Business CTF 2023 - Hacking Blue: Blue Teaming & Hacking Workshop by sebh24

Business CTF 2023 - Hacking Blue: Blue Teaming & Hacking Workshop by sebh24

Source: YouTube · Hack The Box · published Jul 13, 2023 · 29:01

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This session walkthroughs the "Repetitive D" Sherlock on Hack The Box, focusing on investigating a 3D printing server breach through log analysis and network capture to identify the attacker and their tools 3:58.

Key Takeaways:
• Sherlock emphasizes investigative context over flag hunting, encouraging a "purple team" approach where players analyze evidence linearly like a real SOC response 1:27.
• Initial log analysis revealed path traversal attempts and a suspicious User-Agent (curl) from an internal IP (10.255.254.3), suggesting an insider threat or compromised VPN client 10:42.
• The attacks targeted the Apache Repetier Server, confirming the exploitation of CVE-2023-31059 for versions prior to 1.4.1 13:46.

The tutorial highlights the value of completing both offensive and defensive exercises to gain a holistic understanding of the attack and defense lifecycle 2:06.

Sources:

  • 1:27 Definition of Sherlock vs flags and purple team approach.
  • 3:58 Scenario description regarding the 3D printing server breach.
  • 10:42 Detection of path traversal and curl user agent.
  • 13:46 CVE-2023-31059 exploitation details.
  • 2:06 Benefits of purple team approach.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

hello and welcome to my business CTF talk called hack of the blue uh we're covering something I think extremely in my opinion interesting today I probably would say that as um it's very much because I guess our baby over on defensive content uh we're covering Sherlock's today I guess probably sat there wondering what is Sherlock's there's plenty of reading material on this uh but we'll cover it uh both at a high level today and we'll also play through a Sherlock's live um as a part of this talk and that is the main focus of the talk Sherlock's is investigative based content um what we're really covering when we say investigative content is we're talking in particular uh about content within deadly Labs that is called Sherlock's so if we just jump into our dedicated Labs here um we can see …