CyberOps Associates v1.0 – Skills Assessment
1. Introduction
You have been hired as a junior security analyst. As part of your training, you were tasked to determine any malicious activity associated with the Pushdo trojan.
You will have access to the internet to learn more about the events. You can use websites, such as VirusTotal, to upload and verify threat existence.
The tasks below are designed to provide some guidance through the analysis process.
You will practice and be assessed on the following skills:
· Evaluate event alerts using Squil and Kibana.
· Use Google search as a tool to obtain intelligence on a potential exploit.
· Use VirusTotal to upload and verify threat existence.
Content for this assessment was obtained from http://www.malware-traffic-analysis.net/ and is used with permission. We are grateful for the use of this material.
Required Resources
Host computer with at least 8GB of RAM and 45GB of free disk space
Latest version of Oracle VirtualBox
Security Onion virtual machine requires 4GB of RAM using 25GB disk space
Internet access
Instructions
Gather the Basic Information
In this part, you will review the alerts listed in Security Onion VM and gather basic information for the interested time frame.
Verify the status of services
Log into Security Onion VM using with the username analyst and password cyberops.
Open a terminal window. Enter the sudo so-status command to verify that all the services are ready.
When the nsm service is ready, log into Sguil or Kibana with the username analyst and password cyberops.
Gather basic information.
Questions:
Identify time frame of the Pushdo trojan attack, including the date and approximate time.
Type your answers here.
List the alerts noted during this time frame associated with the trojan.
Type your answers here.
List the internal IP addresses and external IP addresses involved.
Type your answers here.
Learn about the Exploit
In this part, you will learn more about the exploit.
Infected host
Questions:
Based on the alerts, what is the IP and MAC addresses of the infected computer? Based on the MAC address, what is the vendor of the NIC chipset? ( Hint: NetworkMiner or internet search)
Type your answers here.
Based on the alerts, when (date and time in UTC) and how was the PC infected? ( Hint: Enter the command date in the terminal to determine the time zone for the displayed time)
Type your answers here.
How did the malware infect the PC? Use an internet search as necessary.
Type your answers here.
Examine the exploit.
Questions:
Based on the alerts associated with HTTP GET request, what files were downloaded? List the malicious domains observed and the files downloaded.
Type your answers here.
Use any available tools in Security Onion VM, determine and record the SHA256 hash for the downloaded files that probably infected the computer?
Type your answers here.
Navigate to www.virustotal.com input the SHA256 hash to determine if these were detected as malicious files. Record your findings, such as file type and size, other names, and target machine. You can also include any information that is provided by the community posted in VirusTotal.
Type your answers here.
Examine other alerts associated with the infected host during this timeframe and record your findings
Type your answers here.
Report Your Findings
Summarizes your findings based on the information you have gathered from the previous parts, summarize your findings.
Type your answers here.
- WE OFFER THE BEST CUSTOM PAPER WRITING SERVICES. WE HAVE DONE THIS QUESTION BEFORE, WE CAN ALSO DO IT FOR YOU.
- Assignment status: Already Solved By Our Experts
- (USA, AUS, UK & CA PhD. Writers)
- CLICK HERE TO GET A PROFESSIONAL WRITER TO WORK ON THIS PAPER AND OTHER SIMILAR PAPERS, GET A NON PLAGIARIZED PAPER FROM OUR EXPERTS
QUALITY: 100% ORIGINAL PAPER – NO PLAGIARISM – CUSTOM PAPER
Why Choose Us?
- 100% non-plagiarized Papers
- 24/7 /365 Service Available
- Affordable Prices
- Any Paper, Urgency, and Subject
- Will complete your papers in 6 hours
- On-time Delivery
- Money-back and Privacy guarantees
- Unlimited Amendments upon request
- Satisfaction guarantee
How It Works
- Click on the “Place Your Order” tab at the top menu or “Order Now” icon at the bottom and a new page will appear with an order form to be filled.
- Fill in your paper’s requirements in the “PAPER DETAILS” section.
- Fill in your paper’s academic level, deadline, and the required number of pages from the drop-down menus.
- Click “CREATE ACCOUNT & SIGN IN” to enter your registration details and get an account with us for record-keeping and then, click on “PROCEED TO CHECKOUT” at the bottom of the page.
- From there, the payment sections will show, follow the guided payment process and your order will be available for our writing team to work on it.
About AcademicWritersBay.com
AcademicWritersBay.com is an easy-to-use and reliable service that is ready to assist you with your papers 24/7/ 365days a year. 99% of our customers are happy with their papers. Our team is efficient and will always tackle your essay needs comprehensively assuring you of excellent results. Feel free to ask them anything concerning your essay demands or Order.
AcademicWritersBay.com is a private company that offers academic support and assistance to students at all levels. Our mission is to provide proficient and high quality academic services to our highly esteemed clients. AcademicWritersBay.com is equipped with competent and proficient writers to tackle all types of your academic needs, and provide you with excellent results. Most of our writers are holders of master’s degrees or PhDs, which is an surety of excellent results to our clients. We provide assistance to students all over the world.
We provide high quality term papers, research papers, essays, proposals, theses and many others. At AcademicWritersBay.com, you can be sure of excellent grades in your assignments and final exams.


