Analyzing Sysmon From Backdoored UltraVNC Malware - HTB Sherlocks - Unit42

Поделиться
HTML-код
  • Опубликовано: 31 дек 2024

Комментарии • 30

  • @dariusjurma4253
    @dariusjurma4253 2 месяца назад +2

    Love the content dude. You are the goat when it comes to ctf videos. You should consider putting together a course, i am sure people would get it.

    • @ippsec
      @ippsec  2 месяца назад +2

      Courses kind of go against my philosophy and how I learned (and learn). They heavily emphasize building repeatable tasks, which is great and what most people probably want. However, in the real world there's an infinite number of configurations, so things don't always appear the same or even work the first time. Not to mention the tools and techniques are constantly are changing.
      I think people that watch the videos somewhat regularly pick up more than what they would in a course, and since CTF's are generally bleeding edge content there is always new stuff going in.
      Not to say myself making a course wouldn't be beneficial, I'm sure I'd make a ton of money going that route but by doing so I think I'd lose a lot of flexibility, self-growth and I don't think it would help many people in the long run.
      Don't want to sound egotistical or anything but most of the time when I hear stories from people just getting started in their careers and are lightyears beyond where I was at that age. They almost always say they got started from my channel and don't watch as much as they used to because they got to a level where they can teach themselves.
      It's very hard for a course to build that discipline.

    • @dariusjurma4253
      @dariusjurma4253 2 месяца назад

      @@ippsec First of all i really appreciate you replying to my comment. I completely understand if that goes against your way of doing things i was just thinking from my perspective you have some of the best content i understand and learn the most from and if it was structured in a way of increasing difficulty and introducing new concepts it would definitely make for the best course out there. But again that's just what i was thinking when i wrote that. Keep doing what you enjoy and making the best htb content out there.

  • @apkanalyze3623
    @apkanalyze3623 2 месяца назад

    healthier look, nice new haircut, three videos in two days, cool t-shirts, and really useful, instructive content-what more could anyone ask from the RUclips ✌

  • @AUBCodeII
    @AUBCodeII 2 месяца назад +16

    We got IppChad in 1440p before GTA 6

  • @behindYOUR6
    @behindYOUR6 23 дня назад

    Always Respect 💙

  • @jmprcunha
    @jmprcunha 2 месяца назад

    Love the tshirt! Thanks again for another great video

  • @Drageum
    @Drageum 2 месяца назад

    This guy is really incredible. Big brain

  • @ryangosking2049
    @ryangosking2049 2 месяца назад

    amazing content! Do you consider explaining current AV Evasion techniques in a video?

  • @NitrogenXP
    @NitrogenXP 2 месяца назад +3

    Wow 3 videos in 2 days. How do you keep going is your motivation, is it just that you like your job?

    • @ippsec
      @ippsec  2 месяца назад +5

      I've wanted to get some sherlocks out for some time now -- The very easy ones don't take too much time to get out. But yes, I do enjoy doing videos

  • @lorenzoanselmetti8495
    @lorenzoanselmetti8495 2 месяца назад

    Hello, Preventivo is italian for "quotation". A user in an office probably clicks it thinking it's a pdf or a docx

  • @alanbusque6645
    @alanbusque6645 2 месяца назад

    Thank you!

  • @visualstorytelling6919
    @visualstorytelling6919 2 месяца назад +1

    Hey IppSec firstly thanks for all the great videos. A small request, can you zoom in a bit when u record videos especially the browser screen as it is difficult to read ..the terminal is perfect, can read well, it is just the other screens , Thanks again, looking forward to learn more from you

    • @ippsec
      @ippsec  2 месяца назад +2

      I'll try to keep that in mind, I generally do try to zoom in but can forgot or maybe I'm not making it large enough -- Whenever leaving comments it helps to put a timestamp so I know what spot you are looking at.

    • @visualstorytelling6919
      @visualstorytelling6919 2 месяца назад

      @@ippsec Thanks man indeed you do zoom in most of the times and may be because you might have a bigger screen it might be difficult to judge on how little is too little, an example was at this point 2:45 ruclips.net/video/1qbkZn8JAw8/видео.html

  • @nullpwn
    @nullpwn 2 месяца назад

    dude, you're the goat. also, idk why i though you're older? :))

  • @izotovdan
    @izotovdan 2 месяца назад

    amazing video, I hope you can do more sherlocks

  • @pabloalfaro2595
    @pabloalfaro2595 2 месяца назад

    Ippsec with cam on, how times have changed :O

  • @alexsparkle2874
    @alexsparkle2874 2 месяца назад

    thank you ippsec

  • @AlienAgencyorg
    @AlienAgencyorg 2 месяца назад

    Ooo yeeee

  • @tg7943
    @tg7943 2 месяца назад

    Push!

  • @boogieman97
    @boogieman97 2 месяца назад

    Hey Ipp, why do I have the feeling that the insane sherlocks aren't that insane as I expect them to be. Is it my experience or is the difficulty level not as hard as insane boxes are ? :-)

    • @ippsec
      @ippsec  2 месяца назад +2

      I haven’t played that many yet to know, but keep in mind offensive CTFs have been happening much longer than defensive. Look at an insane HTB machine from years ago to now, the difficulty does get harder as people get better at both making and solving. I’m sure it will get harder overtime

    • @boogieman97
      @boogieman97 2 месяца назад

      ​​@@ippsecthanks a lot , that really justifies it. Although they are not yet so advanced, they are very enjoyable. I do also believe there are many more non intended routes with sherlocks as with boxes. Especially with malware analysis. You could spend endless time analyzing decompiled code in Ghidra/IDA/Binja or be clever and set the right breakpoints in a debugger including patching anti debug / evasion measures. :-)

  • @hoidamchannel
    @hoidamchannel 2 месяца назад +1

    lmao 1st time saw ippchad face

  • @mateagulashvili4817
    @mateagulashvili4817 2 месяца назад

    IppGoat

  • @Aryamk-cr8ep
    @Aryamk-cr8ep 2 месяца назад

    Hi everyone, I’m Arya and I’ve just entered the field of cybersecurity. I’m relatively a beginner. Is it possible for you to give me your email or web address so I can get some guidance from you? I would really appreciate it. Thank you!

    • @rodneynsubuga6275
      @rodneynsubuga6275 2 месяца назад +1

      The only best advice is read docs no short cut and must know programming everything else comes with time and also use your logic; don't cram understand the logic