Try Hack Me: Windows Event Logs

Поделиться
HTML-код
  • Опубликовано: 10 июл 2024
  • This is the continuation of our Cyber Defense path! This is a very entry level and great way to start learning defense! This is a box all about how to view event logs on windows and how to investigate them.
    If you want to see exclusive content and have the opportunity to game and chat with me about anything check out the patreon!
    Patreon to help support the channel! Thank you so much!
    / stuffy24
    Hacker Discord
    / discord
    Task 1 (00:00:00 - 00:01:20)
    Task 2 (00:01:20 - 00:15:30)
    Task 3 (00:15:30 -00:22:50)
    Task 4 (00:22:50 - 00:34:00)
    Task 5 (00:34:00 - 00:42:45)
    Task 6 (00:42:45 - 00:45:25)
    Task 7 (00:45:25 - 00:54:00)
    Task 8 (00:54:00 - 00:55:00)
  • НаукаНаука

Комментарии • 58

  • @stuffy24
    @stuffy24  2 года назад +6

    Powershell is my favorite way to pull logs! whats yours?!

    • @Surya000Bhakti-xv4xw
      @Surya000Bhakti-xv4xw Месяц назад

      just a question how to copy and paste code into vm of windows I tried and doesn't work

    • @stuffy24
      @stuffy24  Месяц назад +1

      @@Surya000Bhakti-xv4xw ctl c to copy and ctl v to paste

  •  Год назад +6

    XPath really did a number on my head 😅

  • @hensolo8825
    @hensolo8825 6 месяцев назад +1

    this is so helpful!!! thank you! i was so confused with the room alone

  • @DigitalHoplite
    @DigitalHoplite 4 месяца назад +1

    Great content!

  • @JDobermann
    @JDobermann 7 месяцев назад +1

    Thank you man, it was really discouraging room until i found your video. Great Work!

    • @stuffy24
      @stuffy24  7 месяцев назад +1

      Thanks so much

  • @DiamondStumpy
    @DiamondStumpy 9 месяцев назад +1

    Super helpful! its far better to spend 1 hour learning and watching this way then spending multiple hours just on the box itself

    • @stuffy24
      @stuffy24  9 месяцев назад

      Thank you so much!

  • @tamaraf69
    @tamaraf69 Год назад +3

    I recently had been hacked - or at least caught the start of it, and I know nearly nothing about the Windows Event Logs, this really helped me see how to read them and I think I'd like to actually work in this area.

    • @stuffy24
      @stuffy24  Год назад

      That's awesome! So cool to see people learn and progress! Hit me up on the discord and I can give you some paths to get started!

  • @user-oo1xh2mi8b
    @user-oo1xh2mi8b 7 месяцев назад +1

    these are actually helpful!!!

    • @stuffy24
      @stuffy24  7 месяцев назад

      Thank you!

  • @sielecassharpe678
    @sielecassharpe678 3 месяца назад +1

    I completed this room but it was tough for me. Thank you for your walk through and I am going through it again because I want to better understand what Im doing and how to query these longs. Your walkthrough is super duper helpful and now the material makes way more sense the second time around.

    • @stuffy24
      @stuffy24  3 месяца назад

      Glad it helped! That's all I care about

    • @stuffy24
      @stuffy24  3 месяца назад

      Make sure to check out the discord as well for further help

  • @TheSoundEffectZone
    @TheSoundEffectZone 7 месяцев назад +1

    Thanks, Room would have taken forever if you probably didn't upload this. Glad you also explained some extra stuff.

  • @jacvbtaylor
    @jacvbtaylor Год назад +1

    Thank you!

    • @stuffy24
      @stuffy24  Год назад

      Thank you for the support!

  • @silentkille4
    @silentkille4 2 года назад +2

    really like your videos

    • @stuffy24
      @stuffy24  2 года назад

      Thank you!

    • @stuffy24
      @stuffy24  Год назад +1

      @Mr Robot I can try and take a look at it tonight

    • @pograva
      @pograva Год назад

      @@stuffy24 Do you resolve the question? 💪

    • @stuffy24
      @stuffy24  Год назад +1

      @@pograva I will try to look tonight. Can you hop on the discord and remind me?

    • @pograva
      @pograva Год назад

      @@stuffy24 yes don't warry 😊 . I'm find to do the combinaton of the commands, but I think that the question is not very understandable 😔

  • @mallorii86110
    @mallorii86110 Год назад +2

    Thank you. I was so stumped on Task 7 mainly because I'm always hesitant to Google, and there were SO many sources at once- some of which no longer work...
    I wasn't sure what I was meant to already know and what I was "allowed" to look up, if that makes sense. So I really avoided doing it for a few days.

