
Speaker A
that is uh being monitored by the network nessus that's the vulnerability scanner cerakata that would be your agent based uh that would be your security agent that's monitoring the network sourcing so if you have any alerts from your network traffic it would
21:53
Speaker A
probably fall under cerakata um a couple quick questions in your opinion what's the best process oh jordan mcgee we'll get back to that one pull root repeat do you run security onion in a vm vps or bare metal i've
22:09
Speaker A
done all three uh taekwon gong uh i worry about keeping knowledge up and keeping that fire as i continue to learn hacking when things are hard how do you keep motivated when things seem too hard to continue uh you gotta remember you know you gotta
22:23
Speaker A
remember your goals you have to remember what is on the other side personally i've made it i'm doing pretty well um have i made it have i hit all my goals no but i hit a lot of them
22:33
Speaker A
and i myself am like that's why i'm doing this right now frequently with you guys is to help get some motivation through you by i am living vicariously through this community um because i get to teach now i get to
22:47
Speaker A
teach what i know and it's helping with my motivation to stay up to par on my skill sets because i'm doing well and i'm having trouble trying to figure out what my next steps are so back to what we're talking
23:04
Speaker A
all right so let's go over here now now we're 30 minutes into the stream and i haven't even typed a single sentence in here um let me pull up close that go here wonderful pull up my notes okay
23:27
Speaker A
now if again if you're not familiar with ctfs this is what they look like whenever you click on the actual question well chip i thought that they would uh remove my question my aunt previous answers but they didn't um
23:42
Speaker A
so in 101 what is the likely ipv4 address for of someone from the poison ivy group scanning i'm really not batman.com for web application vulnerabilities so if they're scanning that means they're sending packets inbound that means it's probably going to be a
23:56
Speaker A
network-based scan furthermore if there is a firewall in front of the website it's very likely that it's going to block some of those things okay so in that keep in mind i've been working on this over on my channel where i mess around
24:12
Speaker A
and mess up all the information okay so what i'm doing here is i'm searching for a very specific string in this case i'm looking for i'm really not batman.com um and because it's on fortigate is the fortigate as i said for source type
24:36
Speaker A
and then i'm using an asterisk intentionally because what that says is i'm not having to specifically say i need underscore utm records or i need underscore event records or whatever else type of data what i'm saying by utilizing asterisks is i'm saying i want
24:56
Speaker A
anything that comes out of the fortigate which in total includes three separate source types i'm saying i don't care where in the record i just want the string i'm really not batman to pop up by itself oh and i need to adjust for
25:10
Speaker A
some reason it has all time it shouldn't have done that you really do want to make sure that you're hitting the appropriate um and there's a lot we can get into on this but you need the appropriate time date
25:27
Speaker A
stamps to keep the cycles the search cycles down and this data is basically all happened in the month of march of 2016. okay so we're gonna apply that apply that uh we're gonna go verbose mode and we're gonna go search okay
25:47
Speaker A
now it's running a search and as you can see that august 10th there were 13 000 events 13 918 events um jordan mcgee random question what is your favorite whiskey of choice drink it some monkey shoulder myself or starting
26:05
Speaker A
for messi ppt um i am a huge fan of woodford reserve with um basil hayden as a secondary runner-up to that uh jefferson's pretty decent as well and i mean my absolute favorite is blanton's but it's also about 140 a bottle so i tend
26:28
Speaker A
not to get that hardly ever um but yeah it's uh yeah woodford reserve is definitely my go-to bourbon almost on a weekly bi-weekly basis whenever i grab a bottle um so here we see i'm really not batman now just so that way you guys can get
26:50
Speaker A
some hands-on and see what it looks like whenever you have an event this is how things get returned to you as far as events at least the way that i have it in a listing format you can also go table
27:02
Speaker A
format in which it tries to pull everything out i hate that it cuts away there's too much white space let's go raw or i'm sorry let's go list it gives you your timestamp it tells you everything now it's kind of hard to see
27:15
Speaker A
