{"id":24443,"date":"2023-12-19T02:41:27","date_gmt":"2023-12-19T02:41:27","guid":{"rendered":"https:\/\/academicwritersbay.com\/writings\/cyberops-associates\/"},"modified":"2023-12-19T02:41:27","modified_gmt":"2023-12-19T02:41:27","slug":"cyberops-associates","status":"publish","type":"post","link":"https:\/\/academicwritersbay.com\/writings\/cyberops-associates\/","title":{"rendered":"CyberOps Associates"},"content":{"rendered":"<div><\/div>\n<div>Introduction<\/div>\n<div>You have been hired as a junior security analyst. As part of your training, you were tasked to determine any malicious activity associated with the Pushdo trojan.<\/div>\n<div>You will have access to the internet to learn more about the events. You can use websites, such as VirusTotal, to upload and verify threat existence.<\/div>\n<div>The tasks below are designed to provide some guidance through the analysis process.<\/div>\n<div>You will practice and be assessed on the following skills:<\/div>\n<div>o Evaluate event alerts using Squil and Kibana.<\/div>\n<div>o Use Google search as a tool to obtain intelligence on a potential exploit.<\/div>\n<div>o Use VirusTotal to upload and verify threat existence.<\/div>\n<div>Content for this assessment was obtained from http:\/\/www.malware-traffic-analysis.net\/ and is used with permission. We are grateful for the use of this material.<\/div>\n<div>Required Resources<\/div>\n<div>\u2022 Host computer with at least 8GB of RAM and 45GB of free disk space<\/div>\n<div>\u2022 Latest version of Oracle VirtualBox<\/div>\n<div>\u2022 Security Onion virtual machine requires 4GB of RAM using 25GB disk space<\/div>\n<div>\u2022 Internet access<\/div>\n<div>Instructions<\/div>\n<div>Part 1: Gather the Basic Information<\/div>\n<div>In this part, you will review the alerts listed in Security Onion VM and gather basic information for the interested time frame.<\/div>\n<div>Step 1: Verify the status of services<\/div>\n<div>a. Log into Security Onion VM using with the username analyst and password cyberops.<\/div>\n<div>b. Open a terminal window. Enter the sudo so-status command to verify that all the services are ready.<\/div>\n<div>c. When the nsm service is ready, log into Sguil or Kibana with the username analyst and password cyberops.<\/div>\n<div>Step 2: Gather basic information.<\/div>\n<div>Questions:<\/div>\n<div>a. Identify time frame of the Pushdo trojan attack, including the date and approximate time.<\/div>\n<div>Type your answers here.<\/div>\n<div>b. List the alerts noted during this time frame associated with the trojan.<\/div>\n<div>Type your answers here.<\/div>\n<div>c. List the internal IP addresses and external IP addresses involved.<\/div>\n<div>Type your answers here.<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Introduction You have been hired as a junior security analyst. As part of your training, you were tasked to determine any malicious activity associated with the Pushdo trojan. You will have access to the internet to learn more about the events. You can use websites, such as VirusTotal, to upload and verify threat existence. The &#8230; <a title=\"CyberOps Associates\" class=\"read-more\" href=\"https:\/\/academicwritersbay.com\/writings\/cyberops-associates\/\" aria-label=\"Read more about CyberOps Associates\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-24443","post","type-post","status-publish","format-standard","hentry","category-essaywr"],"_links":{"self":[{"href":"https:\/\/academicwritersbay.com\/writings\/wp-json\/wp\/v2\/posts\/24443","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/academicwritersbay.com\/writings\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/academicwritersbay.com\/writings\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/academicwritersbay.com\/writings\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/academicwritersbay.com\/writings\/wp-json\/wp\/v2\/comments?post=24443"}],"version-history":[{"count":0,"href":"https:\/\/academicwritersbay.com\/writings\/wp-json\/wp\/v2\/posts\/24443\/revisions"}],"wp:attachment":[{"href":"https:\/\/academicwritersbay.com\/writings\/wp-json\/wp\/v2\/media?parent=24443"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/academicwritersbay.com\/writings\/wp-json\/wp\/v2\/categories?post=24443"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/academicwritersbay.com\/writings\/wp-json\/wp\/v2\/tags?post=24443"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}