{"status":"success","data":[{"_id":"620174d9e69211004469d46c","id":1,"questions":[{"hint":"","question":"Read the description! Continue to the next task.","questionNo":1,"disableAnswerPlaceholder":false}],"type":"none","title":"Room Outline","taskNo":1,"created":"2022-02-07T19:36:57.842Z","deadline":null,"uploadId":"","description":"<p>This room will cover the concepts of Threat Intelligence and various open-source tools that are useful. The learning objectives include:</p><ul><li>Understanding the basics of threat intelligence &amp; its classifications.</li><li>Using UrlScan.io to scan for malicious URLs.</li><li>Using Abuse.ch to track malware and botnet indicators.</li><li>Investigate phishing emails using PhishTool</li><li>Using Cisco's Talos Intelligence platform for intel gathering.</li></ul>"},{"_id":"620175dae47818005c3152d1","id":2,"questions":[{"hint":"","question":"I've read on Threat Intel and the classifications","questionNo":1,"disableAnswerPlaceholder":false}],"type":"none","title":"Threat Intelligence","taskNo":2,"created":"2022-02-07T19:41:14.900Z","deadline":null,"uploadId":"","description":"<p>Threat Intelligence is the analysis of data and information using\ntools and techniques to generate meaningful patterns on how to mitigate\nagainst potential risks associated with existing or emerging threats\ntargeting organisations, industries, sectors or governments.</p>\n<p><span style=\"font-size:1rem\">To mitigate against risks, we can start by trying to answer a few simple questions:</span></p><ul><li><span style=\"font-size:1rem\">Who's attacking you?</span></li><li><span style=\"font-size:1rem\">What's their motivation?</span></li><li><span style=\"font-size:1rem\">What are their capabilities?</span></li><li><span style=\"font-size:1rem\">What artefacts\nand indicators of compromise should you look out for?</span></li></ul>\n<h3><span style=\"font-size:24px\">Threat Intelligence Classifications:</span><p style=\"text-align:center\"><iframe style=\"border:none\" width=\"800\" height=\"475\" src=\"https://rive.app/s/LLWWBQuit0iINEGlCOycHA/embed\" allowfullscreen allow=\"autoplay\"></iframe></p></h3>\n\n<div style=\"font-family:Inter, -apple-system, system-ui, &quot;Segoe UI&quot;, Roboto, Helvetica, Arial, sans-serif, &quot;Apple Color Emoji&quot;, &quot;Segoe UI Emoji&quot;, &quot;Segoe UI Symbol&quot;, &quot;Microsoft YaHei Light&quot;, sans-serif;font-variant-ligatures:normal;orphans:2;widows:2;text-decoration-thickness:initial\"><p style=\"text-align:justify\"><span style=\"font-family:Ubuntu\">Threat Intel is geared towards understanding the relationship between your operational environment and your adversary. With this in mind, we can break down threat intel into the following classifications: </span></p></div><div style=\"font-family:Inter, -apple-system, system-ui, &quot;Segoe UI&quot;, Roboto, Helvetica, Arial, sans-serif, &quot;Apple Color Emoji&quot;, &quot;Segoe UI Emoji&quot;, &quot;Segoe UI Symbol&quot;, &quot;Microsoft YaHei Light&quot;, sans-serif;font-variant-ligatures:normal;orphans:2;widows:2;text-decoration-thickness:initial\"><ul><li style=\"text-align:justify\"><strong><span style=\"font-family:Ubuntu\">Strategic Intel:</span></strong><span style=\"font-family:Ubuntu\"> High-level intel that looks into the organisation's threat landscape and maps out the risk areas based on trends, patterns and emerging threats that may impact business decisions.</span></li><li style=\"text-align:justify\"><strong><span style=\"font-family:Ubuntu\">Technical Intel:</span></strong><span style=\"font-family:Ubuntu\"> Looks into evidence and artefacts of attack used by an adversary. Incident Response teams can use this intel to create a baseline attack surface to analyse and develop defence mechanisms.</span></li><li style=\"text-align:justify\"><strong><span style=\"font-family:Ubuntu\">Tactical Intel:</span></strong><span style=\"font-family:Ubuntu\"> Assesses adversaries' tactics, techniques, and procedures (TTPs). This intel can strengthen security controls and address vulnerabilities through real-time investigations.