SANS Holiday Hack Challenge The Great Elf Conflict

KC7 The Great Elf Conflict SANS Holiday Hack Challenge

This post is a write-up or clues on how to resolve the KC7 investigation case of SANS Holiday Hack Challenge 2024 The Great Elf Conflict . You can use it as a helpful guide when encountering an obstacle or trying to understand a question. Different ways to answer questions might exist, so feel free to explore your path. Section 1: KQL 101 You got it 馃懢 Section 2: Section 2: Operation Surrender Alabaster鈥檚 Espionage Question 1: surrender...

December 10, 2024 路 6 min 路 1177 words 路 Bader Alrowaiei
HopsNStuff

KC7 HopsNStuff - Section 4: 馃嵀 Sugar Rush

This post is a walkthrough of the KC7 investigation case of KC7 HopsNStuff - Section 4: 馃嵀 Sugar Rush . You can use it as a helpful guide when encountering an obstacle or trying to understand a question. Different ways to answer questions might exist, so don鈥檛 be afraid to explore your path. Section 4: 馃嵀 Sugar Rush Question 1: IP 158.235.158.156 was observed exfiltrating data from mailboxes at HopsNStuff. How many mailboxes were affected?...

October 27, 2024 路 Last Modified: October 27, 2024 路 5 min 路 1015 words 路 Bader Alrowaiei
HopsNStuff

KC7 HopsNStuff - Section 3: Golden 馃悋

This post is a walkthrough of the KC7 investigation case of KC7 HopsNStuff - Section 3: Golden 馃悋 . You can use it as a helpful guide when encountering an obstacle or trying to understand a question. Different ways to answer questions might exist, so don鈥檛 be afraid to explore your path. Section 3: Golden 馃悋 Question 1: A law enforcement agency informed HopsNStuff that an adversary was attempting to gain access to their company....

October 20, 2024 路 Last Modified: November 11, 2024 路 7 min 路 1473 words 路 Bader Alrowaiei
HopsNStuff

KC7 HopsNStuff - Section 2: 馃Info馃挵

This post is a walkthrough of the KC7 investigation case of KC7 HopsNStuff - Section 2: 馃Info馃挵 . You can use it as a helpful guide when encountering an obstacle or trying to understand a question. Different ways to answer questions might exist, so don鈥檛 be afraid to explore your path. Section 2: Question 1: Let鈥檚 take a look at our SecurityAlerts. A security alert flagged on a file that was quarantined on March 31, 2023....

September 11, 2024 路 Last Modified: September 15, 2024 路 12 min 路 2416 words 路 Bader Alrowaiei
KC7 Inside Encryptodera

KC7 Inside Encryptodera - Section 3: F in the chat

This post is a write-up or clues on how to resolve the KC7 investigation case of Inside Encryptodera - Section 3: F in the chat . You can use it as a helpful guide when you encounter an obstacle, as it structured as a fill-in-the-blanks solution. Section 3: Question 1: What username was used to log into the DOMAIN_CONTROLLER_SERVER? AuthenticationEvents | where hostname == "DOMAIN_CONTROLLER_SERVER" | project username Question 2: What laptop did the lihenry_domain_admin account sign into?...

September 6, 2024 路 Last Modified: September 6, 2024 路 3 min 路 553 words 路 Bader Alrowaiei
KC7 Inside Encryptodera

KC7 Inside Encryptodera Section 2: Crypto Conquest

This post is a write-up or clues on how to resolve the KC7 investigation case of Inside Encryptodera Section 2: Crypto Conquest . You can use it as a helpful guide when you encounter an obstacle, as it structured as a fill-in-the-blanks solution. Section 2: Question 1: What is the filename of this note? Do you see it? It is the .txt file name. FileCreationEvents | where path contains "GIMME" | distinct filename | project filename Question 2: What kind of attack is this?...

August 25, 2024 路 Last Modified: September 1, 2024 路 6 min 路 1165 words 路 Bader Alrowaiei
KC7 Inside Encryptodera

KC7 Inside Encryptodera - Section 1: Offensive Odor

This post is a write-up or clues on how to resolve the KC7 investigation case of Inside Encryptodera - Section 1: Offensive Odor 馃懡 . You can use it as a helpful guide when you encounter an obstacle, as it structured as a fill-in-the-blanks solution. Section 1: Question 1: What is Barry鈥檚 role at the company? Employees | where name contains "Barry" | project name , role Question 2: What is Barry鈥檚 email address?...

July 29, 2024 路 Last Modified: August 17, 2024 路 4 min 路 655 words 路 Bader Alrowaiei
KC7 Balloons Over Iowa

KC7 Balloons Over Iowa - Section 4: Helpdesk 鈽庯笍

This post is a write-up or clues on how to resolve the KC7 investigation case of Balloons Over Iowa - Section 2: Aliens 馃懡 . You can use it as a helpful guide when you encounter an obstacle, as it structured as a fill-in-the-blanks solution. Section 4: Question 1: How many emails contained the domain database.io? Table | where <field> <operator> "database.io" | <operator> Question 2: What IP does the domain database....

July 7, 2024 路 Last Modified: July 16, 2024 路 3 min 路 455 words 路 Bader Alrowaiei
KC7 Balloons Over Iowa

KC7 Balloons Over Iowa - Section 3: TopSecret 馃か

This post is a write-up or clues on how to resolve the KC7 investigation case of Balloons Over Iowa - Section 3: TopSecret 馃か . You can use it as a helpful guide when you encounter an obstacle, as it structured as a fill-in-the-blanks solution. Section 3: Question 1: On 2023-02-19 at 05:02, Son Johnson downloaded a suspicious Word document file. What was the name of this file? The question provided the timestamp 2023-02-19 at 05:02 and the user name Son Johnson....

June 17, 2024 路 Last Modified: July 2, 2024 路 7 min 路 1489 words 路 Bader Alrowaiei
KC7 Balloons Over Iowa

KC7 Balloons Over Iowa - Section 2: Aliens 馃懡

This post is a write-up or clues on how to resolve the KC7 investigation case of Balloons Over Iowa - Section 2:Aliens 馃懡 . You can use it as a helpful guide when you encounter an obstacle, as it structured as a fill-in-the-blanks solution. Section 2: Aliens 馃懡 Question 1: Which email address sent a message containing the domain invasion.xyz? Table | where <field> <operator> "invasion.xyz" Question 2: How many users received email with links to the domain invasion....

June 14, 2024 路 Last Modified: June 24, 2024 路 6 min 路 1260 words 路 Bader Alrowaiei