Detect Hackers & Malware on your Computer (literally for free)

Поділитися
Вставка
  • Опубліковано 17 лис 2024

КОМЕНТАРІ • 412

  • @max06de
    @max06de Рік тому +344

    A word of advice: Be careful who you trust. Even a software promising your security can be a disguised bad actor. (Not saying aurora is one of those!)

    • @siren_grnk
      @siren_grnk Рік тому +41

      But it very well could be, who knows what they collect and store. Trust no one.

    • @ftincel
      @ftincel Рік тому +5

      exactly what i thought.

    • @kipchickensout
      @kipchickensout Рік тому +5

      ​@@TheStevenWhitingthat's exactly what I also want

    • @AbandonedVoid
      @AbandonedVoid Рік тому +38

      ​@@TheStevenWhitingCybersecurity used to be a place for computer nerds, now it's filled with Machiavellian sell outs trying to make a quick buck. But if you really care about a project like this being open source, then you should start the project yourself. If it gets enough momentum, I'd probably do bug bounties for it as volunteer work.

    • @farmeunit
      @farmeunit Рік тому +13

      @@TheStevenWhitingWazuh… or Security Onion.

  • @sync9827
    @sync9827 Рік тому +151

    Step 1: Download and execute a binary from a random website I've never heard of. xD

    • @LennyMiller739
      @LennyMiller739 4 місяці тому +2

      It wasn't a binary, it was an exe. Silly billy

    • @vladimirpain3942
      @vladimirpain3942 4 місяці тому +5

      exe? Now I am all calm and comfortable.

    • @LennyMiller739
      @LennyMiller739 4 місяці тому

      @@vladimirpain3942 And to make it even better I'll put it in a little winrar archive. Everybody has a least one memory of opening that little atack of books to decompress the roms and play the games they had as a kid - it's so nostalgic, isn't it. CLICK ME, COME ON - YOU KNOW YOU WANT TO.

    • @thisunity
      @thisunity 3 місяці тому

      @@LennyMiller739 exe is a binary file, silly willy

  • @FIXm8
    @FIXm8 Рік тому +412

    best way to not get hacked is to live in the woods without any technology

    • @Hid4ri
      @Hid4ri Рік тому +53

      What if there is a psycho there with an axe??

    • @franklinndubuisi7479
      @franklinndubuisi7479 Рік тому +6

      ​@@Hid4riYou GAZA the Psycho

    • @hamburgerbuns9752
      @hamburgerbuns9752 Рік тому +37

      @@Hid4ri lol physiclly "hacked"

    • @Hid4ri
      @Hid4ri Рік тому

      ​@@franklinndubuisi7479who's that?

    • @Hid4ri
      @Hid4ri Рік тому

      ​@@franklinndubuisi7479don't get it sorry dude, I was only making a joke because in the woods you may come across a crazy person who is looking to "hack" with his axe. I'm sorry 😢

  • @Rennu_the_linux_guy
    @Rennu_the_linux_guy Рік тому +35

    Bruh John's icon sizes getting progressively bigger in every video like the sheriff's hat in scary movie is killing me

    • @KieSeyHow
      @KieSeyHow Рік тому +1

      Probably holding that CTRL key too long when hyperactive scrolling through windows. :D

  • @myekuntz
    @myekuntz Рік тому +25

    Hey just want to say thank you for taking the time and going step by step on not just this but how to open a zip file ,us noobs gotta start somewhere, thanks again 😊

  • @itsallasimulationman
    @itsallasimulationman Рік тому +5

    "it's not a matter of if, but when." ancient cybersecurity proverb.

  • @5ter1ingNothings
    @5ter1ingNothings Рік тому +12

    Ah! Thank you for this. This won you a subscription from me because this is a great way for me to dive deeper into cyber security and discover more. I appreciate this. New student of Cybersecurity Technician so this will be of incredible use.

  • @youreale
    @youreale 11 місяців тому +8

    Every software you install is increasing your attack surface. It would actually be better to show signs of malware infection rather than installing a magical black box to do it.

  • @CC-Pi
    @CC-Pi Рік тому +24

    Looks interesting but my first thoughts are that the plain text yml based signatures are vulnerable, they should be locked in an encrypted vault, otherwise an attacker can just change the rules before running their attack on a machine and then ta da no alert pops up.

