Incident Response Walkthrough: Solving BFT Sherlock on HTB Labs | Learn with HTB (Episode #5)

Incident Response Walkthrough: Solving BFT Sherlock on HTB Labs | Learn with HTB (Episode #5)

Source: YouTube · Hack The Box · published Sep 25, 2024 · 28:48

Malware Analysis
No ratings yet Log in to rate
Transcript Available
Description

This video demonstrates how to use Hack The Box's Sherlocks for digital forensics training, specifically focusing on MFT (Master File Table) analysis to track malicious activity 0:08.

Key Takeaways:
• Sherlocks are realistic blue team exercises that require using a virtual machine environment for safety when handling potentially malicious artifacts 1:27
• The presenter walks through the "bft" Sherlock exercise, converting an MFT file to CSV using mft2cmd for analysis 4:03
• Timeline Explorer is used to visualize and filter the forensic data to answer specific investigation questions 7:12
• The investigation includes identifying a malicious zip file, extracting download URLs from Zone identifiers, and locating the full path of the malicious batch file 8:21
• Advanced techniques like calculating hex offsets and examining resident MFT files reveal command and control server information 22:12

The tutorial demonstrates practical forensic analysis workflows that cybersecurity professionals can apply in real-world incident response scenarios 28:09.

Sources:

  • 0:08 Introduction to Sherlocks and MFT forensics
  • 1:27 Warning about using a virtual machine
  • 4:03 Converting MFT to CSV using mft2cmd
  • 7:12 Using Timeline Explorer for analysis
  • 8:21 Finding the malicious zip file
  • 22:12 C

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Malware Analysis. Commonly maps to: Security Operations, Security Architecture and Engineering. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

[Music] welcome to learn with hack the Box a unique YouTube series Focus on Fast tracking your career path in either offensive or defensive cyber security whether you're an aspiring sock analyst or pentesters stay tuned for these exclusive tutorial Style videos from experienced cyber security professionals who will guide you with tips and tricks to get you going along the way so by the end of this episode we'll discover things like how to track down malicious files how to correlate data in a timeline or even shutting down a command and control so whether you're new to the field or an experienced vet this guide is going to get you a solid foundation to get you moving on the way so to start things off we're going to get into hack the Box's Sherlocks located on the main website so as I mentio…