Active Countermeasures
Active Countermeasures
  • Видео 107
  • Просмотров 218 817
6. RITA v5 - First Threat Hunt with RITA v5 #rita #freetools #infosec
Chris Brenton guides you through your first RITA network threat hunt by explaining the primary indicators and best practices using RITA version 5.
🔗 Blog post located here -
www.activecountermeasures.com/ritav5-the-video-series/
Real Intelligence Threat Analytics (RITA) is an open-source framework for detecting command and control communication through network traffic analysis. More information and free download of RITA can be found here: www.activecountermeasures.com/free-tools/rita/
🔗 Register for webcasts, summits, and workshops -
poweredbybhis.com
🔗Active Countermeasures Socials
Twitter: ActiveCmeasures
LinkedIn: www.linkedin.com/company/active-countermeasures/
Discord: discord....
Просмотров: 324

Видео

5. RITA v5 - Live Monitoring #rita #freetools #infosec
Просмотров 360Месяц назад
Chris Brenton provides instructions on how to set up RITA and Zeek for live monitoring of your network. 🔗 Blog post located here - www.activecountermeasures.com/ritav5-the-video-series/ Real Intelligence Threat Analytics (RITA) is an open-source framework for detecting command and control communication through network traffic analysis. More information and free download of RITA can be found her...
2024-09-06 Cyber Threat Hunting Level 1 | Chris Brenton #infosec #training #freetraining
Просмотров 1,5 тыс.Месяц назад
🔗 Register for webcasts, summits, and workshops - poweredbybhis.com 🔗Active Countermeasures Socials Twitter: ActiveCmeasures LinkedIn: www.linkedin.com/company/active-countermeasures/ Discord: discord.gg/threathunter 🔗Our Threat Hunting Tool ~ AC-Hunter Features - www.activecountermeasures.com/ac-hunter-features/ Interactive Demo Space - www.activecountermeasures.com/live-demo/ 🔗Act...
4. RITA v5 - Working with PCAPs #rita #freetools #infosec
Просмотров 273Месяц назад
Chris Brenton explains how to import PCAP files for analysis using RITA version 5. 🔗 Blog post located here - www.activecountermeasures.com/ritav5-the-video-series/ Real Intelligence Threat Analytics (RITA) is an open-source framework for detecting command and control communication through network traffic analysis. More information and free download of RITA can be found here: www.activecounterm...
3. RITA v5 - Installation #rita #freetools #infosec
Просмотров 515Месяц назад
Chris Brenton walks through how to download and install RITA version 5. 🔗 Blog post located here - www.activecountermeasures.com/ritav5-the-video-series/ Real Intelligence Threat Analytics (RITA) is an open-source framework for detecting command and control communication through network traffic analysis. More information and free download of RITA can be found here: www.activecountermeasures.com...
2. RITA v5 - Network Architecture #rita #freetools #infosec
Просмотров 306Месяц назад
Chris Brenton explains how to configure your network environment to capture network traffic for monitoring and analysis by RITA. 🔗 Blog post located here - www.activecountermeasures.com/ritav5-the-video-series/ Real Intelligence Threat Analytics (RITA) is an open-source framework for detecting command and control communication through network traffic analysis. More information and free download...
1. RITA v5 - First Look RITAv4 vs RITAv5 #RITA #freetools #infosec
Просмотров 535Месяц назад
Chris Brenton shows some of the differences of RITA version 4 and a first look at the new RITA version 5. 🔗 Blog post located here - www.activecountermeasures.com/ritav5-the-video-series/ Real Intelligence Threat Analytics (RITA) is an open-source framework for detecting command and control communication through network traffic analysis. More information and free download of RITA can be found h...
Understanding C2 Beacons - Part 2 of 2 | Malware of the Day
Просмотров 211Месяц назад
A video summary by Faan Rossouw of the Malware of the Day - Understanding C2 Beacons - Part 2 of 2 🔗 Blog post located here: www.activecountermeasures.com/malware-of-the-day-understanding-c2-beacons-part-2-of-2 🔗 AC-Hunter: www.activecountermeasures.com/ac-hunter/ 🔗 AC-Hunter Community Edition: www.activecountermeasures.com/ac-hunter-community-edition/ 🔗 Register for webcasts, summits, and work...
Understanding C2 Beacons - Part 1 of 2 | Malware of the Day
