
Business CTF 2023 - Hacking Blue: Blue Teaming & Hacking Workshop by sebh24
Source: YouTube · Hack The Box · published Jul 13, 2023 · 29:01
This session walkthroughs the "Repetitive D" Sherlock on Hack The Box, focusing on investigating a 3D printing server breach through log analysis and network capture to identify the attacker and their tools 3:58.
Key Takeaways:
• Sherlock emphasizes investigative context over flag hunting, encouraging a "purple team" approach where players analyze evidence linearly like a real SOC response 1:27.
• Initial log analysis revealed path traversal attempts and a suspicious User-Agent (curl) from an internal IP (10.255.254.3), suggesting an insider threat or compromised VPN client 10:42.
• The attacks targeted the Apache Repetier Server, confirming the exploitation of CVE-2023-31059 for versions prior to 1.4.1 13:46.
The tutorial highlights the value of completing both offensive and defensive exercises to gain a holistic understanding of the attack and defense lifecycle 2:06.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
hello and welcome to my business CTF talk called hack of the blue uh we're covering something I think extremely in my opinion interesting today I probably would say that as um it's very much because I guess our baby over on defensive content uh we're covering Sherlock's today I guess probably sat there wondering what is Sherlock's there's plenty of reading material on this uh but we'll cover it uh both at a high level today and we'll also play through a Sherlock's live um as a part of this talk and that is the main focus of the talk Sherlock's is investigative based content um what we're really covering when we say investigative content is we're talking in particular uh about content within deadly Labs that is called Sherlock's so if we just jump into our dedicated Labs here um we can see …