概要
TryHackMe「Junior Security Analyst Intro」のWalkthroughです。
Task1
Q1.What will be your role as a Junior Security Analyst?
A.Triage Specialist
Task3
Q2.What was the malicious IP address in the alerts?
Hint.What alert message shows an unauthorized connection attempt?
SSH認証に失敗したログが怪しいです。
A.221.181.185.159
Q3.To whom did you escalate the event associated with the malicious IP address?
SOC Team Lead
にエスカレーションします。
A.Will Griffin
Q4.After blocking the malicious IP address on the firewall, what message did the malicious actor leave for you?
ブロックリストにIPアドレスを追記します。
フラグを入手できます。
A.THM{UNTIL-WE-MEET-AGAIN}