Investigating A Ransomware Attack in Splunk : Tryhackme PS Eclipse Walkthrough

Опубликовано: 14 Январь 2025
на канале: I.T Security Labs
635
25

PS Eclipse is a medium difficulty challenge on TryHackMe, utilizing Splunk to investigate a compromise and analyze attacker actions on a device. As a SOC Analyst for the MSSP (Managed Security Service Provider) company TryNotHackMe, you are tasked with investigating events on Keegan's machine on May 16th, 2022. The client has observed unusual file extensions on some files and suspects a ransomware attempt on Keegan's device.
Follow along as we uncover this attack


Tryhackme room: https://tryhackme.com/r/room/posheclipse


Subscribe for more!