Просмотров 4042 месяца назад
A video summary by Faan Rossouw of the Malware of the Day - Understanding C2 Beacons - Part 1 of 2 🔗 Blog post located here: www.activecountermeasures.com/malware-of-the-day-understanding-c2-beacons-part-1-of-2 🔗 StatQuest: Histograms, Clearly Explained ruclips.net/video/qBigTkBLU6g/видео.html 🔗 Register for webcasts, summits, and workshops - poweredbybhis.com 🔗 Our Threat Hunting Tool ~ AC-Hun...
2024-06-25 Cyber Threat Hunting Level 1 With Chris Brenton
Просмотров 1,7 тыс.4 месяца назад
/// 🔗 Lab Resources & FAQ here - www.activecountermeasures.com/hunt-training/ /// ➡️ Register for the next Threat Hunter Training Course Here - www.activecountermeasures.com/hunt-training/ /// 🔗 Get AC-Hunter CE - www.activecountermeasures.com/ac-hunter-community-edition/download/ /// 🔗 Register for future webcasts, summits, and workshops - blackhillsinfosec.zoom.us/ze/hub/stadium ///Active Cou...
XenoRAT | Malware of the Day
Просмотров 1,2 тыс.4 месяца назад
A video summary by Faan Rossouw of the Malware of the Day - XenoRAT /// 🔗 Blog post located here: www.activecountermeasures.com/malware-of-the-day-xenorat/ /// 🔗 PEStudio: www.winitor.com/download /// 🔗 TypeRefHasher: github.com/GDATASoftwareAG/TypeRefHasher/releases /// 🔗 Get AC-Hunter CE - www.activecountermeasures.com/ac-hunter-community-edition/download/ /// 🔗 Register for future webcasts, ...
2024-04-12 Cyber Threat Hunting Level 1 - Chris Brenton
Просмотров 2,5 тыс.6 месяцев назад
/// 🔗 Lab Resources & FAQ here - www.activecountermeasures.com/hunt-training/ /// ➡️ Register for the next Threat Hunter Training Course Here - www.activecountermeasures.com/hunt-training/ /// 🔗 Get AC-Hunter CE - www.activecountermeasures.com/ac-hunter-community-edition/download/ /// 🔗 Register for future webcasts, summits, and workshops - blackhillsinfosec.zoom.us/ze/hub/stadium ///Active Cou...
Malware of the Day - Tunneled C2 Beaconing
Просмотров 6166 месяцев назад
🔗 blog post located here: www.activecountermeasures.com/malware-of-the-day-tunneled-c2-beaconing/ A video summary by Faan Rossouw of the Malware of the Day - Tunneled C2 Beaconing 🔗 Get AC-Hunter CE www.activecountermeasures.com/ac-hunter-community-edition/ 🔗 Register for future webcasts, summits, and workshops - blackhillsinfosec.zoom.us/ze/hub/stadium ///Active Countermeasures Socials Twitter...
2024-02-23- Cyber Threat Hunting Level 1 - Chris Brenton #infosec #training #class
Просмотров 2,6 тыс.8 месяцев назад
2024-02-23- Cyber Threat Hunting Level 1 - Chris Brenton #infosec #training #class
Cyber Threat Hunting Level 1 | Chris Brenton | December 2023
Просмотров 2,3 тыс.10 месяцев назад
Cyber Threat Hunting Level 1 | Chris Brenton | December 2023
Cyber Threat Hunting Level 1 | Chris Brenton | October 2023
Просмотров 2,6 тыс.Год назад
Cyber Threat Hunting Level 1 | Chris Brenton | October 2023
Cyber Threat Hunting Level 1 | Chris Brenton | August 2023
Просмотров 1,1 тыс.Год назад
Cyber Threat Hunting Level 1 | Chris Brenton | August 2023
An Introduction to Threat Hunter Training Level 1 | Chris Brenton
Просмотров 5 тыс.Год назад
An Introduction to Threat Hunter Training Level 1 | Chris Brenton
Threat Hunt Training | May 2023
Просмотров 1,9 тыс.Год назад
Threat Hunt Training | May 2023
Passive Fingerprinting with SMUDGE | David Quartarolo
Просмотров 325Год назад
Passive Fingerprinting with SMUDGE | David Quartarolo
AC-Hunter - Investigation Menus
Просмотров 179Год назад
AC-Hunter - Investigation Menus
AC-Hunter - Safelisting
Просмотров 126Год назад
AC-Hunter - Safelisting
AC-Hunter - Deep Dive
Просмотров 224Год назад
AC-Hunter - Deep Dive
AC-Hunter - Dashboard
Просмотров 240Год назад
AC-Hunter - Dashboard
AC-Hunter - Settings
Просмотров 229Год назад
AC-Hunter - Settings
AC-Hunter Install Options
Просмотров 289Год назад
AC-Hunter Install Options
Threat Hunting Training | April 2023
Просмотров 9 тыс.Год назад
Threat Hunting Training | April 2023
AC Hunter Community Edition - Linux TAR Installer Walk-Through
Просмотров 1,5 тыс.Год назад
AC Hunter Community Edition - Linux TAR Installer Walk-Through
AC-Hunter Community Edition - VMware install Walk-Through
Просмотров 1,7 тыс.Год назад
AC-Hunter Community Edition - VMware install Walk-Through
AC-Hunter Community Edition VS Enterprise
Просмотров 336Год назад
AC-Hunter Community Edition VS Enterprise