</span></li><li style=\"text-align:justify\"><strong><span style=\"font-family:Ubuntu\">Operational Intel:</span></strong><span style=\"font-family:Ubuntu\"> Looks into an adversary's specific motives and intent to perform an attack. Security teams may use this intel to understand the critical assets available in the organisation (people, processes, and technologies) that may be targeted.</span></li></ul></div>"},{"_id":"620176a442023100498a13a6","id":3,"questions":[{"hint":"","question":"What was TryHackMe's Cisco Umbrella Rank based on the screenshot?","questionNo":1,"disableAnswerPlaceholder":false},{"hint":"","question":"<p>How many domains did UrlScan.io identify <span style=\"font-size:1rem\">on the screenshot</span><span style=\"font-size:1rem\">?</span></p>","questionNo":2,"disableAnswerPlaceholder":false},{"hint":"","question":"<p>What was the main domain registrar listed <span style=\"font-size:1rem\">on the screenshot</span><span style=\"font-size:1rem\">?</span></p>","questionNo":3,"disableAnswerPlaceholder":false},{"hint":"","question":"<p>What was the main IP address identified for TryHackMe on the screenshot?<br /></p>","questionNo":4,"disableAnswerPlaceholder":false}],"type":"none","title":"UrlScan.io","taskNo":3,"created":"2022-02-07T19:44:36.758Z","deadline":null,"uploadId":"","description":"<p style=\"text-align:left\"><a href=\"https://urlscan.io\" target=\"_blank\"><b>Urlscan.io</b></a> is a free service developed to assist in scanning and\nanalysing websites. It is used to automate the process of browsing and\ncrawling through websites to record activities and interactions.</p>\n<p>When a URL is submitted, the information recorded includes the\ndomains and IP addresses contacted, resources requested from the\ndomains, a snapshot of the web page, technologies utilised and other\nmetadata about the website.</p>\n<p>The site provides two views, the first one showing the most recent\nscans performed and the second one showing current live scans.</p>\n<p style=\"text-align:center\"> <img src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/db3fb7276dd4c303a5ef7aa04a2ad8a0.gif\" alt=\"Live Scans Page\" style=\"width:749.148px;height:621.629px\" /></p><div style=\"font-variant-ligatures:normal;orphans:2;widows:2;text-decoration-thickness:initial\">\n<h2><span style=\"font-size:24px\">Scan Results</span></h2>\n<p>\nURL scan results provide ample information, with the following key areas being essential to look at:\n\n</p>\n<ul>\n<li> <strong>Summary:</strong> Provides general information about the URL, ranging from the identified IP address, domain registration details, page history and a screenshot of the site. </li>\n\n<li> <strong> HTTP:</strong> Provides information on the HTTP connections made by the scanner to the site, with details about the data fetched and the file types received. </li>\n\n<li> <strong>Redirects:</strong> Shows information on any identified HTTP and client-side redirects on the site. </li>\n\n<li> <strong>Links:</strong> Shows all the identified links outgoing from the site's homepage. </li>\n\n<li> <strong>Behaviour:</strong> Provides details of the variables and cookies found on the site. These may be useful in identifying the frameworks used in developing the site. </li>\n\n<li> <strong>Indicators:</strong> Lists all IPs, domains and hashes associated with the site. These indicators do not imply malicious activity related to the site.</li>\n</ul>\n\n\n<p style=\"text-align:center\"><img src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/5ba68bbdd6e7e9ef2bbe2a0dc13106bc.gif\" alt=\" URL Scan results for the English Premier League site\" style=\"width:100%\" /><span style=\"font-family:Ubuntu\"><br /></span></p><p style=\"text-align:left\"><span style=\"font-family:Ubuntu\"><b>Note</b>: Due to the dynamic nature of internet activities, data searched can produce different results on different days as new information gets updated.