PS Eclipse is a medium difficulty challenge on TryHackMe, utilizing Splunk to investigate a compromise and analyze attacker actions on a device. As a SOC Analyst for the MSSP (Managed Security Service Provider) company TryNotHackMe, you are tasked with investigating events on Keegan's machine on May 16th, 2022. The client has observed unusual file extensions on some files and suspects a ransomware attempt on Keegan's device.
Follow along as we uncover this attack
Tryhackme room: https://tryhackme.com/r/room/posheclipse
Subscribe for more!