Комментарии

  • @osta007
    @osta007 5 дней назад

    Can I run this whole exercise on WSL?

  • @Pul5arKhan-ld9yd
    @Pul5arKhan-ld9yd 14 дней назад

    Does Ac Hunter supports Ubunto 24.4?

  • @Боніст-новачок
    @Боніст-новачок 21 день назад

    Красава, давай ще!))

  • @mnn136
    @mnn136 Месяц назад

    Very nice tutorial, but in some linux diustro's screen isn't install automaticly.. if screen isnt install cronjob won't work.... I had that isseu and try to run rita-roll from /opt/rita/ and I've got the supprice screen wasn't installed... SO i've installed it and now it's running :) Recap to add perhaps in de newer version of this video: 1. install screen; 2. Dry run from /opt/rita/rita-roll

  • @xactobean
    @xactobean Месяц назад

    This new version is great! It would be great to see a video on how to filter out hordes of false positives and find needles in a very big haystack. Populating never_include_domains is arduous and never ending.

  • @djnightandday
    @djnightandday Месяц назад

    Hello. Great content! How is supossed to add the Threat Intel services/feeds? (Like VT or AbuseIPDB?). I saw there is a config file at "/etc/rita/threat_intel_feeds/DO_NOT_DELETE" but I don´t know which is format to integrate with those services... (requires API key)?

  • @SaySupport
    @SaySupport Месяц назад

    When I run Rita List, i'm not seeing the database. Is that because I need to wait a few hours?

    • @ChrisBrenton-yk9eq
      @ChrisBrenton-yk9eq Месяц назад

      If you are reading a pcap, the database should show up right away. If you are creating a rolling database to do live monitoring, the database will get created after Zeek writes out it's logs and then RITA imports them. So yes, that usually takes 1-2 hours to happen for the first time. After that, the database will always be there.

  • @MISTYEYED.
    @MISTYEYED. Месяц назад

    Thank you Chris, for your time.

  • @hptc4400
    @hptc4400 Месяц назад

    With Rita v5, would you advise against installing it on WSL?

    • @ChrisBrenton-yk9eq
      @ChrisBrenton-yk9eq Месяц назад

      I personally run it on WSL2 with the default Ubuntu. The install runs just fine without error. However, Zeek does not run on Windows and I have not come up with an elegant way to reach out from the VM to let Zeek monitor the host's NIC. So if you install on WSL2 you will be able to process pcaps, but probably not do live monitoring. If you do get live monitoring working, please drop me a note and tell me what you did. ;-)

  • @hptc4400
    @hptc4400 Месяц назад

    Appreciated as usual...

  • @x0rZ15t
    @x0rZ15t 2 месяца назад

    Awesome, just today was reading an article about it!

    • @gitgudsec
      @gitgudsec 2 месяца назад

      Part ii is dropping tomorrow 🖖

  • @RazwanM
    @RazwanM 2 месяца назад

    Interesting, however, I installed rite v5 but I cant find beacon-sni beacon-conn and beacon-host in the folder. Should it come together or I need to get it from diff package? thank sman!

  • @x0rZ15t
    @x0rZ15t 2 месяца назад

    Awesome!!!!

  • @0day-Control
    @0day-Control 3 месяца назад

    Team, where can i download the pdf file regarding this training.

  • @crypt2828
    @crypt2828 4 месяца назад

    Lol this is awesome - I cant wait to sit in on the June class

  • @dkhinfosec
    @dkhinfosec 4 месяца назад

    This was great. I look forward to more like this.

  • @omtoi_1018
    @omtoi_1018 4 месяца назад

    great video with an in depth realistic security response i rly liked this

  • @gitgudsec
    @gitgudsec 5 месяцев назад

    awesome stuff bill!

