June 2019 Meetup Recap
Meetup Video
ColaSec Intro Slides
Presenter Info
Presenter Slides
May 2019 Meetup Recap
Meetup Video
ColaSec Intro Slides
Presenter Info
Presenter Slides
April 2019 Meetup Recap
Meetup Video
ColaSec Intro Slides
Presenter Info
Presenter Slides
March 2019 Meetup Recap
Meetup Video
ColaSec Intro Slides
Presenter Info
Presenter Slides
Soda City Battlegrounds Update for March 2019
Lots of progress was made during the last meetup. We now have pfSense setup and running as our primary firewall and have a distinct wireless network setup for accessing the battleground. Our next point of discussion will be how the internal parts of the network should be configured to allow each team access into the battleground without allowing access into areas that they should not be able to interact with. For example, we want the Purple team environment to be inaccessible from the Blue and Red team environments. We will also need to look into getting the VPN setup at some point. For now, the good news is that we can get into the battleground by connecting to it via wireless rather than a cable.
As always, we would like to encourage everyone (experienced or not) to come out to the meetups. We have been having them consistently every other Thursday at Whit E. Octopus. We usually get started around 6:30 PM and go until 8ish (depending on how much progress we are making).
The next meetup at the time of posting this will be March 28th.
February 2019 Meetup Recap
Josh Huff presents OSINT: Breach Data, Ethics, and OpSec... Oh My!
What does breach data look like? Is breach data ethical? How can they be used? What does breach data teach us about privacy and security awareness? What can we do to protect our own data against a breach? Using real-world examples, we’ll discuss these questions and provide resources you can use to leverage breach data in your own investigation.
Read MoreSoda City Battlegrounds Update
Tonight we completed a final inventory of our hardware and identified the go-forward hardware for SCBG. We have a few systems that should be outstanding for phase 1 and are ready to get started after a couple more sessions.
We also permanently racked the firewall, switch, and KVM switch. As a consequence of this, the cables that were previously run for this gear no longer works, so we've striped all of the networking cables.
Next up, on January 31:
Establish cable routes for data, KVM, and power.
Re-cable every server such that they can be serviced independently.
Establish basic connectivity with the gateway from each host.
Extra credit:
Get the Dell storage array working so we can have a sweet SAN
When everything above has been accomplished we'll build a basic remotely accessible VM lab on a single host. This lab will host a network segment for intentionally vulnerable training VMs, set to revert weekly.
Once we get that working regularly, I want to get a contained subnet built with packet capture & security onion upstream to host the known compromised hosts for forensic analysis.
After that it's on to phase 2.
January 2019 Meetup Recap
Meetup Video
ColaSec Intro Slides
Presenter Info
Presenter Slides
December 2018 Meetup Recap
Thanks to everyone for making 2018 another wonderful year for ColaSec!
November 2018 Meetup Recap
Announcements and Intro
Presentation
October 2018 Meetup Recap
Announcements and Intro
Presentation
September 2018 Meetup Recap
Announcements and Intro
Presentation
Investigating NIDS Alerts and Configuring Snort to run within Wireshark
Presented By:David Burkett
We'll cover some really basic stuff to a bit more advanced:
- How full packet capture is typically done
- What Netflow is and how it is typically used
- How Network IDS's typically work
- The anatomy of a Snort rule
- Basic Wireshark
- PCAP Analysis over PCAP Samples that contain actual malware traffic
- How to investigate NIDS alerts without Full PCAP
The only requirement to follow along (Highly recommended! It's the best way to learn!) is an Ubuntu 18.04 or newer Virtual Machine with a minimum of 2 Gig of memory. (More memory is better)
August 2018 Meetup Recap
Announcements and Intro
Presentation
July 2018 Meetup Recap
Much thanks to LockFALE for making the July meetup a great success! Click the logo to be taken to their site for more information.




June 2018 Meetup Recap
Announcements and Intro
Presentation
May 2018 Meetup Recap
Announcements and Intro
Presentation
April 2018 Meetup Recap
Announcements and Intro
Presentation
March 2018 Meetup Recap
Announcements and Intro
Presentation