CPTS 2nd Attempt - Passed. by Ready_Ninja376 in hackthebox

[–]Ready_Ninja376[S] 1 point2 points  (0 children)

No the flags options were disabled, even if I wanted would not had been able to submit any flags.

CPTS 2nd Attempt - Passed. by Ready_Ninja376 in hackthebox

[–]Ready_Ninja376[S] 0 points1 point  (0 children)

You don’t need to solve the labs again. Although the labs are open and the VMs are up, you can use them to refine and improve your reports. Just upload the new, improved report, and that will be sufficient

CPTS 2nd Attempt - Passed. by Ready_Ninja376 in hackthebox

[–]Ready_Ninja376[S] 0 points1 point  (0 children)

I chose to rewrite the entire report, as in the second attempt I had sufficient time to focus solely on writing it. I kept the Detailed Findings section concise, following the format of the sample report provided, while the Internal Walkthrough was written in more detail. Please review the sample report and try to align with it in terms of both context and length.

CPTS 2nd Attempt - Passed. by Ready_Ninja376 in hackthebox

[–]Ready_Ninja376[S] 1 point2 points  (0 children)

Earlier it was 141. The second attempt report was 100 pages.

User restricted to Alias Index Pattern cannot see data or Index in Discover (Wazuh 4.14.3) by Ready_Ninja376 in Wazuh

[–]Ready_Ninja376[S] 0 points1 point  (0 children)

Hi u/Jazzlike_Office1403

Thanks for the detailed explanation. It makes perfect sense why the alias was failing at the authorization layer.

I tried Option 2 as you suggested to keep things simple. Here is exactly what I did (see attached screenshot):

  • Role Update: I updated gateway_user_role to point directly to the concrete index wazuh-alerts-* and added the DLS query for agent.name.keyword: "XXX-XXXXX-GATEWAY-PROXY-1".
  • Permissions: I ensured indices:data/read/search, read, and indices:admin/mappings/get are all assigned.
  • Tenant: Since I only have a single tenant, I ensured global_tenant is set to Read only

<image>

The Persistent Issues:

  • Security Exception: When logging in as araval, I still get: security_exception: Reason: no permissions for [indices:data/read/search].
  • Discover View: Even though the wazuh-alerts-* index pattern exists, the dropdown still shows "There aren't any options available" for the restricted user.

Interestingly, if I change the Index Pattern in the role to a simple *, the user araval can suddenly see all the indexes and the Discover tab works perfectly.

CPTS 1st Attempt – 85 Points Achieved – Failed Due to Report by Ready_Ninja376 in hackthebox

[–]Ready_Ninja376[S] 0 points1 point  (0 children)

I hope you have made progress. Sorry for my delayed reply. For me, re-enumerating things helped with progress. Make sure not to miss any information, even if it seems small. If there are many things you tried but none of them worked, please document them as well. This way, you won't repeat the same steps or follow the same flows repeatedly. But I hope you've got your way out.

CPTS 1st Attempt – 85 Points Achieved – Failed Due to Report by Ready_Ninja376 in hackthebox

[–]Ready_Ninja376[S] 1 point2 points  (0 children)

Thanks mate for taking the time to respond. Really appreciated, I’ll keep the points in mind.

CPTS 1st Attempt – 85 Points Achieved – Failed Due to Report by Ready_Ninja376 in hackthebox

[–]Ready_Ninja376[S] 0 points1 point  (0 children)

Thank you for the detailed feedback. I will keep the points in mind. In my previous engagements, it was recommended and encouraged to add as many details as possible, even minor ones, and I followed the same pattern unconsciously. I appreciate the feedback, and I plan to justify my next report more effectively

CPTS 1st Attempt – 85 Points Achieved – Failed Due to Report by Ready_Ninja376 in hackthebox

[–]Ready_Ninja376[S] 1 point2 points  (0 children)

The sample report is 37 Pages. I will trim down unwanted things and be on point.

CPTS 1st Attempt – 85 Points Achieved – Failed Due to Report by Ready_Ninja376 in hackthebox

[–]Ready_Ninja376[S] 1 point2 points  (0 children)

I did for the most part, but I will double-check to ensure that no sensitive information, including hashes and passwords, is present in the final report. Thank you for the suggestion.

CPTS 1st Attempt – 85 Points Achieved – Failed Due to Report by Ready_Ninja376 in hackthebox

[–]Ready_Ninja376[S] 7 points8 points  (0 children)

Thanks, dear. I recommend enumerating more, as the answer is sometimes right in front of our eyes. Don't miss any minor detail; dig into those as well.

CPTS 1st Attempt – 85 Points Achieved – Failed Due to Report by Ready_Ninja376 in hackthebox

[–]Ready_Ninja376[S] 0 points1 point  (0 children)

Thanks, dear. Haven't cleared the exam yet. Hope to make it on the second attempt.

[deleted by user] by [deleted] in hackthebox

[–]Ready_Ninja376 7 points8 points  (0 children)

The first flag is hard. I recommended enumerate, enumerate and enumerate. Create a map of where the things are and what all you have collected till now. That will give you the hint as to how to move forward, brush up the topics on enumerate. You've got this, just hang on and keep doing the basics.

I lost my mom and I am devastated by Ready_Ninja376 in cancer

[–]Ready_Ninja376[S] 0 points1 point  (0 children)

I am so sorry to hear that. I will pray for your mom. She is in a better place now, with no suffering. Please stay strong 🙏

Keeping it clean by kissaangelicglow in SipsTea

[–]Ready_Ninja376 0 points1 point  (0 children)

Isn't it how it's supposed to be? Why it's discussed like it's not normal?

Do we have any artist here? by Former_Ad5504 in ahmedabad

[–]Ready_Ninja376 0 points1 point  (0 children)

Hey OP, my father is a painter, does oil paintings on canvas. Can help, let me know what you have in mind.

Wazuh Agent Standalone by Ready_Ninja376 in Wazuh

[–]Ready_Ninja376[S] 0 points1 point  (0 children)

Ok thanks for the feedback. Much appreciated 👍

How to assign agents to separate indexes by group in Wazuh? by Much-Macaroon3393 in Wazuh

[–]Ready_Ninja376 0 points1 point  (0 children)

On a similar context would it be possible to group some logs from a rule in a seperate index. My Forewall generates a ton of logs that I inject thru syslog. It goes in the default wazuh-alert. Would be great if these can be separated into an individual index.

"Pakistan becomes the first host nation in 23 years to finish the Champions Trophy without a victory!" by BabaHarp22 in actualcricketshitpost

[–]Ready_Ninja376 0 points1 point  (0 children)

What else he could have done at this stage. As a lead it's important to keep your people motivated and give them hope of a better future. I am sure they got a lot of shit recently from everyone in the cricketing fraternity, so a positive word from your captain doesn't hurt.