</span></p>\n\n<h3><span style=\"font-family:Ubuntu;font-size:24px\">Scenario</span></h3>\n\n</div><div style=\"font-family:Inter, -apple-system, system-ui, &quot;Segoe UI&quot;, Roboto, Helvetica, Arial, sans-serif, &quot;Apple Color Emoji&quot;, &quot;Segoe UI Emoji&quot;, &quot;Segoe UI Symbol&quot;, &quot;Microsoft YaHei Light&quot;, sans-serif;font-variant-ligatures:normal;orphans:2;widows:2;text-decoration-thickness:initial\"><p><span style=\"font-family:Ubuntu\">You have been tasked to perform a scan on TryHackMe's domain. The results obtained are displayed in the image below. Use the details on the image to answer the questions:</span></p><p><img src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/322ccb4ad9e4a6cd7e2998ba6def47ec.png\" alt=\"TryHackMe URL Results\" style=\"width:100%\" /><span style=\"font-family:Ubuntu\"><br /></span></p></div>\n\n\n\n"},{"_id":"624b09f20b33e800492457d1","id":4,"questions":[{"hint":"Search%20through%20the%20ThreatFox%20database%20using%20the%20syntax%20ioc%3A%3Cip%20here%3E%20and%20you%20will%20find%20the%20malware%20alias%20name.","question":"The IOC <b>212.192.246.30:5555 </b>is identified under which malware alias name on ThreatFox?<br />","questionNo":1,"disableAnswerPlaceholder":false},{"hint":"","question":"<p>Which malware is associated with the JA3 Fingerprint <b>51c64c77e60f3980eea90869b68c58a8</b><span style=\"font-size:1rem\"> on SSL Blacklist?</span></p>","questionNo":2,"disableAnswerPlaceholder":false},{"hint":"","question":"<p>From the statistics page on URLHaus, what malware-hosting network has the ASN number <b>AS14061</b>? <br /></p>","questionNo":3,"disableAnswerPlaceholder":false},{"hint":"","question":"<p>Which country is the botnet IP address <b>178.134.47.166</b> associated with according to FeodoTracker?<br /></p>","questionNo":4,"disableAnswerPlaceholder":false}],"type":"none","title":"Abuse.ch","taskNo":4,"created":"2022-04-04T15:08:34.187Z","deadline":null,"uploadId":"","description":"<p><a href=\"https://abuse.ch\" target=\"_blank\">Abuse.ch</a> is a research project hosted by the Institue for Cybersecurity and Engineering at the Bern University of Applied Sciences in Switzerland. It was developed to identify and track malware and botnets through several operational platforms developed under the project. These platforms are:</p>\n<ul>\n<li><strong>Malware Bazaar:</strong>  A resource for sharing malware samples.</li>\n<li><strong>Feodo Tracker:</strong>  A resource used to track botnet command and control (C2) infrastructure linked with Emotet, Dridex and TrickBot.</li>\n<li><strong>SSL Blacklist:</strong>  A resource for collecting and providing a blocklist for malicious SSL certificates and JA3/JA3s fingerprints.</li>\n<li><strong>URL Haus:</strong>  A resource for sharing malware distribution sites.</li>\n<li><strong>Threat Fox:</strong>  A resource for sharing indicators of compromise (IOCs).</li>\n</ul>\n<p>Let us look into these platforms individually.</p>\n<h2><a href=\"https://bazaar.abuse.ch\" target=\"_blank\"><span style=\"font-size:24px\">MalwareBazaar</span></a></h2>\n<p>As the name suggests, this project is an all in one malware collection and analysis database. The project supports the following features:</p>\n<ul>\n<li><strong>Malware Samples Upload:</strong> Security analysts can upload their malware samples for analysis and build the intelligence database. This can be done through the browser or an API.</li>\n<li><strong>Malware Hunting:</strong> Hunting for malware samples is possible through setting up alerts to match various elements such as tags, signatures, YARA rules, ClamAV signatures and vendor detection.