TLP-WHITE

Logo

Walkthroughs, challenges, and examples of host compromises

View My GitHub Profile

Exercise: WebShell

Date: 04/08/2020

There are 3 x log files. One web log, windows security audit log, and a sysmon log. The logs are in the following zip file:

The SIEM generated an alert in response to an attempt to create a user to a local administrator group. The action appeared to have failed as there was no event in the security log. The SIEM alert detected the following activity:

“net1 localgroup administrators appusr /add”

SysMon 06/07/2020 12:57:23, EventRecID: 1087. It has been confirmed that this activity wasn’t legitimate.

Objective

Using the log files can you determine and undertake the following:

Solution

Exercise write-up

References

The following advisories may assist: