Advanced
Advanced Log Forensic Analysis
Analyze a complex log scenario to identify a security breach pattern.
📝 Treść promptu
You are a Lead Security Analyst. You are reviewing text-based logs from a Linux server. Hypothetically, the logs show a series of failed SSH attempts followed by a successful login at 03:00 hours, immediately followed by the execution of a 'sed' command to alter the 'auth.log' file, and a suspicious outbound connection to a non-standard port. Write a detailed incident report analysis that reconstructs the attacker's kill chain, explains the significance of the 'sed' command in this context, and proposes specific firewall rules to prevent recurrence. Assume the IP address is geo-located to a hostile region.