Hey, this is really cool. went over velociraptor in a couple of my sans courses and needed it for an assignment I'm doing right now. ty, <33
@christophernst20483 ай бұрын
Hey - I really liked the video and the demos you gave on Velociraptor! 🙂 In the end of the Video you mention that this demo was part of a SANS class. Would you mind disclosing which SANS course this was part from?
@whoamisecurity95864 ай бұрын
Your radar is awesome Eric 🎉 Unbelievable Incident response Demo ⚔️
@nataaniinez5 ай бұрын
Dude your videos are a hidden gem, like the old internet
@paviterjotsingh63986 ай бұрын
Simply wow
@paviterjotsingh63986 ай бұрын
wow
@shamshoque25468 ай бұрын
Really great structured information. Thanks. How to integrate hyabusa in hunt profile????
@gerarddunphy9 ай бұрын
Incredible demo showing how Velociraptor truly takes IR capabilities to a whole other level! This is a game changer! The only thing missing was did the threat actor actually exfil those plans to the death star :) Thank you for this great insight! I have a new lab to build post haste!
@WarThunderista9 ай бұрын
Amazing stuff :D
@ride_the_wild_wind Жыл бұрын
Thanks a lot for such detailed explanation
@aliakbar307 Жыл бұрын
Hi, thanks for the great video. I have a question. How the shellcode is decrypted and which component will decrypt it?
@holeraholera Жыл бұрын
Great stuff! Thank you. Have you thought about releasing the collected data so that we can play with it in our own velociraptor server?
@richscaglione Жыл бұрын
So I'm currently a windows system administrator and I've been in IT for about 7 years now. I'm looking to pivot into cybersecurity as an entry level SOC Analyst. Would you say this video is a good representation of what a brand new SOC Analyst would do right away or would you build up to this level of knowledge over time?
@edwardwhite8253 Жыл бұрын
Absolutely incredible and in-depth demo! The pacing, the contents are all great! Bravo Eric!
@rolyperez8695 Жыл бұрын
I heard about this at the NCFI and started using it. Cederpelta was the one i used to use. Greetings from LaredoTx.
@KenPryor Жыл бұрын
This was amazing. I just started learning about Velociraptor recently and have much to learn. This video was extremely helpful.
@abhijithTS-f1r Жыл бұрын
how to install OpenSOC on ubuntu?
@civicnox Жыл бұрын
Good video
@JamalRice Жыл бұрын
Good job!
@clasherbak Жыл бұрын
How did you prepared the demo environment with more than 60 workstations? is that a simulator tool? awsome talk by the way and thank you!
@EricCapuano Жыл бұрын
I used a large virtual environment we've built for other trainings like OpenSOC & our Network Defense Range.
@frzen Жыл бұрын
Great talk thanks
@domiflichi Жыл бұрын
Wow! Incredible video, thank you!
@sirisiri2048 Жыл бұрын
This is awesome Really in-depth analysis Just had one question where can I find this data or the malware ? Is their a repository you have used for this ?
@EricCapuano Жыл бұрын
Sadly this was run inside of our live training range so the data is not available otherwise. I’ll see about trying to capture and release the data in the future!
@ChristopherReevesNZ Жыл бұрын
Issues that I see with this: 1. This seems to rely on AD GPO (or some sort of deployment tool), these days people are also using Macs and *inux so you might not get all the coverage. Secondly on this point is if GPO is disabled at the AD / workstation level then this too is rendered useless. 2. I personally don't know of one analyst that knows VQL let alone SQL 3. The UI is 🤮 4. Tools like Crowdstrike kinda do this using ML/AI without all the manual stuff 5. Dropping session seems quite POCCY to me 6. A lot of this stuff can be done using windows remote management in a scripted way
@Impact_Creativity2 жыл бұрын
what an amazing video! thanks for all the info, really usefull!