this and it's intentional because it's word wrapped what you can do is when you click here everything comes into a beautiful little by um into what we call normalized or there is a word that i'm forgetting again but
27:35
Speaker A
joomla nice but basically parsed this is all parsed what we would call parse data meaning that all of the individual fields these are fields that have data within them have been separated when it was indexed okay what's really nice about this stuff was
27:59
Speaker A
when you see that by the way source ip is 40 80 14842 what is this uh host name euro belongs to an allowed category in policy um pass through what's what was the message okay it has everything here but it
28:26
Speaker A
doesn't say anything it says notice but it doesn't actually give a notice of what happened okay whatever um point being is what we are looking for though is right up at the top action allowed because they were doing vulnerability
28:50
Speaker A
scans the action will likely be what we call blocked now i'm going to use we can either say this to a we can either say action equals blocked or we can do action does not equal and then say allowed
29:06
Speaker A
but the problem is that there's more actions than allowed in block there's also passive there's whatever else so you want to try and be specific as possible in this case i know that we want it to be blocked
29:18
Speaker A
cool wonderful now we have 442 events and in this case if we looked at the action that was blocked the attack came from acunex web vulnerability scanner um destination ip 192 168 250 70. so we could actually take that run over to our chart
29:45
Speaker A
and plug that in as i'm not batman.com to let people know uh come on looks like that it basically just recognized that this was a scanner um yeah vendor type it was a signature it recognized that it was a scanner it
30:06
Speaker A
was detected and it was a whatever so odds are this source ip address right here where i just saw it ubs would be down here source ip address here we're going to take this back over here and what's my answer for number one the
30:23
Speaker A
50 points we're going to submit correct boom we got 50 points from that yay round of applause all right what do we have next next what company close this that's 101. what's 102.
30:48
Speaker A
what company created the web vulnerability scanner used by poison ivy type the company name we just said it it's right here acunetix so we can literally just go acu and he takes oh i already had it in there whatever
31:12
Speaker A
submit boom okay we can get that from the same record another 50 pointer what content management system is i'm really batman.com in and if we look at this as well i believe it was actually our previous one right at the top
31:36
Speaker A
i kind of called it out file path joomla images i'm not batman.com which would suggest that joomla is our answer now wonderful now one of the way one of the ways you can also do that if you're very
32:01
Speaker A
specific let's take a look at a different source type so in this i'm going to break up the source type and we are going to go uh stream uh it's right here cool stream http um i'm really not batman
32:28
Speaker A
i'm going to take a look at that as you can tell it takes a little bit so now we have 22 000 events in this particular stream um source head title i'm really not batman.com joomla index which is the
32:49
Speaker A
location uh one of the things you can also look for is called here it is uri or uri path so in this why don't we do we can just do uh stats count by uri let's try that so many joomlas
33:27
Speaker A
yeah and then you get all this other random stuff but that's another method of doing the same thing there's some because you can you have such raw control over the data this is obviously this is basically like excel on you know
33:42
Speaker A
on drugs it is kind of insane on steroids it's it's beefy it's juiced it's you can find individualized records you can port it over there's also a whole use of graphic interfacing here too that we're not talking about
33:59
Speaker A
so we have a lot of options visualization is the one but yeah even even just clicking on visualization it gave me a pie chart of the information and just says other and then here's the count for everything else it looks like jup slash joomla
34:16
Speaker A
administrator joomla index and joomla index.php so let's go back to events wonderful so we answered joomla here [Music] um in this we are going to go down to these are 250 the base points are down here so 250
34:45
Speaker A
250 500 these points values are more difficult there's no real way to get the direct answer from what we know as of right now and we have to build a case so in this so this is why i'm going to jump over
35:02
Speaker A
