Uncover the Secrets of a Home SOC Analyst Lab! [Step-by-Step Walkthrough]

Поділитися
Вставка
  • Опубліковано 29 лис 2024

КОМЕНТАРІ • 116

  • @SimplyCyber
    @SimplyCyber  Рік тому +8

    💥💥🚨🚨 Join us 3/23 4:30PM EST LIVE ua-cam.com/users/liveP_Kl2EnF8_A as we interview Eric Capuano the author of this incredible lab and get ALL of your questions answered! ua-cam.com/users/liveP_Kl2EnF8_A

    • @ildaragishev-yv4iu
      @ildaragishev-yv4iu Рік тому +1

      Hi! Thanks for the walkthrough) Please help: got stuck at [!] rpc error: code = Unknown desc = Incorrect function while running "procdump -n lsass.exe -s lsass.dmp". Can't detect by filtering for “SENSITIVE_PROCESS_ACCESS” events.

    • @roxasdracun8661
      @roxasdracun8661 2 місяці тому

      Just putting this here cause it gave me headaches for when creating sessions commands roun 31:35 ( when using http command)
      My implant was not able to like run or get install mainly do to the port being use (CHECK WITH THIS COMMAND : ps -fA | grep python) then:
      1. Once you run python3 -m http.server 80 ( needs to be killed)
      2. lsof -nti:PORT_NUMBER | xargs kill -9 ; where PORT_NUMBER = 80
      DO this only after using the http commands gets stuck and not responding

  • @Agroth2333
    @Agroth2333 Рік тому +22

    Bookmark this one and keep coming back to it over and over again. The amount of value in this will bring you to the next level.

  • @PharnsGenece
    @PharnsGenece Рік тому +12

    I’m glad you’re doing this…. I’m working through the blog posts and ran into a snag. Working through the snag and hopefully I’ll have it fixed before your video posts tomorrow. If not, you’ll be a good reference.. LOVE YOUR CONTENT.. Thanks, future cyberpreneur

  • @Longlivetony
    @Longlivetony Рік тому +5

    I love how Gerald put Sudo command to elevate permissions on the Windows command prompt. That got me laughing. Love it.

  • @NessHypegaming
    @NessHypegaming Рік тому +2

    YES! we need more videos like this, something to put on a resume.

  • @muhammadnomanilyas5423
    @muhammadnomanilyas5423 Рік тому

    Gerald! I love your way of teaching and interaction , currently enrolled in GRC Analyst Course & you are literally amazing.

  • @h.fontanez5453
    @h.fontanez5453 Рік тому +1

    Just completed part 2 in VirtualBox, totally doable. Thank you for this amazing resource!

    • @gtarules1
      @gtarules1 Рік тому

      VirtualBox!?

    • @yamin1702
      @yamin1702 Рік тому +1

      How did u manage to ssh from the windows vm to the ubuntu. Did u use nat or bridged adapter

    • @MerkabaSS
      @MerkabaSS Рік тому

      @@yamin1702 NAT

  • @DFPathfinder
    @DFPathfinder 4 місяці тому +1

    Thank you for this lab but I'm having trouble at the setup attack system step in part 1. I enter the command ssh user@[Linux_VM_IP] and then say yes to add it. But my password says permission denied. Ive restarted the entire Ubuntu process twice and tried making a new pass but still no luck. Im not using the wrong IP address, password, and i even checked to make sure port 22 was open. IDK what else to do.

  • @suburbanflower
    @suburbanflower Рік тому +3

    Would this lab be possible to set up on a Macbook Pro?

  • @roxasdracun8661
    @roxasdracun8661 2 місяці тому

    NOW WE NEED A SECOND PART LAB , this was very informational and interactive to some stuff that goes to much in theory basis.
    I see the video itself doesnt cover Part 4 of the lab were we do take care of action. Also does any one know if you will get charge then later with the Lima Thing if we dont delete stuff

    • @SimplyCyber
      @SimplyCyber  2 місяці тому

      I made this video before part 4 was written and a follow up video would be cool. I believe Lima Charlie is free up to two agents but you have to verify that. Subject to change

  • @gmalo2105
    @gmalo2105 Рік тому +8

    Just a heads up. If you are doing this on a Windows 10 host, and you get a "Virtualized AMD-V/RVI is not supported on this platform" error, you may need to turn off Hyper-V and WSL2 in Programs and Features.

    • @SimplyCyber
      @SimplyCyber  Рік тому

      awesome tip. Thanks!

