> For the complete documentation index, see [llms.txt](https://jacob-taylor.gitbook.io/security-analyst/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://jacob-taylor.gitbook.io/security-analyst/path-5/security-information-and-event-management/investigating-with-splunk.md).

# Investigating with Splunk

Investigate anomalies using Splunk.

<mark style="color:blue;">A SOC Analyst has observed some anomalous behavior's in the logs of a few Windows machines. It seems the adversary has access to some of these machines and successfully created a backdoor. The analyst has been asked to pull those logs from suspected hosts and ingest them into Splunk for quick investigation. The SOC Analyst's task is to examine the logs and identify the anomalies.</mark>

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2F2MAQJmsHRUJTNN9XypiR%2Fimage.png?alt=media&amp;token=47fe42d7-a863-4375-8b1d-ce10f46945d3" alt=""><figcaption></figcaption></figure>

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FJTxmQI3cI84EEH7vCehQ%2Fimage.png?alt=media&amp;token=47948f94-12d0-4cfa-bd95-c36bd606d84f" alt=""><figcaption></figcaption></figure>

***How many events were collected and Ingested in the index main?***

12256

***On one of the infected hosts, the adversary was successful in creating a backdoor user. What is the new username?***

A1berto

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FEJwWyapsFK021vRVzfVr%2Fimage.png?alt=media&amp;token=1886df9a-33a0-4c21-9b38-56916f91e5ad" alt=""><figcaption></figcaption></figure>

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FVR26F6NlGSLwmw5ro3Od%2Fimage.png?alt=media&amp;token=69d22394-533e-4b85-b448-e99640234d5c" alt=""><figcaption></figcaption></figure>

***On the same host, a registry key was also updated regarding the new backdoor user. What is the full path of that registry key?***

HKLM\SAM\SAM\Domains\Account\Users\Names\A1berto

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FYspo5YYz7ebnpmqW9jRn%2Fimage.png?alt=media&amp;token=cf8810e5-dcbc-45c5-a0d3-381a8b5abe3e" alt=""><figcaption></figcaption></figure>

***Examine the logs and identify the user that the adversary was trying to impersonate.***

Alberto

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FrhGJ6McTu563skKp0uLc%2Fimage.png?alt=media&amp;token=7035004c-2929-42d2-bd15-6bf17a4a4c06" alt=""><figcaption></figcaption></figure>

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FFWdyOyFA0sMEqLOTQ1vG%2Fimage.png?alt=media&amp;token=59398303-022c-4540-95e2-e44e2a033a7e" alt=""><figcaption></figcaption></figure>

***What is the command used to add a backdoor user from a remote computer?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FzwPKhTrJfXwpMPM5W5sB%2Fimage.png?alt=media&amp;token=2be280c7-98af-410c-b9ce-665f21721781" alt=""><figcaption></figcaption></figure>

***How many times was the login attempt from the backdoor user observed during the investigation?***

0

***What is the name of the infected host on which suspicious Powershell commands were executed?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FONFfq2HtDwy0CdP6RC5I%2Fimage.png?alt=media&amp;token=dbb20da8-6b78-443e-a953-f5041de38c41" alt=""><figcaption><p>James.Browne</p></figcaption></figure>

***PowerShell logging is enabled on this device. How many events were logged for the malicious PowerShell execution?***

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2Fd11P6osPRF9mAKQrXKQI%2Fimage.png?alt=media&amp;token=98c26004-6469-4d48-8da1-5e3301cf53de" alt=""><figcaption><p>79</p></figcaption></figure>

***An encoded Powershell script from the infected host initiated a web request. What is the full URL?***

hxxp\[://]10\[.]10\[.]10\[.]5/news\[.]php

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2Fm0mRu7vOYN5cvBwxUGwu%2Fimage.png?alt=media&amp;token=e599ea5f-4c21-4fbb-a239-538064238c00" alt=""><figcaption></figcaption></figure>

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2Fh4cLoPMVeT68t2fH96K5%2Fimage.png?alt=media&amp;token=15d2e465-b9b7-4e43-82dc-493ecd0fb05e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FC0FpPWT2Wxz4PNfRlrnd%2Fimage.png?alt=media&amp;token=6a248ace-b1a5-41bc-a53f-ad2864104fba" alt=""><figcaption></figcaption></figure>

<figure><img src="https://309112325-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdUCUPJ7E8b7n8AB8j3ms%2Fuploads%2FrHMjUbbUqc7wPDB1Ej6k%2Fimage.png?alt=media&amp;token=d57f5f02-699a-407c-92ee-d990c491630e" alt=""><figcaption><p>hxxp[://]10[.]10[.]10[.]5/news[.]php</p></figcaption></figure>
