Syntax Used in This Course
The SEC565 course documentation uses consistent syntax styles with which you should become familiar. This section helps you to make sense of what the material conveys, so you can focus more on course material than styling.
Syntax Descriptions and Examples
Note
The commands listed in this section of the lab are just for reference, so you can become familiar with text styles used in the course materials. No need to actually run them on your system!
-
Text blocks that appear in the format shown below contain commands that you would run in the Slingshot Linux VM or on another system. These code blocks include an icon to the far right that allows you to copy the contents of the block, suitable for pasting into the shell in your class VMs.
cd /tmp/ls -lThe results are shown in a slightly different format. Results will be denoted as "Expected" or "Notional". Expected results should reflect exactly what you get from the commands shown. Notional results are shown when some variation may be present, based on lab or classroom conditions.
Notional results
sec565@slingshot:/tmp$ cd /tmp/ sec565@slingshot:/tmp$ ls -l total 76 drwxrwxr-x 2 sec565 sec565 4096 Mar 17 07:51 3-1 drwxrwxr-x 2 sec565 sec565 4096 Mar 19 06:13 3-3 prwx------ 1 sec565 sec565 0 Mar 19 02:37 clr-debug-pipe-18143-73176294-in prwx------ 1 sec565 sec565 0 Mar 19 02:37 clr-debug-pipe-18143-73176294-out -rw------- 1 sec565 sec565 0 Mar 4 06:39 config-err-WtVFO8 srwxrwxr-x 1 sec565 sec565 0 Mar 19 02:37 CoreFxPipe_PSHost.D83B3A51.18143.None.pwsh srw------- 1 sec565 sec565 0 Mar 19 02:37 dotnet-diagnostic-18143-73176294-socket srw------- 1 root root 0 Mar 4 07:40 dotnet-diagnostic-5421-367637-socket drwxr-xr-x 2 root root 4096 Mar 4 06:39 hsperfdata_root drwxrwxr-x 2 sec565 sec565 4096 Mar 18 20:43 Microsoft.PackageManagement srwx------ 1 mongodb mongodb 0 Mar 4 06:39 mongodb-27017.sock drwxr-xr-x 3 root root 4096 Mar 4 07:40 VBCSCompiler drwxrwxrwt 2 root root 4096 Mar 19 20:44 VMwareDnD drwx------ 2 root root 4096 Mar 4 06:39 vmware-root_815-4282170896 ... -
Direct questions are reflected in the material as shown below.
What is the MD5 hash value for ~/tools/starkiller-1.9.0.AppImage?
7ac3bf00f929239e4da1247fa0e300fdCommand lines
cd ~/tools md5sum starkiller-1.9.0.AppImageExpected results
sec565@slingshot:~/tools$ md5sum starkiller-1.9.0.AppImage 7ac3bf00f929239e4da1247fa0e300fd starkiller-1.9.0.AppImage -
When referring to literal strings inline with narrative text, the strings will be in depicted in Courier New font. For example, a search string of
powershell/privesc/powerup/allchecksmight be noted in the material inline, or via a call-out box as shown below:powershell/privesc/powerup/allchecks -
Some commands follow a "template" format, in which you will replace a part of the template with content you've discovered previously in the lab. These template command lines will include placeholders surrounded by the
<%and%>enclosures with uppercase letters between them. This is an indication that you must alter the template command accordingly. For example, in the following command, you'd replace the<%IP_ADDRESS%>portion of the IP address with some information identified elsewhere in the lab.cd /opt/Empire/empire/server/downloads/<%AGENTNAME%> -
It is generally wise to not use the
rootadministrative account for normal activities. We will follow best practices and use thesudoutility to perform administrative actions within the Slingshot Linux environment wherever needed. Thesec565user has fullsudoaccess to provide a reasonable balance between best practices and a practical classroom-based lab environment. -
In the electronic workbook, some images are clickable, resulting in an enlarged version. This can be helpful when examining a detailed diagram or screenshot. An example of this is below.
