Gain SOC Experience with LetsDefend
8:16
12 сағат бұрын
Cybersecurity SOC Analyst Lab - PDF Analysis
17:17
Пікірлер
@ThandoButhelezi-o5b
@ThandoButhelezi-o5b 52 минут бұрын
Thank you for this! I'm having an issue installing the virtualbox on my laptop. It's telling me to install Microsoft visual c++ 2019 redistributable package, which i have but its still saying the same thing everytime i try to install the virtualbox
@Vinci205
@Vinci205 7 сағат бұрын
I need help.
@Vinci205
@Vinci205 7 сағат бұрын
I cannor download splunk on my vm. It will not let me access the website. Why?
@dtitan1993
@dtitan1993 8 сағат бұрын
Thoughts on Security Onion?
@ololadejoel324
@ololadejoel324 12 сағат бұрын
Kudos
@ololadejoel324
@ololadejoel324 13 сағат бұрын
S0C
@aross5234
@aross5234 14 сағат бұрын
I'm not sure what happened but I was following along and everything was working great, but now for some reason my Shuffler webhooks aren't receiving my alerts. The Mimikatz alert was working but once I tried setting up the second workflow for the linux machine neither work. The corresponding alerts generate in my Wazuh dashboard and I can manually curl the webhooks and they receive the payload. I've gone over the ossec.conf file for my Wazuh manager probably 20 times now to ensure everything is correct and I'm still having the issue. Is this something to do with the shuffle free tier?
@MyDFIR
@MyDFIR 14 сағат бұрын
Interesting, not that I am aware of. I would try doing a fresh shuffle instance and see if that works (create a new webhook)
@aross5234
@aross5234 12 сағат бұрын
@@MyDFIR Nevermind, I figured out the problem occured because I renamed both of my integrations in the ossec.conf file to relfect which machine the webhook was for, not realizing they reference the shuffle wrapper file under var/ossec/integrations.
@MiltonJimenez-o1y
@MiltonJimenez-o1y 15 сағат бұрын
Has to be one by one? :c
@javagamesfanclub5650
@javagamesfanclub5650 18 сағат бұрын
Flare vm downloading is too slow i mean really fkn slow its been almost 5 hours and its still not done
@pcwway2dawn
@pcwway2dawn 20 сағат бұрын
Been using runzero for years, fantastic tool. My MSP setup a dropbox on a raspberrypi to ship to clients and run scans for them.
@MyDFIR
@MyDFIR 14 сағат бұрын
That is awesome!! Track all the assets 😁
@Da-el8nc
@Da-el8nc 21 сағат бұрын
Wow, I don't know if it's because you put together a script very carefully or it's natural talent, but the way you structure the development of the explanation is excellent, it's very digestible and for some reason relaxing too 😅
@MyDFIR
@MyDFIR 21 сағат бұрын
Wow, thank you! Surprisingly no script for the lab portion as I find it very difficult to follow a script while working a lab. Just me and my thought process 😁
@Appu_7_7_7
@Appu_7_7_7 22 сағат бұрын
Thank you for valuable time 😊
@MyDFIR
@MyDFIR 21 сағат бұрын
My pleasure 😊
@tukaram4606
@tukaram4606 23 сағат бұрын
Thanks Steven🙏🏻🙂
@alwarithalkhusaibi7902
@alwarithalkhusaibi7902 23 сағат бұрын
What courses do you recommend in this platform for intermediate and advanced learning?
@the_masked_tailor
@the_masked_tailor Күн бұрын
Your contents are really helpful steven. God bless yoy for not gate keeping. You really help newbies like me gain more insight to the cybersecurity industry. God bless you
@mapletech_22
@mapletech_22 Күн бұрын
Thanks Steven
@blockchain2534
@blockchain2534 Күн бұрын
This is very a insightful Video on CS
@URNEXTCISO
@URNEXTCISO Күн бұрын
Hey Steven just wanted to give you a shoutout. Just got a professional internship as a blue team operator at an mssp and I did reflect the 30days challenge on my CV which really helped during the technical interview. Thank you for everything you do
@ihajikhan
@ihajikhan Күн бұрын
Can you tell me what 30 days challenge is
@ffhub1633
@ffhub1633 Күн бұрын
@@ihajikhan SOC LAB Attack and Defense Simulation
@ihajikhan
@ihajikhan Күн бұрын
@@ffhub1633 is it free or paid
@MyDFIR
@MyDFIR 21 сағат бұрын
LFG!!! Super happy to hear that. I am proud of you. 💙
@MyDFIR
@MyDFIR 21 сағат бұрын
It is this: 30-Day SOC Analyst Challenge | Gain Practical Experience for Free! kzbin.info/www/bejne/jWSoqYZoopt1aJY
@kd2yxs
@kd2yxs Күн бұрын
Best instruction video on snort3. Thanks!
