2018-05-11 - TRAFFIC ANALYSIS EXERCISE - NIGHT DEW

NOTICE:

ASSOCIATED FILES:

 

SCENARIO

"Night Dew" is a nickname for moonshine illegally created by someone's great-grandfather back in the early 1800s.  As decades passed, the old man's descendents kept his moonshine recipe alive.  By the late 1900s, they became a legitimate business named Night Dew Spirits.

In recent years, Night Dew Spirits expanded to several locations across the United States.  Night Dew's expansion includes a network architecture under the name nightdew[.]org.  You work in the Security Operations Center (SOC) monitoring alerts on the company's network traffic.

On Friday 2018-05-11 (UTC time), you receive unspecified alerts on a possible infected Windows host.  Your co-worker retrieves network traffic related to these alerts.  You must review the traffic and draft an incident report.

 


Shown above:  How most people feel after drinking Night Dew.

 

Characteristics of the network traffic:

 

REPORT GUIDELINES

EXECUTIVE SUMMARY:

DETAILS:

INDICATORS:

 

ANSWERS

 

Click here to return to the main page.