DEF CON DFIR CTF 2018 Write-up Part 2 - HR Server Advanced and Expert Challenges
4 minute read Published:
A writeup for the 2018 DEF CON DFIR CTF - Part 2
Introduction Following on from my last blog, I turned to the Advanced and Expert level challenges to try and uncover undoubtedly nefarious deeds. Let’s go!
HR Server - Advanced Challenges Logon Event The first question asks you to name the user that logged on at a specific time (given in UTC), as well as the logon type, logon process and IP address. With all our data ingested and ready for searching in Kibana, this was reasonably straightforward.