OK I think we're live now guys please Let Me Know If I Am Audible and Visible My voice is going to you people once Tell me quickly, everyone. Tell me, tell me quickly ok, till then I will inform you here We ok good evening Good evening to everybody good evening good evening good evening good evening a very good Evening Okay, so the voice is becoming clear, isn't it? It's absolutely clear, please tell me one We It is absolutely clear. Ok. So everyone has one Let me come once. Then We Will Be Starting today's session. As I said with every session that your Upcoming sessions or whatever your next The sessions will be even more interesting. It will keep getting more fun and you will get more It will be more fun. So I hope that today all of you You will learn something interesting and have fun. It will come so much that There are many things you probably haven't seen before. Must have learnt it. You might not know till today. And you will learn that too today. And this I think with every SOC session It happens. In all the sessions that take place it happens. And I hope you get this thing I will definitely agree. I wish. Ah so, me Tell me once that I want to ask all of you. I want to know from everyone. Whatever sessions there were There are SOCs for you to learn something. gets it or feels like nothing There is no special meaning to be learnt. already i No, I already know things. so me Please tell me about it. So That I Get To know. You need to get some idea Even from people. Totally agree okay it turns out okay ok ok ok let's do it good thing one time one time Bars let everyone join at once Many people have not yet arrived, so let them compare. First 106 People Are Here So let's all come at once. have a lot in common. Ok. So Tell me how many of you have this Have you completed class four? SoC Tell me about the sessions once. Just Just Let me know. How many people are in the class? Is it complete till four? Just Class Four Tell me those who have completed it till now. only A ok dun dun Done has completed till class four. Let go You guys already had enough time. Right? You Got Enough Time to Complete Till Four Class four. Right? Because you may have seen that your resources from class four were Right, if I were to go to Class Four resources If I go up to Day Four, you will see that here You had 23 slides in total. 23 slides Means more topics and more content, a lot of Content actually that you had to complete. Right? So if you have completed till class fourth If you have done it then it is great. quite a good thing Is. I hope that it happens to maximum people. will be. And if it still doesn't happen to you Yes, you are the one who is still in class four. Has not happened. So I would request you that Please please please you must reach class four Complete it. Staying on time Complete it. It will help you a lot. And you will need more time to understand further classes. This will help even more. Ok? Let go 145 people have joined here. A I At least I think 200 people joined. Only then will we start the session. So Let's wait a little more because many people There are those who are left out again. Then that message Let us tell you that Sir, a little bit is left. Tha and all extra extra right Ok Sir approximately months to complete this course. Three to four months I think maximum. Three Two four months. Right? Three to four months. Ok. So before we start let me Let me tell you all first. This is a This is my Lindin page where you can contact me You can connect and follow me Are. Follow my journey, whatever it is. Can. This is my personal Lindin Profile. Then you search for defronix do. Lindin Pay You Will Search Just Diphronix. Then you will find our Defronics You will find Lindin's page. You come to this You can follow us. And you will get to Know About Our Company Our Company Updates and All everything. This Twitter is our gift. That's the X Defronics page at X.com Diphronix Adamy come here and follow me Please take it. In the near future, you will find here Some interesting things are going to be found. Some giveaways and some important updates Will meet. So you will come to this. This is our There is a website. Here is our phone number. You Any queries on this, anything related to You can also ask questions. And this You know what it is. Our There is a YouTube channel. So subscribed then It's a good thing. But in this the bell notification which I will always keep you enabled Is. Check if you are still You are watching if you are subscribed then all Make sure to do it because only then will you You will get a notification. Otherwise Notification You will not get it from YouTube. End The most important thing that any live SoC needs Please open the class. any live Like I'm about to open Day Four. Ok? And here in the description when you go So you will get two links. A WhatsApp The Group has a specialized group of SOCs. These. You will get its link. You must join this Please do it. All that relates to associate Your resources are whatever your PDFs are. or whatever resources you have in your classes Will be needed or upcoming which this training The certification done after the end of Details and everything will be shared. Shared here only in this group. And this The second link is this WhatsApp channel. Ours is called Defronix Academy. you come Follow here for all the updates. You can follow us for. whatever things Yes, you will get them. Right? Thank you. I hope you all have joined. Let go Right now you can see that we have 148 people Only Here in the Live. Now tell me that What's the problem? So now tell me a I have a question for you before starting. 350 people live in Question Is Starting The first day. After that about 300 to 250 The date is currently around 150 live. This I I want to know from you guys very sincerely I mean I am asking a little seriously Focusing on this thing Would you be willing to do such training? If you pay Rs 10-15,000 in some institutes Would you still do it that someday We go and someday we go and our Doing according to I think I don't think that You do that. Right? I don't think that You could have done this. So you can find its value in it. Why are you not keeping it? You value it in Why are you not able to give it? I don't have this I understand. Those who are not coming, People are watching the recording, I am talking about them. I am asking why you are not coming live. Are you? Why do you manage your time? Are you not doing it? You prioritize this Why are you not giving it? That's the thing. Right? I am telling you the truth. You can get similar training here. It is there, you won't find it anywhere. it's a Guaranteed I am telling you this with full conviction. Understood? So, you should understand this thing a little. This Feel the thing. You Have to Understand Dec. You will regret it very much later Because let me tell you one thing. Class One, then Class Two, then Class Three. By doing this slowly, make the videos members only. We will start doing it. then that video You won't see them. Then you will neither have to revise He will neither get a chance to do anything nor will he get anything. So you have a chance now. One is live Attend and listen to the recordings now Revise so that you can understand what you are Be able to fully gab. Isn't it? Right? So, just gag this thing a little bit and live it up. Those who come will get special benefits. They want all those videos freely, right? It should become available. Now that comes later He may not have it. So that is their fault Is. Right? So give it some value. I will request the same from you. Ok? Even on Lindin, many people have it till class three. Has shared it. Look, I'll show you I am you. I'm here in the notifications I'm leaving. Enough about Class Three. People have shared it here. SoC's Look, class two is over. Class Three Class There has been slightly less share sharing in Four. Few people have put points on Lindin. Put this in. You put points on Lindin. Is it right? It's really very different. So let's start today's journey. Are. And what we have today is a different A Our class five will understand mindset. In. And this mindset is enough for you. It is going to be interesting. It will be a lot of fun You have to understand this mindset. So let's Let's start. Ok? First of all, the topic we are going to discuss today is That is the Cyber Kill Chain Methodology. We this I am going to understand a little bit. Cyber Kill Chain Methodology. Now look, this is very easy. It is a topic. If you understand it that way, it is very easy. Is. But I want to give you the way I want you to I'll explain it to you like no one else has. It must have been explained and in that way your mind I wouldn't even fit in today. So this thing Please understand. This is a very important concept. It is a very important topic. Any cyber Whether you are pursuing any security certification Level 1 Cyber Security Certification Do you do it or know it or try to do it had been. This topic always comes up in them. It may be indirectly or directly. Matter. There is only this particular thing which You will always find it everywhere. So this Please understand a little. Ok? Yes. Yes. and which I had given a task to one of you. Has he done the task or not? These Tell me. I did something in the last class. I gave you a task. Tell me. That's good Tushar. If you come early. A thanks Pitambar thank you very much We Yes Adi, I saw your sketch and thank you. You very much you probably shared on Lindin Was. So thanks a lot and I commented I also gave you the mail ID so that you can send it there. Give it because that was really nice and Thank you very much for that it was really Great art. So Who Shout Out To Mr. Adi Ok Those who completed the task, it is good. Those who did not do it, please send them next. Do it before the session request because I am going to give you more tasks If I keep giving it to you, then you will get that leg again. The behind will be yours. Now let us understand. Hey, no protein powder. Brother. A guy is talking about protein powder. Not a protein powder. this is called Cold coffee. It's over. protein powder I don't drink just sitting around like this. I am a gym I am taking a bath after getting ready. so it's a Yes, this is cold coffee. Homemade cold coffee. Ok. Let's understand the cyber kill chain. and hacking methodologies of the cyber kill chain Let us understand the difference between them. both two Things happen. I will explain to you First. Look at Cyber Kill Chain, one such Framework that was created or invented was done or For him By whom was it done? Lockheed From Martin. Locked Joe Martin He created this particular framework Whose name was Cyber Kitchen. This cyber What was Kilche? This is a life of attackers. There is a bicycle. a life cycle like these I thought that an attacker who is a hacker When attacking a system Any network infrastructure. this thing You guys listen carefully. Get out of the chat. Good evening. Hello everyone but good evening now. Move away from hello sir and focus on me. Do it. Ok? It doesn't matter, you're still late Yes, but we are just starting now. You are not late. Right? So please focus here Disappear from your chat right now For some time. When hackers attack The systems pay, the networks pay, On infrastructures. So their different There were different approaches. Correct Is? Someone used to hack in some other way. Some used some other method. something else Tools, some other techniques, all of them Things used to happen. But they have a methodology, a Method One of its core methods was the core methodology. It used to be that they were almost similar, whatever The attacks were almost similar to what they are now. It is almost similar to if you were to So let's say you live in Mumbai, right? You have to travel to Delhi, now you are going to Mumbai You can go to Delhi either by bus or by If there is a bus running then you can go by train. You can go by flight, right? You may have used different transports but your There will be some core methodologies such as you You might be going in a particular way, a particular You might be going in a particular way The approach would be a particular thing. I must be going for some particular work I am travelling to Delhi for work. I must have gone at a particular time when I If I want in this particular date range your methodologies, that is, your one There are different ways. Such as You can use different modes of transport. But whatever your purpose is, that purpose is one. And one of its core methodology is that He is also intact, he is also the same. There is a way and you follow the same. further you reach Delhi or Now you have to go to Delhi whenever someone Attacker hacks when an attacker attacks Is there any system on any infrastructure But it has a life cycle that it How did he access the system? Using what methods can one reach there? attacking the systems above him We say that it is defined Inside the Cyber Kill Chain. Cyber Kill Chain inside which Lockid Martin invented Get it done or get it created. Now this cyber kill chain meant that any company, any infrastructure, any major Organizations involved in this cyber kill chain There are steps, if even one of those steps Breakdown, even cutting a step or even stopping a single step succeeds or is successful, then it The entire cycle, this entire life The cycle gets disrupted. This whole life The bicycle breaks down. and right there But that chain breaks. and attacker his jo also his Whatever like whatever his intention or her The intention is there and it ends. His intention ends. He will do it Can't find it. He does not compromise Will get it. So there is no compromise. Even If one single stage is broken down, if so If it happens then in that case it is completely The chain breaks and the attacker is not successful. It is possible to attack the system. That's it. This is the entire cyber kill chain. Full meaning. Now we will explain this in a little detail Will understand. Now, let's get a little technical. If we look at it, it is a linear model that Focuses on the attacker's journey from outside in. The attacker from outside attacks from inside. If he is, then he focuses on his journey. to know how the attacker is entering a How is it getting inside the system? Is. In what ways is he entering? The entire journey. by Breaking the Chain at Any Point You Stop The Entire Attack. to the chain If there is a breakdown from anywhere then there will be a complete attack. Whatever is there will break. The entire attack is stopped Will go. This is the Cyber Kill Chain Methodology And it is used by organizations Teams of companies that are on behalf of Their security teams use it. Understanding this and on the basis of this She wants to break this chain by acting. Whenever an attacker attacks. thats It. watch now Multiple within the cyber kill chain There are stages. You Can Say Seven Stages Are there in the cyber kill chain. Cyber Kill Chain There are seven stages in it. Now it is seven What are the stages? The very first stage You get recognition. The First The stage is recognition. second stage is Weaponization. The third stage is delivery. Fourth The stage is exploitation. Fifth Stage Is Installation. Sixth is command and Control. And Seven is action on Objectives. Ok? This command and The control thing is this, press it twice here. It has arrived. Please ignore this. Seven There are six sixes twice here. Is. Ok? So just ignore it. So these seven Stages: Your Part of This Cyber Kill Chain There are. Now these seven stages, these seven There are so many things in the stage that you need to understand. Not there. Just get it in your mind For life time because this is your hacking Cyber Security on Journey Useful from starting beginner to end Going to do. and its You will use it even if you are a beginner and you You will also become a super expert. Even then you It has to be done. Whether you are in SoC, Digital forensics is where security comes in. into penetration testing or any It is at any place. you are going to follow This cyber culture. This is so important. Just understand this much. Ok? Reconnaissance now Weaponization, delivery, exploitation, all of it. I will give you a little example