to the sorry i just realized i was not screen sharing so what we're seeing here is that we just answered 50 50 base points are 250 for here 250 and 500. so we're going to stick to the 50s because those are the
35:17
Speaker A
very easy style give me's um just to keep things simple and we'll kind of build on this as we get more and more progressive in on what i'm teaching you guys about threat hunting building the investigation next week
35:32
Speaker A
we'll try and hit up some of the 100 and 250s to where we take the information that we learned this week and we drive it into the information for next week okay um what ipv4 address is likely attempting a
35:48
Speaker A
brute force password against i'm really not bad oh um actually we can put in so we think it is what we had said previously right that would make the most likely answer we had put in but it's incorrect and that's fine
36:06
Speaker A
what we're going to do instead is we're going to go back to the 48 firewalls because those are dealing with the network logs and we want to take a look at those so in that case source type and we're going to take a look again for
36:26
Speaker A
i'm really not batman all right wonderful i'm really not batman.com all right and previously we knew that uh the actions that we were doing were we were looking for block to find the vulnerability scanner realistically though we can take a look
36:53
Speaker A
at all addressing that and from the source type and the way we're going to take a look at that is go stats count by source ip if you're unfamiliar with source ip it is when you look here so source ip is in this case it's the
37:14
Speaker A
one that we're familiar with but it means that where the traffic is sourcing or originating from and then the destination because you are you have directional queries within the packet data in this case because a firewall has a website versus an internal side
37:32
Speaker A
uh it will be able to say that it's coming from sourcing away from me coming in and going to this destination usually on your own net right um with that a lot of these terminologies that are here that are coming through
37:51
Speaker A
they are related to what we call the conference common informational model or the cim it's a splunk term and it's a standard it's a standardization method of naming these field types so that way you don't have you know srcip src underscore ips
38:13
Speaker A
you know uh s o u r c e i p and then underscore i p all four of those will be the same meaning the exact same thing right but it makes it difficult to work in a multitude of data types if you
38:32
Speaker A
constantly have something named differently than everything else so in that you want to make sure that it is part of the same information model or standardization of structure in the information with that let's go ahead and count by source ip
38:53
Speaker A
and you'll see we only have two of them so we have this 23 22 6314 we can click on that and we can view the event specifically related to that another thing we can do is we can take
39:09
Speaker A
that ip address we can remove the fortigate requirement and just see what it's been doing in and out of everything that's in within our enterprise environment i'm going to click show fields here pop it out we only have one source type it
39:28
Speaker A
looks like it's only fortigate okay this is a summary of what type of data is available from so we have event type we have uh fortigate fortigate utm and web filter all right not much else to that um
40:01
Speaker A
but we can just try it out real quick the ways that you would confirm what you'd want to confirm with is if you take that oh you know what i bet you here's the issue because i have source ip here
40:13
Speaker A
that's why we're not seeing it we should see this in other log forms yep 5300 events yep there's the other log forms uh-huh now we see different source types so we have stream http we have circada as well so let's take a
40:32
Speaker A
look at cerakata being that that's our event manager for our security event manager for um for the networking data we have event types file info http are the two event types um i'm seeing if there's anything important looks like we have the communication
40:58
Speaker A
back and forth between this ip and that ip and your it looks like it's going to administ joomla administrator index.php if it's going to index.php a lot of times trying to log in there you go and see the difference that i said
41:13
Speaker A
source underscore ip so it looks like it doesn't quite fit into the common information model but it's all right so we'll take this control copy put that in right here submit that's correct as you can see though these are both 50
41:32
Speaker A
points you have 59 here versus 71 up here well what's the difference you get an additional point value uh based on so the base value was only 50.
