Let's Defend: PowerShell Script
Challenge Link: https://app.letsdefend.io/challenge/powershell-script Scenario: You've come across a puzzling Base64 script, seemingly laced with malicious intent. Your mission, should you choose ...
Challenge Link: https://app.letsdefend.io/challenge/powershell-script Scenario: You've come across a puzzling Base64 script, seemingly laced with malicious intent. Your mission, should you choose ...
Challenge Link: https://app.letsdefend.io/challenge/dll-stealer Scenario: You work as a cybersecurity analyst for a major corporation. Recently, your company's security team detected some suspicio...
Challenge Link: https://app.letsdefend.io/challenge/php-cgi-CVE-2024-4577 Scenario: You will confront an attempted exploitation of a newly discovered and unpatched vulnerability (CVE-2024-XXXX) in...
Challenge Link: https://app.letsdefend.io/challenge/batch-downloader Question 1 What command is used to prevent the command echoing in the console? In the ChallengeFile folder on the Desktop I fo...
Introduction to Volatility Volatility is a powerful tool for analyzing memory dump files from a system’s running RAM. Since RAM doesn’t organize data into structured files, tools like Volatility c...
Challenge Link: https://app.letsdefend.io/challenge/upstyle-backdoor File Location: C:\Users\LetsDefend\Desktop\ChallengeFile\sample.zip File Password: infected Question 1 What function is respo...
This cheatsheet provides quick reference tips for using Splunk effectively. Clarity and accuracy are key—let’s dive in! General Tips Case Sensitivity: Searches are case-insensitive by defaul...
Challenge Link: https://app.letsdefend.io/challenge/malicious-autoit File Location: C:\Users\LetsDefend\Desktop\ChallengeFile\sample.zip File Password: infected Question 1 What is the MD5 hash o...
Installing Splunk on Ubuntu cd ~/Downloads/ wget -O splunk-9.4.0-6b4ebe426ca6-linux-amd64.tgz "https://download.splunk.com/products/splunk/releases/9.4.0/linux/splunk-9.4.0-6b4ebe426ca6-linux-amd6...
Question 1 In network communication, what are the IP addresses of the sender and receiver? I used the following Wireshark display filter to limit results to ones containing P13 : frame contains "...