Question
We just detected an intrusion in one of our labs!! Some strange network traffic was seen from one of the Windows servers and it was
We just detected an intrusion in one of our labs!!
Some strange network traffic was seen from one of the Windows servers and it was immediately isolated. Around the same time, there were some alerts for suspicious traffic originating from a Windows workstation in the same lab and we think the workstation might be associated with the intrusion.
We have included a packet capture of the network traffic for those two endpoints during this time frame. Also, we have been able to collect some details about those hosts.
Please take a look at the data and send us a writeup with your analysis. Affected hosts:
dcpfloor.doluscorp.net: This is a Windows server configured as a Domain Controller for this location. This server also acts as a DNS server for this subnet.
labicps.doluscorp.net: This is a Windows workstation and our system administrator Fred, was using this workstation when we detected the intrusion. He did not report any suspicious behavior on his system, but he did mention that he was accessing his personal email accounts and might have clicked on a few links.
Please be cautious while handling the file as we think it might contain live malware. Password for the file incident.zip is incident.
shaincidentzip: cfcebbfbafebc
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Thank you for providing the information about the suspected intrusion in your lab Based on the data provided I have conducted an analysis of the network traffic and host information to identify potent...Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started