    • @gmalo2105
      @gmalo2105 Рік тому +2

      @@SimplyCyber I saw the tip you provided in your follow-up video with Eric Campuano. It unfortunately did not work for me (because I had both Hyper-V and WSL2??). Whatever. Five minutes of troubleshooting and I was back in the game. This is a great lab. Thanks to both you and Mr. Campuano.

    • @Harry_Von_Turbo
      @Harry_Von_Turbo Рік тому

      @@gmalo2105 how did you fix it in the end?

  • @LinuxNation.
    @LinuxNation. 8 місяців тому +1

    typed in the command prompt. because it kept failing on me. Says it ran successfully but I am still getting the same message? any clue?

  • @bluebadgersec
    @bluebadgersec Рік тому

    This is an incredible resource. Thanks Gerald and Eric!

  • @Cyber-Hound
    @Cyber-Hound Місяць тому

    Not sure what I did wrong here but when I try "sessions' it just comes up as empty. I have the payload on the windows VM executed and Jobs shows TCP port 80. Attempted to start from scratch and even rebooted the linux machine and can't seem to get passed this issue. I'd love to finish this project but sadly hung up on this one thing

  • @cybeerninja
    @cybeerninja Рік тому

    great as always. enjoyed the background music. Had to go through some items 3x to figure out what happening but all good.

  • @david90gen
    @david90gen 9 місяців тому

    Awesome lab!! Just a few questions. It seems that some of the order of the blog don't go along with the one or two steps in your video demonstration. Was there an update to the blog post?
    Thank you for the vid, learning a lot!!!

  • @IT_Paleni-bu5cs
    @IT_Paleni-bu5cs Рік тому

    why did the everything after saving the state of the windowsVM deleted? it jumps from saying the next steps r going to b in ubuntu linux to the next steps are going to b from the host os. the video shows the extra steps missing to obtain the IP address and gateway. then shows how to configure the network for ubuntu but all of that is missing in the blog. did I miss something? i also continued with the video but when I pulled up my network settings the word address wont turn green and it aborted the yaml file.

  • @justapersonalaccount
    @justapersonalaccount Рік тому

    This was really fun, thank you for posting. Can't wait to try more advanced activities

  • @Denvercoder
    @Denvercoder 3 місяці тому

    You're doing this on a Windows host but I run Linux Mint. Assuming I use VMWare for linux will I have any issues or should I get a computer that runs Windows as a host?
    (I don't run windows at all, only MacOS and Linux)

  • @happydij
    @happydij Рік тому

    Thank you for sharing this lab. However, I'm getting destination host unreachable. I dont know what to do.

  • @J_G_Network
    @J_G_Network Рік тому

    I watched this one first and then watched the first 20 min video, :)

  • @JeffreyJohnny
    @JeffreyJohnny Рік тому +1

    Does this work only in windows, or it is the same process too in Apple Mac?? Thanks!

    • @SimplyCyber
      @SimplyCyber  Рік тому

      Depends on the chip in the Apple. M chips I don’t think so. You just need to run a hyper visor solution basically so you can run two vm and network together

  • @ugccdrum
    @ugccdrum Рік тому +1

    How do I add this to a website and reference it on my resume? Thank you.

    • @SimplyCyber
      @SimplyCyber  Рік тому +3

      How to show to employers your home lab soc experience #cybersecurity #secops

  • @darnellmorris3622
    @darnellmorris3622 Рік тому +1

    Hi Gerald, what is your advice for a person that wants to get into cybersecurity, but is wheelchair bound? My mind is still sharp, just my legs don't work like they use too. By the way, I'm currently taking your GRC Master Class.

    • @SimplyCyber
      @SimplyCyber  Рік тому

      Can a person in a wheelchair work in cybersecurity? #cybersecurity #career

  • @dustinhxc
    @dustinhxc Рік тому

    So awesome! I’m going to do this thank you!

  • @ZombieGuy_Justin
    @ZombieGuy_Justin Рік тому +1

    I'm going to follow this along, but with VirtualBox. :)

  • @DWJ92
    @DWJ92 Рік тому +1

    Where did kali come from at 21:28 was I suppose to download that

    • @SimplyCyber
      @SimplyCyber  Рік тому

      Not part of lab. I just rewatched and I think I accidentally launched kali.

    • @DWJ92
      @DWJ92 Рік тому

      @@SimplyCyber you had me looking everywhere in that article. I was like i obviously missed a step

    • @SimplyCyber
      @SimplyCyber  Рік тому

      @@DWJ92 sorry friend

  • @MiltonHernandez
    @MiltonHernandez 3 місяці тому

    I'm about to try this but I'm confused at the outset. What are you downloading VMware and the two VMs onto? Is it a windows machine or a linux machine?

