Getting the transcript
Reading the captions from YouTube. A video nobody has opened here before takes 10 to 30 seconds; this page fills in on its own.
Getting the transcript
Reading the captions from YouTube. A video nobody has opened here before takes 10 to 30 seconds; this page fills in on its own.

MyDFIR · @MyDFIR
Where viewers went back to watch this video again, from YouTube's public Most replayed graph, lined up with what was said at that moment.
Most replayed moment #1
8:514.4x the video's typical replay level
go ahead and click on the link for GitHub but since I'm on a Windows machine we'll click on download syon and while that's downloading we should go ahead and start downloading the configuration file that we'll start using for Sison and again all of the
Said at 8:43
Most replayed moment #2
19:203.2x the video's typical replay level
launch droplet console once we have successfully sshed into our virtual machine we can begin performing some updates and upgrades now because by default we're under root we can perform this by typing in apt-get update
Said at 19:12
Most replayed moment #3
15:082.8x the video's typical replay level
can click on operational and this will give you a bunch of telemetry about your system and help you catch evil now that we have our Windows 10 client machine installed along with sysmon let's start setting up Wason next I'll be using digital ocean as my cloud provider if
Said at 15:00
The graph counts replays. It does not show where viewers stopped watching.
Words
3,675
Runtime
23:17
Speaking pace
158wpm
Reading time
15min
158 words per minute, below the 160 25th percentile of 349 measured videos. That distribution comes from the 349-video hook study.
Opening (first 30 seconds)
welcome to part two of five for the series on the sock automation project if you haven't seen part one where we go over on how to build a diagram for this lab I highly recommend you go and watch that today our objective is to install our applications and virtual machines by the end of the video you should have one Windows 10 machine with sysmon installed one Wasa server and one Hive server as a quick side
79 words, the words spoken in the first 30 seconds at 158 words per minute.
Free, no signup. See how the first 30 seconds hold attention, with rewrites.
Sentence shape
What this transcript is
Every word below is the caption track YouTube publishes for this video, pulled from the video itself and reproduced unchanged. It is not Prepublish's writing, not a summary, and not a re-transcription: it is the video's own published captions. English captions, generated automatically by YouTube, in the video’s original language. Source: the video on YouTube. A channel that would rather this page did not exist can ask for its removal through the contact page, and it is removed.
welcome to part two of five for the series on the sock automation project if you haven't seen part one where we go over on how to build a diagram for this lab I highly recommend you go and watch that today our objective is to install our applications and virtual machines by the end of the video you should have one Windows 10 machine with sysmon installed one Wasa server and one Hive server as a quick side note if you running a M1 M2 or an M3 Mac you can still perform this lab but you will have to create the Windows host in the cloud rather than setting up a virtual machine on your host now for those that don't know what Wasa is on their site will provide a very high level overview Wasa is an open-source cyber security platform and integrates Sim and xdr capabilities in a unique solution they provide multiple capabilities such as security analytics intrusion detection incident response and many more they have three main components that build up Wasa which is the indexer server and dashboard as for the hive this is a 4in One op source security incident response platform and we will use this as our case management system as for our virtual machine we will be using Windows 10 as our client PC and I use Ubuntu 20 2.04 for both wah and the hive again both wah and the hive will be spun up in the cloud however I will be using a virtual machine to set up my Windows 10 client hosted on my esxi server but you can always use Virtual box or the cloud and if you aren't too sure on how to install virtual box and sysmon to get set up with Windows 10 I'll start replaying a previous video that I have done in the past to show you otherwise feel free to skip ahead all right so first we'll begin with installing virtual Box by heading over to their site virtualbox.org now depending on the operating system you have that is the one that we're going to be downloading so we can go ahead and click download Virtual box 7.0 from here we know that this machine that I'm using is a Windows host machine so I'll go ahead and click download on that while that's downloading we can actually go ahead and check out the shaw 256 check sums as well when you go into the check sums it will provide you with a list of Shaw 256 hashes and then this way we can verify the downloaded file to determine whether or not it has been altered so let's go ahead and do that we'll head over to the downloads directory in which our file lives in we'll open Powershell and then I'll do a get file hash virtual box hit tab click on enter and by default sh 256 is generated what we can do is double click that and then we can paste it in and see if it matches up so we know for a fact that the file in transit was not changed whatsoever now we can go ahead and double click virtual box to start installing it now we might get hit with a compatibility issue or missing some software