【blueteam-ctf-challenges流量取证部分】PsExec Hunt Blue Team Challenge

Cyber Blue Team labs, CTF challenges, DFIR, and SOC tools

蓝队的题都比较偏向实战,这道题是一个比较简单的流量分析题目,主要是关于内网横向移动的流量,拿到这里和大家分享一下,网上wp比较少,所以写一个记录一下,留着自己看。如果有问题希望师傅们指正。

Q1

In order to effectively trace the attacker's activities within our network, can you determine the IP address of the machine where the attacker initially gained access

找到攻击者攻击的入口机器,根据流量能看出来,10.0.0.130是连接内网的入口机器,大部分文件都是由10.0.0.130发送给其他主机的

Q2

To fully comprehend the extent of the breach, can you determine the machine's hostname to which the attacker first pivoted?

根据第一题知道攻击者首先攻击的是133这个机器,所以看一下133的hostname

从这个session setup 找

Q3

After identifying the initial entry point, it's crucial to understand how far the attacker has moved laterally within our network. Knowing the username of the account the attacker used for authentication will give us insights into the extent of the breach. What is the username utilized by the attacker for authentication?

看一下攻击者用哪个账户进行横向移动的

Q4

After figuring out how the attacker moved within our network, we need to know what they did on the target machine. What's the name of the service executable the attacker set up on the target?

攻击者开启服务用的exe文件是什么,一眼丁真

Q5

We need to know how the attacker installed the service on the compromised machine to understand the attacker's lateral movement tactics. This can help identify other affected systems. Which network share was used by PsExec to install the service on the target machine?

看一下用的哪个共享网络文件夹,用的是ADMIN$上传的

Q6

We must identify the network share used to communicate between the two machines. Which network share did PsExec use for communication?

用哪个共享网络用来交流的

后面发现用的IPC$来对131和133两台计算机进行交流的

Q7

Now that we have a clearer picture of the attacker's activities on the compromised machine, it's important to identify any further lateral movement. What is the machine's hostname to which the attacker attempted to pivot within our network?

攻击者最终打入的是131主机,也就是说这是攻击者的目标靶机,所以看一下131主机的hostname

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

Q1anhuang2

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值