@getoutmore2 жыл бұрын
This was so awesome!!! I could have watched this for hours. Motivated me so much to get my hands on this. Do you have more stuff Like this? Im hungry to learn! Thanks you for the Video
@xDx44442 жыл бұрын
Thanks a lot dude. It would be really nice to upload more scenarios like this one. <3
@bdtechnology99002 жыл бұрын
Hello sir i need your mail or whatsapp for help
@MuhammadImran-xu4fw2 жыл бұрын
Awesome, impressed :) How about if the adversary does the cleanup while doing lateral movement?
@RicondaRacing2 жыл бұрын
32:54 😂
@RicondaRacing2 жыл бұрын
As a prospective blueteamer, this is very valuable. Only issue is having access to the tools to get the experience.
@rpt30662 жыл бұрын
Dont know what more motivation is needed to use this awesome tool - for FREE! Thank you Eric C for sharing invaluable experience for FREE & Mike C for sharing this tech for FREE 👑🙌
@dananderson69922 жыл бұрын
Well done live hunt. thanks for sharing.
@clomok2 жыл бұрын
Wow, such a cool talk. Does velociraptor have to be implemented with a single network? Is there a way to have velociraptor clients from different networks communicate with a single server?
@EricCapuano2 жыл бұрын
Absolutely. The server doesn’t know/care what network the agent checks in from. You can host the server in the cloud and have hosts on many different networks checking in.
@clomok2 жыл бұрын
@@EricCapuano that sounds like a wonderful setup. Can you imagine a situation where velociraptor replaces a MSP's end point detection and aggregates all clients to a universal dashboard?
@EIDEID992 жыл бұрын
wait @23:39 , if a user login , will 4624 stored in the AD on in his/her PC.
@EricCapuano2 жыл бұрын
A 4624 (successful logon) gets generated on the system being logged onto to... The authentication event (4768) shows up on the domain controller.
@PrinterJamOnToast2 жыл бұрын
This is so cool, I hope to work for a company that uses this some day.
@TurboRetard2 жыл бұрын
Im deploying it where I work, glad the sysadmin is open minded to give me free reign on cyber security
@velocidexenterprises87022 жыл бұрын
Really excellent talk with so much information. Great to see Velociraptor wielded by such a skillful defender! A must watch presentation for any Blue Teamer or defender out there!
@mitchimpey17262 жыл бұрын
Great Demo Eric. Excellent example and a great presentation. Thanks, appreciated !
@EricCapuano2 жыл бұрын
Thank you! Glad you enjoyed it.
@mmobini18032 жыл бұрын
Thank you!
@michaelfranco86873 жыл бұрын
Looks like you could’ve gone for “under 15 minutes” 😂 nice content. I don’t know how there are not more subscribed!
@nlay423 жыл бұрын
This was very helpful! Hopefully you can do more videos like this to teach us! If you know of other resources that can bring to light the research process I would like to learn more. Thank You!
@KoEDeath3 жыл бұрын
Is there any kind of simulated environment that someone could use to practice this type of SOC analysis?
@RichardGailey3 жыл бұрын
@32:11 why when loading CyberChef in Moloch, did it say 'Mining Bitcoin Cash', as CC was loading? Also, this was a fantastic scenario walkthrough.
@redlinejoes3 жыл бұрын
It’s a joke. The devs of cyber chef think they are comedians and like all devs who try to be funny, it’s an epic failure.
@ramirez3683 жыл бұрын
Super useful...is SOC Analyst an entry level in Cybersecurity field?
@select_from_users58423 жыл бұрын
Indeed, but not an entry-level IT job. Working Help Desk for a little bit helps build a great foundation for Security and other fields in IT.
@rajatwason21743 жыл бұрын
Hey, great video. Is it somehow possible to exports the logs from a particular stream and for a particular timeframe from the console?
@FajriSiddiq3 жыл бұрын
nice video, really interesting to learn!
@markpfeffer74873 жыл бұрын
This is criminally under viewed for soc analyst applicants. Good content. Subbed.
@slackspace22814 жыл бұрын
This is awesome ! do you mind sharing the eradication script pls
@slackspace22814 жыл бұрын
please ignore this, just saw the link ...keep up the awesome work
@damians84984 жыл бұрын
What's your thoughts on Splunk vs Graylog?
@helloqasim4 жыл бұрын
I thought you said you have no degree or certification, that is not true