    • @SimplyCyber
      @SimplyCyber  3 місяці тому

      i run windows.

    • @MiltonHernandez
      @MiltonHernandez 3 місяці тому

      @@SimplyCyber ok great! so you make a ubuntu vm for the attacker and a windows vm for the target. what if i took a spare machine i have and put ubuntu on it to serve as the attacker and then just setup the windows vm? would your video still appy?

  • @gamerlife_official
    @gamerlife_official Рік тому +1

    What happen after VMware 17 Pro free trial ended? Will it automatically purchasing the license?

    • @samiracle_p
      @samiracle_p Рік тому

      I found a license key on GitHub

  • @vireaknhoung7623
    @vireaknhoung7623 Рік тому

    Hii everyone, I somehow stuck on generating first C2 session payload. There was error saying, rpc error: code = Unknown desc =invalid compiler target: windows/amd64

  • @jersondelgado5142
    @jersondelgado5142 Рік тому +1

    Is it the same settings in VirtualBox? Or downloading VMware best for this lab?

    • @SimplyCyber
      @SimplyCyber  Рік тому

      i cant speak to vmware. i belive you can do it in virtualbox, but you wont be able to find the blog verbatim and just swap virtubalbox for vmware

  • @sasuwayne
    @sasuwayne Рік тому

    Hello Gerald, Thank you for sharing this. Can you help with sharing information on how to achieve this on Mac Silicon systems? Thanks.

    • @SimplyCyber
      @SimplyCyber  Рік тому

      Idk if that hardware supports 🤷‍♂️. Sorry friend

  • @hammazahmed1289
    @hammazahmed1289 10 місяців тому

    During part 1 you didn't change the dhcp (While installing ubuntu) to static like Eric did in blog. Any particular reason for that?

    • @SCole07
      @SCole07 8 місяців тому

      This video is almost a year old, I think the blog was updated since then so Gerry didn't have to follow that step I believe.

  • @Guy_Cyber_Titan
    @Guy_Cyber_Titan Рік тому

    @simplyCyber I've noticed you're able to highlight so many things effectively in your videos. Could you kindly share the method or tools you use to achieve those eye-catching highlights? Your editing skills are impressive and I'd love to learn from your technique. Thanks a lot.
    Regarding the VM Pro station license, I see there are two options: 'Buy' for $199 and 'Upgrade' for $99. I'm a bit unsure about which one would be the best fit for me. Could you please clarify the differences between these options and provide some guidance on which one would be more suitable? I appreciate your help

  • @cacogenicist
    @cacogenicist Рік тому

    I'm probably rather backwards from most people looking to get into this field. I've been using Linux as a daily driver desktop OS for around 15 years, and at this point I find Windows somewhat intimidating. 🙂 Damn slashes go the wrong way.

  • @lamar2009lamar
    @lamar2009lamar Рік тому

    Hi Gerald. I’m stuck on the setup Silver at the end of part 1 in Eric’s blog. I am following this video as well.
    After entering sudo su, and the sudo password prompt comes up, what do I do next?
    This step was left out of the video. Before when I tried this, I copied and pasted in the sliver download block from the blog. However it asked me to try again with the password. Can you advise. Thanks.

    • @SimplyCyber
      @SimplyCyber  Рік тому

      Sounds like you need to input the root password to authenticate sudo su

  • @MerkabaSS
    @MerkabaSS Рік тому +1

    For some odd reason my http listener closes as soon as I open it. I also had an issue with the windows vm retrieving the payload file, which I was able to get to work via ufw http port. I tryed my best to follow right along lol.

    • @jasonryan33
      @jasonryan33 Рік тому

      I can't windows to retrieve the payload file either. It says it can not find part of the path "C:\users\user\downloads\etc...
      On my SSH into my Linux VM, it then says "Errno 104 connection reset by peer"
      I can't figure out what the issue is.

    • @Brandon-tz5pn
      @Brandon-tz5pn 11 місяців тому

      I'm stuck here too. Did anyone figure it out?

  • @boxcarpilot30
    @boxcarpilot30 Рік тому

    Can I follow the same steps with VMWare Workstation Pro 17 for Linux?
    Or do I need a Windows machine as the host?

    • @SimplyCyber
      @SimplyCyber  Рік тому

      Sure that will work . Long as you have a Linux and windows vms for ur lab

  • @CAP.9350
    @CAP.9350 Рік тому

    Can I do it with a M1 chip laptop?