will tell you. I will explain this little by little. After that I will give you a little detailed I will take you there with an explanation. Ok? Let us first understand it in short. Correct Correct correct. now here First comes reconnaissance. See Many people will know about the recognition This is called Ination Gathering, also you can Footprinting from. You can also call it footprinting. Ok? Gathering information on target. In this What does an attacker do? Target's Information gathering on target Does. Infection gathering means the Initial level of gathering. Initial level of Intel which is Intel gathering. Intel Gathering means that the information You do the gathering. So when you are an attacker Ko attack is when you attack an edge attacker or network or any company or any No system or server overhead If Govind attacks then in that case you are the most Your big arsenal would have been There is Infection Gathering which means your Arsenal Hacking is in the arsenal. To all The big one is your way of information To gather. The more you gather information Will do this much for you regarding the target This particular one of yours will become easy. It is an attack, it should be so easy to make it successful. Will go. What is in the example? Researching Company and Employees Finding Emails and Usernames Identifying Target System and Viabilities. Look at this. Now information Gather means for a target. Any information about the target Gather as deep as possible. Suppose that You are facing an attack on a company's network. Have to do as an attacker. Ok? Just Imagine Have to do it. You don't have to do it for real. I have to imagine. Now one of that company's There is network infrastructure. Let's Suppose There is an IP that you are that you that you No, this IP is network infrastructure Is a part of. And I'm going to attack it I want. I want to have that access. So Normally technical flaws are called liabilities. Exploiting and then executing it It is a little tough to do that you have a liabilities Find it first and then exploit it do it. then by delivering the payload and then Do the execution. Then you setup the CNC do it. Then you will have access. These This is all technical flow. Right? This becomes the technical flow. But I'm here But I am saying that if the technical flow If you have a flow that is easier than yours, If you know, would you Don't want to go along? And that's the flow These records flow. Reconnaissance Flow. Reconnaissance plus social engineering is the Most Deadly Combination in Cyber Attacks. If someone is a master in Reconnaissance and Social If he has a master's degree in engineering, then he has the rest that these are all the things that will be needed These remaining steps are very easy. He will go and do all the steps but very Very easily but if regeneration is not good I am not able to do social engineering properly. The execution is not happening well If you are not able to succeed then this The steps will be a little difficult But it will have to be completed with difficulty. It will be there but it will not be as easy as it used to be. It's yours if you achieve it as a master Recon and Social Engineering. Now look When you will do reckon and social engineering Master, you will reckon and after that Direct you here action on You will come to the objectives. And these ones in the middle The steps play only a supporting role. Will remain. Many people stay in supporting roles want. Many people like these two, three, four There are five steps in the middle, these are of that Will come in a supporting role in time. Right? And if your recognition Recognition is not good, then this Will be in the main role. This is in a supporting role I will not stay again. These will be in men Rolls. So you will get a lot through these also. Will have to go deep. But anyway you go It will not fall deeply. you a little bit All these roles are very easy. It will be done. After that these are the steps Two, three, four, five, this is very easy. Will be executed. So if my If I want to attack any company then now I What should I do? I am in the company Before exploring liabilities in the network Mostly by finding the capabilities in the company First I will extract the data of the companies. whatever The company has all the data that brother, this company What does she work on? Their network Infrastructure How it is? How complex is it? How? Are firewalls being used? Which one Which switch is the router using? among them What versions of software can be operated? Are you? How many employees are there? IT Team What kind of thing is it? how much Are you aware? How highly skilled are you? How much knowledge does he have about what? Their upper level hierarchy. Where Where senior members come, Management people come, who are they? Then who is its CEO? Who is CTOS? Who are the CEOs? Who is a Security Engineer? Chief Engineer Who is it? I will find out all this. Everything and I will make a complete list. I will search on Lindin about the company. Go to the People section of the company Lindin If you go there, you will see all their things. There are members, they are mentioned there. Is. Ok. Raj Kulkarni has done a lot here. It has been spammed. He said, Hello Nitesh Sir, I am Learning Cyber Security and Your Bug The Bount Series Has Been Extremely Helpful In Building My Fundamentals and Approach. I would be grateful for guidance from you. Thank you Raj Kulkarni but please don't spam Frequently. Ah I'm really happy that the The series is helping you and I think you should Continuum. You continue like this, Do well. You will be doing good. Correct Is? That's great. Let go. So when I collect all the information I will talk about that particular company, Regarding employees, then I target my I will make one employee. a lower level To the employee. I will make him my target. And I will act at a senior level. Like a management employee. I act Like a CDO. I act Like a CEO. I act as a team lead and I me You must know that this guy is from the IT team who He looks after different operations, so I work in the same team. I act as the team lead of Try Phishing and Social Engineering on Us And I will try so that they get in Trap and when they get into the trap, that's it. This weaponization will make delivery easier Explanation will become even easier It will be super easy. Installation Super Duper It will be easy. Command and Control Most It will be done in the easiest way. and action end The objectives will be achieved without being told. It will be done without any tension. This is power Information Gathering and Social Of engineering. That's it. This is power. Correct. insider threat Absolutely. His role is a very big one. Of insider threat. We will do that sometime later You will understand very well. So it would be the first This is your reconnaissance. The second method comes Weaponization. Now that you have collected everything Information taken, all information taken So now you have to use your weapon. Have to setup. Weapon has to be created. Weapon It doesn't mean that you should take the bomb Have to go. bombing the company Is. Weapon means payload to craft to do. Creating a malicious payload. Payloads R Everywhere. No Matter How Much Technology is advancing or anything payload Meaning of Cannot Be Replaced Because Payload There is no such thing as just one thing. Payload One It is a process, you cannot replace it. So Crafting the Payload Is the Next Part Musious payload. In what ways? Creating Malaysia attachments and links developing malware and Exploits. Now many of you have You might have heard the name of Metasploid. many people must have heard. Have you heard that among you people Someone from? have you heard about Metasploid Guys? Please let me know. Please let me know. how many of you heard About Metasploid which is basically in Kali It comes already preinstalled. Graphical There is also a version. The Uban tool is available on any Linux. You can easily install it from the store. I'm talking about the Metasploid Framework. I. Ok. Yes. Metasploid Framework. So Metaspoid Framework Ah Is Mostly Collection of different kinds of exploits, Payloads, auxiliaries nab a right Encoders Accept Accept. This which Metastide etc., all this means we are our Even in training etc. like our There is a DCGSP course. We are very good at that Let us tell you from. How to use it, what I have to do extra extra. So a You already know many things about Metasploid. People know. Many people have also heard it. This is a framework that you can use to Exploits can be developed. Exploit You can create it. Delivering payloads Can. encoding and encryption All of the things you can do with this help. So you can do this in weaponization in the second step. The kinds of payloads that are there make it happen. They develop malware. You develop the exploits that exist. Are. This is weaponization, brother. Gathered the information. Now we that Payloads based on information Will develop or craft. After that Our delivery is coming brother. This delivery. Now delivery means sending the weapon to Target. Now you have made the weapon. Now such What is a bomb if it doesn't explode? made a bomb Buttocks should be burst. Then what is the use? So whenever Weaponization happens, then it comes after that Talk about delivery. to fire that weapon now Is. So where to run? above target Have to run it. So what do you do in that? Now There can be different types of weapons. As Either sending phishing mails containing malicious There will be attachments, there will be malicious links or malware through malicious websites Get it downloaded on the target's system or Execute the exploits that are there Give it to the target's system. So this is what happens In the delivery phase. Ye Attacker Delivery Do it in phases. And then our delivery After this comes exploitation. now when Brother, I have already put the exploit there. Meaning they have executed the payload You have executed sorry when Now that the system has been exploited It's time to exploit the system When you sent the payload, when you launched this weapon The weapon has been delivered, now it is the turn of that To exploit a particular exploit Now exploitation in that particular process What will happen is that you actually By running the exploit you are actually You are executing the exploit On the system. That's it. Now it runs malware and Exploit Code Trick User Inu Enabling Macros because macros based liabilities There are many exploits available Infected USB drives or rubber duckies, such as drives installed or any infected Drive where you have any such placed an executable that is malware or Trojan contains and as soon as that person He will execute it, his system will be corrupted Will be done. His system is complete There will be a compromise. So this is the fourth phase. happens in which we exploit to the system. We Just Exploit the System. Ok? Fifth here is installation. Now Brother, when we compromised the system If you have taken it then what are the steps after that? These What does installation mean? installation means you now install a backdoor Are. Trying to Create Persistence End unpatched software Trying to exploit vulnerability We do. This is your installation phase. Now What the installation phase basically consists of that you create back doors or persistence Let's try to do it. and a way You make it for yourself. way means bye chance in any way if the system or in that particular network infrastructure One realizes that the system is probably If compromise has been made then that effort Will view from all sides from every possible angle Get rid of this compromise. So attacker What happens if one path is closed? Another path should open. setup something like this will give on that system on that server After the network infrastructure I did that from behind through the back door, that's why Its name is Back Door Its name is Back Door You must be looking at the way first, a how Backdoor is created to create this backdoor What do you guys think about this right now? A single command will create a backdoor. It will be a deal in the upcoming future classes this is complete each complete that Dude, I mean backdoor creation is a thing in itself. There is a whole class. Right? So we direct No, he can't do it. A little about the concept You have to focus a bit. Ok? Then I I told you to go with me, go with the flow. You will get everything. I just guarantee it I will give it to you. You will get everything. Who Whatever is going on in your mind right now You put it in the message in the chat that Sir, its What does it mean? I am giving you this so that I'm not going too deep right now because if I Let me go to that. Suppose I am on backdoor creation If I go to backdoor creation, you can do it in many ways. Can do. Persistence can be used in many ways Can be made from. Lots of tools available Are. And there are multiple methods. Butt again Then there is a whole class for him. So that We will later when we need it. If there is such a need to make it persistent So definitely we will be doing that. So now comes the installation of the backdoor. Now You must have seen many people before or even today So it happens in fashion. Whatever used to be there before Your villages are villages The houses that used to be in villages are now homes. There are also many such that have two doors. Were. One was the main gate which used to be the main gate. Which was the main entry and the houses of a village There was a door at the back also. back Door from the very back. You know this You know, some of you know If you see this thing in your village life or you will have a house in the village or you If you know then I think you will know this Right about the thing, let's see how many People know how many of you have seen And no about this, yes sir, yes sir, many people You are from the village, friend, it seems you people are from the village. yes what Wow Yes sir, yes to escape from the robber That's right, yes that's right, first the bandits had to do so much I did not have the brain nor did I surround it from the front. Surround the poor guy from behind as well as from the front. They used to surround us, they did not know that behind The door is now very smart. Brother, now you will follow me from behind too. Two or four will remain standing, okay now underground will have to be made okay so there used to be two doors Similarly, here when an attacker attacks the system He completes it. complete He takes control. then after that a He makes his way, back door behind. so that many by chance if a door If it closes, I have a back door which It will remain open. Again and again I return I will keep hitting enter. And there he Creates persistence. Persistence System. Persistence means that Again and again whenever that guy assumes laptop Restarts as well as shutdowns Is. Then when it starts back up The attacker automatically connects to that system Will go. This is your persistence To create. How wonderful is that? Automatic connection was made. Nothing to do Is. Right? And for this he works on that system Exploit Present Unpatched Vulnerabilities He does it. Meaning, there is no such thing on that system. Software or particulars with capabilities There is a program lying around which he further He exploits it. And a backdoor from it He creates it. This is the thing. backdoor It is not that easy to create. until one unpatched vanity It cannot be found within a system. It's very tough. either vulnerable system as such Program software will find that attacker And then exploit it and create a backdoor He will either already know it or If it is available there then create a backdoor for it. It would be easy to do, but if at all There is nothing like this from Page Software. Creating a backdoor is equally difficult. But when an attacker attacks at such a big level They attack and infrastructure If they attack, they already have a lot to say. I know already de ah ah already de ah No, which system, which software How programs are exploited Can go. This is our fifth. Then comes our sixth command and control. Now this is the command and control which You can also call the command CNC or C2. End control. This is compromise Controlling the system remotely. Its This means compromise whatever The system is to control it remotely. Yes, what happens is communicate with the attacker. C2 Server Execute Commands Remotely The attacker has a C2 server, the command end The control server communicates this to him Right and then you connect remotely. from that particular machine and execute You can simplify the commands with a simple Meaning, understand its meaning in a simple way. A kind of reverse sale, a kind of you can say Reverse Shell You are remotely connected to a system. One through the tunnel and that's what command and Control Dus. that it. You are inside it Can run multiple commands. Execute Can do. Run whatever commands you want Can execute on target system. End after that comes last Actions on objectives. Deploy Ransomware & Latch DDoS & Get Any Kind of File Sensitive Information Download Any Kind of Inaction Execute Further malwares and Trojans key loggers and further exploitation in actions on Objectives come. That means whatever What is your objective? Are you objective? The attacker may be able to steal sensitive data. Stealing information and making lateral movements of lateral movement in the network It means that in the same network Multiple devices on one network when he enters a device And there if Zero Trust is not followed If it is there then it is inside multiple devices He can make his entry into Because Zero Trust is not applicable They say take it. That's Why the Zero Ah The concept of trust, ah, which came up on this Had come. Because Zero Trust Was Veracious And was very needed. Because the attacker once If he entered the network, the network would catch him. I used to trust that brother, you are the attacker You are trusted, friend. You have entered a Get into everything on the device. Now attacker is cool He used to sit very comfortably. Great with a system doing it second second third third fourth He kept entering and entering. I don't even know People thought that brother, this is a system It was infected. 