Security Operations Investigations/Challenges

Phishy - V1

You have been sent a phishing link. Sadly the threat actor doesn’t know who they were dealing with. From only one phishing link find out all you can about th...

Network Analysis - Web Shell

The SOC received an alert in their SIEM for ‘Local to Local Port Scanning’ where an internal private IP began scanning another internal system.

Peak

A web developer at Mountain Top Solutions discovers anomalous activity on a development server. Review different log types and auditd rules to work out what ...