  • @bdhdjdbbfbfb2372
    @bdhdjdbbfbfb2372 Рік тому

    Does it have to be a VMware pro?

  • @iceingdeath86
    @iceingdeath86 Рік тому

    need some help.....around 22:38 in the video the command nano /etc/netplan/00-installer-config.yaml is executed but in my VM I'm getting a blank screen in the GNU, where do i go wrong?

    • @SimplyCyber
      @SimplyCyber  Рік тому

      Looked quick. Not sure if you have to but this site says you have to run “net plan generate” if file doesn’t exist. billysoftacademy.com/how-to-set-a-static-ip-address-on-linux-ubuntu-server-20-04-lts/

  • @alexanderjunior9442
    @alexanderjunior9442 Рік тому

    Please I have a question sir, I want to go into GRC, should I go for networking by learning the CompTIA net+. Thanks 🙏

    • @SimplyCyber
      @SimplyCyber  Рік тому

      Do you need to know networking to work in GRC? #cybersecurity #career

  • @jaybell0819
    @jaybell0819 Рік тому +1

    anyone else stuck on Part 2 task 3? Im able to generate --http [linux_VM_IP] --save /opt/sliver. but after I exit im not able to cd into /opt/sliver even though it says "File exists" when I try to mkdir /opt/server. Also when typing command "locate /opt/sliver" i am able to find it. just not able to cd into it and it doesnt appear to generate payload onto /opt/sliver

    • @benettogeorge2169
      @benettogeorge2169 Рік тому

      I am, and I am not able to resolve it. have you or anyone resolved it?

    • @jaybell0819
      @jaybell0819 Рік тому

      @@benettogeorge2169 yes. You need to just create a folder and transfer the executanble in it

  • @JamesJrxMMA
    @JamesJrxMMA Рік тому

    New to this. When I try to open virtualization form it says
    VMware workstation
    Failed to read from file.
    Is this familiar or should I just redo everything?

    • @samiracle_p
      @samiracle_p Рік тому

      I’m getting the same…did you manage to solve?
      I attempted this lab a few months ago and didn’t have this issue but was unable to complete it due to time constraints, and now that I have time, I keep getting this. Very frustrating. Will troubleshoot tonight.

  • @MRSEEK100
    @MRSEEK100 Рік тому

    Do I need VMware workstation PRO or does PLAYER work too?

    • @SimplyCyber
      @SimplyCyber  Рік тому

      The free version that hits vms is all you need. Look at the blog post in the description for links. I think player is enough

  • @jaysinps
    @jaysinps Рік тому +2

    Some of my notes from running running windows 11 as the base OS and VMware Workstation 17.x:
    I ran the bcedit command but was still getting the nest vm error when trying to start up the Windows vm.
    I went to Windows security > Data Security > Core Isolation > turn off memory integrity and rebooted and the windows dev VM was able to boot
    On the windows 11 dev box I wasnt getting any kind of internet so sysmon download was failing. This might have been a misconfiguration on vmware workstation/bridged interface. I shutdown the vm and removed both the NAT and host only network cards. Re-added the nic and set it to bridge and was able to download the files. (need to move it back to NAT and test to make sure it works) as I walk through this

    • @demariojernigan4776
      @demariojernigan4776 Рік тому +1

      Thanks for passing along your information. Saved me and hopefully a lot of other people the trouble. I ran the bcedit command as well and was still not getting the start up. Got it running after going into Windows Security > Device Security > Core Isolation. Respect!

    • @jaysinps
      @jaysinps Рік тому

      @@demariojernigan4776 Glad to hear it helped someone else out!

  • @aa-vp1nf
    @aa-vp1nf 11 місяців тому

    Is there anyone who has a problem with getting "debug" enabled? I tried restarting sessions and did it from admin cmd and admin PowerShell and nothing helped.

    • @aa-vp1nf
      @aa-vp1nf 11 місяців тому

      Sorted -_- . A bit of focus and 2 hours of going backward and forward through documentation. One more reminding to me about how respectful and careful you should be with instructions.

  • @itspratikamin
    @itspratikamin 9 місяців тому

    4:27 VMWare error requested power operation is already in progress and powershell fix
    I tried this fix and it didnt work for me

    • @SimplyCyber
      @SimplyCyber  9 місяців тому

      Ooof . That’s unfortunate

    • @itspratikamin
      @itspratikamin 9 місяців тому

      @@SimplyCyber should I just download a windows iso and perform the tasks ?