50 systems here Have been infected. And lots of it There are examples. like I told you Its huge role in supply chain attacks Is. I told you about supply chain attack. Guys. You remember supply chain attacks? To you Remember? Tell me. Remember the supply chain attack? Dude, look at the comments, first of all you Whoever is left, please hit like. Those who did not hit. The second thing is that when If I ask, please answer everything in the chat. You don't answer me here Then it is not fun. Look when I'm free if job ready I am giving training, apart from money. Fulfill all the expectations that you have You will have to. Remember, the money is the same I am not asking for it. Money for training I am neither asking for it nor will I ever ask for it. This I guarantee you that. No one pays a single penny for training. It is about to happen. So at least do that. Yes. What's up Prince, have you set up your wazoo? I have taken it, it is a very good thing you are going Great, very nice, this is a very good thing I gave you a task, if you did it So that's a very good thing, it's good Congratulations and you are doing well Like I hope everyone completes it well With honesty and dedication, SoC Analyst L1 is a very easy person to be. If you, I'm giving you a guarantee. I have said before that if you Full 100% dedication and showed my honesty Neither in doing this training nor in what I say I have been following him And if you are eligible for the job, you have passed 12th. If you are from the same class, you will not be able to go and do a job. Like Elon, he is all about knowledge and skill. It would be great if you had such a skill. I will get it now and by the time I finish college You will become a master. Then there's nothing stopping you Can't even apply for a job. Your job Will follow behind. So for the school children She wasn't there, but she's in college, in her third year. Yes, in the final year, pre-final year, all these is in. So you will not get any L1 certificate before taking the job. The interviewer will also not be able to stop you. i you I guarantee this. of the interviewer You will have the answer to every question. After training. I will give it in writing I can. Because I am doing this training After finishing the interviews, some different I will run a series of videos. four or five or Two or three, it depends on that. I am specially here for your interview. I will prepare you how and in what way questions and I think that The interviewers are from L1 of SOC. who conducts interviews in India All the companies that interview me It seems they should change the pattern of interview. will have to do it after that because they It will seem that whoever is coming is watching the videos. Look, he is cracking the interview. Two people are being hired. over there Applications have come for 50 people and 50 others. The interview is getting cleared. How will this happen Brother? Now well, how would that be? What will happen then to whom inside the company? Will you hire me? Let's say for 50 interviews. Have come. 50 interviews DeFronix I have seen the sessions of SOC. and 50 have Absolutely every question has been answered correctly. Tell me how will they hire? And Hiring a team of only two people In. Right? So this possible eligible person will be me I say all 50 are eligible. Buddy. Let's assume all 50 of them are freshers. I am a college pass out. Tell me this. so too Maybe 100 people arrived. 50 people Pass out of college. Hiring just two or Three have to do it. 50 Do this. Then what will be? Stone Paper Scissors. Stone Paper Scissors. Yes, this is also correct. These The fist one is not like that Yes, we will use stone paper or teeth. You will cut such fingers in such a way that She cut it more by turning right and left there. will hire I think that will do it Yes, I am saying change them. They will have to have their own process for the interview. The question may be asked in a slightly different way. I think I might have to take it We will check CGPA, yes this is also there. First Yes, and you guys go for the interview. Be sure to tell that if someone asks for an interview If you go to give certification then you can do anything. Take. Do SOC from anywhere Certification. I don't care. Because as many Whatever certification you do, whatever is taught in it He will be taught less than here. I I will give it to you in writing. this thing too Write down somewhere that whatever you are in the world Get certified for SOC across India All Over World's Certifications SoC's I am talking about L1 as many as are available. I'm always talking when I'm talking about L1 for now because I Whatever I get done, whatever I get done, I will get done I will say I don't want to talk nonsense, okay? So whatever certification of L1 is related to it Do it and whatever is taught in it Less than what I'm doing here. If you stay, go somewhere and tell someone. Tell me and if there is more than this anywhere else So tell me, I will tell you everything that day I will remove the videos if you tell me to. Sir, please remove me from your videos. found it somewhere Ok Week in the series of Sir Bug Bunty Bhai Bug Bunty Please bring me a video, it's a request Videos of Bug Bunty will come brother, tension will come Don't take it, they will come soon in Bug Bunty, so much I have just uploaded the videos, friend, if only he If you complete it, you will become a master. You will go. We recently have a learner My name is Narendra. He was fined Rs 5000 Is. And you people say that Sir I am not able to complete it. many Many people have excuses. Sir, no gets. No bounty is given. Dude, you guys They come out from here, right? Think about how their It is happening. Something is happening. something about Will happen. Right? Narendra Modi Oh my friend Narendra Narendra There is a boy named Narendra or something else. Is it Narendra Patel or something like Narendra Modi? No Narendra Modi does not do bug bounties, brother. There is no need to do bug bouncing Ok Modi doesn't need bug bounties. to do All this is made for the poor, friend. All this bug Bunty, all this is done by poor people. as a means As we are, we do it. If we need money, we do it. Let's jokes apart, this is a big joke. Was. Please do not take this seriously and This should not be made an issue. Let's move forward Let's grow. So here is this action on objectives. So Do lateral movements. in one device Breaking in and destroying the entire network. End Ransomway Air Liya DOS Attack or DD Basically DDoS attacks launch. Meaning Ransomware attacks will latch on. Come on brother Encrypt all files. Encrypt important files. Lock it. Now brother, so many bitcoins, so many So many Ethereum or whatever cryptocurrency it is. Transfer it and then we will remove the lock. many cases I move away. Does not go away in many cases Is. In many cases they fool us. So There are multiple things right? there are multiple there are multiple things Sir, I will file a case against you. yes do it brother Do the case, hurry up friend, will you file the case? I will enjoy it if you do the case. At least the popularity will increase a little. If a person comes into it Come on, these seven phases Exploitation means that you You've delivered your payload there. on top of the system and you have run it By exploiting the capabilities of And you have already gained access to that system. yes. This is what happens in exploitation. Ok? That's it. Got it? This happens Exploitation. Let go Now here come the stages of cyber kill Some of the chains Activities that are ethical activities Let's understand the inside of ethical hacking. Let us do a little bit to give more clarity. You should get more clarity on this. one thing at a time It is very important. If you are thinking that there is nothing important in this, then this You have a big misunderstanding. and each and every thing Important means that it is important to you The little things that are yours The one that is the biggest It is going to become a weapon during the interview. In. So keep these things in mind You will miss small things now and then. You do not answer during the interview. Will find. You have to understand it. Ok? The first is recognition. Recognition Gathering Intel on the Target. I told you this. Ok? and ethical What is activity? passive and active Footprinting. In this we do passive or Do active footprinting. do this Are. The second is weaponization. Coupling an Exploit with a Back Door. Meaning We combine an exploit with a back door Are. create a weapon or We basically prepare the exploit. Creates payloads. Payload Crafting with Metasite or Cobalt Strike. We do this work. Delivery Sending the weapon to the victim. Whether he Be it via email, via USB, via the web through, anyhow we're fishing in it Simulation is an example of this. This is a Phishing simulations. Ok? Then our exploitation the boom Movement Triggering the Wanability. Now from him triggers vulnerability. Executing a Buffer in Exploitation Overflow and SQL injection. when we Execute SQL injection or vulnerabilities such as buffer overflows Let's execute. of exploitation It is a part. Installing in the installation Persistent Malware on the Victim's Assets or system setting up persistence shell and Root kits where when we victimize the system Root kits or we persistence shells which is They do the setup. Where we repeatedly The installation process is essential for getting access. C2 Command and Control Establishing a Remote channel for control. Remote control of a tunnel Let's take control through. He Tunnels Mostly There are secure tunnels. end system pay The control becomes ours. Configuring C2 Frameworks like Mythic and Havoc. This way The framework comes from C2 Frameworks. These Let's configure it. This client is a C2 There are frameworks. In a way that your victim They get installed on. gets configured Are. and command and control servers that Our attacker brother has a connection with them. They happen. and further whatever commands I have to do world runs, whatever I have to do All the things that you attack through this He does it. Then comes the action, the final goal. In which data is transferred, encryption It happens, destructions happen. all this Something happens. And what happens in it? Data Exfiltration Testing. Ok? In which the data was exfiltrated data is stolen, extracted It goes in different ways. And then this Our last step is done. The Main Thing Is this. So this particular whole thing There are seven steps, now these steps Even one of the steps, such as Take any one step successfully Was the attack mitigated or stopped there itself? If it is stopped then this entire cyber The kill chain fails and the attacker The attack stops. Weaponization of the Attacker be stopped, delivery stopped Let's stop exploitation, If the installation is stopped, run the command end The control should be stopped. So, here it is An attack fails. and companies to Basically this is what you have to do, it is very simple. Here But that's why I have written here that bye Breaking the Chain at Any Point, You Stop the Entire attack. At any point in this chain You broke it and stopped the entire attack. Gave. Age Association Analyst Your job is this You will also have to focus on the thing that you are doing in this chain. Break it down by any means you wish to yourself. Break L2 L3, take help from your seniors Take the help of a security engineer Get help from your manager or whatever. Whatever hierarchy you have to take, L1 L2 L3 Engineer Manager & CTO CEO Whatever But break it where it has left you this chain Break it there and you become a hero and there You successfully mitigated a major attack Is done. Let us now each one of us It is part of the chain, with examples Technics with and as a SoC you which The way you should approach him Also understand. Ok? Now if I wanted So I'm going to end the kill kill chain right here. I can. This is what the cyber kill chain is all about. framework I showed you everything Explain it. I can and this particular Topic Right Here and You Will Not Let You Will not be knowing that here beyond this something happens. I can do this. But As I told you, I told you That is why I say again and again that such a You won't find training anywhere else. Frequently That's why I focus. you you You must also feel like this, hey sir, is there only one You keep repeating the same thing again and again. then repeat Killing is my habit. Many people are my Getting troubled by the habit of repeating things Are. Right? Even in real life. But what do I should I? If it is a habit then you will have to bear it. So I repeat the truth. So in repeat here it is that again and again and again and again I explain things over and over again. The reason behind this is that I take it to a level I am getting it done at a different level. this is normal It's not like training. Live Training Which became some normal training. There is basically no such training on Detronics. It doesn't happen at all. as many as Difronix It's training, everyone is like this mostly. So you will have to understand this thing a little bit. You will have to take it sincerely. you took Sincerely, your life will be set. I I will look at you and you will go to that MLM which is multilevel marketing There are seminars and all these things that happen. You will see a person coming in it. He says he has seven cars. Rolls Ryce You have a BMW, not a Lamborghini. Lamborghini does not speak LMG A Lamborghini said something like this I said I said, it means I don't even know how to speak. Still they keep everything there, poor fellow But think how much motivation they give you and People also get motivated there. taking money They are here in different ways than you So even without taking money, if I give you such If I am giving you something then motivation should come within you. You need it. Right? Yes. Yes, let's see. Let's see. some posts I like it. It's fun live, isn't it? Yes, that's it I said friend. It's fun live. Yes, yes, those MLM people don't get anything. to do. Just add three people. How many classes are there going to be in the future? It depends on the course. Three