Cyber Mayhem Blue Team Gameplay: Process Monitoring with Snoopy (LD_Preload)

Cyber Mayhem Blue Team Gameplay: Process Monitoring with Snoopy (LD_Preload)

Source: YouTube · Hack The Box · published Oct 30, 2020 · 1:27:20

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video demonstrates using Snoopy, an ld preload logging tool, to monitor Linux processes during Hack the Box Battlegrounds defensive gameplay 00:00.

Key Takeaways:
• Snoopy logs dynamically linked executable commands, providing visibility when attackers use system tools against the machine 08:25
• The tool has limitations, as it cannot monitor statically linked binaries or certain Python file operations, creating potential blind spots 14:30
• Defensive gameplay includes creative countermeasures like renaming binaries and patching vulnerabilities partially to observe attacker adaptation techniques 22:15

Understanding monitoring tool limitations is essential for effective blue team strategy in cybersecurity games and real-world scenarios.

Sources:

  • 00:00 Introduction to Snoopy for process monitoring in Hack the Box Battlegrounds
  • 08:25 Explanation of Snoopy's functionality and installation process
  • 14:30 Demonstration of Snoopy's limitations and blind spots
  • 22:15 Implementation of defensive techniques during gameplay

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

what's going on youtube this is ipsec and we're gonna be playing another round of cyber mayhem we're still focusing on the blue team because streaming is not allowed on this platform mainly because it's so easy to script out attacks from the red team because there's only so many ways you can prone each machine but on the blue team side it's an open world you can defend however you want in this video i'm going to show a lot of that like doing unique defenses against a player to not completely patch the castle but to try to make them adopt and try something that i don't expect and maybe i'll learn from them just because i stopped the most common way of exploiting something it's a lot of fun the main focus of this is going to be setting up linux process logging with an application called snoo…