41:44
Speaker A
then you get an additional point value based on how much time has elapsed because i am because we are you know it starts at a four hour mark because it starts at a four hour mark and it's been counting down because i
41:57
Speaker A
did a lot of prep work on this um we're getting very low scores now all right what else we got here we go oh this one's going to be fun okay what is the name of the executable uploaded by poison ivy
42:21
Speaker A
please include the file extension okay so with that we're talking about what was the name of the executable uploaded so let's go here and readjust this we don't see these fields so we can see everything here i'm going to remove all of this
42:45
Speaker A
and we are going to i want to see anything that went to i'm really not batman.com and i want to do it by it said what executables let's see what xq rules did go up well can't make sense of that can we
43:12
Speaker A
um this is a post to the index get der contents and send what equals both looks a little fishy straight up straight up this is url injection but anyway um what else we got how to splunk handle data that is being exfiltrated via
43:41
Speaker A
encrypted tunnel methods splunk doesn't handle any of that so keep in mind that this is it splunk is an information uh store processor and presentation it does nothing as far as um information management information handling now you can trigger via what we call plugins
44:06
Speaker A
uh you can trigger work to occur based on alerts that are fired based on you know whatever whatever whatever and that goes into automation but that that's a whole different topic about secure you know maturing security operation centers
44:24
Speaker A
um it's one of the things i actually technically specialize in and it's one of the conversations that so what we're reading right now is in this case so this is stream http this is just a printout of what came through
44:43
Speaker A
on the uh circada instance that was monitoring the network traffic um i just saw sarah connor down here where are you at so this is cerakotta ids in where it said file info 3791.exe wow we just stumbled onto that
45:00
Speaker A
okay uh 3.791.exe uh and the http method was post i'm really not batman posted here blah blah blah blah source ip was the ip that we knew was bad and it was going to index that but in this we see cerakata and it's calling
45:21
Speaker A
out and it's alerting on what information is bad and that is what it it handles now we could have configured circada to block file uploads but that's not realistic right we can also block file uploads for specific instances or specific ports and
45:39
Speaker A
sir coddle would be the handler because it handles network data as the event manager to block that type of information on inspection um now specifically for encrypted and tunneled methods you can only defend what you can identify right so if you want to inspect that
46:02
Speaker A
information there are ways and methods of doing that um one way is and you'll find this in the financial sector they will do what's called ssl breaking so the secure state they will break it at the boundary of the
46:18
Speaker A
um of the company and they will inspect and then repackage it up and resend it over to you know wherever else it was going it is fully legal because you're you are on the banks assets right so yeah there's all sorts of stuff there
46:40
Speaker A
um in this we have this is likely the answer but the other thing too i want to show you guys is there so circada has that particular event but one thing that we can also do here is we can go
47:00
Speaker A
this is a threat hunting tactic so threat stats count by and we are going to say msg what that means is that's going to be message so what message did we receive back um file is infected url belongs to an
47:21
Speaker A
allowed category in policy makes things really easy there right files infected view events and then we see very clearly that this is all completely infected what device id is there let's break this all out so file name is this
47:55
Speaker A
the virus attack malware operations ec blah blah blah and it tried to go to the vendor action is monitored that was intentional uh the virus is 32 sport crit and yeah so another thing that we can do is we
48:24
Speaker A
can legitimately take oh buddy i'm going to add that to search temporarily just so i can copy it and i'm going to play off the cuff real quick here we go so with that come on with that if we go to virustotal and we
49:03
Speaker A
put in what that is an uh sha 256 hash we put in the shot 256 hash and we get there we go 59 of 69 security vendors uh and no sandboxes flagged this file as malicious that's a pretty
49:21
Speaker A
decent number um and what i would say suggest is never using these [Laughter] um joking but yeah everyone um now but you can go is to the details and you get md5 sha-1 all the different properties and i
49:45
Speaker A
say that because since we know what this is back one second by the way did somebody catch something really interesting in there profile honeypot access this is intentional honeypot so this is one method you can see it being used
50:08
Speaker A
jordan mcgee if the ctf was a real-life event would a waff been able to prevent this well it depends on what type of inspection that's occurring at the waff if you're just talking point to point are you on a block list type of
50:19
Speaker A
inspections then no it would not have if you're doing contextual inspections where you're breaking out the packets or you're doing full reassembly of the packets into files and then detonating the files into you know just depends on everything what
