10. Which IP has connected to this computer using RDP?
(Level 2: Admin PC)
|
6 months, 11 days after release (2020-05-21 14:24:06)
|
300 |
7. Could you find the name of a program that can help exonerate Salvador?
(Level 2: Admin PC)
|
6 months, 11 days after release (2020-05-21 14:01:16)
|
275 |
8. There has been a recon action on this computer. When did this recon started?
(Level 2: Admin PC)
|
6 months, 11 days after release (2020-05-21 13:55:48)
|
275 |
6. When was the service used by the exfiltration software installed?
(Level 2: Admin PC)
|
6 months, 11 days after release (2020-05-21 10:05:55)
|
250 |
5.When was the last file successfully exfiltrated?
(Level 2: Admin PC)
|
6 months, 11 days after release (2020-05-21 09:52:48)
|
250 |
4. To which remote computer was the data exfiltrated to?
(Level 2: Admin PC)
|
6 months, 11 days after release (2020-05-21 09:48:23)
|
225 |
3. Which program has transmitted most data on 05/Nov/2019 ?
(Level 2: Admin PC)
|
6 months, 11 days after release (2020-05-21 09:29:53)
|
225 |
12. How many items (at most) where copied in order to be exfiltrated?
(Level 1: File Server)
|
6 months, 11 days after release (2020-05-21 08:34:06)
|
175 |
2.Which song is going to be used for the EHP project?
(Level 2: Admin PC)
|
6 months, 9 days after release (2020-05-19 09:48:41)
|
200 |
1.Where in the system is hidden the folder "Secreto" (Secret)
(Level 2: Admin PC)
|
6 months, 9 days after release (2020-05-19 09:47:33)
|
200 |
6. Which users have connected (using any kind of protocol) to the system in last month?
(Level 1: File Server)
|
6 months, 8 days after release (2020-05-18 10:06:59)
|
100 |
7. Which user was online when the file lista_candidatos.xlsx was modified the last time?
(Level 1: File Server)
|
6 months, 8 days after release (2020-05-18 10:04:18)
|
125 |
11.Which executable do you think was used to exfiltrate data
(Level 1: File Server)
|
6 months, 8 days after release (2020-05-18 09:54:45)
|
175 |
10. Which registry key is the responsible for the non-matching timestamps in the previous challenge?
(Level 1: File Server)
|
6 months, 7 days after release (2020-05-16 17:49:57)
|
150 |
9. According to MFT, which time was last accessed the file README.txt.txt? And what time was REALLY opened this file with notepad.exe
(Level 1: File Server)
|
6 months, 6 days after release (2020-05-16 17:37:35)
|
150 |
8. Which user tried to mount \\*\C$
(Level 1: File Server)
|
6 months, 7 days after release (2020-05-16 17:21:08)
|
125 |
4.EHP Project has a candidate list (the shortlist that was leaked). When was this list last accessed?
(Level 1: File Server)
|
6 months, 6 days after release (2020-05-16 09:36:57)
|
75 |
3.The EHP database is encrypted using PGP. What's the database name?
(Level 1: File Server)
|
6 months, 6 days after release (2020-05-16 09:25:12)
|
75 |
2.How many subfolders are in this shared folder
(Level 1: File Server)
|
6 months, 6 days after release (2020-05-16 09:16:16)
|
50 |
1.CHITONSRV has a shared folder. What's its name?
(Level 1: File Server)
|
#4,
6 months, 6 days after release (2020-05-16 09:11:57)
|
50 |