The timeline is from 1 to 4 months. as many as Classes should be held and the entire course should be completed There will be that many people. Ok? So let me explain it to you and end it here. Could have done. But here I am and further sorry And I'm going to take you further so that You should understand this in a professional manner and Also professionally as a SoC Mindset helps you understand that age is SOC is how you should tackle it. So the first Ours is reconnaissance. The First One Is Reconnaissance. What happens here? Attacker Collects In About Target Without Touching It Directly. Mostly we call this passive Reconnaissance. Where the attacker is separated from the target There is no direct connectivity. We call it passive reconnaissance or passive infusion. They call it gathering or passive attack. and where You interact with a target We call it active recognition. This is called a reactive attack. Active Infection They say gathering. Remember this. Active Means see, connect it like this. Active means making connections. To connect. Passive means doing it from the side, from behind. Attacker's Mindset. Attacker mindset here What happens? Before attacking I must know Who What Were and How. Before attack. So Three Ws and One H 3WH WWWH. Ok? So Understand it like this. w w w You know this about the World Wide Web. And Then H Understood? Think of it like a World Wide Web hacker. It means who, what, where and how. it The attacker thinks. Now I'll give you some If real world examples are seen through it Let me explain finding employee emails. Finding employees' emails to prevent phishing And a separate campaign can be launched. Identifying Company Domains and Subdomains So that by using those domains or subdomains Exploiting the SPF record or Phishing through SPF records Emails can be crafted to match company mail By attacking end subdomains on behalf of Vulnerable subdomains or vulnerable databases details from where they can be exploited Finding Technologies Used Like WordPress is using Apache. IS is being used or which theme is being used Which language is being used? What is his version? so that we can see that that particular version or that particular Software is vulnerable to any particular From vanity or not. If it is venerable then Is it exploitable or not? is exploitable Then how to exploit them so that We can easily exploit the entry by exploiting it. Be able to do it. Studing Lindin profile. Lindine Profile Helps You A Lot. A Lindin From the profile you will get information about a particular employee. Much is known about the What are you working on, how are you working? Used to be. From the company's lindin profile that You can learn a lot about the company Is. What project is underway? Who are the people assigned to the project? Which one The person who is his employee works in which role? doing. And that will give you an idea. Which particular employee to target Is. Finding leaked passwords is very easy. There are many companies whose data branches are already Has happened. And the passwords were leaked. Are. There have been a lot of password breaches. And those passwords are used by many companies. Their employees use it. Bridged to the password. Now Google and Chrome etc. etc. You will receive notification of the bridged password. It also gives you the password if you enter it. But still many people think that it is easy to use. It is easy to memorize. then use it Are. Brother, what happens? who is coming Why run after us so much? So this is one of them There are examples. These are the things to find Let's try. Now which tools and techniques are included in these What is used? So enough of Google Docking. There are more use cases in Renosense. who is Lookups are done for websites etc. DNS enumeration for domains DNS enumeration of websites is done through You need to use DNS entries and DNS records. It turns out that the domain of that company has a What are records What are Cinem Records What is MX Records? Your TXT What are the different NS name servers? What is a record about? The address of the registrar reveals a lot. When does the domain buy and when does it buy How to setup domain with expiry date Everything that has been done becomes known. Ok? So these are very important factors. Now I told you that whenever I I give you classes so that you can understand things. I have to explore it myself. Ok? Without If you move ahead then it will be dangerous. I am telling you in advance. So what now Want to explore? Some people were asking, Sir. What to explore? means which Do you want to do the topic? So I told you already that whenever any important topic You can see me when I am doing it. speaking Am. That's just me saying it. Just Write It Down Somewhere or When Watching Recordings So you point it out, write the point. Like Google Docs for many people. Google Docking May Be a New Thing for Many People For it's already an old technique or known techniques that are used by many people who Don't know what Google Docking is? No friend, one Google Pay Google Docking what Is Google Docs Chat GPT on Google Write about docking and search for it. take a little infusion about I don't He is saying that go deep into it. Go get confused Google Google Docking Itself who is looking up itself can be a Very broad topic in which you can say a lot can learn. But you don't have to enter that much. Is. You Don't Have to Master Google Docking And who is looking up right now for the time being in if Hum SoC Perception If you bring it then don't master it now but We have to keep knowledge of that. That's it. So its Do a little search about it. DNS enumeration How does it happen? Search about it do it. and Oceant Open Source Intelligence There is also a use case. Search about it do it. If you want to read about Osent Live on our Defonus Academy YouTube channel Go to the section or playlist. There's a whole playlist of Ocean there. Learn Ocent for free. Now from this What more can you do? If Structured Very In Depth Learning If it has to be taken then we have a training program. DCCI's Defronic Certified Cyber Crime Investigator including Cyber Crime Investigation and Its a Different At the level you will find many things in a structured way. It is taught deeply. So if you get paid Interested in training and mentorship Together you can come to DCCI. In DCCI When, how, what is to come, when will the next batch start For that, when you visit our website Will go to the top number one on defense.com It is written. Simply send a message to that number. Have to put it in. Whatever your query is, sir Regarding when will the DCCI batch arrive? Information has to be given. It may be possible for you Waiting to be added to the group in the list because the waiting list is always in it People keep getting added for the next batch And when any announcement comes, you have to wait. You will be known in the listed group You can come and join after the announcement. Ok? If You want to go for the paid training then Of course you will come. Yes, here now What is the defensive view of the SOC? This As a SoC in a particular scenario, your What could be the defensive view? who are you How to look at this particular reconnaissance You will monitor the attack extensively. For DNS queries, if any of your There is a guy speaking on top of the system server. Raha Hai DCCI ka full form Defronic Certified Cyber Crime Investigator Yash Tomar is saying DCCI is the best Training Thank you Yash If you liked DCCI, you would It is obvious that he has been a part of DCCI That's why you said it, so thank you very much. for that Okay, look, we're here for anything. He doesn't speak. Direct students themselves We need to know about that particular thing. Give a review. Maybe someone was just In DCCI here, Yash is named after him. Is saying DCCI is the best training Because that's what you get. It gets like that So there's a job at Difronix. I will get it brother You will get a job. Will get it soon. Too much You will get more. jobs at defronix The hiring spree will come after some time. where we will be hiring a lot then you People will definitely be informed and All our previous students They will get the first chance among the batches if If someone from them is interested We don't follow any educational qualification Ah ah a mark that this should be that should be Needed We don't follow any prejudiced one Only if you approach this way will you Job will be given. We Simply Believe In Skills Pure Skills. If you are in 12th class also has children if you have skills and You want to do a job. And if someone really wants to work and their families are totally Okay with that then we are also okay with that. So now when this happens you will absolutely Don't worry. You will be informed about It. Ok. Ok. So So as an associate analyst you Monitor accessive DNS queries That there are too many DNS queries. So something is wrong brother. there is something That should be noticed. Track scanning behavior. You are running the scanner, scanning If yes, then monitor his behavior so that Some Different Kind of Things You Are Getting Something different, something strange, something you are getting Yes, if you feel something is strange then you Will notice. Watch Unusual Ocean Based Fishing Patterns. Ocean based if any Fishing patterns you find over and over again. On a particular pattern, you If you are getting phishing attempts then you can You will notice it as a SoC and you Will try to mitigate. As a L1 If you can, you should definitely do it Solve it yourself. And if it cannot be It seems more complex and If you are facing any problem then you can It is good practice to give it to L2. Please escalate it. escalation that occurs She doesn't show your weakness there. When you are working in a SoC environment If you are with a team then escalation means your There is no weakness. It is a professionalism Which makes you more professional. If you are confused, let's say So you're not a god right? you are not a Master and you're not an you don't you don't know Everything about some topics. nobody Knows. Right? Someone about every topic nobody know. Maybe better than you There are other people who know more than you. My There are many people who know more than this. So Nobody can be an expert in a particular Thing or go to the top. So you escalate We do. So you have professionalism there. Let's show that yes, I cannot tackle this. I am getting it. So please do it fast. So that We Can Make a Safer Network Ah In Infrastructure for This Company and We Can Secure the company. Right? So this age Associate his view is in terms of In which? In Reconnaissance. Now we weaponize Let's talk about. So what happens in this? Attacker prepares a payload plus exploit. The attacker can then send a payload from an exploit here. Generates in weaponization. Right? Yes. SOC Is All About Teamwork. At once You are absolutely right. SoC Adi is saying had taken the batch of DCGSP I have. Sir, I got a lot of help. what's the matter Is. This is a very good thing. Etcetera It’s fun. When one of you students Yes, you are a learner and when he reviews without asking They give it in such chats publicly, right? So a different kind of confidence build up It happens. It happens to me especially. And it feels like we have done something. means something We have torn apart cybersecurity meaning The good one. Which no one has been able to do yet. Right? That's what DeFronix did and can do. Has been. i you Let me tell you one thing. in cyber security Right now in today's time, mostly institutes Whoever is yours, whom you know. whichever You also have favorite institutes which you You know, whatever it is, I'm telling you. Everything you know is a fake We do. Ok? Now you will think, hey sir You told everyone. Yes, I told everyone Is. I have told each one of them. In the type of company They are running it, they are all doing fraud. Are. fooling all the students Are. They are driving me crazy. their money wasted Are doing. In terms of giving knowledge and Skills. One-year diploma course Taking lakhs of rupees and wasting his money, You are wasting time. And people are Getting scammed. Because they had hope Is. They have a hope that I will be here You will get something to learn from it. This to parents I think my child my child skills He will gain. My child will come back having learnt something. Better in Cyber Security Will do. How does she know that her child's Money is being lost. Her own career being drowned and their money being drowned Have been. So until later I realize By then he would have drowned. And this is what I I speak because I have a lot Of experience regarding this. a lot of Students have reached out to us. and their I felt a little strange after listening to these things. It so happens that there are many who, Sir, are mine There was a scam here. Had given ₹00. Nothing Learned. Imagine you get a message from such a student. That Sir, I gave you ₹00 to learn ethical hacking. For. I didn't learn anything there for ₹00 And your DCGSP of 2499 which I took There was a recorded course in which there was more than I have learnt it. Imagine the difference. I DCGSP is not promoting here That our recorded course is ours. I'm not doing promotion kind of thing. Of a thing, but I will tell you the facts. I will keep saying it till the last moment. Whether you feel like a promotion or anything else, Don't care at all so DCGSP 2499 has a By taking the course, someone can earn money from a course of Rs 300. He is comparing and he is saying that I've got more here then you think. Whether we actually give it or not Yes, we just tell you that we If I am saying this here then that is the difference Between a Between Us and Others and then There are a lot of people behind us. Are. Many people have problems. I know. Now I Can't Name Everybody Because you can't take it on YouTube at all. Are. Or else Technical Navigator if needed There are videos on our YouTube channel as well. I will bring it because there are videos on that anyway. I don't know. So I'm thinking of a video like this I should definitely bring it so that people can understand. That everybody is knowing. When they post about scam on Lindin, about companies that have children when If you post on Lindin then those companies Forcefully deletes those posts By threatening. Yes, don't put it in, otherwise The career is ruined. She does this and that. When she posts such a post. Now look at the threat and Those two things are correct. any problem Not there. But two for something authentic. No. If something is being done against you. If you're doing it right, someone else is doing it. If you have it then give it. But you yourself are doing wrong. Above You are being threatened by. So this is wrong No. It is a wrong practice. It's a wrong Practice. Right? That's What Has Been Done by a lot of institutes in India and Cyber security should be made the base Used tobe. Ok? Will put. Don't worry. Quickly over it Will bring the video. Let us now come to weaponization. now here Focus on it. Now get out of the chat, friend. You People spend a lot of time chatting, man. You guys pass your time here in chatting. Do you. I saw it in the chat You guys talk, man. I am sure 100% that your guys have girlfriends etc. Not there. That's when you guys get to chat here. It must be fun. Rakesh Kumar Rakesh Kumar Shah has said This organization is scam sir I did it He manipulated me, he definitely did. So it is a complete scam, it is a complete scam. So we also posted about his scam. I'm on the channel. They do a complete scam Don't get personal, sir, I will go. personal He is saying don't get personal sir ji, definitely He will offend only if he doesn't have a girlfriend. It's happening, it's okay, friend Girlfriend is not everything, focus on your Career and Skills Ok Let us go What happens in weaponization? Prepares a Payload and Exploits Means Using Payload Exploit One means prepares what the payload is What Runs After the Exploit? The next run is the payload. What is Exploit? How Vulnerability is Look at abused, there is a simple funda Software is developed, a developer develops Does the software. develop the software At the time of doing it, let's suppose