</li>\n</ul>\n<p style=\"text-align:center\"><img style=\"width:100%\" src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/55890b3448b3ecf9a55705cd1bd20b08.gif\" alt=\"Malware Bazaar Dashboard\" /></p>\n<h2><a href=\"https://feodotracker.abuse.ch\" target=\"_blank\"><span style=\"font-size:24px\">FeodoTracker</span></a></h2>\n<p>With this project, Abuse.ch is targeting to share intelligence on botnet Command &amp; Control (C&amp;C) servers associated with Dridex, Emotes (aka Heodo), TrickBot, QakBot and BazarLoader/BazarBackdoor. This is achieved by providing a database of the C&amp;C servers that security analysts can search through and investigate any suspicious IP addresses they have come across. Additionally, they provide various IP and IOC blocklists and mitigation information to be used to prevent botnet infections.</p>\n<p><img style=\"width:100%\" src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/22e34a463f65fbf7e621a54e347543be.gif\" alt=\"Feodo Tracker Dashboard\" /></p>\n<p> </p>\n<h2><a href=\"https://sslbl.abuse.ch\" target=\"_blank\"><span style=\"font-size:24px\">SSL Blacklist</span></a></h2>\n<p>Abuse.ch developed this tool to identify and detect malicious SSL connections. From these connections, SSL certificates used by botnet C2 servers would be identified and updated on a denylist that is provided for use. The denylist is also used to identify JA3 fingerprints that would help detect and block malware botnet C2 communications on the TCP layer.</p>\n<p>You can browse through the SSL certificates and JA3 fingerprints lists or download them to add to your deny list or threat hunting rulesets.</p>\n<p><img style=\"width:100%\" src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/78bb7ba13a89c203b3ed331df18e2c4d.gif\" alt=\"SSL Blacklist Dashboard\" /></p>\n<h2><a href=\"https://urlhaus.abuse.ch\" target=\"_blank\"><span style=\"font-size:24px\">URLhaus</span></a></h2>\n<p>As the name points out, this tool focuses on sharing malicious URLs used for malware distribution. As an analyst, you can search through the database for domains, URLs, hashes and filetypes that are suspected to be malicious and validate your investigations.</p>\n<p>The tool also provides feeds associated with country, AS number and Top Level Domain that an analyst can generate based on specific search needs.</p>\n<p><img style=\"width:100%\" src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/f388122492011e9506410912afd749d1.gif\" alt=\"URLHaus Dashboard\" /></p>\n<h2><a href=\"https://threatfox.abuse.ch\" target=\"_blank\"><span style=\"font-size:24px\">ThreatFox</span></a></h2>\n<p>With ThreatFox,  security analysts can search for, share and export indicators of compromise associated with malware. IOCs can be exported in various formats such as MISP events, Suricata IDS Ruleset, Domain Host files, DNS Response Policy Zone, JSON files and CSV files.</p>\n<p><img style=\"width:100%\" src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/e0fffff3133f4641f85190228990bdfb.gif\" alt=\"ThreatFox Dashboard\" /></p>"},{"_id":"620176dd42023100498a15f2","id":5,"questions":[{"hint":"Use Thunderbird to open the email and you should recognise the famous social platform via the logo.","question":"<p>What social media platform is the attacker trying to pose as in the email?</p>","questionNo":1,"disableAnswerPlaceholder":false},{"hint":"","question":"What is the senders email address?<br />","questionNo":2,"disableAnswerPlaceholder":false},{"hint":"","question":"<p>What is the recipient's email address?</p>","questionNo":3,"disableAnswerPlaceholder":false},{"hint":"Cyberchef has a defang recipe","question":"<p>What is the Originating IP address? Defang the IP address.</p>","questionNo":4,"disableAnswerPlaceholder":false},{"hint":"","question":"<p>How many hops did the email go through to get to the recipient?<br /></p>","questionNo":5,"disableAnswerPlaceholder":false}],"type":"vm","title":"PhishTool","taskNo":5,"created":"2022-02-07T19:45:33.301Z","deadline":null,"uploadId":"67a8aefad08d1f35157a7b83","description":"<p style=\"text-align:justify\"><span style=\"text-align:left\">Before going into the task, click the </span><span style=\"font-weight:bolder;text-align:left\">Start Lab Machine</span><span style=\"text-align:left\"> button to start the attached VM and open it in Split View. You will be using the same machine through tasks 7 and 8.