Загрузка...

TryHackMe — SeeTwo Walkthrough (Wireshark, PyInstaller Decompile + Python Code Reviewing)

#TryHackMe #SeeTwo #Wireshark
In this detailed TryHackMe SeeTwo walkthrough I show end-to-end analysis: packet capture inspection with Wireshark, exporting HTTP objects, then binary analysis and decompilation of a PyInstaller-created ELF binary to recover the Python source — finally automating C2 stream decryption with a Python script.

What you'll learn (high-level)
• How to use Wireshark Conversations & filters (tcp.port == 22 / 80 / 1337) to find suspicious traffic.
• Recognize base64-encoded payloads and PNG decoys used by C2.
• Export HTTP objects from a PCAP and recover downloaded files.
• Identify a PyInstaller ELF, extract .pyc, fix pyc header (magic bytes) and decompile with uncompyle6.
• Build a short Python script to automate combining streams + base64 → XOR decryption.
• Tools used: Wireshark, pyinstxtractor, ImHex (hex editor), uncompyle6, Python (3.8).

Why watch:
SeeTwo is a great lab for learning real-world C2 and binary-forensics techniques — perfect for CTF players, red-teamers, and defenders who want practical packet-to-source reverse engineering.

If this helped you:
👍 Like, Subscribe, and hit the bell for more CTF & reverse-engineering tutorials.
Questions or stuck on a step? Comment the timestamp and I’ll reply.
#TryHackMe #SeeTwo #Wireshark #CyberChef #ReverseEngineering #BinaryAnalysis #CTF #MalwareAnalysis #PyInstaller #PCAP

Видео TryHackMe — SeeTwo Walkthrough (Wireshark, PyInstaller Decompile + Python Code Reviewing) канала Junhua's Cyber Lab
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять