Redline Analysis Lab Part 1
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *
Already have an account? Sign In »
1 hour 21 minutes
Hello. My name's David. Welcome to analyzing attacks. Fellow journey er's
to the realm of knowledge.
Yes. Well, I don't know about you, but in our last episode, we ran our red line analysis
on an infected machine virtual machine in order to get some line memory analysis underway. So we had loaded up our redline lab. Right here was this folder is open, and we also began running her dot t x C,
which we had downloaded from the Internet.
Now, as you can see, I had my process hacker open. So it is running. So what I can do is now actually terminate that process and get it off of a system that's running
now for future reference for uses. So
we're on the same path here now that I've run this in my Windows virtual machine. If I'm not gonna use this portable receiver, anything else I'm gonna restored back through steak? That way, any other kind of analysis lab work that I do will possibly be affected.
The infection I caused during this lab Now, in real world, that's too, because every time you do analysis, you want start clean system. That way, there's no contamination from prior infections that you ride or anything along those lines.
Now we can see that the audience folder was created here in my analysis session one. And the good thing about Red Line is you could run this across multiple systems, and then each analysis session's gonna be named something different. In this case of Alice, Session one, in some instances in, they
start naming them by the system name so that you can identify them when you go back to begin your analysis and in large outbreaks
of Mount where, where you're doing memory analysis for several machines, that's pretty handy, especially if you're utilizing a nice size. It's hard drive. Remember, what's one of the limitations of memory analysis?
Right? Your image has to fit onto the extra drive, along with any other
analysis that you get. So if we look here at our analysis session and check our properties out, we're going to see its nine gigs so we can't use a four gig come Dr thinking that
we're going to store all this data on it, it's gonna have to be
either an external hard drive over a very large thumb drive on in today's day and age. Of course, that's not hurt under on it. So you can take a look here. You can see some of the different files that have been created by red line. And if you want to be really curation started Mina 1 40
at one. Ooh,
See, you're one of three looks like
and it ran all the way down to 1 41
So it took Ah, roughly almost 40 minutes to run on this system itself. Right here. Now, since I haven't saved, what I want to do is get a copy off of my, um,
virtual machine, and I want to carry it over to my announced system. Now, in real world, you would do this via thumb drive. You bring some drive back
implanted into your announced system on DDE,
you realize in then to denounce is not, I repeat, not going to do this analysis on the infected machine on Di did repeat that because it sometimes people being in Russia at starting the analysis on the sheet and
it creates a whole other problem. So you want to wait, if at all possible.
Hopefully this year's there. Okay, I have run into some technical issues. Transferring Stiles. Look, for whatever reason, somebody's in my VM where that's like cotton them out on my machine on
there's the problem.
What's open this back up.
We can't possibly do something a little different here.
I love the fact that I'm Moses when she hears my red line. See Pinky copy out this way.
And unfortunately, some of this is the kind of things we're gonna run into our world. I've watched a lot of labs online. We're not smoothly functioning on. They don't run into any kind of technical issues. That's not the real world, just Italian. You need to be able to troubleshoot the tools that you're using,
because you're gonna have to do in the real world. So even in labs like this one, on any others that you run, you need to be able to actually troubleshoot through way through any issues that you might love it. And, you know, you can ask yourself questions. I could this be because I'm *** lives only, um,
therefore, kinds of the areas like that can cause problems
in the transfer of this information out
on. We'll see here. This one works
says, Let's cancel and P file in Berkeley. Machine is interested.
That did not correct Harry. Oh,
so since we
I need this device
Well, Jean, you're not walking after, says reacted. It's an added.
I said I was the only change that
So what I will do. Don't take my Sessions folder copy and this seems like Han drop out the entire file. Since it's probably a little bit smaller, we will work a little bit
just talking to my wife and blabbing because I was letting this run thought erl aside and she was like, Why aren't you in there recording your videos and we'll win? Am I supposed to do just that? They're insane to the audience while I wait for you to run in and you see, it's a minute troubling,
so you would have had a good 40 minutes
of my annoying, melodious voice seeing Europe. We had actually done it that way. Now, hopefully this method will work and who their session files out so we can take a look at it in red line. Unfortunately, this is the kind of thing which face again, like I said
in the real world, troubleshooting and try it.
Figure out what the problem. This and it looks like this is going to work. Now, I know this may seem like a waste of time to you for a lab, but again, 1/2 distress. You've got to be able to troubleshoot working away pursuit of some of these problems was leaves me now to say
so. It's pouring other avenues under the site security
Go learn some network plus go learn some A plus. That way you start getting good basic understanding of systems and networks. How work? In order to boost your own ability to handle incidents and understand what's going on in the background,
place those files in this case. Now, what I want to do is some of the parts, my beautiful machine.
Remember when I tell you to do with this,
Yes. Restore it back between version. I did not do it on that one. I'm just telling me that. So let's see. Here we have
are analyzed eight and you can see you've got different choices that you could rate so we could say from a safe file. Or we could say from a previous analysis,
Let's jump over here to desk up Here we have my lab. Red line.
It's X 64 with nothing, and we have six. Not so we've not done any analysis on the jet, which makes a certain amount of sense. So let's go back to 86. We've got nothing again and
It is puzzling me. So,
yes, we've got quite a procession.
Come in here and knock it. ISS. Now again, let's trouble few keys. Walk through this process. Now, when you see here is it's ready to go ready, I'll click it.
It will open it up in red line and begin to live. Now again, this is gonna take a little bit of time. Locusts and higher session up in the red line. So we're gonna pause a video, ready it low, and then when it gets truly later, we'll come back with a little work together. Take a look at some of the things that you might be able to learn from this.
Yeah, And from that particular consume our
Yeah, we don't nation you have any questions? I'm old library. Look for me, baby. 13 bodies. Be happy, Doctor.