Windows Event Logs
Windows Event Logs Tolkien Ring Dusty Giftwrap |
|
Windows Event log file (.EVTX) |
In the terminal, we are asked a series of questions from the .EVTX file. |
As the 1st step, we convert the powershell.evtx to CSV
|
Q3. The contents of the previous file were retrieved, changed, and stored to a variable by the attacker. This was done multiple times. Submit the last full PowerShell line that performed only these actions. |
Answer : $foo = Get-Content .\Recipe| % {$_ -replace 'honey', 'fish oil'} |
The attacker retrieved contents of the file, changed, and stored to a variable. So, they may have used "Get-Content" |
Q4. After storing the altered file contents into the variable, the attacker used the variable to run a separate command that wrote the modified data to a file. This was done multiple times. Submit the last full PowerShell line that performed only this action. |
Answer :$foo | Add-Content -Path 'Recipe' |
To write altered file contents from a variable to a file, attacker may have used Add-Content.
|
Q5. The attacker ran the previous command against one file multiple times. What is the name of this file? |
Answer : Recipe.txt |
|
Q6. Were any files deleted? |
Answer : Yes |
Looking for usage of 'del' command in PowerShell events. Looks like 2 files were deleted.
|
Q8. What is the Event ID of the logs that show the actual command lines the attacker typed and ran? |
Answer : 4104 |
Looking for the event id of the event showing file deletion and It looks like 4104
|
Q9. Is the secret ingredient compromised (Yes/No)? |
Answer: Yes |
This is because : # The attacker got the content from original recipe file and replaced the honey with fish oil and put that updated value in the variable $foo
And then wrote the changed variable back to the original file named Recipe
|
Q10. What is the secret ingredient? |
Answer: Honey |
From the answer to the question 9) the ingredient which got replaced in the original recipe file was honey. Therefore, the secret ingredient is honey |
The objective is now completed and we get
10 coins as well |