clo.ng

  •  Home
  •  Blog
  •  Contact
  •  
  • Search
  • Menu
  •  Home

  •  Blog

  •  Contact

  •  

Recent Posts

Leveraging osquery to examine the XProtect Behavioral Service DB

July 27, 2023

Sunsetting DetectionLab

December 31, 2022

Quick and Dirty Linux Forensics

September 27, 2021

My Take on the Decent Coffee Cart

January 2, 2021

Installing DetectionLab on ESXi

November 4, 2020

Working Through Splunk's Boss of the SOC - Part 6

July 13, 2020
bots6

Working Through Splunk's Boss of the SOC - Part 5

July 12, 2020
bots5

Working Through Splunk's Boss of the SOC - Part 4

July 7, 2020
bots4

Working Through Splunk's Boss of the SOC - Part 3

June 28, 2020
bots3

Working Through Splunk's Boss of the SOC - Part 2

June 27, 2020
bots2

Working Through Splunk's Boss of the SOC - Part 1

June 26, 2020
bots

2019 in Review

January 3, 2020
2019_in_Review

Setting Up Wireguard VPN with Algo

March 30, 2019
algo

Completing My Multi-Computer Desk Setup

August 13, 2018
desk

Using Osquery to Detect Reverse Shells on MacOS

January 21, 2018

pwnable.kr: [mistake]

December 7, 2017
mistake

Working Through Splunk's Boss of the SOC - Part 5

July 12, 2020 Chris Long

12 minute read

bots5 <p><strong>During the attack, two files are remotely streamed to the /tmp directory of the on-premises Linux server by the adversary. What are the names of these files? Answer guidance: Comma separated without spaces, in alphabetical order, include the file extension where applicable.</strong></p>
  • Continue Reading
    • bots
    • splunk
    • threathunting

    Working Through Splunk's Boss of the SOC - Part 4

    July 7, 2020 Chris Long

    9 minute read

    bots4 <p><strong>What is the name of the user that was created after the endpoint was compromised?</strong></p>
    • Continue Reading
      • bots
      • splunk
      • threathunting

      Working Through Splunk's Boss of the SOC - Part 3

      June 28, 2020 Chris Long

      10 minute read

      bots3 <p><strong>AWS access keys consist of two parts: an access key ID (e.g., AKIAIOSFODNN7EXAMPLE) and a secret access key (e.g., wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY). What is the secret access key of the key that was leaked to the external code repository?</strong></p>
      • Continue Reading
        • bots
        • splunk
        • threathunting
        • Previous Page
        • Next Page

        Chris Long

        Recent Posts

        Leveraging osquery to examine the XProtect Behavioral Service DB

        July 27, 2023

        Sunsetting DetectionLab

        December 31, 2022

        Quick and Dirty Linux Forensics

        September 27, 2021

        My Take on the Decent Coffee Cart

        January 2, 2021

        Installing DetectionLab on ESXi

        November 4, 2020

        Working Through Splunk's Boss of the SOC - Part 6

        July 13, 2020
        bots6

        Working Through Splunk's Boss of the SOC - Part 5

        July 12, 2020
        bots5

        Working Through Splunk's Boss of the SOC - Part 4

        July 7, 2020
        bots4

        Working Through Splunk's Boss of the SOC - Part 3

        June 28, 2020
        bots3

        Working Through Splunk's Boss of the SOC - Part 2

        June 27, 2020
        bots2

        Working Through Splunk's Boss of the SOC - Part 1

        June 26, 2020
        bots

        2019 in Review

        January 3, 2020
        2019_in_Review

        Setting Up Wireguard VPN with Algo

        March 30, 2019
        algo

        Completing My Multi-Computer Desk Setup

        August 13, 2018
        desk

        Using Osquery to Detect Reverse Shells on MacOS

        January 21, 2018

        pwnable.kr: [mistake]

        December 7, 2017
        mistake

        About

        I'm the creator and maintainer of https://detectionlab.network.

        Learn More

        © 2026 clo.ng . Powered by Hugo