someone By mistake a small bug remained in his goes. That bug is widely attacked by They find it and exploit it. Let me write it down. Unless this bug is that particular to the software developer or that particular To the development team or to the company What we call that particular vendor That zero day vulnerability is not known It is called a zero day exploit. Whatever is exploited and when that By using the flexibility that the code A piece of code is written in which that Used it according to its availability Goes to Target Any System We call that exploit. and when The file that is sent to the target The execution that is done, the thing for which That is the payload. Payload only connectivity Makes exploits easier to execute After from your attacker. So, what is the example? Is? Malware Embedded in a PDF. PDF There is a malware embedded in it. that is a Kind of exam example of weaponization. Reverse Shell Hidden in Word Mac. World's The reverse shell is hidden in macros. On this There are different exploits available. You See Can. Exploits for an unpatched Service. Any service that is unpatched. It hasn't been patched yet. For him Exploit is also an example of this. attacker What happens in the mind? I have info. Now I build a weapon. I have an info Is. I have ination. I have my Everything is there. What do you have? Are? These The thing is the same that I have the information. I will build a weapon. If this is what I want, I will make a weapon. of SoC What is the perspective brother? So the SOC The poor guy's perspective is that the file should be sent to Kesh. Will do the analysis. I look at the dude SOC a lot It's a big role, friend. I have had SoC many times It is very sad that the SOC people who There are people who do a lot of things. Very Some very full security posture on them The responsibility is to set up the network Of security posture. Right? yes this There are examples. Sweet 32 Nafeez these you guys I am giving examples. It's a good thing. You People know the example and cry all this Of. That's great. That's absolutely correct. of all scammers It is about to close. That will definitely happen. Surely it will happen. Just now on my Distronix at the time 1 The lakhribar mark will be completed in which Time should also reach 1 lakh crore mark. After that there will be so many explosions that You might not have ever imagined it, meaning it is full Time will keep on blasting, only you guys on that 1 Take it up to lakhs, share it over and send it here and there Do what is in your power Then you see what happens after that. 500000 is going to be 1 lakh anyway By the time this happens, there will be so many classes. They will be gone and then more such things will come after that that Distronix will become a cyber hub Security Hub for you where you will come and You will learn and go somewhere else. There will be no need for a scam to happen. What the SoC will do is analyze the hash of the file. Checks if there is a mismatch in the hash The correct hash is perfect, the hash that was created is the same. Hash Hai Original Hash Hai Malus Sand Boxing It will make a mess, meaning it will be sandboxed. Separate Environments in an Environment By executing it in the environment Check out Karega and Non Exploit Will detect signatures. Any Exploit signatures for each exploit, such as A signature is a database. where if Create a database of any non-exploitable If it has happened then it will match the signatures in it. That brother, this is not the same person. If by chance That's not the thing. So these things will do the edge SOC. Now comes the delivery. what happens Here? Weapons are delivered to the victim. Now deliver the weapon you created. It will be given to the victim. How? phishing email through, through malicious attachments, Malaysian Drive By Drive By website USB for downloads etc. Drop USB via compromised aids or There has been an AIDS compromise. AIDS also Compromises happen. Through him. Now You will see that this is an ad and it is doing well. Is. But that would be a compromise ad. from there You did it and went from there. it would have been like this Is. So don't do this turn-term work. You have it. So whenever you do something on the internet So first examine it thoroughly, understand it. Investigate and then execute. Otherwise you will face a big problem. This should also be your motive for Edge SoC. That the main motive of SOC should be the main mindset Needed whatever there is First Investigate Deeply Then Create The Report any alert that comes According and then whatever is yours Follow whatever process is next. This is a complete system. Now the example In Human Resources HR Receive a Resume pdf.exec via email. Now double here The extension is a matter of whether pdf.exe to Bypass something. And here you can see It is believed that this is a malware bound file. Now If this is executed, then a Malware, which is a Trojan, is executed It will go to the victim's system. SoC What is the Controls SOC? Email Gateway Filtering. Email gateway filtering Can be applied. Increasing URL reputation URL reputation will be increased so that Malaysian Attempts could not be made. Attachment Sand Boxing means attachments that are open when If done, he should be given a sand box Environment is different and separate should be opened in the environment so that that Do not infect other systems or networks Can do it only in a contained environment Executable and testable This was delivery. Now what comes is Exploitation. What happens here? The Viability is actually triggered. In this Vulnerability is actually triggered is or is executed. Such as User clicked on the link triggered Went. Software buffer overflow triggered. Triggered by exploits from outdated plugins It's done. Mac execution triggered. So these are the different trigger methods. As Any particular vulnerability It has to be triggered through exploit. So He would have exploited you in this. Is. Now here's a concept that no Exploitation is equal to no Compromise. If a system exploit If it has not happened then it is not a compromise. will be. That is not compromised. thats It. It's a simple funda. Ok? and SoC Teams try to break the chain here. Now here Pay SOC teams try to chain To brake. Because here if the chain Once the break is over, all the remaining further attacks Or the rest of the attacks are useless. Will go. He will no longer have any role. their There will be nothing left. So the SoC's here The main work is done on this chain right here. Put a break. Exploitation is the Step Where Associate Teams Try There Best to break the chain and here so that he The chain should break and that particular It is an attack, it should stop. That's it. Right? Correct. So here's a just Yes Correct Absolutely Right Pitambar Pitambar has given you the information about email gateway here. Some examples are given, you can see here Email gateways or email security tools as if ok practical when will you conduct the practical There will be no practical brother, you should stay in the class. Leave two, practical, not practical will be Don't run after practicals, friend. are you Friends, I have already said it, but still Looks like you're new here. Let us go So the SOC teams are there to break this chain. She tries to do it. That's the main thing. What does the SOC team do? break this chain Will do. She will try it somehow. Now comes Installation after exploitation. Installation Key What Happens Here malware that is malware that is installed Persistence is the exploits whose Persistence is what you're doing through things. Installation means persistence It means even if the system restarts. I stay even if the system restarts I will remain there, I am everywhere And I will remain in it in an unbroken form. It is a thing, it means it is okay, where is it? I am everywhere, I am all around and all around The one on the side is and I'm always there. So The persistence is the same. What is the technique? Registry Run Keys Through Registries It should be run repeatedly on startup. This should be done through scheduled tasks. Run This should be done through the startup folders. Back door should be done through users. Any Backdoor user has been created. through him This persistence should be created again and again. be done with a time delay that a time Automatic revert to execution after yes. by entering it into the registry Repeated execution or schedule The task should be done through it or Startup through startup folders This should be done through programmes. Depend Does. What is the focus of the SOC? End Point Detection Response (EDR) here It is used. Basically through EDR An attempt is made to detect. Different changes inside the registry or Different types of registry Malaysian changes or some of the changes that Create doubt within you. that type Changes are monitored. End Auto Run Analysis When Auto Run Exactly or in Startup Programs What is there? Auto Run What Things Is it happening the right way? That too on all Monitoring is done to ensure that auto-run is not happening yes. Everything should run on auto run now. Some of the startup programs Unidentified startup applications or There may be no software or any files. This the kinds of things you have to monitor As a SoC. Now that I'm talking about command and control So a little bit on command and control Extra Focusing Is Variant Because It devours Extra Focus This is the life cycle of command and control. There is a total of five hierarchies here. Five The way I explained it to you here Is. This is the entire command and control There is hierarchy. So the first one is first In command control, that is the initial There is a compromise. like different kinds Have used the technique of. phishing email, Explain that whatever technique you use, you Let's make an initial compromise. yes goes. Then malware gets installed Are. Meaning whoever your victim is On top of that, you have installed malware or Trojans. Whatever I did to you, that particular thing of yours will continue the session that is on your system Will give you access to. Then C2 Channel It gets established. That is, a C2 A connection is made which is a two-way channel. It happens to connect the attacker to that system For. Then commands are issued. Then remotely whatever is there, commands are there It is executed by the hacker On a particular system. and then data Exploitation or lateral movement occurs. Or then from one system to another It enters. either if it is not something If lateral movement is not possible then the same whatever data needs to be extracted from the system or whatever You need to fetch files or any data. is done. This is a complete CNC There is a process. Then there is command and control. This which The step is of command control, so now in that Let's see exactly how this way What happens? So compromised systems What happens? Compromise Systems Talks to attacker server. Whatever compromise There are systems that talk to the attackers' systems. We do. That's it. from the attacker's system Let's interact. communicating to him Are. What is an example? Beckoning Every 60 Seconds DNS Tunneling STDPS Base C2. So there are different types of communication Which can be compromised by the attacker's system in different ways. There may be a conversation. Ok? Now a way This can happen in which the victim's system is that system every few times But every few time intervals, there is a The message is going. a particular Connectivity message particular request Particular connectivity is being done is above each time interval. So that Basically when this happens then there is a problem of persistence. It happens through and that persistence happens. Needed Otherwise this is not possible. dirt When executed, a particular Those things are getting executed at fixed time Is. So that could be any time. Here 60 seconds 1 minute 2 minutes whatever time Decide what is decided is decided by the attacker it It is possible. Ok? DNS Turning Turning Through DNS Is a Different Concept. Now, as this is an important You got the topic. a little bit above it You can do the research. You can a little Bit of Research You Can Do. So DNS It happens through tunneling. That is, DNS means Domain Name System where Resolve your host name or domain It is in IP addresses. So there is a tunnel in it By creating a tunnel through it and tunneling through her Using the resolving feature from within Basically now I am taking it very deep If I go, you will get confused. It will take. And we use the rolling feature Have you used your DNS cache or Use whatever feature that DNS offers By doing this we connect. The attacker who is Connects with that particular victim. Meaning the victim opened something here and something there From the attacker's website IP address resolved and there it was DNA connects to the attacker's server Sterling basically means something like this What happened is that you opened As a Victim, there's something else. domain and you are actually on some other domain Transferred back end to another domain You access means you access the front end which are similar in appearance You think it is available, but it is the attacker's Attacker Controlled Domain in Control You open the domain and then open something else. but you open attracker control domain then that Its through https base c2 which is a little bit Supports end-to-end encryption Attackers have also become very clever. End Here the attackers are using secure tunnels. Use it to connect with the victim. What will come out in SOC detection, brother? Abnormal outbound traffic means traffic from outside Some abnormalities from your network on the side Traffic will go. Outbound firewall rules I told you. It was also shown last in the previous probably previous videos. It was told that there is an outbound rule Farewell has an inbound rule. So when Outbound traffic is moving in an abnormal manner If it is, you have to monitor it. That will come under detection in SOC. Beckoning Patterns on which pattern which particular is yours Communication is happening, let's assume each one Pattern means that every few time frames Communication is happening every time frame Some things like your data packets I am travelling and execution is taking place. All that is a pattern that you will monitor. Non-bad IPS or domains such non-IPS or You should have a list of domains You must have a database Where there are bad IP addresses and domains which They are used for malicious purposes. Where the CNC is setup is mostly C2 The setup is mostly done. Their list It should be so that if you buy such an eyepiece If you detect it, you will understand that this is an attacker. It could be the IP of someone else or the IP of a hacker. Might be possible. Ok? Now let's get to the action Objective which is your I think last last will be. Ok? Action on Objectives. These What happens in this? attacker does what they Come for what you came for, do the same thing. Are. What do attackers do? stealing data Are. Deploys ransomware. Credentials, User Passwords, All of these Let's deploy. Lateral Movement Network They keep moving from device to device inside. No work gets done. financial fraud Meaning, he commits some finance related fraud. so that a company can have these important financial The condition can be disrupted. company's Whatever your financial condition is problems can be brought to light so that they disrupt less Tax the company's operations. So this is a Financial fraud also occurs. So right here The maximum damage is caused by Action is on objectives where The exact damage is done to you that company or that particular network In infrastructure. I think even It must have become clear to everyone. tell me Please let me know everybody. As many people as there are Present here, clear to all of you. Happened? Please let me know. Ok. Tell me whether it is clear or not. Is everything clear? Great. It's a good thing. Is it clear then? Good. Ok. Thank you brother. Love you too. Thanks Nisha. This was the best explanation of the cyber kill chain. Thank you. Ok Manish. Explain lateral movement. hey told me So friend, lateral movement. Inside a network When you walk in and there's zero trust It has not been applied and