    • @dgfokfgxfglhmkfmlgh
      @dgfokfgxfglhmkfmlgh 8 місяців тому +2

      You can prolly make a rule to detect the rules manipulations I guess

  • @EliteTech24
    @EliteTech24 Рік тому +7

    A little bit of click bait and knowledge not simplified for the public viewers who is really trying to find solutions. But great work from the ones who understands.

  • @FuzzerHash
    @FuzzerHash Рік тому +16

    Thank you, John, for sharing content like this with us.

  • @sagenorris693
    @sagenorris693 Рік тому +12

    You always find the coolest tools and resources! Awesome stuff, John, as always!

  • @holetarget4925
    @holetarget4925 11 місяців тому +4

    Most of famous software companies are in fact selling user data to aggregators. I know this because I bought these when I worked in a famous consulting co😢😅

  • @floridapenguin6330
    @floridapenguin6330 Рік тому +4

    Great Job I absolutely love it I already have something flagged that antivirus did not flag and I think this is one of the ways to get familiar with how ones system works even from a beginners level of understanding.

  • @itssoaztek4592
    @itssoaztek4592 Рік тому +3

    Great stuff! Thank you! I am very excited about your idea to have more content exploring Aurora EDR. Can't wait 🙂

  • @TC-hl1ws
    @TC-hl1ws Рік тому +43

    Too complicated for the general public including me but thanks for bringing this to our attention.

    • @aDaily1222
      @aDaily1222 Рік тому +10

      This video isnt for the general public lol

    • @jjann54321
      @jjann54321 Рік тому +5

      I think John said something about "Blue Team Professionals" or aspiring Blue Team Pros? This must be your first John Hammond video...? Oh, and the CLI isn't scary once you've worked with it for a while, give it a shot.

    • @OGMann
      @OGMann Рік тому +7

      Funny how i lived in the command line for 35 years, and people today are just discovering it. Thank God for gui's, eh? 😂

    • @wooshbait36
      @wooshbait36 Рік тому +6

      @@OGMann wow you are so cool. You want a medal?

    • @sCiphre
      @sCiphre Рік тому +7

      @@wooshbait36 we'd be just fine without one if you'd kindly step off the lawn.

  • @megsman4749
    @megsman4749 Рік тому +5

    My internal sigma rule detects adware.

  • @xCheddarB0b42x
    @xCheddarB0b42x Рік тому +6

    Interview reply from employer when I inquired about expectations: "No incidents." I almost popped off, "How do you know you aren't in one now?" heh

    • @KieSeyHow
      @KieSeyHow Рік тому +1

      There are two psychology thought experiments to try on prospective employees, one is the Gift Scenario, and the other is the Meadow Scenario. But the bottom line is, threats not perceived or expected result in different behaviour than otherwise. Good perception, leads to mitigating behaviour, before threat vectors resolve. All intelligence assets undergo such training, perhaps IT security personnel should also be taught to think in similar ways. Expect threats, when there are none. Just because none is detected, does not mean it is not there. This also applies to industrial maintenance, inspection, police work, intelligence, public works, and actuarial work.

    • @luiytheninja3655
      @luiytheninja3655 2 місяці тому

      @@KieSeyHow Idk why you got your information for this comment, but... From day one, I've been taught to be proactive, and look for threats before they occur, which is exactly how to do what you described.
      Guess, I'm just having trouble, understanding the purpose, of your comment.

  • @2Kayz177
    @2Kayz177 3 місяці тому +1

    it’s easy to remove if it’s in temp or application data but… if it’s in your kernel it’s a different chapter

  • @2b2tJourney
    @2b2tJourney Рік тому +4

    The day I get infected and I am looking for something to remove the malware this video comes out and I find out about it to late this is why y’all need to turn notifications on!!!

  • @aDaily1222
    @aDaily1222 Рік тому +10

    John I think you're trying to appeal to the "average user" but the average user doesn't have the technical knowledge for this stuff. I didn't realize until scrolling through the comments how many people outside the industry are watching these videos. People in the industry know you're a legend and take you seriously. Alot of your viewers right now dont even know who you are. I'm honestly not sure how they found this video. They probably got a virus and searched "how to know if i got hacked" lol. Anyways, you're great. So is the content. We appreciate it! Keep it up!

