Misc Operations and Incident Response Flashcards

1
Q

Metasploit

A

Exploitation Framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Cuckoo

A

Malware-testing sandbox

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

theHarvester

A

open source intelligence gathering tool

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Nessus

A

Vulnerability scanner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

netstat -a

A

Can show all active connections in windows, using the -a flag

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

hping

A

A packet generator and analyzer. A packet analyzer and packet building tool often used to craft specific packets as part of penetration tests and attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Nessus

A

A popular vulnerability scanning tool - can also scan ports and identify open ports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

curl

A

The curl command-line tool supports downloads and uploads from a wide variety of services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

nmap

A

port scanner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

route

A

a command-line tool to view and add network traffic routes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

netstat

A

a command-line tool that shows network connections, interface statistics, and other useful information about a system’s network usage. does not incorporate automatic service identification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

memdump

A

a command-line memory dump utility that can dump physical memory - Linux

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

exiftool

A

metadata-retrieval tool

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

sn1per

A

A pen test framework. Can conduct a port scan and recognize open ports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

FTK Imager

A

a free tool that can image both systems and memory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

dd

A

Used to image drives. useful for capturing disks, not really for memory dumps.

17
Q

Autopsy

A

A forensic tool for drive analysis and forensic investigations. A forensic analysis tool and does not provide its own imaging tools

18
Q

Strings

A

command-line tool that retrieves strings from binary data

19
Q

Scanless

A

a tool described as a port scraper, which retrieves port information without running a port scan by using websites and services to run the scan for you

20
Q

WinHex

A

Disk Editor

21
Q

Logger

A

a Linux utility that will add information to the Linux syslog. It can accept file input, write to the system journal entry, send to remote syslog servers, and perform a variety of other functions

22
Q

tcpreplay

A

The tcpreplay tool is specifically designed to allow PCAP capture files to be replayed to a network, allowing exactly this type of testing

23
Q

tcpdump

A

Used to capture packets

24
Q

The Volatility framework

A

a purpose-built tool for the acquisition of random access memory (RAM) from a live system

25
Q

Netcat

A

a tool used to transfer data or to make connections to systems across a network

26
Q

journalctl

A

used to query the systemd journal. On systemd-enabled Linux distributions, the journal contains kernel and boot messages as well as syslog messages and messages from services