Home - Justin-Boyd/CIT-Class GitHub Wiki

Kahoots

Windows 10 ova

EndPoint Security

HoneyPots

Data Loss Prevention

Chapter 4: Mail Security

Advances SIEM:

  • sourcetype="snort" AND 8.8.8.8

Lab1 - Log Queries:

  • source="/var/log/auth.log"
  • source="/var/log/*"
  • source="/var/log/auth.log" authentication failure
  • source="/var/log/auth.log" authentication failure user=student

Lab 2: Log parsing - extracting fields

  • source="/var/log/apache2/access.log"
  • status_code = 404

Lab3: Search Operators

  • host IN ("studentub" , "DESKTOP-0UMTA4K")
  • source = "/var/log/apache2/access.log" AND (status_code=200 OR status_code=404)
  • source = "/var/log/apache2/access.log" AND status_code=200
  • source = "/var/log/apache2/access.log" NOT request_url = "/random"

Lab4: Advanced Queries

Installing Demisto

  • just enable a bridge adapter to VM to have a direct connection to the internet. NOT VIA PFSENSE. Lab getting stuck at demisto/stix docker pull.
  • https://localhost:8443/#/login - Demisto UI!!

Extra links