dependencies but we'll deal with that when the time comes click on yes and from here we notice that there is a Microsoft Visual C++ 2019 package dependency so what we'll do is we'll go ahead and install this dependency and I'll put the link down in the description below just in case that you get hit with this dependency as well I went and downloaded the dependency and installed it so now we can go ahead and double click the virtual box installer again hit yes and now it doesn't give me that dependency error anymore we are presented with some of the features which we can install and they are all set to be installed by default but you do have that option to customize it which is quite nice here you can change where you want virtual box to be installed in for example if you don't have enough space in the C drive you can always install it in a different drive if you like but in this case we'll go with the default and hit next this will provide you with a warning that it will reset your network connection and temporarily disconnect you hit yes and install the needed dependencies once it's done installing you should see the sign all you got to do is click on finish and then virtual box should automatically pop up and just like that we'll navigate to the link which I'll list down in the description for you and once we're on this page we can go ahead and scroll down and click on download tool now this will download what is called a media creation tool which will help you generate a Windows ISO image file so we can go ahead and double click that to open the file click on yes and now it will get a few things ready you'll eventually be presented with this license agreements page and we can go ahead and hit accept it will say getting a few things ready again once it is done check checking things you should be presented with this screen now displaying two options one to upgrade your PC or two create an installation media what we want to select is create the installation media and hit next you have the option to customize your settings such as language addition and architecture but I'll leave mine checked to use the recommended option for this PC and hit next now we are presented with two media choices to use a US be flash drive or an ISO file we'll select the ISO file and hit next and save the ISO file anywhere you like and it will start downloading so now that my windows ISO image has been successfully downloaded we can now jump over to our virtual box and start creating a virtual machine we'll open up the window for virtual box and click on new here we can enter a name for a virtual machine and select the directory where we want to store our files so I will go ahead and name our virtual machine demo I'll leave the folder as is as for the iso image I will click on this and select the drop down click on other and now I'll find the iso image that I just downloaded it was listed under documents and double click the windows ISO at the bottom there's an option where you can check skip unattended installation which I will do actually that way I can install the operating system manually now you can uncheck this or check this it's up to you I'll click on next here we have the options to configure our virtual machine specifications however do be aware that this will be relying on your computer's specifications for this demo I'll set my base memory for this virtual machine as gigs and we'll have it as one CPU I'll click on next for the virtual hard disk I'll leave as 50 gigs and hit next now this will give you a nice summary as to what your settings are for this virtual machine if you're good to go click on finish and now we can go ahead and start powering it on to power it on you just hit this arrow that says start now once it's running we should be able to start seeing this Windows 10 setup so we'll go ahead and select next and hit in install now once you're presented with this activate Windows screen go ahead and select I don't have a product key and as for the option select Windows 10 Pro hit next accept the license terms and here you have the option to upgrade or custom install Windows only I'm going to select custom install Windows only hit next and then now with Windows 10 should be installing in the background what we want to do is open up a web browser once you're on this site you want to click on download Sison unless you're running Linux then you can go ahead and click on the link for GitHub but since I'm on a Windows machine we'll click on download syon and while that's downloading we should go ahead and start downloading the configuration file that we'll start using for Sison and again all of the this will be in the description down below once we're on this page we want to scroll down to find cismon config.xml click on that once you're on this page you want to click on raw and then it'll load this up and then you all you got to do is right click click save as and then you can save it as anything you want in this case I'll just type in Sison config and then saves it as that now that cismon has successfully been downloaded what we can do is start extracting it so I'll right click it and click extract all I want to extract and what we want to do is not double click this executable instead we want to open up a Powershell window and we might need administrator privileges so so why don't we go ahead and open up a Powershell with admin PRS so we go on the bottom left corner click on the Windows button type in Powershell from here you can click on run as administrator or you can right click and run as administrator click yes and now we want to make sure that we're in the same directory as the extracted