Real Time SOC Analyst Simulation | TryHackMe SOC Simulator | Phishing Unfolding

  Рет қаралды 3,492

Motasem Hamdan | Cyber Security & Tech

Motasem Hamdan | Cyber Security & Tech

Күн бұрын

Пікірлер: 39
@boh70326
@boh70326 27 күн бұрын
Wow , amazing as usual Mot ..you re the first guy on KZbin that got it done ✔️ super 👌 thanks a lot man
@MotasemHamdan
@MotasemHamdan 26 күн бұрын
Glad you liked it!
@Jennifer-o2b8i
@Jennifer-o2b8i 27 күн бұрын
I was looking forward for this, thank you !
@MotasemHamdan
@MotasemHamdan 27 күн бұрын
Glad it was helpful.
@easy94883
@easy94883 25 күн бұрын
PLEASE PLEASE PLEASE make an hour long video going through different types of alerts and how to investigate them and report. This was so helpful for learning!! I subscribed ❤
@MotasemHamdan
@MotasemHamdan 25 күн бұрын
Thank you ! Noted.
@mazenal-emad8680
@mazenal-emad8680 24 күн бұрын
@@easy94883 +1
@Michael_ATL_82
@Michael_ATL_82 Күн бұрын
Wow, you just made all this stuff I learned in class click. Thank you.
@MotasemHamdan
@MotasemHamdan 21 сағат бұрын
Glad it was helpful!
@florecista1
@florecista1 21 күн бұрын
Excellent video 👏
@MotasemHamdan
@MotasemHamdan 21 күн бұрын
Thanks for the visit
@Sena-kj8wg
@Sena-kj8wg 24 күн бұрын
please do more of it, thank you, i appreciate that. A brazilian hug for you my friend!!
@MotasemHamdan
@MotasemHamdan 24 күн бұрын
Thanks for the feedback, I'll definitely look into creating more of these.
@reals4483
@reals4483 22 күн бұрын
I TRIED TO DO IT. bUT MY SIMULATOR KEEPS LOADING BUT ITS NOT OPENING.
@sanphotos
@sanphotos 24 күн бұрын
am on m 3rd month as SOC analyst and am learning from this. thanks
@MotasemHamdan
@MotasemHamdan 24 күн бұрын
Glad to hear it's helpful!
@sanphotos
@sanphotos 24 күн бұрын
@@MotasemHamdan I'm curios why you didn't escalate the case?
@MotasemHamdan
@MotasemHamdan 24 күн бұрын
@@sanphotos Because the root cause of the incident was determined and as such, the next action is to eradicate the infection and recover the system.
@sergiojhdz
@sergiojhdz 16 күн бұрын
Did you have to do anything in splunk, to be able to view the data? when splunk opens up for me, there is no data for me to search. I try different queries and it displays nothing
@MotasemHamdan
@MotasemHamdan 15 күн бұрын
try "index=*" and make sure the time is set to "all time"
@raul_d2747
@raul_d2747 25 күн бұрын
Just ran into your channel. Great content. You explained the steps very well. Can you do more of these?
@MotasemHamdan
@MotasemHamdan 25 күн бұрын
Thank you !
@jamilshekinski
@jamilshekinski 16 күн бұрын
Thank you habibi!!
@MotasemHamdan
@MotasemHamdan 15 күн бұрын
You're welcome 😊
@islamicwarrior9449
@islamicwarrior9449 27 күн бұрын
Beautiful, you’ve pretty much analysed the attackers entire TTP in like 10 minutes, my only question is that the case report that you write for that one alert, would you write the same case report for every high alert that had followed that alert?
@MotasemHamdan
@MotasemHamdan 27 күн бұрын
If the artifacts are the same, the case report will be the same 😀
@kingdwight1
@kingdwight1 25 күн бұрын
Why wouldn't the alert require escalation? I would think it definitely need to be escalated as data has been exfiltrated.
@MotasemHamdan
@MotasemHamdan 24 күн бұрын
Because the root cause has been determined and the next phase should be to eradicate the infection.
@kingdwight1
@kingdwight1 24 күн бұрын
Wouldn't eradication require an escalation?
@johnvardy9559
@johnvardy9559 24 күн бұрын
Motasem great work, could we do this lab with elastic search?
@MotasemHamdan
@MotasemHamdan 23 күн бұрын
Unfortunatrely its only available on Splunk
@hiasfa
@hiasfa 15 күн бұрын
Why wont it require escalation , As i believe the attacker now has access to financial records wont that be a matter of concern to be escalated?
@MotasemHamdan
@MotasemHamdan 15 күн бұрын
The event is escalated when the analysts who investigated the event couldn't reslove it so they escalate it to teams on upper tiers. This happens most often when there is a malware sample to analyze or reverse engineer.
@hiasfa
@hiasfa 15 күн бұрын
@@MotasemHamdan in an actual company , wont this be escalated to maybe senior as critical data has been exposed so shouldn't it be escalated for damage control?
@MotasemHamdan
@MotasemHamdan 15 күн бұрын
Maybe breach notification as part of legal compliance.
@hiasfa
@hiasfa 13 күн бұрын
@@MotasemHamdan Thanks for Clarifying
Real Time SOC Analyst | P2 | TryHackMe SOC Simulator Phishing Unfolding
35:55
Motasem Hamdan | Cyber Security & Tech
Рет қаралды 1,1 М.
Investigating Phishing Emails | Letsdefend Walkthrough | Case SOC326
26:48
Motasem Hamdan | Cyber Security & Tech
Рет қаралды 1,3 М.
Quando eu quero Sushi (sem desperdiçar) 🍣
00:26
Los Wagners
Рет қаралды 15 МЛН
So Cute 🥰 who is better?
00:15
dednahype
Рет қаралды 19 МЛН
Interview with Computer Security Trainer
10:49
Programmers are also human
Рет қаралды 279 М.
i dove down the 7z rabbit hole (it goes deep)
12:50
Low Level
Рет қаралды 624 М.
Gain SOC Experience with LetsDefend
8:16
MyDFIR
Рет қаралды 11 М.
Underrated Cyber Security Certs that WILL get you HIRED
12:19
UnixGuy | Cyber Security
Рет қаралды 104 М.
SHODAN Explained! (It's Scary Easy to do) | Let's Hack
7:58
Let's Hack
Рет қаралды 524 М.
HackTheBox CDSA vs BTL1: Which One You Should Pursue?
5:07
Motasem Hamdan | Cyber Security & Tech
Рет қаралды 2,2 М.
Cybersecurity Roadmap 2025 | From Beginner to Advanced
6:27
Motasem Hamdan | Cyber Security & Tech
Рет қаралды 2,2 М.
Quando eu quero Sushi (sem desperdiçar) 🍣
00:26
Los Wagners
Рет қаралды 15 МЛН