{"id":2464,"date":"2026-03-11T19:30:00","date_gmt":"2026-03-11T19:30:00","guid":{"rendered":"https:\/\/zombierollz.blog\/?p=2464"},"modified":"2026-03-11T16:30:22","modified_gmt":"2026-03-11T16:30:22","slug":"brim","status":"publish","type":"post","link":"https:\/\/zombierollz.blog\/?p=2464","title":{"rendered":"Brim"},"content":{"rendered":"\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-9993c32c1328dd693a1a8890af126b5d wp-block-paragraph\"><a href=\"https:\/\/tryhackme.com\/room\/brim\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/tryhackme.com\/room\/brim<\/a><br>Created by: tryhackme<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"892\" height=\"811\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-10-115451.png\" alt=\"\" class=\"wp-image-2465\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-10-115451.png 892w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-10-115451-300x273.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-10-115451-768x698.png 768w\" sizes=\"auto, (max-width: 892px) 100vw, 892px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"863\" height=\"150\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-10-121559.png\" alt=\"\" class=\"wp-image-2466\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-10-121559.png 863w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-10-121559-300x52.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-10-121559-768x133.png 768w\" sizes=\"auto, (max-width: 863px) 100vw, 863px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"565\" height=\"401\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-10-130829.png\" alt=\"\" class=\"wp-image-2467\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-10-130829.png 565w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-10-130829-300x213.png 300w\" sizes=\"auto, (max-width: 565px) 100vw, 565px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"942\" height=\"286\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-10-130908.png\" alt=\"\" class=\"wp-image-2469\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-10-130908.png 942w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-10-130908-300x91.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-10-130908-768x233.png 768w\" sizes=\"auto, (max-width: 942px) 100vw, 942px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-ef32140840c2eee01f0582f015a48ee4 wp-block-paragraph\">&#8220;Process the &#8220;sample.pcap&#8221; file and look at the details of the first DNS log that appear on the dashboard. What is the &#8220;qclass_name&#8221;?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"642\" height=\"522\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-054550.png\" alt=\"\" class=\"wp-image-2470\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-054550.png 642w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-054550-300x244.png 300w\" sizes=\"auto, (max-width: 642px) 100vw, 642px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-10f3f472dcc59cc0b554e2d4467905c9 wp-block-paragraph\">&#8220;Double click to bring up an easy to read format of the logs. You can also right click then click &#8220;Open Details. &#8220;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"770\" height=\"690\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-054735.png\" alt=\"\" class=\"wp-image-2471\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-054735.png 770w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-054735-300x269.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-054735-768x688.png 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-fbe7433101edb34620991a55da130e45 wp-block-paragraph\">&#8220;Look at the details of the first NTP log that appear on the dashboard. What is the &#8220;duration&#8221; value?&#8221;<br><br>I had to reset my VM and relaunch the sample.pcap file as it was not populating the Duration for me. Once I did this, I had more logs and was able to see the duration time as well.<\/p>\n\n\n\n<figure class=\"wp-block-image alignwide size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"676\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-062123-1024x676.png\" alt=\"\" class=\"wp-image-2472\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-062123-1024x676.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-062123-300x198.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-062123-768x507.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-062123.png 1179w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-97509b8bc7ea2c7efee458972a13ae5d wp-block-paragraph\">&#8220;Look at the details of the STATS packet log that is visible on the dashboard. What is the &#8220;reassem_tcp_size&#8221;?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image alignwide size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"540\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-062301-1024x540.png\" alt=\"\" class=\"wp-image-2473\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-062301-1024x540.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-062301-300x158.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-062301-768x405.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-062301.png 1183w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-04a41ae362a69ec92c571c0a6a15d64b wp-block-paragraph\">In task 4, Default Queries, various search query filters are shown that can be used with Brim. If you have recently done any of the Zeek rooms, this will be familiar. We will be using a new pcap file, &#8220;task4-sample-b.pcap&#8221; for this task.<br><br>&#8220;Investigate the files. What is the name of the detected GIF file?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"611\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-064732-1024x611.png\" alt=\"\" class=\"wp-image-2474\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-064732-1024x611.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-064732-300x179.