</span></p>\n<p style=\"text-align:justify\">This task will introduce you to a tool, <strong>PhishTool,</strong> that you would add to your toolkit of email analysis tools. Please take note that it would not be necessary to use it to complete the task; however, the principles learnt would be helpful.</p>\n<h2><span style=\"font-size:24px\">Email Phishing</span></h2>\n<p style=\"text-align:justify\">Email phishing is one of the main precursors of any cyber attack. Unsuspecting users get duped into opening and accessing malicious files and links sent to them by email, as they appear to be legitimate. As a result, adversaries infect their victims’ systems with malware, harvesting their credentials and personal data and performing other actions such as financial fraud or conducting ransomware attacks.</p>\n<p style=\"text-align:justify\">For more information and content on phishing, check out these rooms:</p>\n<ul>\n<li style=\"text-align:justify\"><a href=\"https://tryhackme.com/room/phishingemails1tryoe\">Phishing Emails 1</a></li>\n<li style=\"text-align:justify\"><a href=\"https://tryhackme.com/room/phishingemails2rytmuv\">Phishing Emails 2</a></li>\n<li style=\"text-align:justify\"><a href=\"https://tryhackme.com/room/phishingemails3tryoe\">Phishing Emails 3</a></li>\n<li style=\"text-align:justify\"><a href=\"https://tryhackme.com/room/phishingemails4gkxh\" target=\"_blank\">Phishing Emails 4</a></li>\n<li style=\"text-align:justify\"><a href=\"https://tryhackme.com/room/phishingemails5fgjlzxc\" target=\"_blank\">Phishing Emails 5</a></li>\n</ul>\n<p style=\"text-align:justify\"><a href=\"https://www.phishtool.com\">PhishTool</a> seeks to elevate the perception of phishing as a severe form of attack and provide a responsive means of email security. Through email analysis, security analysts can uncover email IOCs, prevent breaches and provide forensic reports that could be used in phishing containment and training engagements.</p>\n<p style=\"text-align:justify\">PhishTool has two accessible versions: <strong>Community</strong> and <strong>Enterprise</strong>. We shall mainly focus on the Community version and the core features in this task. Sign up for an account via this <a href=\"https://app.phishtool.com/sign-up/community\" target=\"_blank\">link</a> to use the tool. <strong>Note</strong>: The tool may be geo-blocked in some locations, and therefore you can take appropriate action towards accessing it.</p>\n<p style=\"text-align:justify\">The core features include:</p>\n<ul>\n<li style=\"text-align:justify\"><strong>Perform email analysis:</strong> PhishTool retrieves metadata from phishing emails and provides analysts with the relevant explanations and capabilities to follow the email’s actions, attachments, and URLs to triage the situation.</li>\n<li style=\"text-align:justify\"><strong>Heuristic intelligence:</strong> OSINT is baked into the tool to provide analysts with the intelligence needed to stay ahead of persistent attacks and understand what TTPs were used to evade security controls and allow the adversary to social engineer a target.</li>\n<li style=\"text-align:justify\"><strong>Classification and reporting:</strong> Phishing email classifications are conducted to allow analysts to take action quickly. Additionally, reports can be generated to provide a forensic record that can be shared.</li>\n</ul>\n<p style=\"text-align:justify\">Additional features are available on the Enterprise version:</p>\n<ul>\n<li style=\"text-align:justify\">Manage user-reported phishing events.</li>\n<li style=\"text-align:justify\">Report phishing email findings back to users and keep them engaged in the process.</li>\n<li style=\"text-align:justify\">Email stack integration with Microsoft 365 and Google Workspace.</li>\n</ul>\n<p style=\"text-align:justify\">We are presented with an upload file screen from the Analysis tab on login. Here, we submit our email for analysis in the stated file formats. Other tabs include:</p>\n<ul>\n<li style=\"text-align:justify\"><strong>History:</strong> Lists all submissions made with their resolutions.