
University CTF 2024: Let's Sherlock! An introduction to Blue Team Training
Source: YouTube · Hack The Box · published Dec 12, 2024 · 30:51
The video walks through "Op Tinsel Trace 3," a defensive cybersecurity challenge that simulates real-world incident response by analyzing a Windows 10 memory dump to uncover malicious activities 0:14-0:23. Participants use volatility to identify suspicious files and processes, ultimately tracing a link file that executes a PowerShell script to search for and run VBS files, leading to a remote command execution via a base64-encoded URL 1:30-1:45.
Key Takeaways:
• Sherlock challenges mirror real-world defensive investigations by posing forensic questions similar to incident reports 0:14-0:23.
• The challenge begins with a Windows 10 memory dump analyzed using volatility to identify files and running processes 0:54-1:08.
• A suspicious file, "present for santa.zip," is found on the desktop and extracted from memory 1:09-1:18.
• The link file "click for present.link" executes PowerShell with a base64-encoded command to recursively search for and run VBS files in user directories 1:30-1:45.
• The VBS script obfuscates its payload and eventually calls powershell.exe with a URL derived from a string extraction function using a custom pattern 2:05-2:28.
This hands-on investigation highlights core defensive techniques such as memory analysis, file extraction, and understanding attacker behavior through obfuscation and lateral movement.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
hey this is oxf and uh welcome to University CTF 2024 uh hopefully this is going to be an exciting time for you all and hopefully these talks are providing some value um today we are going to talk about Sherlocks and uh what are Sherlocks um Sherlocks are investigatory challenges meant to mirror realworld tasks that you'd run into working in a defensive cyber security role uh they come in a handful of categories sock deer Cloud maare analysis threat intelligence um and they different boxes and challenges on the platform in that they don't you're not just seeking a flag or you're not trying to read a root. text and if you think about it it doesn't really work that way for defensive investigation in a Red Team Challenge you start off with no access we give you an IP address and you have to f…