2016-01-07 - TRAFFIC ANALYSIS EXERCISE - ALERTS ON 3 DIFFERENT HOSTS

ASSOCIATED FILES:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

 

SCENARIO

You are working as an analyst reviewing suspcious network events at your organization's Security Operations Center (SOC).  Things have been quiet for a while.  However, you notice several alerts occur within minutes of each other on 3 separate hosts.


Said one analyst to another:  A lot of these alerts contain the word "evil."

 

THE REPORT

Your were able to retrieve a pcap of network traffic, and you have a list of Snort and Suricata events from the activity.  You'll need to write a report.  Your report should include:

 


And by "write" we mean type...  Get it together, Dave!

 

ANSWERS

 

Click here to return to the main page.