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-064732-768x458.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-064732.png 1187w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-efd1960e0dd6e5d7ecb28c735666fb02 wp-block-paragraph\">&#8220;Investigate the conn logfile. What is the number of the identified city names?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"876\" height=\"422\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-065400.png\" alt=\"\" class=\"wp-image-2475\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-065400.png 876w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-065400-300x145.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-065400-768x370.png 768w\" sizes=\"auto, (max-width: 876px) 100vw, 876px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-4eb64cb7b75ba1a840f21cb93fb520d3 wp-block-paragraph\">&#8220;Investigate the Suricata alerts. What is the Signature id of the alert category &#8220;Potential Corporate Privacy Violation&#8221;?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"880\" height=\"632\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-065730.png\" alt=\"\" class=\"wp-image-2476\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-065730.png 880w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-065730-300x215.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-065730-768x552.png 768w\" sizes=\"auto, (max-width: 880px) 100vw, 880px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-c3677978aa3f38be1609669915b98496 wp-block-paragraph\">I ended up doing the filter: alert.category==&#8221;Potential Corporate Privacy Violation&#8221; | sort alert.severity,alert.category<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"916\" height=\"494\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-070031.png\" alt=\"\" class=\"wp-image-2477\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-070031.png 916w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-070031-300x162.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-070031-768x414.png 768w\" sizes=\"auto, (max-width: 916px) 100vw, 916px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-cc0f85461db6893c3821bfa70d0695bc wp-block-paragraph\">Task 5, Use Cases, goes over examples of search queries that can be used when it comes to traffic analysis. Below are the basics.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"923\" height=\"622\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-070327.png\" alt=\"\" class=\"wp-image-2478\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-070327.png 923w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-070327-300x202.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-070327-768x518.png 768w\" sizes=\"auto, (max-width: 923px) 100vw, 923px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"953\" height=\"573\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-070358.png\" alt=\"\" class=\"wp-image-2479\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-070358.png 953w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-070358-300x180.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-070358-768x462.png 768w\" sizes=\"auto, (max-width: 953px) 100vw, 953px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"961\" height=\"109\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-070602.png\" alt=\"\" class=\"wp-image-2480\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-070602.png 961w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-070602-300x34.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-070602-768x87.png 768w\" sizes=\"auto, (max-width: 961px) 100vw, 961px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-5612a35d1f9ee9b185024da6b6a3ac35 wp-block-paragraph\">On to Task 6, Exercise: Threat Hunting with Brim | Malware C2 Detection! Make sure you open the &#8220;task6-malware-c2.pcap&#8221; pcap file. THM presents a technical step-by-step investigate of malicious C2 activities. In order to obtain the answers we need, it&#8217;s advised to follow along.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"667\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-073807-1024x667.png\" alt=\"\" class=\"wp-image-2481\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-073807-1024x667.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-073807-300x195.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-073807-768x500.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-073807.png 1125w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"388\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-074020-1024x388.png\" alt=\"\" class=\"wp-image-2485\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-074020-1024x388.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-074020-300x114.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-074020-768x291.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-074020-1536x583.png 1536w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-074020.png 1611w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"916\" height=\"489\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-074216.png\" alt=\"\" class=\"wp-image-2484\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-074216.png 916w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-074216-300x160.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-074216-768x410.png 768w\" sizes=\"auto, (max-width: 916px) 100vw, 916px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-6a5b482a04892a176fe35a5dfe42ed98 wp-block-paragraph\">&#8220;What is the name of the file downloaded from the CobaltStrike C2 connection?&#8221;<br><br>Using filter: event_type==&#8221;alert&#8221; | count() by alert.severity,alert.category | sort count<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"914\" height=\"481\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-074924-1.png\" alt=\"\" class=\"wp-image-2486\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-074924-1.png 914w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-074924-1-300x158.