SIMULATION -
You are about to enter the virtual environment.
Once you have completed the item in the virtual environment, you will NOT be allowed to return to this item.
Click Next to continue.
Question and Instructions -
DO NOT perform the following actions within the virtual environment. Making any of these changes will cause the virtual environment to fail and prevent proper scoring.
1. Disabling ssh
2. Disabling systemd
3. Altering the network adapter 172.162.0.0
4. Changing the password in the lab admin account
Once you have completed the item in the virtual environment. you will NOT be allowed to return to this item.
TEST QUESTION -
This system was recently patched following the exploitation of a vulnerability by an attacker to enable data exfiltration.
Despite the vulnerability being patched, it is likely that a malicious TCP service is still running and the adversary has achieved persistence by creating a systemd service.
Examples of commands to use:
kill, killall
lsof
man, --help (use for assistance)
netstat (useful flags: a, n, g, u)
ps (useful flag: a)
systemctl (to control systemd)
Please note: the list of commands shown above is not exhaustive. All native commands are available.
INSTRUSTIONS -
Using the following credentials:
Username: labXXXadmin -
Password: XXXyyYzz!
Investigate to identify indicators of compromise and then remediate them. You will need to make at least two changes:
1. End the compromised process that is using a malicious TCP service.
2. Remove the malicious persistence agent by disabling the service's ability to start on boot.
dangerelchulo
Highly Voted 2 years, 7 months ago23169fd
9 months, 4 weeks agoyoungprinceton
2 years, 7 months agodangerelchulo
2 years, 6 months agoyoungprinceton
2 years, 6 months agoyoungprinceton
2 years, 6 months agoBroesweelies
Highly Voted 2 years, 1 month agoIT_Master_Tech
Most Recent 1 year agoe4af987
1 year, 1 month agoSirL
1 year agoWaltsthe
1 year, 1 month agoD1960
1 year, 3 months agoIT_Master_Tech
5 months agoDelab202
1 year, 3 months agoTrap_D0_r
1 year, 3 months agoD1960
1 year, 3 months agoAnarckii
1 year, 4 months agojoinedatthehop
1 year, 5 months agoPluDou_111
9 months, 1 week agoD1960
1 year, 3 months agoUncle_Lucifer
1 year, 7 months agoUncle_Lucifer
1 year, 7 months agoUncle_Lucifer
1 year, 7 months agopawnpusher
1 year, 8 months agoUncle_Lucifer
1 year, 7 months ago[Removed]
1 year, 10 months agoBLADESWIFTKNIFE
2 years, 2 months agoMikeyMaster
2 years agoMostofMichelle
1 year, 8 months agobobby44
2 years, 2 months agobobby44
2 years, 2 months agoToneBar
2 years, 2 months agojekster
2 years, 3 months agoFOURDUE
2 years, 2 months ago