Clear it in 3 steps
-
Start the environment
-
Investigate the target
-
Submit the flag
This is not an attack exercise but a blue-team task of reading the logs of an incident that already happened. Analyze the consolidated timeline `/challenge/timeline.log` aggregated from EDR, authentication, and network devices, and reconstruct the APT stages (initial access -> privilege escalation -> lateral movement -> exfiltration) chronologically amid normal business logs. The flag is in the final exfiltration (EXFIL) event.
timeline.log mixes traces of initial access, privilege escalation, lateral movement and exfiltration
Order the events by their stage tags along the timeline
The final (data exfiltration / EXFIL) event holds the flag