sysmon so in this case the the directory is C colon back/ user in the user download folder essentially so we want to double click that copy it via right click copy or you can do what I did and which is uh contrl C then all we got to do is jump over to the Powershell prompt type in CD for change directory and just for good practice you can put it in a quote paste that in by right clicking then quote again so now we should be in the correct directory so what we want to do is also make sure that our sysmon configuration is in the same directory as well so in this case we can either copy it or we can cut it I'll just drag and drop it into that folder to be honest double click it make sure that it's there and indeed it is there beautiful you might have noticed that there's various EXE aables for cismon we want to focus on the cismon 64 simply because this is a 64-bit machine so all we got to do is just type in [Music] sysmon sysmon 64 and then hit tab that should autocomplete for you and if you hit enter nothing will happen it will just show you the help menu and essentially it'll just tell you how to install it and update the configurations and all that other good stuff and to double check if we have or have not installed cismon we can do this in a couple ways so first and foremost we can go in the bottom left corner click on the start menu and type in Services hit enter this should pop up the services that are installed onto your computer and then what you want to type in is or actually what you want to click and type is s and then you want to look for cismon if there's no cismon installed then you will not see sysmon so in this case I can confirm that I do not have sysmon installed the second way we can do it is go through event logs we can do this by typing Event Viewer hit enter there this will show you all of the logs associated with this machine so what you want to do is click on applications service logs open that up and then you want to expand Microsoft from there expand [Music] windows and now we want to look for cismon so if I scroll all the way down is there going to be any cismon and no doesn't seem that cismon is installed so what we want to do now is Type in cismon again 64 tab now that auto completes and now we want to install the configuration by using the TAC I command right here install service and Driver optionally take a config configuration file so we'll press space and type in Symon and then we can tab until we find it or we can just type in cismon config since we know that we named it that way hit Tab and it'll autoc complete from there we can hit enter and this will pop up which is essentially your license and agreement you can hit agree and then it should go ahead and run its course and install cismon so to double check to make sure that cismon is installed we can run through those steps that I've shown previously first we go through the services we don't have to close and reopen it we can easily just refresh it once I click refresh you can see that there's Sison 64 exists here same goes for the Windows Event Viewer what we can do is click on action click refresh and unless I'm a liar there should be Sison somewhere here all right so I guess I am we have to close Event Viewer and reopen it so again click the Windows button type in Event Viewer or event and then from there click on applications and service logs and expand Microsoft Windows scroll all the way down and see if you have system on in this case we do beautiful so that is how you install system on and get that up and running we can click on operational and this will give you a bunch of telemetry about your system and help you catch evil now that we have our Windows 10 client machine installed along with sysmon let's start setting up Wason next I'll be using digital ocean as my cloud provider if you wanted to follow along you can sign up using the link provided down below that will provide you with $200 credit for the first 60 days but you must provide a valid credit card this is extremely helpful for those that have a M1 M2 or M3 Max to begin I'm going to be building our Wasa server first so we can create that by clicking on the top right corner under create now with digital ocean droplets or virtual machines so I'll click on droplet and from here you want to select the region that you're currently residing in in my case I'll just select Toronto scroll down and we want to select Ubuntu and the ver version 22.041 gigs of RAM and 50 gigs hard drive space so we can go with the option of $ 48 a month now again with the $200 credit this doesn't really seem too much so this is what I'm going to be choosing the basic plan premium Intel and the $48 a month scroll down we want to create a password or an SSH key whichever suits you but for me I'm just going to create a password do make sure that you use a password manager because we will expose this to the internet eventually but not in the beginning once you put in your password scroll down you'll see an option to change your host name I'll change this to Wasa scroll down and then hit create droplet at the bottom while we wait for this droplet to be created I highly recommend you start set setting up a firewall otherwise you'll get spammed from external scanners we can create a firewall by heading over to networking at the left hand side and then firewalls tab click on create firewall Now by default we have SSH open to the public I'm going to name this as firewall I mean you can name it as whatever you want but I'm going to name it as firewall and I am going to select all TCP I'll remove all IPS and only add my public IP now to get your public IP open up a new