General Operator Flashcards
Mission of N.B.T.
To assess and evaluate the security posture of Naval Networks.
IBTV
Requested by command. Command pays all expenses. Purpose is to train!
IBTV Stage II
Train and Assist IFOR. Used to help command fix any security hits
IBTV Stage III
Actual inspection used to score command (OCA assess network as is!)
5 Host Diagnostics
- Ping (Test Connection)
- Resolve DNS (ID’s Host IPs)
- WMI (Win Management Interface)
- Admin Share (Test Access)
- Remote Registries (Test Remote Access)
Blue Scope Services
P.S. Exec (Secondary Connection)
WMI (Primary connection)
How to connect to Blue Scope
Username?
IP?
Port?
Difference between Linux Host and Windows Virtual Machine?
Linux Host: All findings stored here
Win VM: Blue Scope Runs on…
What is the purpose of creating an input file for NMAP?
So it knows what to scan
XSLTPROC:
Command to convert the NMAP.xml to html file. Enables easy reading of data for operator.
Purpose of Nipper Tool?
Router Configuration. TELNET NOT Enabled!
Courier Card/Letter
Card: allows the carrying of classified material when out of area travel is not required
Letter: allows you to carry classified material on commercial travel
Letter of Transmittal (LOT)
Used for inventory of all gear. Point of contact is required to sign at the site verifying the arrival of all equipment
Creating an OU
Properties, Group Policy Tab, Check Block Inheritance. We use for User and Computer Accounts
What is the Attila Command?
Script on Linux (File path of data location) Anti-virus
Scans/Deploys
Browser Info Virus Definitions Windows User Accounts USB Detect Open Source
*Active scans use more bandwidth and run from bluescope. Deploys= Send to host machines, and host machines send back.
What do we use to analyze data?
Blue Scope (Collects) Sequel (Holds) Network Bench (Reviews)
Deploys
Snarf
Browser Info
Configure Payloads in Blue Scope
Use config button
Know Pythagoras path….
Stage II scoring sheet that we no longer use
Everyone Group vs Authenticated Group
Everyone group can be seen by anyone and the authenticated group only specific authenticated people.
How to start/stop SQL service?
Sudo service mysqld start/stop
5 sections of a report Explain Each
- Executive Summary
- Key Findings
- Analyst Comments
- Tables
- Score Sheet
- Mitigating guides/documents
- POC Forsight
NAT/Bridged
NAT: The ship’s network sees IP/MAC addresses as one for both the laptop and the VM. **Preferred method
Bridged: The ship’s network sees TWO IP/MAC address for both the laptop and the VM. *Is set as default.