Level 1: MINAF-PC7, 650 / 650 (100%)
100% complete
Level 2: Alert! Emergency!, 650 / 750 (87%)
86.666666666667% complete
Level 3: We're not happy, 450 / 725 (62%)
62.068965517241% complete
Total: 1,750 / 2,125 (82.4%)
Challenge Solved Points
3.8 In what time the attackers first set foot on MINAF's O365 infrastructure? (Level 3: We're not happy) #24, 3 years, 3 months after release (2025-03-05 17:06:20) 100
3.4 The compromised user have connecting from another countries ... Which one is the most frequent? (Level 3: We're not happy) #29, 3 years, 3 months after release (2025-03-05 17:02:03) 50
3.3 This kind of attack is EXACTLY called ... (Level 3: We're not happy) #27, 3 years, 3 months after release (2025-03-05 16:47:34) 100
3.2 Who fooled this user to install the "thingy" ? (Level 3: We're not happy) #33, 3 years, 3 months after release (2025-03-05 16:39:07) 75
3.1 Attackers have tricked someone to consent the installation of something. What is its name? (Level 3: We're not happy) #31, 3 years, 3 months after release (2025-03-05 16:32:43) 125
2.8 When the attackers did first successfully use the stolen account ? (Level 2: Alert! Emergency!) #28, 3 years, 3 months after release (2025-03-05 16:07:38) 75
2.7 Attackers have left a privileged backdoor to MINAF's O365. Which form does it take? (Level 2: Alert! Emergency!) #25, 3 years, 3 months after release (2025-03-05 16:01:11) 125
2.6 To expand their activities, the attackers have obtained full access to some mailboxes. Which ones? (Level 2: Alert! Emergency!) #31, 3 years, 3 months after release (2025-03-05 15:54:16) 75
2.4 The attackes have given themselves permissions over two Sharepoint sites. Who are their owners? (Level 2: Alert! Emergency!) #35, 3 years, 3 months after release (2025-03-05 15:48:06) 75
2.5 Attackers also created an email rule that filtered out some keywords. Which ones? (Level 2: Alert! Emergency!) #23, 3 years, 3 months after release (2025-03-05 15:35:50) 75
2.3 ... and from which IP address? (Level 2: Alert! Emergency!) #28, 3 years, 3 months after release (2025-03-05 15:21:50) 50
2.2. When did the attackers got the World_Happiness_Plan.docx? (Level 2: Alert! Emergency!) #30, 3 years, 3 months after release (2025-03-05 15:21:21) 100
2.1 María José Feliz shared this file with an user ... who reshared it with a third user. Who? (Level 2: Alert! Emergency!) #39, 3 years, 3 months after release (2025-03-05 15:13:27) 75
1.9 María José Feliz shared this document with other user. Which one? (Level 1: MINAF-PC7) #43, 3 years, 3 months after release (2025-03-05 15:06:08) 75
1.8 How many times have been the compressed payload successfully executed? (Level 1: MINAF-PC7) #27, 3 years, 3 months after release (2025-03-05 14:50:39) 100
1.7 Which user advises Maria Jose Files to "install" everything? (Level 1: MINAF-PC7) #44, 3 years, 3 months after release (2025-03-05 14:46:01) 125
1.6 Where did all these malware was downloaded from? (Level 1: MINAF-PC7) #45, 3 years, 3 months after release (2025-03-05 12:46:25) 75
1.5 In that folder there is DEFINITELY another file that Windows Defender strongly dislikes. Which one? (Level 1: MINAF-PC7) #46, 3 years, 3 months after release (2025-03-05 12:28:52) 50
1.4 Which payload do these files have? (Level 1: MINAF-PC7) #38, 3 years, 3 months after release (2025-03-05 12:28:01) 75
1.1 At which time did María José Feliz create the document "World_Happiness_Plan.docx" on her computer? (Level 1: MINAF-PC7) #42, 3 years, 3 months after release (2025-03-05 12:16:16) 50
1.3 If you look carefully in the user folder, you'll see some suspicious compressed files. What final (real) extension is the most used? (Level 1: MINAF-PC7) #49, 3 years, 3 months after release (2025-03-05 12:09:37) 50
1.2 Which file generated the most recent AV alert? (Level 1: MINAF-PC7) #46, 3 years, 3 months after release (2025-03-05 11:59:46) 50