@MyDFIR
@MyDFIR Күн бұрын
Wow, thanks!
@visionaryeyes1759
@visionaryeyes1759 Күн бұрын
Great video man, really
@MyDFIR
@MyDFIR Күн бұрын
Glad you liked it!
@frankurhioke1964
@frankurhioke1964 Күн бұрын
Do you have a discount on your course presently or a payment plan in place?
@MyDFIR
@MyDFIR Күн бұрын
Not yet but definitely something I plan on doing soon
@mackthetrucker9456
@mackthetrucker9456 Күн бұрын
I’m a beginner should I start here or get certifications first?
@MyDFIR
@MyDFIR Күн бұрын
Great question. As a beginner I would do a 80/20 split. Focus on theory so you can understand the concepts and put 20% of your effort into applying the theory you learned into practical experiences.
@sheershchandela128
@sheershchandela128 2 күн бұрын
Can I use SOC automation lab to perform projects other than security response using wazzuh
@MyDFIR
@MyDFIR Күн бұрын
Yeah, it is entirely up to your creativity. If a tool has an API, you can do alot with it.
@x0rZ15t
@x0rZ15t 2 күн бұрын
Remember kids, PDF really stands for Payload Distribution Format
@MyDFIR
@MyDFIR Күн бұрын
Love this 😂
@somadinaamadi1672
@somadinaamadi1672 2 күн бұрын
I just letsdefend VIP with your code ❤
@MyDFIR
@MyDFIR Күн бұрын
Awesome! Happy learning 💙
@mufcabbage7116
@mufcabbage7116 2 күн бұрын
Awesome video as aways!
@MyDFIR
@MyDFIR Күн бұрын
Thanks!
@Aaron_Mullen
@Aaron_Mullen 2 күн бұрын
This is great! Thank you so much for creating this! I am wanting to get into the cyber security field. I have been working as a desktop support analyst for 3 years as my first role in IT. I feel like things are stagnating for me now within this role and I am interested in cyber security. My hope is to accomplish this without a degree. I will commit to any certs needed and do my best to learn online with resources (like this one!) that are available. Thank you so much for your efforts and generosity with this free lab.
@MyDFIR
@MyDFIR 2 күн бұрын
My pleasure! There are even more labs/projects available on my channel that you can tackle afterwards. Just remember, consistency is key. You got this 💪
@Raviteja-le6mt
@Raviteja-le6mt 2 күн бұрын
just observation: he said first couple of bytes but he copied first 4 bytes for file singnature
@MyDFIR
@MyDFIR 2 күн бұрын
Heheh english is hard but yes you’re correct.
@oussamaelmasakoui826
@oussamaelmasakoui826 2 күн бұрын
After searching and reporting for index="endpoint" , it gives me 0 data , I even watched the troubleshooting video (I checked everything even the firewall ) , any ideas ? (It's been 3days since I'm stuck)
@MyDFIR
@MyDFIR 2 күн бұрын
Some questions to ask yourself: Is the time range correct? Restart service? Index exist? Port is open to receive data?
@oussamaelmasakoui826
@oussamaelmasakoui826 2 күн бұрын
Thanks , btw for those who had the same problem, I created a rule on my firewall (for port 9997) then restart the service, then try to change your time range to 7 days .
@royalkingzzfight
@royalkingzzfight 2 күн бұрын
SOC!
@MISTYEYED.
@MISTYEYED. 2 күн бұрын
Thank you.
@crzyassgoon181
@crzyassgoon181 2 күн бұрын
I cant get my vbox to allow guest-additions to work. I tried installing it, but for some reason I'm not able to utilize my mouse. It only happens on my ubuntu server.
@crzyassgoon181
@crzyassgoon181 2 күн бұрын
I just realize that I was trying to do everything on the vm and not powershell... Is that the reason why u use PShell?