</li>\n<li style=\"text-align:justify\"><strong>In-tray:</strong> An Enterprise feature used to receive and process phish reports posted by team members through integrating Google Workspace and Microsoft 365.</li>\n</ul>\n<p style=\"text-align:center\"><img style=\"width:969.821262886598px;height:437.140625px\" src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/4c5d66d92d6aeb83d67961be5239842d.png\" alt=\"PhishTool Dashboard\" /></p>\n<h3><span style=\"font-size:1.5rem\">Analysis Tab</span></h3>\n<p style=\"text-align:justify\">Once uploaded, we are presented with the details of our email for a more in-depth look. Here, we have the following tabs:</p>\n<ul>\n<li style=\"text-align:justify\"><strong>Headers:</strong> Provides the routing information of the email, such as source and destination email addresses, Originating IP and DNS addresses and Timestamp.</li>\n<li style=\"text-align:justify\"><strong>Received Lines:</strong> Details on the email traversal process across various SMTP servers for tracing purposes.</li>\n<li style=\"text-align:justify\"><strong>X-headers:</strong> These are extension headers added by the recipient mailbox to provide additional information about the email.</li>\n<li style=\"text-align:justify\"><strong>Security:</strong> Details on email security frameworks and policies such as Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC).</li>\n<li style=\"text-align:justify\"><strong>Attachments:</strong> Lists any file attachments found in the email.</li>\n<li style=\"text-align:justify\"><strong>Message URLs:</strong> Associated external URLs found in the email will be found here.</li>\n</ul>\n<p style=\"text-align:justify\">We can further perform lookups and flag indicators as malicious from these options. On the right-hand side of the screen, we are presented with the Plaintext and Source details of the email.</p>\n<p style=\"text-align:justify\"><img style=\"width:100%\" src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/03364f3a4fb2177cce13abc3b181bca9.gif\" alt=\"Email analysis\" /></p>\n<p style=\"text-align:justify\">Above the <strong>Plaintext</strong> section, we have a <strong>Resolve</strong> checkmark. Here, we get to perform the resolution of our analysis by classifying the email, setting up flagged artefacts and setting the classification codes. Once the email has been classified, the details will appear on the <strong>Resolution</strong> tab on the analysis of the email.</p>\n<p style=\"text-align:justify\"><img style=\"width:100%\" src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/b13d63d0c2fe177085a1b487efb4065e.gif\" alt=\"Email investigation resolution\" /></p>\n<p style=\"text-align:justify\">You can now add <strong>PhishTool </strong>to your list of email analysis tools.</p>\n<p style=\"text-align:justify\"> </p>\n<h2><span style=\"font-size:24px\">Scenario</span></h2>\n<div style=\"text-align:justify\">You are a SOC Analyst and have been tasked to analyse a suspicious email, <strong>Email1.eml</strong>. To solve the task, open the email using <strong>Thunderbird </strong>on the attached VM, analyse it and answer the questions below.</div>","taskVmRegions":["us-east-1","ap-south-1","eu-west-1","eu-central-1","eu-west-3","us-west-2"],"hasUploadOwnership":false},{"_id":"620a4c9f269aa3005f574f9f","id":6,"questions":[{"hint":"Use the IP addressed discovered in Task 5 and search for it.","question":"<p>What is the listed network owner of the IP address from the previous task?</p>","questionNo":1,"disableAnswerPlaceholder":false},{"hint":"Perform a WHOIS lookup against the IP to identify the customer, if you cannot find the information on Talos.","question":"<p>What is the customer name of the IP address?