Try Hack Me: YARA

  Рет қаралды 6,266

stuffy24

stuffy24

Күн бұрын

Пікірлер
@stuffy24
@stuffy24 2 жыл бұрын
Get 20% OFF @manscaped + Free Shipping with promo code STUFFY24 at MANSCAPED.com! #ad #manscapedpod
@jacobmurphy8579
@jacobmurphy8579 2 жыл бұрын
Thank you for the walkthrough! Going through the SOC 1 path right now and some of the linux commands were a pain in the butt.
@stuffy24
@stuffy24 2 жыл бұрын
of course man we are all trying to get better just gotta work together sometimes!
@rafaeldacosta8581
@rafaeldacosta8581 9 ай бұрын
27:23 is THM room teaching us to not trust Yara detection? since file2 is flagged as bening, 'thou it's just b374k webshell in later version
@stuffy24
@stuffy24 6 ай бұрын
Yara rules are as good as you make them.
@frybait0626
@frybait0626 3 ай бұрын
how we're you able to identify and cat out the specific rule inside the .yar file? there's alot of rules inside the thor-webshells.yar What is the specific command or grep that you did.
@SecTechie
@SecTechie Жыл бұрын
Great walkthrough. Thanks so much.
@stuffy24
@stuffy24 Жыл бұрын
Thank you!
@adalparedes1
@adalparedes1 Жыл бұрын
thank you for this video and your time, I really appreciate it. thank you again for sharing
@alechernandez5506
@alechernandez5506 7 ай бұрын
Thanks brother. Going to be taking CySA soon and applying for SOC positions in the next few months.
@stuffy24
@stuffy24 6 ай бұрын
Best of luck! You got this
@treedents839
@treedents839 4 ай бұрын
i did the same process, my VM doesnt let me use the cp command to copy the file 2 in Loki, getting quiet pissed off at that haha
@stuffy24
@stuffy24 4 ай бұрын
@@treedents839 lol that's super frustrating
@BartekFreestyle
@BartekFreestyle 11 ай бұрын
Thank you for this, I couldn't do it if I wasn't following and listening to the explanation. However I have encountered an issue with writing the Yara rule in Task 10. Despite copying the python3 yarGen.py -m /home/cmnatic/suspicious-files/file2 --excludegood -o /home/cmnatic/suspicious-files/file2.yar command. the response on the console was that it couldn't find file2. Not sure if only me had this issue
@stuffy24
@stuffy24 11 ай бұрын
Feel free to join the discord and throw the question in the questions chat
@chbihmrabih9666
@chbihmrabih9666 Жыл бұрын
Thank you, please keep going on it was very clear and helpfull
@greenonblack2790
@greenonblack2790 2 жыл бұрын
great walkthrough thanks 🙏📈
@MFmyk3
@MFmyk3 Жыл бұрын
cant get the copy cp command to work following your input. keeps saying cp" can not stat: No such file or directory" - trying everything im going crazy with this. stuck for 2 hours. checked both dir. all files an pathway exist. not sure what i am doing wrong, im copying the exact inputs.
@stuffy24
@stuffy24 Жыл бұрын
Hop in the discord and put screenshots plz
@MFmyk3
@MFmyk3 Жыл бұрын
@@stuffy24 hoping in now thnks, didnt see ur comment update.
@thatoneguywithtwothumbs
@thatoneguywithtwothumbs Жыл бұрын
Ok but why won’t it let me save it. 😅
@thatoneguywithtwothumbs
@thatoneguywithtwothumbs Жыл бұрын
Nvm I have the tism
@williamthomas3233
@williamthomas3233 Жыл бұрын
I’m still having a hard time exiting and saving
@thatoneguywithtwothumbs
@thatoneguywithtwothumbs Жыл бұрын
@@williamthomas3233 ctrl + x to exit. "y" to save. then enter.
Try Hack Me: Intro to ISAC
25:27
stuffy24
Рет қаралды 223
Yara Rules Explained | Complete Tutorial | TryHackMe Yara
29:26
Motasem Hamdan | Cyber Security & Tech
Рет қаралды 8 М.
Арыстанның айқасы, Тәуіржанның шайқасы!
25:51
QosLike / ҚосЛайк / Косылайық
Рет қаралды 700 М.
Try Hack Me: Windows Event Logs
55:06
stuffy24
Рет қаралды 9 М.
Hands-On Traffic Analysis with Wireshark - Let's practice!
51:04
Chris Greer
Рет қаралды 39 М.
Introduction to YARA Part 1 - What is a YARA Rule
9:50
OALabs
Рет қаралды 8 М.
Try Hack Me: MISP
20:27
stuffy24
Рет қаралды 4,2 М.
TryHackMe Walkthrough // Wireshark Basics Room - SOC Analyst 1
20:24
Cyber Threat Intelligence Platforms | OpenCTI | TryHackMe
23:09
Motasem Hamdan | Cyber Security & Tech
Рет қаралды 7 М.
The 7 Desktop OS I Run Every Week (& why!)
15:43
ExplainingComputers
Рет қаралды 6 М.
Cyber Incident Response with Splunk |  TryHackMe Incident Handling with Splunk
44:44
Motasem Hamdan | Cyber Security & Tech
Рет қаралды 27 М.
Active Directory Basics : Tryhackme
42:29
stuffy24
Рет қаралды 23 М.