Learning Objectives In today's task, you will:
- Learn to understand incident analysis through the Diamond Model.
- Identify defensive strategies that can be applied to the Diamond Model.
- Learn to set up firewall rules and a honeypot as defensive strategies.
After the machine is up. login via ssh. credentials:
Username: vantwinkle
Password: TwinkleStar
After Succesfull login Swith to root user
sudo su -
Now go to /home/vantwinkle/
You will find a script named as Van_Twinkle_rules.sh
Run this script.
data:image/s3,"s3://crabby-images/ab6cb/ab6cbcd6d08c8f312de207b4be5d944a93391b59" alt="script"
QUESTIONS
- Which security model is being used to analyse the breach and defence strategies?
Answer
Diamond model
- Which defence capability is used to actively search for signs of malicious activity?
Answer
threat hunting
- What are our main two infrastructure focuses? (Answer format: answer1 and answer2)
Answer
firewall and honeypot
- Which firewall command is used to block traffic?
Answer
deny
- There is a flag in one of the stories. Can you find it?
Answer
THM{P0T$_W@11S_4_S@N7@}
First Scan the machine using nmap.
data:image/s3,"s3://crabby-images/72c30/72c30ed284d851fdbb18469249f8d7a6eacea86b" alt="nmap"
The flag is in the port 8090 but this port is blocked by the firewall. To enable 8090 port
Command
ufw allow 8090/tcp
data:image/s3,"s3://crabby-images/34c45/34c4530fbc79e42ab1dff51459d27e0fcb7957e5" alt="Screenshot 2024-01-03 at 4 12 02 PM"
data:image/s3,"s3://crabby-images/dbdf6/dbdf628d8a814a01cd8542bf628b8eddbca70166" alt="flag"