    • @SCole07
      @SCole07 8 місяців тому

      hey , I was just stuck on this I did not extract my files so that's why I kept getting the error

  • @andreaordonez7925
    @andreaordonez7925 Рік тому

    I am having issues when trying to save the implant in /opt/sliver. I am using a MACBOOK pro M1. I keep getting:
    [*] Generating new windows/amd64 implant binary
    [*] Symbol obfuscation is enabled
    [*] Build completed in 23s
    [!] Failed to write to: /opt/sliver
    Any advice please?

    • @yamin1702
      @yamin1702 Рік тому

      Are u in the /opt/sliver directory, if not then that could be the problem

    • @andreaordonez7925
      @andreaordonez7925 Рік тому

      @@yamin1702 I was. I think the problem is the M1

  • @LinuxNation.
    @LinuxNation. 8 місяців тому +1

    a lot of information is out of date on this video, stuck on the Lima Charlie task.

    • @SimplyCyber
      @SimplyCyber  8 місяців тому

      Thx I’ll check a Eric and see what’s changed

    • @SimplyCyber
      @SimplyCyber  8 місяців тому

      Can you give me a time stamp at where it’s changed or ur stucj

    • @LinuxNation.
      @LinuxNation. 8 місяців тому

      @@SimplyCyber 16:30 and moving forward with setting up Lima Charlie. Also is this being set up in the windows VM or on the operating OS?

    • @LinuxNation.
      @LinuxNation. 8 місяців тому

      @@SimplyCyber Also, all the commands using Invoke-WebRequest are invalid for Symon. At least for me, maybe I'm doing something wrong?

  • @Brandon-tz5pn
    @Brandon-tz5pn 11 місяців тому +1

    31:11 The payload isnt showing up in my downloads for some reason

  • @monutulani3667
    @monutulani3667 Рік тому +1

    @SimplyCyber Can you share the resume bullet points for this lab like josh madakor does in his tutorials. Those are very helpful instead of messing up.

  • @randalljnbaptiste587
    @randalljnbaptiste587 Рік тому

    Where did you get the Ubuntu iso image from?

    • @SimplyCyber
      @SimplyCyber  Рік тому +1

      Hey Randall! Thanks for watching the video. It depends on the system that you are running but if you type into google: "ubuntu iso download". From there, just download what you need. Let me know if there is anything else I can help you with. Also, If you join the discord there are Thousands of students taking this course as well. Hope to see you there!

    • @randalljnbaptiste587
      @randalljnbaptiste587 Рік тому

      @@SimplyCyber ok thank you so much

  • @samiracle_p
    @samiracle_p Рік тому

    why am i unable to import the MS VM: WinDev####Eval.ovf
    I keep receiving an error: Error while converting to a virtual machine: Failed to read from file: C;\Users\....\AppData\Local\Temp\f9f953fa-f03f-40b8-88ce-32e75939dfb9_WinDev 2310 Eval.VMWare.zip.fb9\WinDev 2310 Eval-disk1.vmdk.

    • @SimplyCyber
      @SimplyCyber  Рік тому

      Tough problem yo troubleshoot. Could be corrupt image. Would Google issue and troubleshoot that way

    • @samiracle_p
      @samiracle_p Рік тому

      @@SimplyCyber Iv re-downloaded the image a number of times but still the same. Does it need to be windows develeoper, can I used win10 iso

  • @yamin1702
    @yamin1702 Рік тому

    For some reason @25:37 I got the following error in the windows terminal "ssh: connect to host ip port 22: connection refused" but when I did it from the Linux terminal it worked
    @gerald, could you please tell me why that is.

    • @SimplyCyber
      @SimplyCyber  Рік тому

      Make sure when you deployed Ubuntu you selected the ssh option

    • @yamin1702
      @yamin1702 Рік тому

      @@SimplyCyber I installed ssh using sudo install as I'm doing it using virtual box

    • @SimplyCyber
      @SimplyCyber  Рік тому

      @@yamin1702 ok. I used VMware so not sure w virtual box. Make sure right creds, service listening on 22, network connection is allowed…. 🤷‍♂️

    • @yamin1702
      @yamin1702 Рік тому

      @@SimplyCyberthanks I'll try these options, if they don't work then I'll just switch to vmware

    • @yamin1702
      @yamin1702 Рік тому

      ​@@SimplyCyber it's fixed, I just had to change the network type from nat to bridged

  • @twcable02
    @twcable02 2 місяці тому

    (22:39 mark) had to use /etc/netplan/*