</p>","questionNo":2,"disableAnswerPlaceholder":false}],"type":"none","title":"Cisco Talos Intelligence","taskNo":6,"created":"2022-02-14T12:35:43.456Z","deadline":null,"uploadId":"","description":"<p>IT and Cybersecurity companies collect massive amounts of information\nthat could be used for threat analysis and intelligence. Being\none of those companies, Cisco assembled a large team of security practitioners\ncalled Cisco Talos to provide actionable intelligence, visibility on\nindicators, and protection against emerging threats through data\ncollected from their products. The solution is accessible as <a href=\"https://talosintelligence.com\" target=\"_blank\">Talos Intelligence</a>.</p>\n<p>Cisco Talos encompasses six key teams:</p>\n<ul>\n<li><strong>Threat Intelligence &amp; Interdiction:</strong> Quick\ncorrelation and tracking of threats provide a means to turn simple IOCs\ninto context-rich intel.</li>\n<li><strong>Detection Research:</strong> Vulnerability and malware\nanalysis is performed to create rules and content for threat\ndetection.</li>\n<li><strong>Engineering &amp; Development:</strong> Provides the\nmaintenance support for the inspection engines and keeps them up-to-date to identify and triage emerging threats.</li>\n<li><strong>Vulnerability Research &amp; Discovery:</strong> Working\nwith service and software vendors to develop repeatable means of\nidentifying and reporting security vulnerabilities.</li>\n<li><strong>Communities:</strong> Maintains the image of the team and\nthe open-source solutions.</li>\n<li><strong>Global Outreach:</strong> Disseminates intelligence to\ncustomers and the security community through publications.</li>\n</ul>\n<p>More information about Cisco Talos can be found on their <a href=\"https://www.talosintelligence.com/docs/Talos_WhitePaper.pdf\">White\nPaper</a></p>\n<h2><span style=\"font-size:24px\">Talos Dashboard</span></h2>\n<p>Accessing the open-source solution, we are first presented with a\nreputation lookup dashboard with a world map. This map shows an\noverview of email traffic with indicators of whether the emails are\nlegitimate, spam or malware across numerous countries. Clicking on any\nmarker, we see more information associated with IP and hostname\naddresses, volume on the day and the type.</p>\n<p><img src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/e8ad635a9e449c698e081895bbb13ab1.png\" alt=\"Talos Dashboard\" style=\"width:100%\" /><span style=\"font-size:1rem\"><br /></span></p><p><span style=\"font-size:1rem\">At the top, we have several tabs that provide different types of\nintelligence resources. The primary tabs that an analyst would interact\nwith are:</span><br /></p>\n<ul>\n<li><strong>Vulnerability Information:</strong> Disclosed and zero-day\nvulnerability reports marked with CVE numbers and CVSS scores. Details\nof the vulnerabilities reported are provided when you select a specific\nreport, including the timeline taken to get the report published.\nMicrosoft vulnerability advisories are also provided, with the\napplicable snort rules that can be used.</li>\n</ul>\n<p><img src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/c761ada971950f5c2b676263d6e328a8.gif\" alt=\"Talos Vulnerability Information Navigation\" style=\"width:100%\" /></p>\n<ul>\n<li><strong>Reputation Center:</strong> Provides access to searchable\nthreat data related to IPs and files using their SHA256 hashes.\nAnalysts would rely on these options to conduct their investigations.\nAdditional email and spam data can be found under the <strong>Email\n&amp; Spam Data tab</strong>.</li>\n</ul>\n<p><img src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/e14c377b524b9eb51b0a8ed8f1ee8356.gif\" alt=\"Talos Reputation Center\" style=\"width:100%\" /></p><p><br /></p>\n\n<p>\n<img src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/844f12e63a5a255b85df2ad6d261facb.gif\" alt=\"Talos Reputation Center\" style=\"width:100%\" /></p>\n<h2><span style=\"font-family:Ubuntu;font-size:24px\">Task</span></h2>\n<p>Use the information gathered from inspecting the <b>Email1.eml</b> file from Task 5<span style=\"font-weight:600\" class=\"notion-enable-hover\"> </span>to answer the following questions using Cisco Talos Intelligence. Please note that the VM launched in Task 5 would not have access to the Internet.