List internal ip addresses and external ip addresses involve

Assignment Help Business Management
Reference no: EM133597097

Assignment: CyberOps Associates- Skills Assessment

Introduction

You have been hired as a junior security analyst. As part of your training, you were tasked to determine any malicious activity associated with the Pushdo trojan.

You will have access to the internet to learn more about the events. You can use websites, such as VirusTotal, to upload and verify threat existence.

The tasks below are designed to provide some guidance through the analysis process.

You will practice and be assessed on the following skills:

A. Evaluate event alerts using Squil and Kibana.
B. Use Google search as a tool to obtain intelligence on a potential exploit.
C. Use VirusTotal to upload and verify threat existence.

Content for this assessment was obtained and is used with permission. We are grateful for the use of this material.

Required Resources

A. Host computer with at least 8GB of RAM and 45GB of free disk space
B. Latest version of Oracle VirtualBox
C. Security Onion virtual machine requires 4GB of RAM using 25GB disk space
D. Internet access

Instructions

Part 1: Gather the Basic Information

In this part, you will review the alerts listed in Security Onion VM and gather basic information for the interested time frame.

Step 1: Verify the status of services

A. Log into Security Onion VM using with the username analyst and password cyberops.
B. Open a terminal window. Enter the sudo so-status command to verify that all the services are ready.
C. When the nsm service is ready, log into Sguil or Kibana with the username analyst and password cyberops.

Step 2: Gather basic information.

A. Identify time frame of the Pushdo trojan attack, including the date and approximate time.
B. List thealerts noted during this time frame associated with the trojan.
C. List the internal IP addresses and external IP addresses involved.

Part 2: Learn about the Exploit

In this part, you will learn more about the exploit.

Step 1: Infected host

A. Based on the alerts, what is the IP and MAC addresses of the infected computer? Based on the MAC address, what is the vendor of the NIC chipset? (Hint:NetworkMiner or internet search)

B. Based on the alerts, when (date and time in UTC) and how was the PC infected? (Hint: Enter the command date in the terminal to determine the timezone for the displayed time)

How did the malware infect the PC? Use an internet search as necessary.

Step 2: Examine the exploit.

A. Based on the alerts associated with HTTP GET request, what files were downloaded? List the malicious domains observed and the files downloaded.

Use any available tools in Security Onion VM, determine and record the SHA256 hash for the downloaded files that probably infected the computer?

B. Navigate to www.virustotal.com input the SHA256 hash to determine if these were detected as malicious files. Record your findings, such as file type and size, other names, and target machine. You can also include any information that is provided by the community posted in VirusTotal.

C. Examine other alerts associated with the infected host during this timeframe and record your findings

Step 3: Report Your Findings

A. Summarizes your findings based on the information you have gathered from the previous parts, summarize your findings.

Reference no: EM133597097

Questions Cloud

Determine the risk associated with the vulnerabilities : Based on the Assignment Scenario, determine the risk associated with the vulnerabilities. Use NIST SP 800-30 to calculate the risks for each vulnerability.
What will yousef most likely ask the dispatcher to send : What will Yousef MOST likely ask the dispatcher to send for this patient? fire truck ambulance police cruiser non-transport vehicle
Develop a listing of administrative and technical tools : Develop a 1-page listing using Microsoft Word of at least two administrative and technical tools that are available to support control monitoring.
What management can and cannot do during unionization effort : Outline a infographic as a valuable one-stop visually pleasing tool showcasing what management can and cannot do during unionization efforts per the National
List internal ip addresses and external ip addresses involve : List thealerts noted during this time frame associated with the trojan. List the internal IP addresses and external IP addresses involved.
Who reflects which cultural dimension : Diane Jones, a full-time marketing manager at the Equinox Corporation, is very concerned that there is a clear, detailed, and predictable plan for caring for
What can you do to analyse and decide on the most optional : What can you do to analyse and decide on the most optional solution to make the customer happy? Explain in a paragraph.
Define international law and describe its various sources : Define international law and describe its various sources. What best matches the definition of international law? a body of rules and norms that regulate
What is the first sign the lender is taking action : What's the first sign the lender is taking action? A police officer delivers a letter to the homeowner. The lender doesn't do anything except files for

Reviews

Write a Review

Business Management Questions & Answers

  Caselet on michael porter’s value chain management

The assignment in management is a two part assignment dealing 1.Theory of function of management. 2. Operations and Controlling.

  Mountain man brewing company

Mountain Man Brewing, a family owned business where Chris Prangel, the son of the president joins. Due to increase in the preference for light beer drinkers, Chris Prangel wants to introduce light beer version in Mountain Man. An analysis into the la..

  Mountain man brewing company

Mountain Man Brewing, a family owned business where Chris Prangel, the son of the president joins. An analysis into the launch of Mountain Man Light over the present Mountain Man Lager.

  Analysis of the case using the doing ethics technique

Analysis of the case using the Doing Ethics Technique (DET). Analysis of the ethical issue(s) from the perspective of an ICT professional, using the ACS Code of  Conduct and properly relating clauses from the ACS Code of Conduct to the ethical issue.

  Affiliations and partnerships

Affiliations and partnerships are frequently used to reach a larger local audience? Which options stand to avail for the Hotel manager and what problems do these pose.

  Innovation-friendly regulations

What influence (if any) can organizations exercise to encourage ‘innovation-friendly' regulations?

  Effect of regional and corporate cultural issues

Present your findings as a group powerpoint with an audio file. In addition individually write up your own conclusions as to the effects of regional cultural issues on the corporate organisational culture of this multinational company as it conducts ..

  Structure of business plan

This assignment shows a structure of business plan. The task is to write a business plane about a Diet Shop.

  Identify the purposes of different types of organisations

Identify the purposes of different types of organisations.

  Entrepreneur case study for analysis

Entrepreneur Case Study for Analysis. Analyze Robin Wolaner's suitability to be an entrepreneur

  Forecasting and business analysis

This problem requires you to apply your cross-sectional analysis skills to a real cross-sectional data set with the goal of answering a specific research question.

  Educational instructional leadership

Prepare a major handout on the key principles of instructional leadership

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd