Advent of Cyber 2024 [ Day 2] Writeup with Answers | TryHackMe Walkthrough

Advent of Cyber 2024 [ Day 2] Writeup with Answers | TryHackMe Walkthrough

Welcome to TryHackme — Advent of Cyber 2024

Event Link:

https://tryhackme.com

More log-on attempts? Could this be a hack? It looks like The glitch, with a brute force attack

Confusion then reigned, with “hmms” and head scratches, it seems that applied….were security patches???

Using the SOC Superpower

The SOC has a superpower. When they are unsure whether an activity is performed by a malicious actor or a legitimate user, they can just confirm with the user. This privilege is not available to the attacker. A SOC analyst, on the other hand, can just send an email or call the relevant person to get confirmation of a certain activity. In mature organisations, any changes that might trigger an alert in the SOC often require Change Requests to be created and approved through the IT change management process. Depending on the process, the SOC team can ask the users to share Change Request details for confirmation. Surely, if it is a legitimate and approved activity, it must have an approved Change Request.

Task 8: One man’s false positive is another man’s potpourri.

1. What is the name of the account causing all the failed login attempts?

We can able to find out that under user name column....

Medium Writeup


Karthick D

Linux | DevSecOps | Cyber Security | Python | AWS | Docker | K8s | Ansible | Salt | Terraform | ELK | Zabbix | Content Writter @Medium

3 个月

Useful tips

回复

要查看或添加评论,请登录

Karthikeyan Nagaraj的更多文章

社区洞察

其他会员也浏览了