    • @jjann54321
      @jjann54321 Рік тому +6

      IMO I think as John's audience grows, more and more people are joining (watching) for reasons other than the "core" of his channel's message/content. From day one, his content has been on focusing on Red/Blue Team day-to-day with some videos being very technically detailed while others (his most popular, ironically) are John installing TOR and trolling the *Dark Web.* If you look at John's video catalog you can see the spectrum from Skiddie to Malware Analyst/Engineer and everything in between. Rather than people criticizing John's content for it not being "double-clicking on the .exe file and selecting Accept, Next, Next, Finish" they should challenge themselves, step up their game and possibly learn something, gain a little insight and experience.

    • @alfonzo7822
      @alfonzo7822 11 місяців тому

      Funnily enough that's roughly how I found John's channel 2 years ago! Now working in IT and doing a degree in Cyber Security, so it worked out ok for me.

  • @zuberkariye2299
    @zuberkariye2299 Рік тому +20

    It's quite confusing to determine the number of EDR/SIEM/SOAR tools available, as there are numerous options such as Splunk, Aurora, Corelight, Zeek, MS Sentinel, Snort, Wireshark, Datadog, Graylog, Security Onion, ELK, LogRhythm, and Google Chronicle. As a beginner, it can be overwhelming to choose the right tool. Can someone please explain the differences between these tools and offer guidance on which one I should focus on?

    • @denissetiawan3645
      @denissetiawan3645 Рік тому +2

      Focus on your company that already have, or in budget.

    • @CYBERSECURITY.101
      @CYBERSECURITY.101 11 місяців тому +18

      Choosing the right security tool can indeed be overwhelming, especially with such a diverse landscape! Understanding the differences between EDR, SIEM, SOAR, and specific tools like the ones you mentioned is crucial for making an informed decision. Let's break it down:
      Types of Tools:
      EDR (Endpoint Detection and Response): These tools focus on protecting endpoints (laptops, servers) from malware, exploits, and intrusions. They monitor endpoint activity, detect anomalies, and enable incident response. Examples: Crowdstrike Falcon Insight, McAfee Endpoint Security, SentinelOne.
      SIEM (Security Information and Event Management): SIEM tools aggregate security data from various sources (firewalls, logs, servers) to provide a unified view of security events. They help with log analysis, threat detection, and compliance. Examples: Splunk, ArcSight, LogRhythm.
      SOAR (Security Orchestration, Automation and Response): SOAR tools automate repetitive security tasks like incident ticketing, remediation workflows, and playbook execution. They integrate with other security tools to streamline incident response. Examples: Demisto, Palo Alto Cortex XSOAR, Rapid7 Nexpose.
      Understanding the Differences:
      EDR is focused on endpoints, while SIEM has a broader scope, covering all security data.
      SIEM provides visibility, while EDR offers deeper analysis and response capabilities for endpoints.
      SOAR automates tasks based on SIEM and EDR data, streamlining incident response.
      Choosing the Right Tool:
      Consider your needs: What are your main security concerns? Do you need endpoint protection, centralized event management, or automated response?
      Evaluate your budget: Tools vary in pricing and complexity. Choose one that fits your budget and skillset.
      Start small: Don't try to implement everything at once. Begin with a core tool (e.g., EDR for endpoint protection) and expand later.
      Research and compare: Look for independent reviews, test demos, and compare features before making a decision.
      Specific Tools:
      Splunk: SIEM platform with advanced analytics and reporting capabilities.
      Aurora: Open-source SIEM platform known for its flexibility and customization.
      Corelight: Open-source network traffic analysis tool for intrusion detection.
      Zeek: Another open-source network traffic analysis tool with strong threat detection capabilities.
      MS Sentinel: Cloud-based SIEM and SOAR solution from Microsoft.
      Snort: Open-source network intrusion detection and prevention system.
      Wireshark: Network traffic analyzer for troubleshooting and security investigations.
      Datadog: Cloud-based monitoring platform with security features.
      Graylog: Open-source SIEM platform with a user-friendly interface.
      Security Onion: Open-source security suite with various security tools.
      ELK Stack: Open-source stack combining Elasticsearch, Logstash, and Kibana for log analysis and visualization.
      LogRhythm: SIEM platform with built-in SOAR capabilities.
      Google Chronicle: Cloud-based SIEM and SOAR solution from Google.
      For beginners:
      Start with a free or open-source tool: Many excellent options are available like Corelight, Zeek, Security Onion, ELK Stack.
      Focus on learning the fundamentals: Understand the concepts of EDR, SIEM, and SOAR before diving into specific tools.
      Seek help from the community: Join online forums and communities to learn from other security professionals.
      Remember, the best tool is the one that fits your specific needs and budget. Take your time, research, and don't hesitate to ask for help.

