🎯 Goal

Today’s objective was to strengthen foundational cybersecurity knowledge by completing several TryHackMe learning rooms covering:

  • Linux CLI basics
  • Windows CLI basics
  • Operating system security
  • Data representation
  • Data encoding

The focus of the day was to deepen understanding of how computers store, process, and manipulate data, and how command-line interfaces (CLI β€” text-based system control environments) allow analysts and administrators to interact directly with operating systems.

These concepts form an important baseline for both SOC investigations (Security Operations Center β€” teams that monitor and investigate security alerts) and system-level troubleshooting.


πŸ›  What I Did

Today I completed the following TryHackMe rooms:

  • Linux CLI Basics
  • Windows CLI Basics
  • Operating System Security
  • Data Representation
  • Data Encoding

Linux CLI Basics

I reviewed and practiced fundamental Linux terminal commands used for navigation, file management, and system interaction.

Important commands revisited included:

pwd β€” print working directory
ls β€” list directory contents
cd β€” change directories
cat β€” display file contents
echo β€” output text or variables
mkdir β€” create directories
rm β€” remove files
cp / mv β€” copy and move files

The Linux command line is extremely important in cybersecurity because:

  • Most servers run Linux-based systems
  • Many security tools operate in the terminal
  • Investigations often rely on log parsing and command pipelines

Working comfortably in the terminal dramatically speeds up analysis and system inspection.


Windows CLI Basics

I also explored the Windows command-line environment, primarily using:

  • Command Prompt (cmd)
  • PowerShell

Important commands reviewed included:

dir β€” list directory contents
cd β€” change directories
ipconfig β€” view network configuration
whoami β€” display current user
tasklist β€” show running processes
systeminfo β€” view OS and hardware information

PowerShell in particular is extremely powerful because it allows administrators and analysts to interact with the operating system using object-based commands, rather than simple text output.

In SOC environments, analysts frequently examine PowerShell activity because attackers often abuse it for:

  • remote command execution
  • downloading payloads
  • privilege escalation

Operating System Security

This section focused on how operating systems enforce security boundaries.

Key concepts included:

Authentication vs Authorization

Authentication = verifying identity (passwords, keys, biometrics)
Authorization = determining what actions a user is allowed to perform.

Principle of Least Privilege

Users should only receive the permissions necessary to perform their job.
This reduces damage if an account becomes compromised.

Access Control

Operating systems enforce permissions through mechanisms such as:

  • file permissions
  • user groups
  • security policies
  • privilege levels

Linux and Windows implement these controls differently, but the underlying principle remains the same: restrict access to sensitive resources.


Data Representation

This section explored how computers represent information internally.

Since computers operate using electrical signals, all data must ultimately be represented as binary (base-2 numbers).

Common number systems used in computing:

Binary (base-2)
Decimal (base-10)
Hexadecimal (base-16)

Binary example: 01001000 01101001
Hexadecimal representation: 48 69
ASCII interpretation: Hi

Hexadecimal is widely used in cybersecurity because it provides a compact representation of binary data, which is easier for humans to read during investigations.

Understanding these representations is important for:

  • packet analysis
  • malware analysis
  • memory forensics
  • reverse engineering

Data Encoding

Finally, I studied how information is encoded for storage and transmission.

Encoding transforms data into a different format without necessarily encrypting it.

Common encoding methods include:

ASCII (American Standard Code for Information Interchange)
Represents characters using numeric values.

Example: A = 65

Unicode

A more modern encoding system that supports characters from many languages.

Base64

A widely used encoding scheme that converts binary data into text characters.

Example Base64 string: SGVsbG8=
Decoded result: Hello

Base64 commonly appears in:

  • email attachments
  • HTTP authentication headers
  • malware payload delivery
  • command-and-control traffic

Recognizing encoded data is an important skill for analysts because attackers frequently hide payloads using encoding techniques.


πŸ”— Key Cybersecurity Connections

Today’s topics connect directly to several real-world security tasks.

