Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Examples This page is useful for create a library of online samples files.
When you create an example, you put the url to the file and when you process it, the application download event file and process it.

___________________________
@hacking_Attack
@Hacking_Video
Elastic In this page, you can create searches to you Elastic instance and create a graph of the result. You can create filters about: Hostname of host machine. Sysmon event ID SourceIP DestinationIP DestinationIP Type (Internal or External) UserAccount Process Name All this filters can be inclusive or exclusive and can be contain group of values separated by commas.
You can create more than one filter and all of created filters uses "AND" such logical operator between each other.
In this page you can include Powershell Scripting (https://www.kitploit.com/search/label/Scripting) Logging events in the results. 

___________________________
@hacking_Attack
@Hacking_Video
Graph Graph page is the core of this application and the researching interface of it.
In the other pages you select your data and this pages send you to graph page, if you go directly to graph page, nothing will be there or the last data searched for you.
In this page are two tabs, one for sysmon and other for Powershell events.
There are two types of elements, nodes and edges. Nodes represent entities such process, file or registry key (https://www.kitploit.com/search/label/Registry%20Key) and edges represent actions such as create, delete or connect.

___________________________
@hacking_Attack
@Hacking_Video
Sysmon We are in the core.
This part use the information in the database to create graphs about the events analyzed.

___________________________
@hacking_Attack
@Hacking_Video
You can navigate in the graph, watching about process creation, named pipes connected ... but there is usually too much information to work comfortably.
Inside the tab are a hidden section about graph filters. Filters

___________________________
@hacking_Attack
@Hacking_Video
In this area you can work with the graph filtering data.
You can filter nodes by this entities: Computer Process Threat Connection (IP) File Pipe Registry Key DNS Query DNS Resolution You can filter process nodes also by: Process integrity Process session User Also, you can filter edges by this actions: Create Finish Access Change Delete Rename Connect Owned (belongs to) Load Animations One great feature is create animations about the data in the graph, this is very useful for example in Parent PID Spoofing or when some user in a computer execute commands remotely.

___________________________
@hacking_Attack
@Hacking_Video
Delete groups When graph has too much information, is possible delete one node, one edge, a group of nodes or a group of nodes recursively.
Delete group of notes works selecting one node and the application will delete all de nodes that his parent is the selected node.
Delete group recursively works also selecting a node but application will go through nodes deleting until finish this tree branch. If branch has a lot of information, this will take a long time. Graph Settings On bottom of the screen it's possible to change physics of the graph.
When graph has a lot of information could be useful disable physics in order to stabilize the graph.
You can play whit physics, it's funny. Powershell logging In the Powershell tab is possible analyze powershell (https://www.kitploit.com/search/label/PowerShell) commands.
Commands are showed in an accordion and inside each row, if command contain a base64 command, it will be decoded and parsed.
You can search in all events for encoded o decoded part of the command.

___________________________
@hacking_Attack
@Hacking_Video
BackendTwo — HackTheBox — Writeup

Hello guys sorry for uploading late. I didn’t had time so let’s start talking. Btw this box is UHC box. (Ultimate Championship Hacking)…Continue reading on Medium »
Read more...
Dark Reading: Attacks/Breaches
Critical VMware Bug Exploits Continue, as Botnet Operators Jump In

A critical VMware bug tracked as CVE-2022-22954 continues to draw cybercriminal moths to its remote code-execution flame, with recent attacks focused on botnets and Log4Shell.
hacking: security in practice
Learn Computer Science or Hacking first?

Hello everyone! Should I learn Computer Science (Self-study) first or Hacking (Using HackTheBox Academy) first? Which do you think is better to learn first?

Thank you!

submitted by /u/ThatOneEpicAstronaut
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video