Hammered Cyberdefenders
Category : Digital Forensics Log Analysis Honeypot Apache2
Q1 Which service did the attackers use to gain access to the system?
cat auth.log | grep -F 'Failed'
Q2 What is the operating system version of the targeted system? (one word)

Q3 What is the name of the compromised account?

Q4 Consider that each unique IP represents a different attacker. How many attackers were able to get access to the system?


Q5 Which attacker's IP address successfully logged into the system the most number of times?

Q6 How many requests were sent to the Apache Server?

Q7 How many rules have been added to the firewall?

Q8 One of the downloaded files to the target system is a scanning tool. Provide the tool name.


Q9 When was the last login from the attacker with IP 219.150.161.20? Format: MM/DD/YYYY HH:MM:SS AM

Q10 The database displayed two warning messages, provide the most important and dangerous one.

Q11 Multiple accounts were created on the target system. Which one was created on Apr 26 04:43:15?

Q12 Few attackers were using a proxy to run their scans. What is the corresponding user-agent used by this proxy?

Last updated