you enter the edge attacker inside a system inside a device And you are trusted by the network. By verifying that you are a trusted user If you are an authenticated user, then you can connect to the same network. All the other devices inside You are also travelling, which means you are entering into that as well. You are executing that too inside him You are going to compromise on that too. You are going from one system to multiple systems Moving forward while compromising yes No one explains this much, sir. Thank you You Himanshu. Best class. Thank you brother. What does credential dumping mean? Sujoe. Credentials dumping means a Credentials means any kind of Sensitive login details Or Any data that is sensitive, such as What does credit card credentials mean? Credit card number and its CVV These credentials have expired and you have logged in. Usernames, Passwords, OTPs in the sense of Once the credentials are in place, this is what happens. credentials so dumping them means their It's okay to get information Sir, are you watching the T20 World Cup? I will take it whenever there is an India match. I will see something more special for me. There is no interest Pakistan may have already refused. Is he on 15th to play against India or does he know No, when is Pakistan of India, maybe it came I don't know whether Pakistan will exist or not. Refused to play against India They know they will lose because right now India's T20 team is very dangerous. So that Because of that fear, I am thinking of giving up playing. Don't. I have found a good excuse. But it's okay, friend. From the second time, explanation learns a Lot. Thanks brother. We It's good that you came to my channel first. I was saved from being scammed, yes absolutely correct. The thing is, you're completely saved. Sir, let us go to eat, the mess will be closed. Go ahead, friend, keep it running on your mobile. Have dinner, who can stop you from having dinner? I can stop you from eating food. it's wrong Nawaz Ali Sheikh Sir I am from Pakistan. Hey brother But big fan thank you Nawaz. like you We would also love it if you were Pakistani. Is. But there are some people from Pakistan who Very foolish and He talks like an illiterate person. But many such I have students from Pakistan who are very Smart and well spoken And still stay connected with us. and they Learn from us. So I welcome all those kind Of people. I don't have any problem with people. There is a problem with everything else. Let go. soy You should learn well Nawaz. I hope that you Well, you must be feeling good. from good You will learn well. Ok. If access is gained via and exploit but No Persistence Is Established and the The defense team blocks it, why is it the attackers? Access Lost. This is a simple idea, isn't it? You are this system, right? You have installed the system I compromised. When you do any such thing If there is a situation then you can compare it to real life. Join together. Your answer will become easy. You You will answer this yourself. Real Life how to connect to that if you want to connect a system You attack as a hacker. You have his You have received access and if you If persistence is not established then now Suppose that particular exploit or That file or payload is removed from the system. being given. is being deleted or reformat sorry the format is being changed or after rebooting the system If the file is not working then the connection may be lost. Will go. But if there is persistence then it will happen when Also the system will reboot or whatever there is will be that particular exploit or The file will be executed again. Startup through the registry through the Startup Programs folder Get through by copying one of the services His execution should be done through window service Startup through services different kind of things then that Will keep coming again and again, that's the difference Thanks Nawaz. Thank you very much brother. Yes, I will tell you about it Prince. I'll make this a deal with four alerts about. Ok? So that clarity comes. I will tell you. I will tell you in some detail In. Isn't it? Key logger and payload Please explain. Hey Key Logger and Payload Look, the payload is something that you're delivering. Two Victims Which is executed through end connection attacker The process of compromise He completes it. And Key Logger Is Kind of part of that payload. it can be a Part of the payload that is further processed by you Any actions performed within the payload He will go through the attacker and help him in that. Will do. That key logger will do his work. As Suppose there is a remote access Trojan R AT is Rat. The lodger inside her is a There may be functionality. where the key logs Which is basically whatever keys you stroke Yes, they should be locked. that can be a Functionality. Key Logging is Just a Concept Is. Where the keys should be locked. Bus That's it and nothing else. I started with DCGSP DEHE bug Bunty and now Soc. Thank you sir for Getting such a wonderful class to all. Wow Great. That's very good, Ashwin. you have A complete hierarchy has been followed. DCGSP, D, EACHIE BUG BUNTY AND SOC And absolutely correct. Ashish has written that if Has any of you completed this? The way you have enrolled a DCGSP I agree that the basics are clear but I don't know anything. Everything is clear here, I have seen the EJPT level. That content is being given for free there It is already given that many things are bugs I watched Bunty's series on web pen testing. You have got it in abundance there. Those are the top 10 covered and SOC cars If you take it then the job is complete, friend, it's all yours. That's it you're all completed and sorted It. I get the notes anyway, brother. You will get notes What? If you are asking this, you are asking the wrong question. Because you are definitely not in the WhatsApp group yes. Join the WhatsApp group. Notes Everyone meets there. Whatever I am here for I am showing you that PDF on PPT. You get it in the format. But I will give you I have already warned you that you can only do this Don't depend on PPT and PDF. Any time in the future maybe I'll give you I should stop giving PDF and PPT as a Notes. Then you will say, Sir, please give me the notes. Two. Then you will come here and bother me. They You don't have to do it. You should make your own notes Is. Dependency has to be maintained on that only. on the same Have to have faith. My Notes and PDFs I don't have to trust that I will give it. Give. Anytime your mind wanders, take notes. I will stop giving it. Then your own There should be notes. I will do that so That your notes should also be made. Note-P Ye I don't want to do any spoon feeding. Mix it like this in a spoon, put the spoon in your mouth I fed you, I gave you drink and Made it skillful. Doesn't happen like this. by myself Have to do it too. Ok. What's up friend? There are a lot of people here Dude dude. I Started with Oscent Free Course DHE Bug Bunty Now Soc. Thank you. Welcome brother. What is the matter. I also Started with DCGSP, DCCI bug Bunty and now in DCAPT. Yes Pitamber. I have remembered Pitambar's name. only Is one of our one of from our batch. And I Hope you love those trainings and all. Let go It's a good thing. Sir I want to conduct webinar sessions for Cyber Security Awareness. How Do I Get Started? The University Then University I can give physical sessions on behalf of. Directly to Cyber Security I can contribute. This is a webinar Have to conduct. So simply you ah first so Establish your online presence Do it. End from any social media Then the audience will come to you. OtherWise Audience It is not going to come. And then when in the audience If you gain confidence, people will know you. You can approach your college To universities that I want to do this Yes, I have to try this. And if they think that You are fit. You are a good person to go to then give Will surely welcome you as a speaker. So there are many of my students who today Such security talks and seminars We still conduct webinars today. End I would like to see such people leave. go deliver it there so that a little You guys should also make DeFronis famous. Also through. So here you understand that you can take action on it. Objectives. Now comes the standard Over hacking methodologies. This which so far You were watching, this is the whole Cyber Kitchen. There was something. How and in what ways in Cyber Kitchen It makes things happen and operates. Now Here are the standard hacking methodologies What happens? Now it's 119 people, friend. Tell me friend, there are still some things left. Now! So now this standard has to be implemented in cyber security. What are hacking methodologies? In this Comes your reconnaissance, scanning, gaining Access, Maintaining Access and Clearing Tracks. This is our standard hacking There is a methodology by which hackers When I mentioned earlier in the beginning To you Cyber kill chain was told in the beginning describes the life cycle of the attacker and Hacking methodology is what it is Practical execution flow which attacker Practical execution flow of Shows it to him. So the attacker's practical What are execution flows? that this Falls in five main steps. First Reconnaissance Inauguration Gathering. Second scanning The systems have to be scanned. Venerable Finding service ports. Gaining Actual entry into the access system To compromise. Maintaining Access Creating and Clearing Persistence Tracks. whatever your logs are or whatever your also have an establishment or whatever of your own there Remove any digital footprints Do it with that system so that whatever is there catches you Don't go and keep your traces away. It can be done and cannot be reached to you. These Generally attackers do it. Now as a hacker you If you get caught then it will be a bit difficult. Actually no one is fully secure. No One is fully a Like you can say that fully you keep yourself safe Can you protect yourself from any particular doxing or Any particular reverse image you are doxing Or whatever it is, it is not the right thing. It's not true. Any Hacker in This World Can Be Traded Down And none of the methods can make you escape out of That is not possible. But still, save as much as you can. We can save ourselves. Right? as much as possible to save Will be saved. Just as a thief steals something It doesn't leave any holes or evidence. No. Similarly, when even a big hacker If you do hacking then you will get something or the other. It goes against those who digitally Tracks can be traced back. Ok? So security is just an I already know this is an illusion. But clearing tracks 100% is also an Illusion or anonymity is also an Illusion. Remember this also. Let's go here There are standard methodologies. Now I give you Explains a little difference between the two Am. See When I talk about Cyber Kitchen or I Let's talk about standard hacking methodologies of. Both will look almost similar to you. But in both There is a lot of difference. Your cyber kill chain End hacking tells the perception of the attacker Methodology describes its practical flow Is. There is a difference between these two. Cyber Kill Reconnaissance takes place in the chain. In this also Reconnaissance happens. Both beans are at this place Is. In this we call it weaponization. In this It is called preparation for exploit. Work one It is there. Delivery takes place in it. In this Payload delivery is almost the same. In this we Exploitation does. In this we access We gain. This is also almost the same. In it we do the installation. In this Maintaining access. Maintain Access We do. Here C2 is setup. Here through persistence we basically Let's take control. That also means in the back end Everything is beans. Everything in the back end is beans Is. But the use cases are quite different. One The practical one is your perception. Went. A complete work flow that Done. The attacker had a journey and this Its practical implementation has taken place. And these actions post exploitation in this. So here's an overview of what both of them mean. I have prepared a chat for you so that You can get a little idea about the exact What are both the things? That's all I did for you created so that both are Everything in the background in a similar back end Things are going the same. But one who is one The flow describes the attacker's life cycle and Second, its practical exploitation The practical process of it Defines it. If it is between the two If someone asks you what are the two different things? Are? How are you? So he can tell you this thing in a manner. That's it. Amazing content. Thank you brother. Thank you very much. Ajay Devgn in Drishyam Is. Yes, that's right. Perfection is much Correct. Just skills matter. Sir, never stop This course. Your teaching method is excellent. Yes, okay. Thank you. not doing. Sorry sir, I am leaving tomorrow for sure. I will take the video because I am attending a function now. I am going to do it. So sorry sir, it's okay Go, it's fine, go, no problem, function Is variant now let's come here Watch Virat Kohli Virat Kohli Virat Kohli Do you know how he became Kohli? Other players will also try to Why couldn't he become Virat Kohli? Sachin Tendulkar type people because Virat Kohli was Virat Kohli, Sachin Tendulkar was Sachin He was Tendulkar, so he became Kohli. Became a tendulka. Why? Many more There are stories, there are things. I don't know what What is true, what is false. But if even 1% Is it also true or is even one story true? So Now, it is a very important thing that someone belongs to someone. and still He is devoted to cricket. Living All Dozent things. Bigger than cricket Could have been for him or would be. Right? so that's it People become Virat Kohli again. then after People cry in me. I am going Virat I am not Kohli. This is how it happens, isn't it me? So he could not play like Virat Kohli or If I could not become Virat Kohli, brother How will you become Vilat Kohli when you are Virat Kohli? If you do not have these symptoms then associate How will you become an analyst, you don't even have the symptoms So I have to go to the function, oh you know The function stops meaning the function does not go away. Will it stop, brother? If it stops, then go. It's amazing brother what is the function This is this, that is, I don't know what will happen. well Let's go. I won't comment much On this. Everyone has their own personal choice. Let go. Hey friend, tell me one thing. my my friend's The wedding invitation had arrived. to me first Had to go there. I couldn't go into that. I am sitting here in front of you all. Well friend, think about it, it was for me too. Brother, I can go too, the rest There are other events on dates like marriage. except We go there too, we are good friends It is from one week 10 days ago but I know If this gets disrupted then where will I be? I went but you guys have to go, go go eat sweets Meaning two or four paneer, two or four puris and two or four People go there to enjoy the free fun. Okay, leave this thing. Come on sir, you are the real Virat Kohli. I I am not Virat Kohli brother. I am Nitesh Singh Am. I don't even want to become Virat Kohli. I Nitesh Singh is fine. In itself Best. Let's go here to alert reporting. Now we come to our next On the topic called Alert Reporting. In the previous session, we We alerted I read about Troy. did you read it Brother, tell me once. When did I say, oh no friend, I will not get you roasted. Hey Roshan Kumar, don't send these flowers and leaves brother If not in the comments I will do that and I will time you out. I taught you about the alert track. I have alerted you now that the track is complete. After Trag means after Alert sorry We looked at both Alert and Alert Track. Now whatever happens after that, you will be reporting Also have to be done. After reporting There is also escalation and then communication. it occurs. There are three things. Ok? We He'll see a little bit of all three things. There are three things that should be Understood. The first is reporting, Alert, trag, alert, alert. Look like this It happens. I'll give you a little overview Am. An alert occurs. Then you try. You do the reporting. Give you Do escalation. Then