Walkthroughs, challenges, and examples of host compromises
Date: 04/08/2020
There are 3 x log files. One web log, windows security audit log, and a sysmon log. The logs are in the following zip file:
The SIEM generated an alert in response to an attempt to create a user to a local administrator group. The action appeared to have failed as there was no event in the security log. The SIEM alert detected the following activity:
“net1 localgroup administrators appusr /add”
SysMon 06/07/2020 12:57:23, EventRecID: 1087. It has been confirmed that this activity wasn’t legitimate.
Using the log files can you determine and undertake the following:
The following advisories may assist: