Questions
1. What is the other activity made by the user glitch aside from the ListObject action?
data:image/s3,"s3://crabby-images/ef48d/ef48dd3753192cb031347954f5c28bf96755dac1" alt=""
PutObject
2. What is the source IP related to the S3 bucket activities of the user glitch?
data:image/s3,"s3://crabby-images/10a5c/10a5c43d48008a476f2752557b82f0ec0c266642" alt=""
53.94.201.69
3. Based on the eventSource field, what AWS service generates the ConsoleLogin event?
data:image/s3,"s3://crabby-images/e14e3/e14e3123d56b73e582efda75828675cf34f53d5f" alt=""
signin.amazonaws.com
4. When did the anomalous user trigger the ConsoleLogin event?
data:image/s3,"s3://crabby-images/e14e3/e14e3123d56b73e582efda75828675cf34f53d5f" alt=""
2024-11-28T15:21:54Z
5. What was the name of the user that was created by the mcskidy user?
jq -r '.Records[] | select(.eventSource=="iam.amazonaws.com" and .eventName=="CreateUser" and .userIdentity.userName=="mcskidy") | .requestParameters.userName' cloudtrail_log.json
data:image/s3,"s3://crabby-images/d73cc/d73cc4d4cccd011a22f85b1cd3e1a4853b9056cc" alt=""
glitch
6. What type of access was assigned to the anomalous user?
jq -r '.Records[] | select(.eventSource=="iam.amazonaws.com" and .eventName=="AttachUserPolicy" and .requestParameters.userName=="glitch") | .requestParameters.policyArn' cloudtrail_log.json
data:image/s3,"s3://crabby-images/d17e2/d17e283e0f431f5be093014dbf66cf06e4229d5b" alt=""
7. Which IP does Mayor Malware typically use to log into AWS?
jq -r '["Event_Time", "Event_Name", "Source_IP"], (.Records[] | select(.userIdentity.userName=="mayor_malware") | [.eventTime, .eventName, .sourceIPAddress // "N/A"]) | @tsv' cloudtrail_log.json | column -t -s $'\t'
data:image/s3,"s3://crabby-images/9e889/9e8891cbb8b203d70ee177445f29e1fc312dece2" alt=""
8. What is McSkidy’s actual IP address?
jq -r '["Event_Time", "Event_Name", "Source_IP"], (.Records[] | select(.userIdentity.userName == "mcskidy" and .eventName == "ConsoleLogin") | [.eventTime, .eventName, .sourceIPAddress // "N/A"]) | @tsv' cloudtrail_log.json | column -t -s $'\t'
data:image/s3,"s3://crabby-images/1feca/1fecac833133a9ca86de79d74c7191806d77392d" alt=""
9. What is the bank account number owned by Mayor Malware?
grep "INSERT INTO wareville_bank_transactions" rds.log | grep "Mayor Malware"
data:image/s3,"s3://crabby-images/bb484/bb484a4594ad977be283c9c58b59c7e81d04dfee" alt=""