Aap Communication We do. Something in this flow, this is your flow It is made. Ok? Best Teacher Love From Bangladesh Love From India Brother Ok Flow flow is correct, absolutely correct, great It's a good thing. Thanks. This is a simple geric flow. I am very Jerry, look, I'm teaching you all the things In the Jeric Way with the Jeric Flow I am telling you. I'm too deep, too much I am not going in a complex way at all. Also so that you can understand. So basically This is a flow created in which first of all a An alert occurs. Dan tracks him down. Dues are reported. than escalation It happens. Giving is communication. So this We have to understand the flow. So we first See the alert and trigger flow I had already taken it. Now who we are today Reporting Escalation and Communication Co We will see. Along with this, our alert The existing funda will end. Alert Things will end. Right? So when If an alert comes, we try it. Let's see. Meaning that is true positive Or a false positive. Ok? All these things we Let's do a little bit of major. Two more Joe Alerts We will see later what that is. These Let's track. Dena after that when track If you go, you have to write a report. Is. A documentation has to be made. End On that basis, you can then escalate and There is communication. Escalation needed If it happens, you will escalate. communication key If needed, communication takes place. These All things happen. Now the alerts come On reporting of. Okay, let's go. So What is alert reporting? Alert Reporting is the process of formally Documenting. This is called documentation Are. Like you guys report in Bug Bounty You write the same thing, this is some trick. Is. You have to create a report here. One Documentation has to be done. what was detected, what was analyzed, what Conclusion Was Reached, What Action Was Taken and recommended. In this you basically Do you remember the five Ws you read? To? Five Ws? Do you remember guys? The Five Ws We Had Learned About in Previous Sessions Tell me, do you remember Kitty? Tell me the 5 Ws, tell me quickly. Brother, what happened to the Five Ws, man, what? when h Ware Y was this yes let's one wrote Mr. robot is a very good thing the hamja good good etc. good cyber nukes great Darshan is Darshan ok good Prince ok The Great Prince Prince Gokhale A OK Ok Okay, that's a good thing, sorry, so these five WS has to be answered that When you report in reporting If you do documentation, then this is your effort. It should be noted that your report is There is documentation in it, those five Ws You should get the answer to five Ws like What When Were h Why should I get the answer to this if I get this answer He is going to be perfect in your reporting. Reporting will be called that reporting doesn't Need Anything Else That's Just Perfect Reporting If It's Not Documented It Didn't Happen SOC This is a golden rule. If If it's not documented, it hasn't happened. Is. It's the truth. This will be considered. Not Know Documentation Nothing Has Happened. That's it. Why Alert Reporting Matters? matter Why does he do this? Why it matters? So this What matters is to create an audit trail. audit Enables to create trails Handwork Between Shifts Supports Incident Response Protects Analysts Legally Help Improve Detections So it matters for different things. To help with incident response Protection for all the analysts It can be given legally so that it means somehow There is some legal trouble later Done to improve detections goes. And let's say you're in a shift. You are working. Now second to you The shift begins with another analyst Going to do. So you swiftly hand it over I can do it. This will be known through this because On the basis of this reporting, when there is another If he takes over the shift, he will know. That's exactly what you wrote. Exactly what is this alert about. What is its description, what is its impact? has happened, how has it happened, what There has been an impact. All this clarity comes from this Will get it. In Real Socs Bad Reporting Is Equal to bad analyst even if traag was Correct. Trag you got it right but if If the report is not prepared correctly then you can apply for a good There is no SOC. To be a good SoC You will have to make a good report. That's it. Now this can be explained through example interview. Let us understand a little about that level. accept it Understood an interview type from interview type. A summary will be given. Suppose in the interview Power Shell Execute with Encoded Command Triggered by Word Document on Finance User system. This is a summary. to this summary Please understand and think a little. Power Shell is executed as an encoded command Triggered by a Word document. On which system? A finance user On the system. Finance of any finance The department will have a user on its system. Now how do you analyze this? Meaning this particular reporting that you did How is it reported in this If we understand this a little bit then in that In the summary, you should mention this in this manner Gaya in the time of summary means after that In the analysis, you mention something like this Will execute according to this summary Your summary is done, okay, like this. Now that the analysis is done, what about the details? will write execution according to outside Business Hours Parent Process Was Winv Exc External Connection Observed This One Your analysis is done, it's okay when you I will write this report. I will write this report. Method I am telling you the first summary, this is just a There is a summary, then analysis, then verdict. If yes and then your recommendation is In the analysis, you will write that Execution outside business area The parent process is winrd.exe which is Word. is the official process of and external The connection is observed. means that one The external communication connection is It has come under observation. What is Verdict? Verdict is True Positive. What is the Verdict? Is it yours? is true positive. So Verdic True Positive means it is absolutely correct. A suspicious execution has taken place. it's a Suspicious execution. what is the recommendation Is? Escalate to SOC L2 for containment. Escalate this to L2 because You think a serious execution And here's a further deep investigation. So you should be L2 or DFIR which team i.e. digital forensics and There is an incident response team, you can call it You can transfer it. So a company Inside L1, L2, L3 Can transfer. means escalate Can. Either L2 DFIR is also included in it Let's go. They can come into it You can take an interest in or support it. Can help out in that Digital Forensics and Insights There is a response team. So here It will escalate. Right? Just make it clear Your report is ready. Did you understand? Now Escalations come. What is escalation? What is escalation? Escalation means this Alert is by tier one authority and Requires higher expertise and action. Escalation is then done Escalation is done when the bus of L1 Let there be no talk of this. L1 feels that brother, this We will not be able to handle it. It's not just a matter of It is ours. Ok? So at that time, escalation it occurs. So Tier One is not fixing this. Will do. L One means it will not fix. End Tier One just identifies it and ends it. This will escalate further. This escalation It happens in. He will identify and see will document it and escalate it It is necessary to document it brother. you something You have to document it also. also escalate If you do it, you have to document it. close too You will have to document it. False Positive You will close it but still have to document it. Is. Documentation is the main key for Associate Analyst. And without him your report or whatever you find Yes, all that is useless. Ok? It's just all useless Is. Got it? You must have understood this much? Got Everything? Did you understand? Good. Very Excellent. Now let's come here when should The one which is L1, Tier 1, does it escalate? When? These escalate Should I do it? When should Tier One escalate? This is if you have any of the following conditions: If you get a true answer, then you can escalate. will edge associationlist l1 in all If you have any one of the conditions True meets you will ask yourself Will investigate if it is true Escalating like a malaise If you are getting activity confirmed then You have to escalate. you have to Escalate Privileged Accounts Any Involved If it is happening then you have to escalate. As That the malware was executed. Privilege I am the admin user here. Critical Have any assets been affected? as if someone Your server has been affected. assume someone Your server has also been affected. So that In case you escalate it. Multiple Alerts correlate multiple alerts that are one Relate with it if you can. that case You will escalate in this also. such as phishing Plus execution is done. So this escalates do. Don't exalt everyone, brother. Not everyone has to escalate. Look at this wrong We should not have this approach that Sir, everyone Will escalate. Then it's your bad That will happen. Then it will get spoiled for you. Yes That will get spoiled. Don't do it like this. Then that reputation of yours. It will go down. Ok? I don't know the DC that would have been the domain controller Is. It's basically in Active Directory. You read about it. domain We are currently monitoring the controller server. Are. Able to collate multiple alerts Are. Data Risk Acts If any data If there is risk or exploration risk, then it Will escalate. Policy Requirements escalation or any if suppose high or If there is any such alert, then it Mostly if you escalate it, it will be more Is good. I have already said Escalation is not failure. it's a Professionalism. These fellows will not speak. We will call this professionalism. This is yours There is professionalism. Being a good Soc. it Part of the escalation. Now to escalation Let us understand through an example. Ok? What Is? How do you document it? do. Region of escalation confirmed Suspicious Power Shell execution with External communication. You confirmed this I gave you a reese. evidence you Will attach it. Process tree command line Destination domain. You put this In Evidence. You have marked the severity high Gave. You put in the recommended action End point isolation and memory analysis. Meaning, isolate it completely from the end point. Particularly right now I mean whatever laptop you have Whatever your desktop is or whatever virtual desktop it is Desktop environment has end memory analyze so that there is some kind of There should be no question of any infection. This thing you Will report at the time of escalation or We will document it and L2 will enjoy it. Will go. L2 will feel wow, what reporting It's curry. So Reese will explain the escalation. We will attach evidence to it. Indicate the severity and recommended action if If you can tell me, please do tell me. not too I will tell you, no problem. L2 handle Will take. Right? Ok? Ok. Jedi Coder Now comes the matter of SoC communication. Now We will talk about communication with SoC. it It is a very important thing. This is underestimated because Without communication, everything collapses. Will go. There will be many such cases when you are at the age of SOC you have to communicate. Without You do not do anything further with communication Will find. Communicating between teams It happens. A team is a team that is the other team Communicates with. Cross Team Communication has to be done. of a same team The communication is with your higher authority Or it happens through management. So all this You have to do things. What is SoC Communication? SOC Communication is Analyst's Communication with the analyst. Analyst From the Incident Response Team To have communication. IT Analyst or Communicate with the admin department Happen. Communication between SOC and management Or the analyst or the entire SOC team. Communication with management. So this There are different types of communications. So every Someone is communicating with each other. Only then there is teamwork. Then, like a team The work gets done. And then an effective Security posters should be prepared. Can. So you are translating technical risk into actionable into actionable Information. You are taking a technical risk Convert it into actionable information Have been. That's all you're doing Through communication. It's a very big Thing. If you think about it, you will understand Will come. It's a huge thing. Now communication What are the principles? which is your standard What should happen? It should be very clear that your There should be communication. Must be factual. There should be no assumptions in it. Panicick language ah it's it's a very a very ah large ah it's a very dangerous ah malicious Attack. Please don't do this. please don't do Dec. Please disconnect the voice, disconnect The hard voice, the disconnect Kill Switch Please execute the kill switch And all, doing this will not create panic for you. It has to be done within the team. No blame this No, not me, it is the L2 one who has the problem. L3 It is the owner's fault. L1 It's not my fault Is. I did everything right, so it was his fault. Is. You don't have to do all this work. so like that if I have to say one line that hack the system It has been done. So, I will not speak like this. The system is hacked very badly. System Is Hacked and Everything Is Compromised Badley. Don't say this after doing this. To you Saying Suspicious Activity Detected It is under investigation. If you speak lovingly, you will understand more. I will come. Isn't it? Suspicious Activity Detected Under Investigation. Done. This There is no need to panic in this manner. Or correct. No panicky languages. And Don't get emotional brother. In the emotional No. The system was attacked. System A compromise was reached. How to do it now? Now What to do? I am feeling very sad brother. This way Don't do it. Ok? One should not keep too much in sorrow. Let go. Now let's come to communication types. Which ones are there? this is communication It happens this way. also for communication There are types. An internal internal Communication happens. IT or Admin Communication happens and management Communication happens. These three communications There are types of. Internal SoC What happens in communication? When to use this Are they done? When shifts change, When escalation happens, when collaboration happens Is. So obviously this is an internal team There is communication between. So when someone There is a shift change, someone else is L1 in your place If he is coming then you have to communicate with him. So that became internal communication. escalate L2 to L3 internal communication Went. You have to collaborate with others, suppose you are L1 L2 communicates with L3 DFIR Digital comes to collaborate Forensics or incident response team If you want to collaborate less then that is internal Our communication is done. Ok? As Alert escalated to end point Pending isolation monitoring ongoing. So This is basically your internal communication. IT Or what is admin communication? used When action is needed. Now assume someone If you want to take action immediately then brother IT Communication with you through the team of You have to do it. Please the admin team Isolated Fin Lab 07 This One Suppose Someone The system or server name is from the Network as suspicious activity was Detected. I mean, there's a system here. Particular. Suspicious activity on this It was detected. So here's to the IT team. It is being said please isolate it. Quick So you remove it from the rest of the network. No So the big band will play through lateral movement Attackers of the entire network infrastructure will spread throughout the network or this malware Or the virus or worm spreads throughout the network Will go. There is malware everywhere. Run Run Malware is everywhere. Run, run Malware is everywhere. The gift comes Management Communication. This high level There is communication. Management does not want Logs. Management can keep your logs out of the fog It doesn't make any sense. Why management Meaning? What will be the meaning of technical things? Brother? Management is management. In IT For