SOC investigations

Analysts frequently:

  • inspect logs
  • decode encoded payloads
  • analyze command-line activity
  • identify suspicious processes

Malware analysis

Malware often uses:

  • Base64 encoding
  • obfuscated scripts
  • encoded network traffic

Understanding encoding and representation helps analysts recognize hidden payloads.

Threat hunting

Many attacks leave traces in:

  • shell command history
  • PowerShell logs
  • encoded network requests

Recognizing these patterns is crucial during investigations.


πŸ” Investigation Questions

When suspicious command-line activity or encoded data appears in logs, a SOC analyst might investigate questions such as:

  • What process executed the command-line activity?
  • Was PowerShell or another scripting interpreter used?
  • Does the command output contain encoded strings such as Base64?
  • Was the encoded data used to download or execute additional payloads?
  • Did the process establish network connections after decoding the data?
  • Are similar command patterns appearing across multiple endpoints?

These questions help determine whether command-line activity represents legitimate administration or malicious activity.


🚨 Detection Opportunities

Possible detection strategies related to these topics include:

  • monitoring suspicious PowerShell command execution
  • detecting Base64-encoded strings inside command-line arguments
  • identifying unusual command-line activity executed from user directories
  • monitoring processes spawning from scripting interpreters
  • correlating command execution with network activity or payload downloads

Useful telemetry sources include:

  • PowerShell logs
  • process creation logs
  • endpoint detection and response (EDR) telemetry
  • command-line auditing logs.

🧭 MITRE ATT&CK Techniques

The techniques discussed relate to several MITRE ATT&CK entries:

  • T1059 – Command and Scripting Interpreter
  • T1059.001 – PowerShell
  • T1027 – Obfuscated/Compressed Files and Information
  • T1140 – Deobfuscate/Decode Files or Information

These techniques describe how attackers frequently use scripting and encoding to execute and disguise malicious activity.


⚠ Challenges

Some parts of the material required careful attention, especially:

  • Understanding the difference between encoding vs encryption
  • Mentally converting between binary, decimal, and hexadecimal
  • Recognizing why attackers frequently use encoding to disguise malicious payloads

While these topics initially appear theoretical, they become extremely practical when analyzing logs, scripts, or network data.


πŸ“š What I Learned

Today reinforced several key lessons:

  • Command-line interfaces are essential tools for system analysis.
  • Operating systems enforce security through layered access controls.
  • All computer data ultimately reduces to binary representation.
  • Encoding transforms data formats but does not provide security.
  • Attackers often use encoding as a simple obfuscation technique.

These fundamentals will appear repeatedly in future cybersecurity topics such as:

  • malware analysis
  • packet inspection
  • digital forensics
  • exploit development

➑ Next Steps

Moving forward, I want to continue building deeper understanding of:

  • Linux system internals
  • Windows security mechanisms
  • process monitoring
  • log analysis

I will also begin applying these concepts more frequently in hands-on labs, where encoded data and command-line activity appear during simulated investigations.


🧠 Reflection

Although today’s topics were mostly foundational, they represent important building blocks for understanding how systems actually work under the hood.

Cybersecurity is often about seeing through layers of abstraction β€” understanding what is really happening behind user interfaces, applications, and network protocols.

The more comfortable I become with command-line tools and data representation, the easier it will be to investigate complex security events.


🧩 Lessons Learned

What worked

Reviewing both Linux and Windows CLI environments helped reinforce the similarities and differences between operating systems.

What broke

Binary and hexadecimal conversions initially required slowing down and carefully reviewing how numbers translate between bases.

Why it broke

These concepts are rarely used in daily computing but become critical when working close to the system level.

Fix / takeaway

Continue practicing with real examples such as encoded strings, log entries, and command-line output to build intuition.


πŸ“ˆ Skill Progression Context

Today’s work strengthened the technical foundations needed for SOC analysis and detection engineering.

Understanding:

  • command-line environments
  • system security principles
  • data encoding and representation

provides the groundwork for later skills such as:

  • log parsing
  • packet analysis
  • malware investigation
  • detection rule development

These fundamentals will directly support future investigations where analysts must interpret raw system data and encoded artifacts during real-world security incidents.