@MyDFIR
@MyDFIR Күн бұрын
Bingo! Powershell makes everything so much easier, i hate working within the vm
@CreatineCowboy
@CreatineCowboy 2 күн бұрын
Which ones are strongest for your resume? I have two different labs on my resume already or should i remove these? - setup SIEM on azure vm and geologation map of RDPA -performed vulnerability management with openVAS and remediated vulnerability I do already perform some vulnerability management with and incident response with pillr and sentinel one at my current role. So maybe it's meh to keep.
@OrioMaldo
@OrioMaldo 2 күн бұрын
Amazing! I also noticed they got "SOC Analyst Prerequisites" path which dives into topics like Windows/Linux fundamentals, Bash/Powershell scripting, Intro to Networking and AD.. which are crucial for a SOC Analyst. I would like to hear your opinion on the new PJSA from TCM. Thank you for reviewing the CDSA, as I'm planning to take it
@boomfire6413
@boomfire6413 2 күн бұрын
im right now im studying about the pentest, if i want to learn soc analyst are the best way to do that is by home labe or i need first study about tools of soc ....
@johnpaulj.pamintuan8529
@johnpaulj.pamintuan8529 2 күн бұрын
Hi, i couldn't get th e IP address on Kali, i double check and re-did it. there is nothing that said "inet = IP address" and i tried to search on how to locate the Ip address on kali just to verify it. any advice or suggestion?
@royalkingzzfight
@royalkingzzfight 2 күн бұрын
SOC
@royalkingzzfight
@royalkingzzfight 2 күн бұрын
SOC
@royalkingzzfight
@royalkingzzfight 2 күн бұрын
SOC
@deepakdiwakar2968
@deepakdiwakar2968 3 күн бұрын
Thanks for the walkthrough sir. But i am stuck at adding agent policy step, I am using Azure , and I followed each step and similar steps as in azure. And after successfully adding the agent policy , i think that my window server is not properly connected to fleet server even though the elastic agent is successfully installed, and showing an error "the metric is not available , you may have not the corret permission to retrive it." ; Sir, May you please help me to sort this out? Update : when i put my window server in same vnet as fleet and elk, and open fleet to windows public network. Now its works good and retrieving logs.
@AnbuSecOps
@AnbuSecOps 3 күн бұрын
My elastic failed to start due to control process exited with error code. Anyone have this?
@Amy-z9w9g
@Amy-z9w9g 3 күн бұрын
SOC I hope not so late, thanks for your time and knowledge. Thank you for bridging the gap.
@MyDFIR
@MyDFIR 2 күн бұрын
Any time!
@tokenblack444
@tokenblack444 3 күн бұрын
Tool 1: Hair cut, Tool 2: shave face.
@MyDFIR
@MyDFIR 3 күн бұрын
10/10 tools would recommend!
@mapletech_22
@mapletech_22 4 күн бұрын
Thank you Steven. Awesome 👌
@MyDFIR
@MyDFIR 3 күн бұрын
Glad you liked it!
@zoltron30
@zoltron30 4 күн бұрын
I'm coming from a NOC/CCNA/ISP back ground. Would I have to learn Linux first?
@MyDFIR
@MyDFIR 3 күн бұрын
Not necessarily, but it wouldn’t hurt to know the basics!
@isaiahbodre5738
@isaiahbodre5738 4 күн бұрын
Wassup man i have a quick in regards to a part you mentioned in your video. You had stated that taking courses is a good way to kinda break into cybersecurity. What's your thoughts on the foundation of cybersecurity program provided by google on coursea?
@MyDFIR
@MyDFIR 3 күн бұрын
Its great, provides a nice high level overview and you get a voucher at the end for sec+. Its not going to teach you everything so you’ll need to dig into more if you’re really interested!
@Da-el8nc
@Da-el8nc 4 күн бұрын
thank you so much steven!
@MyDFIR
@MyDFIR 3 күн бұрын
My pleasure!
@suleimanabdussamad666
@suleimanabdussamad666 4 күн бұрын
Thank you Steven, you're Dfirent 🙌🏽
@MyDFIR
@MyDFIR 3 күн бұрын
My pleasure!
@Dylanset15
@Dylanset15 4 күн бұрын
I need an opinion from anyone that has some knowledge… so there’s this boot camp that’s 18k and it’s 18k, it’s a bootcamp from Penn state university, they help you build your resume and look for jobs 🤨 train you and al those stuff, but I’m scared because idk if I should invest all that
@MyDFIR
@MyDFIR 4 күн бұрын
18k is a lot of money - this will really depend on your background and experience. DM me on my socials (X or Instagram) I would like to know more before you decide to pull the trigger.