    • @MogensHertz
      @MogensHertz 10 місяців тому

      Both question and answer was brought to you by ChatGPT 😅

    • @jollygrimreaper
      @jollygrimreaper 10 місяців тому

      @@CYBERSECURITY.101 okay, AI

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун 9 місяців тому +1

      how about asking yourself if you need any of them? they are for sysadmin or for a corporate segment. In that case it might be wise to use what is already purchased, installed and working.
      Otherwise, and especially for a private/small home network it's recommended to use standard security package included in your windows defender, like HIPS and similar utilities.
      If you feel it's not enough, consider enhanced protection from Eset, or Kaspersky, or Comodo, or Zonealarm, or similar

  • @justinpinson8575
    @justinpinson8575 Рік тому +2

    love it as always. would love to see more along this path!

  • @BenjaminTiessen
    @BenjaminTiessen Рік тому +7

    I hate that i have to give my personal information to download it... Not worth it.

  • @FlyboyHelosim
    @FlyboyHelosim Рік тому +4

    Video is all about getting hacked... clicks accept on cookies prompt without an ounce of care.

  • @pedrobarthacking
    @pedrobarthacking Рік тому +5

    Amazing content always John! Thank you!

  • @Felttipfuzzywuzzyflyguy
    @Felttipfuzzywuzzyflyguy Рік тому +1

    Thank you SOC Analysts!

  • @Robert.C-z2x
    @Robert.C-z2x Місяць тому

    Big fan of your videos ! For all the beginners out here ,is the AV detecting a false positive because Aurora is using sigma rules ? Would be great to hear your take on this matter

  • @8eck
    @8eck Рік тому +1

    Very interesting topic, would love to see more series about it. Like & Subscribed!

  • @KCM25NJL
    @KCM25NJL Рік тому +1

    I can see an opportunity for someone to write a little beautiful soup that skims the LOLbins and generates sigma files on the fly as new attack vectors are published.

    • @seansingh4421
      @seansingh4421 Рік тому

      Yes Yes Yes !! Thanks for the idea, If I can manage to it (I’m ChemE not software lol) I’ll even give you cut 😂

  • @Wildmikes
    @Wildmikes Рік тому +3

    Block all incoming connections at firewall built in setting with some exception rules. Plus VPN and DNS leak tweak at regedit you should be gold.

    • @KieSeyHow
      @KieSeyHow Рік тому +1

      With Windows 10 and above you'd have to start with zero trust, blocking both out and in, so each connection can be verified and researched. My local systems (both Linux and Windows) have run like that for more than 10 years.

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун 9 місяців тому

      indeed the most of the job is done by properly configured firewall.
      the rest of the job is done by properly configured HIPS utility
      and you might want to get an antivirus just for your convenience , to help you make a right decision
      secure DNS with or witthout filters to avoid phishing,
      other stuff like ublock origin are for a better protection and mostly for convenience

  • @techfan7808
    @techfan7808 Рік тому +4

    A very nice ad for aurora

  • @evanottinger1672
    @evanottinger1672 11 місяців тому

    The jump scare when this came on after a softly spoken Tib3rius video

  • @5c4rfAc3
    @5c4rfAc3 11 місяців тому

    loved this one!! always great education, and inspirational! keep it up!

  • @TheCodingHat
    @TheCodingHat Рік тому

    I saw it was you and was bamboozled by the comments. Surprised you arent a bit more popular

  • @justanothergrunt9053
    @justanothergrunt9053 Рік тому +12

    To be fair, if someone preaches this to me I feel like it’s gonna probe my stuff regardless. I’ll look into it 😂.

