Cyberops associates v1.0 – skills assessment

Screen%20Shot%202017-08-30%20at%202.29.42%20PM.png

CyberOps Associates v1.0 – Skills Assessment

CyberOps Associates v1.0 – Skills Assessment

1. Introduction

You have been hired as a junior security analyst. As part of your training, you were tasked to determine any malicious activity associated with the Pushdo trojan.

You will have access to the internet to learn more about the events. You can use websites, such as VirusTotal, to upload and verify threat existence.

The tasks below are designed to provide some guidance through the analysis process.

You will practice and be assessed on the following skills:

· Evaluate event alerts using Squil and Kibana.

· Use Google search as a tool to obtain intelligence on a potential exploit.

· Use VirusTotal to upload and verify threat existence.

Content for this assessment was obtained from
http://www.malware-traffic-analysis.net/ and is used with permission. We are grateful for the use of this material.

Required Resources

Host computer with at least 8GB of RAM and 45GB of free disk space

Latest version of Oracle VirtualBox

Security Onion virtual machine requires 4GB of RAM using 25GB disk space

Internet access

Instructions

Gather the Basic Information

In this part, you will review the alerts listed in Security Onion VM and gather basic information for the interested time frame.

Verify the status of services

Log into Security Onion VM using with the username
analyst and password
cyberops.

Open a terminal window. Enter the
sudo so-status command to verify that all the services are ready.

When the nsm service is ready, log into Sguil or Kibana with the username
analyst and password
cyberops.

Gather basic information.

Questions:

Identify time frame of the Pushdo trojan attack, including the date and approximate time.

Type your answers here.

List the alerts noted during this time frame associated with the trojan.

Type your answers here.

List the internal IP addresses and external IP addresses involved.

Type your answers here.

Learn about the Exploit

In this part, you will learn more about the exploit.

Infected host

Questions:

Based on the alerts, what is the IP and MAC addresses of the infected computer? Based on the MAC address, what is the vendor of the NIC chipset? (
Hint: NetworkMiner or internet search)

Type your answers here.

Based on the alerts, when (date and time in UTC) and how was the PC infected? (
Hint: Enter the command
date in the terminal to determine the time zone for the displayed time)

Type your answers here.

How did the malware infect the PC? Use an internet search as necessary.

Type your answers here.

Examine the exploit.

Questions:

Based on the alerts associated with HTTP GET request, what files were downloaded? List the malicious domains observed and the files downloaded.

Type your answers here.

Use any available tools in Security Onion VM, determine and record the SHA256 hash for the downloaded files that probably infected the computer?

Type your answers here.

Navigate to
www.virustotal.com input the SHA256 hash to determine if these were detected as malicious files. Record your findings, such as file type and size, other names, and target machine. You can also include any information that is provided by the community posted in VirusTotal.

Type your answers here.

Examine other alerts associated with the infected host during this timeframe and record your findings

Type your answers here.

Report Your Findings

Summarizes your findings based on the information you have gathered from the previous parts, summarize your findings.

Type your answers here.

End of document

2020 – 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page
1 of
6 www.netacad.com

2020 – 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page
6 of
6 www.netacad.com

image1.png







Calculate Your Essay Price
(550 words)

Approximate price: $22

Calculate the price of your order

550 words
We'll send you the first draft for approval by September 11, 2018 at 10:52 AM
Total price:
$26
The price is based on these factors:
Academic level
Number of pages
Urgency
Basic features
  • Free title page and bibliography
  • Unlimited revisions
  • Plagiarism-free guarantee
  • Money-back guarantee
  • 24/7 support
On-demand options
  • Writer’s samples
  • Part-by-part delivery
  • Overnight delivery
  • Copies of used sources
  • Expert Proofreading
Paper format
  • 275 words per page
  • 12 pt Arial/Times New Roman
  • Double line spacing
  • Any citation style (APA, MLA, Chicago/Turabian, Harvard)

Our guarantees

Delivering a high-quality product at a reasonable price is not enough anymore.
That’s why we have developed 5 beneficial guarantees that will make your experience with our service enjoyable, easy, and safe.

Money-back guarantee

You have to be 100% sure of the quality of your product to give a money-back guarantee. This describes us perfectly. Make sure that this guarantee is totally transparent.

Read more

Zero-plagiarism guarantee

Each paper is composed from scratch, according to your instructions. It is then checked by our plagiarism-detection software. There is no gap where plagiarism could squeeze in.

Read more

Free-revision policy

Thanks to our free revisions, there is no way for you to be unsatisfied. We will work on your paper until you are completely happy with the result.

Read more

Privacy policy

Your email is safe, as we store it according to international data protection rules. Your bank details are secure, as we use only reliable payment systems.

Read more

Fair-cooperation guarantee

By sending us your money, you buy the service we provide. Check out our terms and conditions if you prefer business talks to be laid out in official language.

Read more

Order your essay today and save 10% with the coupon code: best10