tab and go into what is my IP address and then you can select the first link and then you should see your public IP address copy that out and then paste it into your sources now you want to do the same for UDP as well just in case once that's done scroll all the way down and click on create firewall once your firewall had been created cre we can start adding our virtual machine onto this firewall now the reason why we're doing this if you don't create Rules by default SSH is open to the public so anybody or any scanners out there will hit your box and try to break in but because we specified our public IP our virtual machine is only accessible through us let's head over to our virtual machines by selecting droplets on the left hand side and here we can see the public I i p of our Wasa server let's click on Wasa and from there we want to select networking scroll down until you see firewalls click on edit and then you want to select your firewall that you just created from your firewall click on droplets and select add droplets look for your virtual machine my case was Wasa I'll select Wasa and click on ADD droplet now the firewall will be protecting our virtual machine there are a couple of ways that you can access your virtual machine firstly you can use something like putty to use SSH or from the droplets tab under Wasa you can click on the access Tab and then select launch droplet console once we have successfully sshed into our virtual machine we can begin performing some updates and upgrades now because by default we're under root we can perform this by typing in apt-get update and at-et upgrade you will eventually get presented with this screen we can just hit enter and finally It'll ask you which Services should be restarted again we can just hit enter once it's been finished updating and upgrading we can start with the installer of Wasa to get started with Wasa we can run a curl command that is also found on their website but I'll leave it here as well as in the description down below if you wanted to just copy that after aoup couple of minutes Wasa should be finished installing now there is one thing to keep in mind and that is the username and password you want to make sure that you copy the username admin as well as your password because you will need it to log in to your wasel dashboard so let's go and do that right now to log into wasal do take note of your public IP of the server in this case my public IP for Wasa is 1739 I'll go ahead and copy Cy this and then open up a new tab and in your browser make sure you type in HTTPS and then paste in the IP now we can click on Advanced proceed and we're presented with wasa's dashboard we can put in our admin user and paste in the password and now we're in perfect awesome we have our client machine and Wasa up and running the next is to install the hive similar to Wasa we'll be using Ubuntu 20 2.04 to begin select create at the top right corner and select droplet you want to choose the region that's closest to you I'll select Toronto scroll down we'll use create droplet you want to make sure that the hive is placed in the firewall that you created earlier to do that we can click on the hive go into networking scroll down to firewalls click on your firewall go to droplet and then add droplet now we want to type in our host name which is the hive and click on ADD droplet perfect now both wah and the hive is being protected by our firewall and it can only be accessible by Us and nobody else I've opened up a new Tab and sshed into the hive now we can start installing some prerequisites again this could be found in their documentation and I will also leave it in the description so you can just easily copy and paste with the hive we must install four components the first one is Java second is Cassandra third is elastic search and fourth is the hive itself once we finished installing the prerequisites we can start installing Java whenever you are presented with this screen you can go ahead and hit enter once Java had finished installing the next one is Cassandra then we can install elastic search and finally we can install the hive this whole process for installing the hive and Wasa takes about 10 to 15 minutes but once it's finished installing the next step is to configure it now that we have installed our virtual machines Wasa and the hive we must configure these to get them to work across the board and we will do this in the next episode that is it for the video and if you had some problems setting these up please let me know in the comment section down below and I'll try my best to help you out
The words are the caption track's own and nothing is reworded or re-transcribed. Paragraph breaks are placed between sentences so the text reads as prose.
Free tools for your own script. No signup, no login.
Paste your draft and see where viewers are likely to drop off, with a rewrite for each weak line.
Paste the first 30 seconds of your own draft for a hook score and rewrites.
Check your draft against YouTube's advertiser-friendly guidelines before you record it.
Read this channel's public videos and transcripts, and download a writing brief for it.
| Measure | This transcript |
|---|---|
| Sentences | 1 |
| Average words per sentence | 3675.0 |
| Longest sentence | 3,675 words |
| Questions asked | 0 |
| Sentences containing a number | 1 |
Most used terms
Filler phrases
9 in total: like 4 · actually 3 · I mean 1 · uh 1.
A literal whole-word count of the same phrase list the Prepublish browser extension uses, so a phrase inside another word is not counted and a phrase used in its ordinary sense still is. It is a count and not a judgement.