2016-01-07 - TRAFFIC ANALYSIS EXERCISE - ALERTS ON 3 DIFFERENT HOSTS

NOTICE:

ASSOCIATED FILES:

 

SCENARIO

You are working as an analyst reviewing suspcious network events at your organization's Security Operations Center (SOC).  Things have been quiet for a while.  However, you notice several alerts occur within minutes of each other on 3 separate hosts.


Said one analyst to another:  A lot of these alerts contain the word "evil."

 

THE REPORT

Your were able to retrieve a pcap of network traffic, and you have a list of Snort and Suricata events from the activity.  You'll need to write a report.  Your report should include:

 


And by "write" we mean type...  Get it together, Dave!

 

ANSWERS

 

Click here to return to the main page.