    • @Sloptit
      @Sloptit Рік тому

      Specially when its this guy saying that stuff

    • @justanothergrunt9053
      @justanothergrunt9053 Рік тому +4

      @@Sloptit Yeah. It's a product push. TRUST ME I AM- . No one's taking that away from him but come on this is an advertisement video. No you can't have my data.

    • @KieSeyHow
      @KieSeyHow Рік тому +3

      Pretty much the same vibes here, especially when delivered by some guy who feels like he is on uppers or speed. I learned in my work to never fully trust people with that kind of energy.

    • @justanothergrunt9053
      @justanothergrunt9053 Рік тому

      @@KieSeyHow Yeah

    • @aDaily1222
      @aDaily1222 Рік тому

      its literally John Hammond. Dudes a legend. You must not be in the CyberSecurity field lol. @@KieSeyHow

  • @hugohernandez6968
    @hugohernandez6968 8 місяців тому

    Hi John, thank you for sharing this. I was actually setting up wazuh through another great video you made. Essentially are they the same except wazuh does give you central management?

  • @joshmorgantech
    @joshmorgantech Рік тому +3

    Why do they have to ask for my email??

  • @ShinobuFX
    @ShinobuFX Рік тому

    I love this! please do more, thank you!

  • @JeffNoel
    @JeffNoel Рік тому +3

    They need to add the ---board command just for the sake of it.

    • @humpalum
      @humpalum Рік тому

      Kudos... that one -ed right over my head

  • @imaantagonist6322
    @imaantagonist6322 11 місяців тому +3

    Was this a giant ad? Felt like it.

  • @LokiScarletWasHere
    @LokiScarletWasHere Рік тому +1

    Eww. Proprietary. Definitely want to use it in a virtual playground only.

  • @overthe1
    @overthe1 Рік тому +1

    Thanks for very useful content. Very interesting for every Cyber Security Specialist.

  • @LennWeltmeister
    @LennWeltmeister Рік тому +2

    Video starts at 7:16

  • @GhostRevenge36
    @GhostRevenge36 6 місяців тому +3

    Ive got a problem. My antivirus won't let me download this because it wants to tamper with Windows defender. And the antivirus sees this as a threat. I just don't want a hacker piggy backing on any downloads. Did anyone else get this?

  • @Muziek37414
    @Muziek37414 Рік тому +1

    Would love to know more about the sigma rules and how to create custom ones

  • @joshuameaders8053
    @joshuameaders8053 10 місяців тому

    With so many tools & tech, do you think reviewing so many would eventually have a negative impact on the I.T community? Deluding the pool of options so great that paralysis by analysis inevitably sets in. I find myself overwhelmed with tools when coming to your page.

    • @phabeondominguez5971
      @phabeondominguez5971 8 місяців тому

      Maybe IT isn't for you then? Tech is always advancing so it's always changing, ya gotta keep up or else YOU become irrelevant.. feel me?

  • @powerstock9464
    @powerstock9464 5 місяців тому +4

    When I was dwonloading i had 2 threats by windows saying two trojons

  • @Abbaking-i4b
    @Abbaking-i4b 11 місяців тому

    Buying softwares norton and more have been brutal

  • @rakesharman4203
    @rakesharman4203 3 місяці тому +2

    My windows defender is considering this as malware 😮

  • @joelanzo
    @joelanzo 2 місяці тому +1

    Huntress Agent similar to Aurora uses a web browser dashboard, why not a local dashboard installed on the computer ?

  • @sirdewd2197
    @sirdewd2197 Рік тому +2

    Can it be out on routers or other network devices or is it only on end user devices?

  • @OHWRDAMI1
    @OHWRDAMI1 10 місяців тому +14

    Unwatchable ads every 30 seconds.

  • @Dominik-K
    @Dominik-K Рік тому

    Thanks for the video, this tool is certainly one I'll look into more deeply

  • @Vicorcivius
    @Vicorcivius 10 місяців тому +1

    Running windows and talking about detecting malware on your computer. :D

  • @mranonymous9355
    @mranonymous9355 10 місяців тому +1

    Thanks John. Was this a paid presentation?

