user123

3rd place

3701 points


Awards


Solves

Challenge Category Value Time
1 - Discover 0 - Section Unlocks 50
1.1 - Setting the Stage 1 - Discover 50
1.2 - Messing with Time 1 - Discover 50
1.3 - Choose index pattern 1 - Discover 50
1.4 - Sort by field 1 - Discover 50
1.5 - Open document 1 - Discover 50
1.6 - IDS Data 1 - Discover 50
1.7 - Zeek and you shall find 1 - Discover 50
1.8 - ALL the logs 1 - Discover 50
2 - Visualizations 0 - Section Unlocks 50
2.1 - Highest Client Byte Count 2 - Visualizations 50
2.2 - Client Peak Time 2 - Visualizations 50
2.3 - Highest Server Byte Count 2 - Visualizations 50
2.4 - Server Peak Time 2 - Visualizations 50
3 - Lens 0 - Section Unlocks 50
3.1 - Server port 3 - Lens 50
3.2 - Record Count 3 - Lens 50
3.3 - Summary data 3 - Lens 50
3.4 - Record spike 3 - Lens 50
4 - Dashboards 0 - Section Unlocks 50
4.1 - Top Talkers 4 - Dashboards 50
4.2 - Rush hour 4 - Dashboards 50
4.3 - Out of the norm 4 - Dashboards 50
4.4 - Connection count 4 - Dashboards 50
4.14 - Hosts and Ports 4 - Dashboards 50
5 - Security App - Explore 0 - Section Unlocks 50
5.1 - Interactive 5 - Security App - Explore 50
5.2 - Mandatory 5 - Security App - Explore 50
5.3 - Hosts 5 - Security App - Explore 50
5.4 - Who is making the most noise? 5 - Security App - Explore 50
5.5 - Network 5 - Security App - Explore 50
5.6 - Which tool? 5 - Security App - Explore 50
5.7 - Dynamic 5 - Security App - Explore 50
5.8 - Top domain 5 - Security App - Explore 50
5.10 - But Is It Local? 5 - Security App - Explore 50
5.9 - Walking the path 5 - Security App - Explore 50
6 - Security App - Detection Rules 0 - Section Unlocks 50
6.1 - Query types 6 - Security App - Detection Rules 50
6.2 - Rule schedule 6 - Security App - Detection Rules 50
6.3 - Sequencing 6 - Security App - Detection Rules 50
7 - Security App - Alerts 0 - Section Unlocks 50
7.1 - Get the message? 7 - Security App - Alerts 50
7.2 - Abnormal User Agent 7 - Security App - Alerts 50
8 - Security App - Timelines 0 - Section Unlocks 50
8.1 - Change the data, change the world 8 - Security App - Timelines 50
Hunt Training Gate 0 - Section Unlocks 50
8.2 - Who's there? 8 - Security App - Timelines 50
8.3 - How many? 8 - Security App - Timelines 50
H1.1 - CONN Protocols H1 - CONN - Aug 1 50
H1.4.A - Top Service H1 - CONN - Aug 1 50
H1.4.B - Expected Port of Top Service H1 - CONN - Aug 1 50
H1.4.C - What about those other connections? H1 - CONN - Aug 1 50
H1.2 - Top Talkers - Originators H1 - CONN - Aug 1 50
H1.3 - Top Talkers - Responders H1 - CONN - Aug 1 50
H1.5 - Spike from one IP H1 - CONN - Aug 1 50
H1.6 - But at what time? H1 - CONN - Aug 1 50
H1.7 - Recap H1 - CONN - Aug 1 51
H2.2 - What port is that? H2 - HTTP - Aug 1 50
H2.3 - URI H2 - HTTP - Aug 1 50
H2.4 - Status Code H2 - HTTP - Aug 1 50
H2.5 - User Agents H2 - HTTP - Aug 1 50
H2.6 - Referrers H2 - HTTP - Aug 1 50
H2.7 - Recap H2 - HTTP - Aug 1 50
H3.1 - SSL Version H3 - SSL - Aug 1 50
H3.2 - Non-standard Ports H3 - SSL - Aug 1 50
H3.3 - SSL Validation H3 - SSL - Aug 1 50
H3.4 - Validation failed on non-standard port H3 - SSL - Aug 1 50
H3.5 - More filters! H3 - SSL - Aug 1 50
H3.6 - Originating Host H3 - SSL - Aug 1 50
H3.7 - Responding Host H3 - SSL - Aug 1 50
H3.8 - Server Name H3 - SSL - Aug 1 50
H3.9 - SSL Issuer H3 - SSL - Aug 1 50
H3.10 - Recap H3 - SSL - Aug 1 50
H2.1 - Top Talkers - HTTP H2 - HTTP - Aug 1 50