Blue Team Post Incident Analysis - Hack The Box Brutus Walkthrough
Hopsy
0:00 / 0:00
Blue Team Post Incident Analysis - Hack The Box Brutus Walkthrough
349 просмотров · 1 год назад
Hopsy
1,75 тыс. подписчиков
349 просмотров · 1 год назад
I literally never heard of auth.logs and wtmp logs before this, also utmpdump no longer exists so we had to find an "interesting" workaround aka taking the data from somewhere else.
Hack The Box description:
In this very easy Sherlock, you will familiarize yourself with Unix auth.log and wtmp logs. We'll explore a scenario where a Confluence server was brute-forced via its SSH service. After gaining access to the server, the attacker performed additional activities, which we can track using auth.log. Although auth.log is primarily used for brute-force analysis, we will delve into the full potential of this artifact in our investigation, including aspects of privilege escalation, persistence, and even some visibility into command execution.