<br /></p>"},{"_id":"620a4cd2269aa3005f57522d","id":7,"questions":[{"hint":"","question":"According to <b>Email2.eml</b>, what is the recipient's email address?","questionNo":1,"disableAnswerPlaceholder":false},{"hint":"","question":"<p>On VirusTotal, which year recorded the first submission details of the mentioned file?</p>","questionNo":2,"disableAnswerPlaceholder":false}],"type":"none","title":"Scenario 1","taskNo":7,"created":"2022-02-14T12:36:34.633Z","deadline":null,"uploadId":"","description":"<p style=\"text-align:center\"><img src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/8e3277d4996e27e57bcc63ae0705549e.png\" style=\"width:700.225024px;height:492px\" alt=\"A team of THM Security Analysts.\" /></p>\n<p><span style=\"font-size:1rem\"><b>Scenario</b></span><span style=\"font-size:1rem\"><b>:</b> You are a SOC Analyst. Several suspicious emails have been forwarded to you from other coworkers. You must obtain details from each email to triage the incidents reported. </span><br /></p><p><b>Task</b>: Use the tools and knowledge discussed throughout this room (or use your resources) to help you analyze<span style=\"font-size:1rem\"> </span><b style=\"font-size:1rem\">Email2.eml</b><b style=\"font-size:1rem\"> </b><span style=\"font-size:1rem\">found on the VM attached to <b>Task 5</b> </span><span style=\"font-size:1rem\">and use the information to answer the questions.</span></p>"},{"_id":"625f1b26ddc51f005f53c745","id":8,"questions":[{"hint":"","question":"What is the name of the attachment on <span style=\"font-weight:bolder\">Email3.eml</span>?","questionNo":1,"disableAnswerPlaceholder":false},{"hint":"","question":"<p>What malware family is associated with the attachment on <span style=\"font-weight:bolder\">Email3.eml</span>?<br /></p>","questionNo":2,"disableAnswerPlaceholder":false}],"type":"none","title":"Scenario 2","taskNo":8,"created":"2022-04-19T20:27:18.847Z","deadline":null,"uploadId":"","description":"<p style=\"text-align:center\"><img src=\"https://cdn-images.tryhackme.com/user-uploads/5fc2847e1bbebc03aa89fbf2/room-content/8e3277d4996e27e57bcc63ae0705549e.png\" style=\"width:700.225024px;height:492px\" alt=\"A team of THM Security Analysts.\" /></p>\n<p><span style=\"font-size:1rem\"><span style=\"font-weight:bolder\">Scenario</span></span><span style=\"font-size:1rem\"><span style=\"font-weight:bolder\">:</span> You are a SOC Analyst. Several suspicious emails have been forwarded to you from other coworkers. You must obtain details from each email to triage the incidents reported. </span><br /></p><p>Task: Use the tools and knowledge discussed throughout this room (or use your resources) to help you analyze<span style=\"font-size:1rem\"> </span><b><span style=\"font-size:1rem\">Email3.eml</span><span style=\"font-size:1rem\"> </span></b><span style=\"font-size:1rem\">found on the VM attached to <b>Task 5</b> </span><span style=\"font-size:1rem\">and use the information to answer the questions.</span><br /></p>"},{"_id":"623cc56d613737004281e117","id":9,"questions":[{"hint":"","question":"Read the above and completed the room","questionNo":1,"disableAnswerPlaceholder":false}],"type":"none","title":"Conclusion","taskNo":9,"created":"2022-03-24T19:24:29.671Z","deadline":null,"uploadId":"","description":"<h2><span style=\"font-size:24px\">﻿</span><span style=\"font-size:24px\">There's More Out There</span></h2>\n<p>You have come to the end of the room. However, this is just the tip of the iceberg for open-source threat intelligence tools that can help you as an analyst triage through incidents. There are plenty of more tools that may have more functionalities than the ones discussed in this room.</p><p>Check out these rooms to dive deeper into Threat Intelligence:</p><ul><li><a href=\"https://tryhackme.com/room/yara\" target=\"_blank\">Yara</a></li><li><a href=\"https://tryhackme.com/room/misp\" target=\"_blank\">MISP</a></li><li><a href=\"https://tryhackme.com/room/redteamthreatintel\" target=\"_blank\">Red Team Threat Intel</a></li></ul>"}]}