  • @iWhacko
    @iWhacko Рік тому +2

    anything like this for Mac?

  • @ianraphael8968
    @ianraphael8968 Рік тому

    nice work john...love all the way from Kenya

  • @anonfourtyfive
    @anonfourtyfive Рік тому

    Just install my program bro, I'll clean everything.
    EVERYTHING.

  • @custume
    @custume Рік тому

    on this business our mantra is : "there are NO invulnerable systems, only hard to crack"

  • @uuu12343
    @uuu12343 11 місяців тому

    Question, does this work over the network? Or just the local machine?

  • @SimonePGGG
    @SimonePGGG Рік тому

    What is the difference between this and thor can you help me understand please?

  • @james_nash
    @james_nash 7 місяців тому

    Noob here. Why do this instead of your av system off the shelf? What’s the benefit?

  • @stoltzld
    @stoltzld 11 місяців тому +1

    SHA1, lovely and secure.... *cough*

  • @vladimirmisata
    @vladimirmisata 10 місяців тому

    To Watch This In Absolute SLO-MO Is Quite Annoying And Frustrating. Like Bro, Great Stuff, But What Could Be Even Greater Is The Speed To Mind Input Ratio. Like, Giving Some Time To Take In And Absorb The Info, Then Proccess The Information By A Couple Of Seconds Than The Causual Milli-seconds!? Would Love To Match And Be On Par, But Their Are Days That Go Against The Forces Of The Universe In Which The Universe Always Wins! A Couple Seconds Invested Would Be A Real Great Benifet As A Win, Win From A Team Perspective Angle. Much Gratitude. Thank You And Appreciated For Your Dedicated Service!

  • @CoreyANeal2000
    @CoreyANeal2000 11 місяців тому

    Could this be done with a complete copy of a device or through data?

  • @johannjohann6523
    @johannjohann6523 5 місяців тому

    Thanks for the Aurora software tip. But 2 things : 1) Waaaayyyy too much caffeine before making the video. Still you spoke pretty well (meaning understandable) yet 2) But you still spoke far too fast. I didn't know it was a race. lol I'm curious however, you really didn't show any good examples. Just "theoretical" ones. "Use your imagination" is not why me and others get on this UA-cam internet site. But I'm curious if you are putting out this information, wouldn't a good hacker be able to go under or around Aurora and still achieve their goals? I've been trying to find the procedures and software that would allow me to monitor my computer. But it seems VPN is the way to go, and no worries?? I haven't been convinced of that either.

  • @wetware_br
    @wetware_br Рік тому

    Hello, I'm from Brazil, your channel for me is a reference on the subject of cybersecurity

    • @realtruth8162
      @realtruth8162 10 місяців тому

      I´m from Brazil too, can you explain to me what this is all about ? I´m a completely noob

  • @TheNeoublie
    @TheNeoublie 11 місяців тому

    It is great that when you download a Security tool it get flagged by your Anti virus software as malicious software.

  • @PurpleTeamer
    @PurpleTeamer Рік тому +2

    Tried to download the license file from the link in the email, but getting a PR_END_OF_FILE_ERROR. could not access my license file.

    • @bartomiejb6730
      @bartomiejb6730 Рік тому +1

      ufffffff i got that same situation.

    • @florian2251
      @florian2251 Рік тому

      @@bartomiejb6730 Could you make sure that you're using an up-to-date browser? Which version of Firefox do you use?

    • @kimpedersen
      @kimpedersen Рік тому +1

      Same - but its working now.

    • @PurpleTeamer
      @PurpleTeamer Рік тому

      @@kimpedersen
      Thank for sharing an update.
      Will retry this evening 👍

  • @batmob8437
    @batmob8437 Рік тому

    "Sometimes it misses..." Lols! Deliberately even! 😝

  • @petefluffy7420
    @petefluffy7420 11 місяців тому

    That's all too easy, there will be adolescent wearing an "anonymous" style mask sitting in my chair.

  • @dlcrdz00
    @dlcrdz00 3 місяці тому

    Hi John, is there a download or install for Aurora on Linux?

