SibaSec

cat "${quotes[RANDOM % ${#quotes[@]}]}"
"If you think technology can
solve your security problems,
then you don't understand the
problems and you don't
understand the
technology."
Bruce
Schneier

CCD Review

Certified CyberDefender is an intermediate certification course on CyberDefender’s platform. The course covers SOC fundamentals, incident response, digital forensics (network, memory, disk), and threat hunting. The exam is a 48-hour practical covering each domain of the course except for incident response.

2023-07-11

CyberDefenders: Elastic-Case

Elastic-Case is a medium-difficulty challenge hosted by CyberDefenders. It involves using Elastic as a SIEM to trace malicious activity on a compromised network.

2023-06-15

TryHackMe: Revilcorp

This is a medium-difficulty challenge hosted by TryHackMe. The challenge involves using Redline to investigate a compromised machine. The machine was reported to have exhibited ransomware-like behavior.

2023-06-13

TryHackMe: Disk Analysis & Autopsy

Disk Analysis & Autopsy is a Medium-difficulty forensics challenge. It involves analyzing a forensic disk image in Autopsy to determine what malicious software was installed, by which users, and to uncover various other artifacts.

2023-06-13

CyberDefenders: AfricanFalls

AfricanFalls is a medium-difficulty forensics challenge. We’re given an AD1 image of a drive and tasked with the suspect’s actions.

2023-06-12

BlueTeamLabs: Memory Analysis - Ransomware

This is a medium-difficulty memory forensics challenge hosted by Blue Team Labs Online (BTLO). The challenge requires the use of Volatility to analyze a memory dump and determine the malicious processes.

2023-06-10

TryHackMe: New Hire Old Artifacts

This is another medium-difficulty Splunk challenge from TryHackMe. We’re tasked with uncovering the malicious activity that occurred on a compromised endpoint.

2023-06-08

Cyberdefenders: DumpMe

DumpMe is a medium difficulty memory forensics challenge hosted by CyberDefenders.

2023-06-05