  • @triumphant_54
    @triumphant_54 5 месяцев назад

    hi Chris, i miss this Training, will i still get the certificate if i do the recording ?

  • @x0rZ15t
    @x0rZ15t 6 месяцев назад

    Yet another fantastic webinar, Chris! Thank you so much for sharing your knowledge with the community, truly inspirational! 🙏

  • @strippi8284
    @strippi8284 6 месяцев назад

    What a bunch of dorks

  • @UNcommonSenseAUS
    @UNcommonSenseAUS 6 месяцев назад

    Nice vid.

  • @gitgudsec
    @gitgudsec 6 месяцев назад

    very clear, lucid explanations thanks Chris.

  • @neverbetter5434
    @neverbetter5434 6 месяцев назад

    Oh man, the mcedit tool has never looked so cool Bill!

  • @louisvarre2197
    @louisvarre2197 7 месяцев назад

    Excellent thank

  • @gitgudsec
    @gitgudsec 7 месяцев назад

    Bill "1006 different projects" Stearns 😆

  • @sivaramakrishnan6947
    @sivaramakrishnan6947 7 месяцев назад

    Thanks for this amazing session

  • @gitgudsec
    @gitgudsec 8 месяцев назад

    great work team AC, the new UI is beautiful! y'all should be proud :)

  • @x0rZ15t
    @x0rZ15t 8 месяцев назад

    Awesome as usual!

  • @oscart7506
    @oscart7506 8 месяцев назад

    "Promosm" 😞

  • @cristobalvalladares973
    @cristobalvalladares973 9 месяцев назад

    Will the product work in a AWS environment? A tap makes me think a data center. I maybe wrong but all work will be with ec2 instances. Just need more info.

  • @krisg900
    @krisg900 9 месяцев назад

    This was an excellent presentation. Extremely helpful.

  • @x0rZ15t
    @x0rZ15t 10 месяцев назад

    Yet another awesome webinar by Chris! Thank you so much to Active Countermeasures and Chris Brenton for this wonderful content 🙏

  • @markgoproductions
    @markgoproductions 10 месяцев назад

    Great session! Very interesting method for monitoring network. Wish we could've touched a bit more on zeek, zeekctl, and other relevant CLI stuff. Thanks, Chris Brenton!

  • @vonniehudson
    @vonniehudson 11 месяцев назад

    thanks, unfortunately I don't see the rolling database, only the examples

  • @menno763
    @menno763 Год назад

    Really cool way of threat-hunting, would u say something like this could be created in Splunk with the right log sources?

  • @joshuamichau5122
    @joshuamichau5122 Год назад

    Super cool presentation. 😀

  • @x0rZ15t
    @x0rZ15t Год назад

    Special thanks to Chris for going through with this October version despite being sick 🙏👏👏👏

  • @x0rZ15t
    @x0rZ15t Год назад

    Awesome!!!!

  • @comosaycomosah
    @comosaycomosah Год назад

    Watched the last one it was really good

  • @elpatito2004
    @elpatito2004 Год назад

    Good Stuff😁😁

  • @gitgudsec
    @gitgudsec Год назад

    fun fact re: US driving on RHS instead of LHS: in the United States, large freight wagons driven by teams of horses would often have the driver sitting on the left rear horse, holding a whip in his right hand. This position allowed the driver to have a better view of the road if he was driving on the right side.

  • @rocksonarthur-e7q
    @rocksonarthur-e7q Год назад

    am loving ac-hunter it makes analysis easy with securityonion and pfsense. thanks guys for making this free for enthusiast.

  • @itspat87
    @itspat87 Год назад

    Another gem of content. Perfect for someone new to the role such as myself!

  • @pierre-huguesaubertin1654
    @pierre-huguesaubertin1654 Год назад

    It's been a while since I took the course... Nice improvement and might be attending next live session

  • @x0rZ15t
    @x0rZ15t Год назад

    Fantastic! Can't wait for the August training as well!

    • @gitgudsec
      @gitgudsec Год назад

      ditto - see you there :)

  • @TIMOTHYBURTON-vj2fc
    @TIMOTHYBURTON-vj2fc Год назад

    If I am using Option 4, how do I get to use Zeek?

  • @gitgudsec
    @gitgudsec Год назад

    second time i'm doing this and just signed up for the advanced training on 24+25 august. you are an incredible teacher chris - looking fwd to getting in deeper!

  • @Hamza_Ajaj
    @Hamza_Ajaj Год назад

    Great ,Thanks you for sharing 😊

  • @lightwire123
    @lightwire123 Год назад

    will April's recording be posted here?