  • @saschafahling4698
    @saschafahling4698 5 місяців тому +2

    Edge won't let me download saying it is a trojan👍

  • @tlskillman
    @tlskillman 8 місяців тому +2

    Just tried to download free Aurora. No go. Never got the verification email.

    • @martinhoneves
      @martinhoneves 3 місяці тому

      I got the verification but never the links....

  • @Unpluggeddddd
    @Unpluggeddddd Рік тому

    Best macOS equivalent?

  • @johnarnold893
    @johnarnold893 10 місяців тому

    This is a Windows only thing so what does that tell you?

  • @thegeminiclub
    @thegeminiclub Рік тому

    Hey!
    How do hackers make it look like I’m using Facebook and dating apps/sites on my phone if I don’t have any of those ?

  • @louey2x
    @louey2x Рік тому

    is it actually Cisco using TCP? and how do we confirm that it is, maybe it's one of the unassigned UDP ports.

  • @amzakambou6762
    @amzakambou6762 Рік тому

    thank you John for sharing This software

  • @prive_ik_ben_wie_ik_ben
    @prive_ik_ben_wie_ik_ben 11 місяців тому

    Looks good but still a fan of Wazuh.

  • @beniii3958
    @beniii3958 8 місяців тому

    lite version is litterally without sigma rules, which you are hyping and want to test with.

  • @gaylewashburn1137
    @gaylewashburn1137 11 днів тому

    When I go to "extract" I get a "virus detected" message.

  • @bleakyfinder2692
    @bleakyfinder2692 10 місяців тому +1

    why fix, if it anit broke.

  • @garycacoon
    @garycacoon 7 місяців тому

    Is this the same as sysdig and falco

  • @GAmerJUM
    @GAmerJUM 10 місяців тому

    It is mind boggling that the port 1900 and dns grouping is commonly turned on, it is simply reckless.

  • @shawnhenderson2968
    @shawnhenderson2968 Рік тому

    Not sure what I'm doing wrong but I can't access aurora in the terminal. So it won't let me run the scripts. Any help is appreciated

  • @samblack8344
    @samblack8344 11 місяців тому

    When I ran the script I never got a warning from aurora what does that mean in?

  • @richardglabella
    @richardglabella Рік тому

    Interesting. Thanks for sharing!

  • @Helpexplorer
    @Helpexplorer Рік тому +2

    Can you Show a Linux Solution?

  • @GrahamIsOnTheTube
    @GrahamIsOnTheTube 11 місяців тому

    My zx spectrum 48k has never been hacked in 40+ years

  • @emdxemdx
    @emdxemdx 11 місяців тому

    So, it's basically like Snort, right?

  • @tonderaishowmoretaruvings84
    @tonderaishowmoretaruvings84 10 місяців тому

    Thanks John

  • @wellox8856
    @wellox8856 Рік тому +4

    "sigma" "based" "free"
    I mean... They certainly know some good keywords to use 🤣

  • @senshi01
    @senshi01 6 місяців тому

    I received the email. Gone to the link to download it. No download button for me I guess...

  • @oculosprudentium8486
    @oculosprudentium8486 Рік тому

    Can I use this for Android phone and tablet ?

  • @cattameme
    @cattameme Рік тому +1

    Reinstalling windows from a USB drive to an NVME drive literally takes 5minutes. No internet connection. All worry free. Also, reinstalling windows could reset some program trials for you (if they're not connected to social media account)

  • @aaronag7876
    @aaronag7876 Рік тому

    What if you bought a laptop / Desktop from eBay with windows already installed ? How can I check that they haven't installed a key logger or Malware etc ? I bought a laptop and moved the 1TB M2 Drive onto the 2nd drive and not primary drive. My primary drive is 512gb has a Dual boot Ubuntu / Win11 but I want to use the 1TB M2 drive but don't want to add my personal details till Im sure it's clean. Thanks

    • @phabeondominguez5971
      @phabeondominguez5971 8 місяців тому

      No matter how thoroughly you "clean" it you won't ever be 110% sure,. So it's ALWAYS best to wipe it and clean install an OS on it. PEACE

  • @CitizenFortress
    @CitizenFortress Рік тому

    Wouldn't Wazuh be able to do all this too?

  • @willi1978
    @willi1978 11 місяців тому

    is there no log of commands somewhere in windows?