50:34
Speaker A
do you have turned on right um if very specifically there's a lot that you can do so for example we've i've used wafts before that if a file was if a file was passed went past the laugh um
50:56
Speaker A
it would be collected and detonated and then the behaviors would be studied within a sandbox environment detonated meaning that it was automated automatically you know uh automatically interacted with hit you know start executed and you know there was a lot of indicators that would
51:20
Speaker A
come off that having said that if the if it is found to be suspicious enough of a file it would send an alert over to those that were you know working in ir instant response or security operation center
51:40
Speaker A
and then we would have to go and lock out that computer grab that file double check make sure it was correct um and the reason we have to double check make sure it's correct is a lot of the
51:51
Speaker A
uh quick applications stuff that's not coming from an actual vendor they would they would alert so stuff that was brewed internal in in-house would alert so let's take a look at this um and go back over here and submit this
52:10
Speaker A
that was a name and then we're going to bounce down to the next one what is the md5 hash of the executable uploaded really interesting that i pulled a virus total right and then we have right here the md5 hash of some of that particular
52:29
Speaker A
instance so we're able to knock out a 250 real quick and submit that boom be able to grab that as well so in that i've now shown you guys i'm sorry i keep forgetting to turn this on really interesting i'll show you guys
52:48
Speaker A
this again really interesting that here on this when we found that shaw 256 we're able to look it up we're able to pull this file out from md5 put it over here i put it in here i hit upload
53:04
Speaker A
and we were correct so by just simply taking the shot 256 that came out of message file is infected it already knew the virus knew everything in here and we had the analytical sum also known as the file hash
53:25
Speaker A
right so you can see where in this you can see where you start with one and you slowly migrate over based on the information that you know and you do continuous research of the information as you're going and you're able to pull up
53:43
Speaker A
these instances um excellent well you know i i think we are getting to that time if you don't mind me saying now please don't drop just yet um let's not drop just yet and the reason is we have coming up i believe a dj b sec
54:23
Speaker A
um let me pass the info over to you guys of course he's got that bump in let me get this over to you guys real quick so you have an option there we go okay so we have that option
54:50
Speaker A
right there available i'm going to be popping into sub chat after this um definitely listening to hanging out with dj b sick over on his channel on twitch and also i want to say guys thank you so much for coming out
55:05
Speaker A
i really do hope that i was value added and i'm going to answer real quick uh in your opinion was the best process for pitching new ideas to securing the enterprise such as disabling stuff uh to vps of a company
55:18
Speaker A
what so what now what we've done multiple videos on this but really you need to quickly be able to show you know what is occurring what is the configuration so what why is it's a problem now what what do you need to do to do that
55:37
Speaker A
the less money that needs to be spent the less manpower that needs to be spent the easier it will be to make that change in alteration but you have to make sure that you get the right stakeholders into the meeting
55:51
Speaker A
so we can talk about it more um if you if you want hit me up on the personal channel hit me up on the discord and guys hey look it's the end of the night really great want to remind you guys
56:02
Speaker A
that we have um i have my show on mondays that i'm doing now called jack of all trades over on twitch you can join me there on monday nights it is definitely a place for me to be able to drop four letter words and
56:14
Speaker A
drink and mess around with stuff that doesn't always cyber related or whatever else um but we are coming in tonight i want to thank my mods for their ongoing work and i want to thank you guys yes you so
56:24
Speaker A
much for coming to hang out i hope i was value-added and you enjoyed yourself please hit exclamation point discord drop some suggestions for improving and join us in sub chat for continued conversation cheers cheers cheers to you guys
56:38
Speaker A
um he who goes to bed and goes to bed mellow lives as he ought to and leaves an honest fellow hey thanks for watching i want to thank neil on the cyber insecurity channel for providing a place to have real
56:52
Speaker A
conversations with real people feel free to throw a like or to follow me on the socials in the description please remember to click subscribe hit that notification bell and if you want to see other videos click that stuff that's all
57:03
Speaker A
over the screen see you next time
Topics:Boss of the SOCSplunkCybersecurityCTFGovernance Risk ComplianceSIEMCybersecurity trainingWeb vulnerabilitiesRansomwareInformation management

Get More with the SozAI App

Transcribe recordings, audio files, and YouTube videos — with AI summaries, speaker detection, and unlimited transcriptions.

Or transcribe another YouTube video here →