that, for technical things, they want Impact Plus status. They mean that Bhaiya, what is the impact in the end? What The situation was a particular attack scenario Of? They have to go to that. that would mean Is. Suspicious activity in the example Detected on one finance use system. No Evidence of Data Exploitation So Far Incident under investigation. These Communication was made to management that a Bhaiya, there was some serious activity. Detect It happened on a finance user's system. There is no such special feature of data exploitation. There is no news. I don't know anything special It's gone. Investigation is ongoing. As We will update you as soon as something happens next. The management was happy. Yes, okay. Tell. I won't know anything now, I will know in some time. Then you will get pressure from above that brother, this Give me some updates. Management will put pressure. DFIR L3 Incident Response in Sub Team Believe it or you can say that it is the IT team The IT team then means it like this This is through the downward hierarchy. Will Work. The most senior is that of his junior His junior speaks like this They will go away and the last one gets crushed. Poor guy. This is what happens in corporate. Yes, communication is the key. absolutely correct Is. So basically reporting Basic Reporting Escalation Communication How does it all fit in? I already told you. Alert It gets detected. The alert is tried. Report Is made. The report is written. Escalation occurs. If Needed There is communication. And then the action which is It is performed. That's it. Yes Yes We Want The Only Status Absolutely Right is absolutely correct And what time will today's class be? Brother, the class is about to end, don't worry. I have to take it, I have to be absolutely carefree If you take tension then how will life work? will miss any step soc failure in Missed any one of the steps Then the SOC failure will be considered for the entire team. Any step that is considered a failure That should not be missed right this is the man Thing About Associa Communication and About Reporting Escalation and Communication. Bus You must have understood this and I hope that All these things will become clear. Right? Everything is now clear. Let's go here now I am coming. And I'm going for the try Hack me pay. But I am going here. Now Let me give you one thing. As a task I give. You all have to do it. very easy You will get the task. There is a SoC L1 Reporting. There is a lab. You open this Please take it. Here you will come down towards the pay. I think there is some network there is some Issue. Ok. If you come down here, you will see Pay A Or Report Guide In this you have to answer some basic questions. You please answer this. In the Escalation Guide If you come down here, you will Flags to be submitted. You submit this Please do it. Here at SOC Communications I have to answer some questions. You won't even do this Will work. Mainly yours is the escalation guide Whatever is there in this, you have flags here These flags let you come and take them in. Flags you have to submit and see You are able to submit these flags yourself. Are they there or not? This is the task. So please do this Please complete the task. it's a Request to all of you. Ok? What is the matter. very good thing. Gin People have already completed them. Don't do it. Those who have not done Complete please complete this room. If you are in If you can do it in total then it is a good thing. Or else You can also only guide the escalation I will have to read the rest of the room. So Please read it. The escalation guide is available here Pay a flags are these you can see here Please answer correctly and fill it. To you You will need a little idea about it. Right? Ok sir, please tell me, there is no request. Ok Brother, thank you. I gave the order. This Have to get it done. Ok? Let's do this a little There was a task. And as I said, All the important topics you will find in this You can see all those topics yourself. Will explore. Like if you saw Cyber Kill Chain so although I did everything Taught in great detail but still a little You will explore. Hacking Methodology You will explore it a little. here You are seeing a phishing email. So fishing Explore something related to what happens do. Here you can see a like What are drive-by websites? For him You'll explore a bit. here What is EDR for you? Will explore a bit. give you life Explore about Cycle of CNC You can do it. ransomware here What is deployment? About this You can explore. lateral movement What happens? a little about it yourself You can explore. Xeric Hacking What are methodologies? About this You can explore. You can do all These things. Right? So this is you as a task Please do it. The second thing I keep saying I think it will be great for you. If you do as I am telling you, If you do, it will be very good for you. whatever If you conduct classes live, then You should definitely do it, it is a good thing. But Live Then, watch the recording again. And make notes during that time. own notes Make it. Don't depend on my notes. don't Depend on my ppts pdf. that's me I will give it but I may never give it. Then great sorrow You will have it. It could be that I am a So I am giving it regularly. could be possible That I should give PPT of next two-three classes I will give you the PDF later, after 10 days. So will your flow break or not but If you have notes, they will not break. You have to make your own notes and prepare them yourself. and whatever points you have to make Their points have to be put on Lindin And we have to tag it after putting it on Lindin. Put as much as you can on Lindin. Everyone please enter. No profile on Lindin Yes, create a profile, it is created for free. And tag us by searching for Difronics You can also tag me or me. Can tag both Defronics and me Or you can tag the differences only by searching Give it. We will find out. Right? So We see a little of your activity. yes We can comment on your post with all our feedback. Posts should not get likes from everyone. But We definitely see the posts. myself I personally see all your posts. You guys also put it. Right? So you guys Keep putting it. We will know about you How active you are, how sincere Are. And this is very beneficial for you. It will happen later. Because the more active you are The more sincere you will be in the end, the more You will get more help from our side. I I am telling you this thing again and again. I am giving a hint. But as many people as possible have to understand Do you understand? I am not understanding anything. No problem. At last you understand Will come. But you get more guidance, more Support and more things to you See you in the coming months and coming In Days. So please do whatever you Complete classes as you go along If you have completed class four then class four Come to the comments and write there. Write your full name and complete it like this That's an attendance mark, that's an attendance mark. so you have to maybe we can do those If you give away comments, then those comments So let us give away that brother, the most Comments are meant for four videos whose Nowadays it is the era of AI, friend, it is very EG that most of these four videos The comments that he is making on a regular basis Flutter out the comments and top three We are giving away vouchers for the trike. Give Zomato vouchers or blink vouchers Swiggy Vouchers Amazon Vouchers Flipkart Book Mysho vouchers that I want a voucher brother, I will give you that voucher but if you do it You have seen it right, I am teaching everything for free. I am also providing quality training. I am also giving you a voucher, what now brother, what now? tell me you should what more can I do You should at least read it well. Ok? You are welcome guys. So you guys are Please do it in the comments because you Look, this is not a very good thing. First Class has 350 plus comments. Then there are 300 comments, 250 comments. Here I've almost reached 200 comments. After speaking. So you can get an average of 250 comments. Take me along so that I can tell you that there are 250 people here. Continue watching. Then it will be fun too. Right? So you do this. Please do this To you. I will not comment at all It won't be known. I am just saying it loudly and clearly. Please do it. And share the videos Then keep its screenshot with you. When you share videos, then Keep a screenshot. Because we are the ones who We are doing voucher or whatever giveaway. On a sharing basis, on a comment basis, both Taking it on a different basis every time Will come. Once on a sharing basis, once Comments basis. So you have a screenshot It should happen with time. Then Only We Will B A Selecting You Right ok I do it, it is a very good thing people I share, thank you very much I am Really delighted, let's go here to the fans' top It's the fans' turn to see the list of top fans. Let's take one last look at the top fans List Here Again Pop up will make the chat visible in big size Little Top Fans: So these are our top fans today. I was not able to do it in the last session. End Mr. A Mr. Jet Top Rishi The Root Mr. Robot Prince Gokhale OK Tush Lalit Adi Pitambar Sky Enchanting Kashmir Kashmir Pride Ishlern Nisha Damja Himanshu Aman Shaikh Harik Vaid Paul, look brother, there is a mistake in pronunciation. So please forgive me. This Shailin Narayan Manish Rajput Amit Yadav Radhika Sharma Anamika Aditya Singh Ashok Sahni Logan Master Gaming Abhishek Devanand Devanand Devanand sahab has come to see our video. Hello Devand ji, Devanand has also come to our house. What's the matter brother, taking SOC class? So popular our class is so popular Coronation Sudama Brother, is this your name for real or is it just like this? Do you give anything in the username, tell me brother Sudama has also come to us along with Devand. Sujoe Cybernex Mr. Elliot taking classes Sagar Vikas Happy Hack Rahul Shubh Habibullah Salute Gabbar Watch Gabbar has also come, Gabbar is back, Gabbar has also come Look Shaf is gone Emo Namin Joker Joker is also there Joker has also come Everyone has come, friend, everyone is in this class. Loki Loki has also come brother the Avengers one Radio Punjabi is also a Punjabi radio It's a matter of friend anime That's right friend, you will enjoy reading the name. Used to be. Correct. I think from now on Kapil Sharma, leaving Tarak Mehta, you people I will just read their names. More in the top fence I am enjoying this. Next time Doctor Strange comes, Iron I come, everyone come. let's go okay okay Guys. So thank you very much for attending the Session. I hope you enjoyed the session. I hope you Learn something and you learn something different. And I hope you can hone your skills like this. Will keep moving forward. This is how you do skilling Will be attending this session live Will remain. I hope that as much as time as long as you continue to attend live Till then I will be happy and if I am happy then Mogambo was happy. If Mogambo is happy Classes will continue. So keep Mocambo always Happy while attending the live sessions. Thank you guys. Thank you very much. have a good Knight. See you brother on the next SOC In class. Tata good night. Good night guys. Good night. Hey brother, good night. Good Night Good Night Yes, Ram Ram Sat Shri Akal Kem Cho If nothing comes next, sorry for the rest of you. Don't mind, I'll learn it slowly. Brother, I am being by doing non-human work. It's okay if you don't become human We love you sir hey I love you too guys Radhedhey Radhe-Dhe Bhai Ok When will the next session come? Come soon brother, come soon It will go, friend. It will come back just like it came today. I will tell you in the WhatsApp group The link is given in the description of the video Stay involved in it. Join the WhatsApp channel Wait, you will find out everything. Sir I really appreciate how you make Complex Topics Easy to Understand And you have made a lasting impact on me Learning. What's the matter Lalit? Thank you very much Very nice. If I have like Any Kind of Impact on Your Learning Journey. Thank you very much. Sir, do you know about Dash Dash Tech? What? Yes, I know. Know the YouTube channel I have it. I have heard those people too. They People also get scammed. network Marketing. I have heard. Those people too They make us crazy in the name of paid training. I don't know if I have heard this. You are welcome. Today's session was amazing. Thank you You. Thank You Brother If You Found The Session amazing. Sir, you do a lot for us. They The sketch is a gift for you from me. Thank you etc. etc. you have sent to email Is that a sketch? Email I Mentioned Have you sent it to that also? If If not sent, email is given in your comments. It has happened to me. So please also on that email Please send it. Its HD quality or It will be of original quality. So It Will Be Great. Sir, the class gap is increasing a bit. No friend, it is not happening much. Absolutely It's getting better. The class gap is not much. Are happening. This gap is being created deliberately. So that those who were left behind, those who are now No comments at all, if there are no comments If you do, how will you know that you have done it? Have done the classes. Joe Last Day Four There was a class and there were only 100 comments in it. This means the rest of the earlier comments Those who are there did not see it. They Do not comment. If you comment then I I'll assume you're ready for next time. Class. So it depends on you. Right? And a comment should appear only once. Not multiple times. Ok. Thank you. Thank you. Okay guys. Thank you You very much. Have a good night. See you in the next associate session.
Dear Defronixters !! This is the 5th Class of our SOC Analyst Job Ready Free Blue Teaming Course by Defronix Cyber Security. In this class we will learn about Alert Reporting, Alert Escalation, Communication & detailed Cyber Kill Chain along with some other concepts. Kindly share this video with your those friends who are really interested in becoming a professional SOC Analyst. I hope you will learn something that will add up to your skills. ⮕ Join the SOC WhatsApp Group for Certification & other Updates for this training : https://chat.whatsapp.com/FXCm4brqQGtC0lO2ioAJwp ⮕ Join Our WhatsApp Channel (Search Defronix Academy On WhatsApp Channels) For Updates & Resources : https://www.whatsapp.com/channel/0029VaGltobEKyZ8eX8Ki82w Disclaimer : Dear Learners, Videos coming in these classes & trainings are meant to educate you all about various fields of Cyber Security & Information Security. We teach all techniques & steps so that you might understand how various type of Cyber Attacks works, how to countermeasure them effectively, how to make systems & servers safer & how to stop such type of unauthorised attacks. Please learn accordingly & follow all the Cyber Laws of respective countries before executing any of the methods. Cyber Crime is an offense & is dealt with severe punishment & fines. We neither support nor instigate of such things. We are an Ed Tech company & we provide Education for knowledge, skills & building career in respective domain legally. Download Our Official Android App To Learn & Make A Career In Cybersecurity : https://play.google.com/store/apps/details?id=co.robin.pqbpg Download iOS App Here : https://apps.apple.com/in/app/myinstitute/id1472483563 (use org code : bdivfy ) after installation. Enroll To Our Cybersecurity & Ethical Hacking Mastery Course - DCjSP : https://defronix.com/cybersecuritymasterycourse ⏩ Please share the video with your friends & who really wants to learn SOC from scratch. ⏩ Get in touch with us through our Social Handles to never miss any updates that can be helpful. ⮕ Instagram : https://www.instagram.com/defronixacademy ⮕ LinkedIn : https://www.linkedin.com/company/defronix ⮕ Twitter : https://twitter.com/defronixacademy ⮕ Facebook : https://www.facebook.com/defronixacademy ⮕ Official Telegram Channel: https://t.me/defronixacademy 🌐 Website : https://defronix.com Subscribe To Defronix Academy {Unit Of Defronix Cyber Security Pvt. Ltd.} : @defronix Keep Learning & Hustling. Thank You ! #soc #securityoperationscenter #socanalyst #cybersecurity # #cyberkillchain