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-074924-1-768x404.png 768w\" sizes=\"auto, (max-width: 914px) 100vw, 914px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-117c42189d7965a96a1cd53e96d44e99 wp-block-paragraph\">&#8220;What is the number of CobaltStrike connections using port 443?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"623\" height=\"232\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-075241-1.png\" alt=\"\" class=\"wp-image-2487\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-075241-1.png 623w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-075241-1-300x112.png 300w\" sizes=\"auto, (max-width: 623px) 100vw, 623px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-5c8294dbe4b311758d27f711eae2772b wp-block-paragraph\">&#8220;There is an additional C2 channel in used the given case. What is the name of the secondary C2 channel?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"823\" height=\"728\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-080527.png\" alt=\"\" class=\"wp-image-2488\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-080527.png 823w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-080527-300x265.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-080527-768x679.png 768w\" sizes=\"auto, (max-width: 823px) 100vw, 823px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"283\" height=\"165\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-080555.png\" alt=\"\" class=\"wp-image-2489\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"602\" height=\"335\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-080647.png\" alt=\"\" class=\"wp-image-2490\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-080647.png 602w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-080647-300x167.png 300w\" sizes=\"auto, (max-width: 602px) 100vw, 602px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-be95db64d84392f018e64182fb3e40de wp-block-paragraph\">Our last task is involving crytpo mining! Make sure you open the pool &#8220;task7-crypto-mine.pcapng&#8221;.<br><br>&#8220;How many connections used port 19999?&#8221;<br><br>_path==&#8221;conn&#8221; | cut id.resp_p, service | sort | uniq -c | sort -r count<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"596\" height=\"508\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-092754.png\" alt=\"\" class=\"wp-image-2491\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-092754.png 596w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-092754-300x256.png 300w\" sizes=\"auto, (max-width: 596px) 100vw, 596px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-588440e1752db4b3210f73129ed5e8b0 wp-block-paragraph\">&#8220;What is the name of the service used by port 6666?&#8221;<br><br>Staying on this filter, we obtain our answer to this.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"614\" height=\"402\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-092945.png\" alt=\"\" class=\"wp-image-2492\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-092945.png 614w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-092945-300x196.png 300w\" sizes=\"auto, (max-width: 614px) 100vw, 614px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-8d10607e2c34c700838c203d60e71376 wp-block-paragraph\">&#8220;What is the amount of transferred total bytes to &#8220;101.201.172.235:8888&#8243;?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"657\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-094111-1024x657.png\" alt=\"\" class=\"wp-image-2493\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-094111-1024x657.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-094111-300x192.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-094111-768x493.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-094111.png 1138w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-56190c230b7c2fe44d0dff0c8447b8db wp-block-paragraph\">&#8220;What is the detected MITRE tactic id?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"882\" height=\"252\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-093348.png\" alt=\"\" class=\"wp-image-2494\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-093348.png 882w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-093348-300x86.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-093348-768x219.png 768w\" sizes=\"auto, (max-width: 882px) 100vw, 882px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"769\" height=\"689\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-093253.png\" alt=\"\" class=\"wp-image-2495\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-093253.png 769w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-11-093253-300x269.png 300w\" sizes=\"auto, (max-width: 769px) 100vw, 769px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>https:\/\/tryhackme.com\/room\/brimCreated by: tryhackme &#8220;Process the &#8220;sample.pcap&#8221; file and look at the details of the first DNS log that appear on the dashboard. What is the &#8220;qclass_name&#8221;?&#8221; &#8220;Double click to bring up an easy to read format of the logs. You can also right click then click &#8220;Open Details. &#8220; &#8220;Look at the details of the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2464","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"blocksy_meta":[],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts\/2464","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2464"}],"version-history":[{"count":2,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts\/2464\/revisions"}],"predecessor-version":[{"id":2496,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts\/2464\/revisions\/2496"}],"wp:attachment":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2464"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2464"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2464"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}