    • @mallorii86110
      @mallorii86110 Год назад

      But once I actually knew what to filter it wasn't so bad. With finding the downgrade attack, the version being 2.0 was also a giveaway IIRC

    • @stuffy24
      @stuffy24  Год назад +1

      Thank you! I def understand what you mean! That's tough to know when you know something well enough!

    • @mallorii86110
      @mallorii86110 Год назад +1

      @@stuffy24 It was literally making me so stressed for days LMFAO then it was so simple.

    • @stuffy24
      @stuffy24  Год назад

      @@mallorii86110 literally hacking in a nutshell lol

  • @adamwilliams9307
    @adamwilliams9307 4 месяца назад

    I noticed TryHackMe doesnt' do this, but in the LogName section of the query, it's not listed on this Details View on the XML chart. So how do we know when to use "Application" versus "Security", etc? Is it solely due to the data we are looking to retrieve? Is there a comprehensive list of the LogNames we can look at? Tried searching but no luck. (and BTW I thought that all of this info would be on the Event Viewer XML Details tab, but TryHackMe doesn't really explain why we needed to use "Application" when it first teaches the command in the modules. Thanks for helping me understand.

    • @stuffy24
      @stuffy24  4 месяца назад

      Application logs are going to corelate to Applications where security corelates to security actions such as access logs

  • @kananalasgarli2193
    @kananalasgarli2193 Год назад

    Where did you find log clear evet id 104. I also searched and just found 1102. Task 7 q3

    • @stuffy24
      @stuffy24  Год назад +1

      Just a quick bit of research and this was one of my first google responses if you want to check it out kb.eventtracker.com/evtpass/evtpages/EventId_104_Microsoft-Windows-Eventlog_64337.asp#:~:text=The%20%253%20log%20file%20was%20cleared.&text=This%20event%20is%20logged%20when%20the%20log%20file%20was%20cleared.&text=This%20is%20a%20normal%20condition.

    • @kananalasgarli2193
      @kananalasgarli2193 Год назад

      ​@@stuffy24 Thanks for quick response bro

    • @pograva
      @pograva Год назад

      27736

  • @tryme8191
    @tryme8191 Год назад +1

    task 3 question "What event files would be read when using the query-events command?" does anyone had an issue with submitting the answer "Read events from an event log, log file, or using structured query"? it keeps saying this is wrong answer!!!

    • @tunechilee15
      @tunechilee15 11 месяцев назад +1

      I know this is late but the answer is "event log, log file, or structured query" they shortened the answer.

    • @deanhaycox
      @deanhaycox 10 месяцев назад

      @@tunechilee15 just tried it and it works

  • @denza2843
    @denza2843 Год назад +1

    Network Security and Traffic Analyst was way more interesting then going through EndPoint Security Monitoring( it was kinda boring).
    I hope that Siem and Phishing will be more interesting.
    Someone with simlar thinking?

    • @stuffy24
      @stuffy24  Год назад +1

      Haha well to be fair most SIEM's will ingest these logs and then you can search for them but the reality is you have to know how to do this for offensive and defensive because you have to understand what is getting logged and how it appears to avoid it. Endpoint security is insanely fun just not reading logs lol

  • @johnvardy9559
    @johnvardy9559 3 месяца назад

    @stuffy24 could you tell me CDSA or CCD cert?

    • @stuffy24
      @stuffy24  3 месяца назад +1

      That depends on you and what your trying to get them for.

    • @johnvardy9559
      @johnvardy9559 3 месяца назад

      @@stuffy24 thanks stuffy, what interests me is to acquire skills, and after that to be able to ASK for Job.

    • @stuffy24
      @stuffy24  3 месяца назад +1

      @@johnvardy9559 Well those both will provide skills to you. Neither will get you a job.

    • @johnvardy9559
      @johnvardy9559 3 месяца назад

      @@stuffy24 I agree, that's why I asked you which of the 2 will give me more stuff and more value.

    • @stuffy24
      @stuffy24  3 месяца назад +1

      @johnvardy9559 that entirely depends on you though. What your goals are and what you want to get out of them. I can't tell you what skills you need to learn since idk your current skillsets.

  • @dited555dited7
    @dited555dited7 10 месяцев назад +1

    Task 3 /if:true does not work.

    • @stuffy24
      @stuffy24  10 месяцев назад

      Feel free to join the discord and throw your questions with screenshots in there

    • @dited555dited7
      @dited555dited7 10 месяцев назад

      It’s /lf:true (it was an L)

    • @deanhaycox
      @deanhaycox 10 месяцев назад

      @@dited555dited7 I put I as well until I heard on the video as L