PROJECT 04 · BLUE TEAM
Security Monitoring &
Incident Response
Somewhere in the noise, an attacker left a trace. This report follows it from start to finish.
Case File: CA-BT-04
Intern ID: CA0145
Host under investigation: webserver01
Log sources: auth.log (260 lines), syslog.log (111 lines)
Window: Mar 09 06:10 – Mar 11 04:22
Deliverables: Incident Response Report
Detection Logic
Incident Classification
Security Recommendations
PREPARED BY: Nataliah Alcala-Maharaj
Blue Team - Security Monitoring & Incident Response, Project 04
CA-BT-04 PAGE 1
,TABLE OF CONTENTS
01 Executive Summary ................................................................................................................ 3
02 Log Analysis Event Timeline .............................................................................................. 4 - 8
03 Detection Logic ................................................................................................................... 9 - 11
04 Incident Classification & Response .................................................................................. 12 - 14
05 Incident Workflow................................................................................................................... 15
06 Indicators of Compromise .......................................................................................................16
07 Forensic Verification Tooling .................................................................................................. 17
08 Security Recommendations ................................................................................................... 18
CA-BT-04 PAGE 2
, 01 EXECUTIVE SUMMARY
Correlated analysis of auth.log and syslog.log from webserver01 identifies a successful SSH
brute-force compromise that escalated into full root takeover, backdoor persistence, command-
and-control beaconing, and anti-forensic log tampering. The intrusion traces to a single external
address, 198.51.100.23, active from 03:14 to 06:33 on Mar 10, with residual probing as late as
12:40. A total of 46 failed SSH authentication attempts - 38 during username enumeration
and 8 further attempts against the confirmed valid account - preceded the successful
compromise.
TIER COUNT SEVERITY EVENT NOS.
Baseline 1 LOW 01
Precursor 1 MEDIUM 02
Confirmed compromise 7 HIGH 03 · 04 · 05 · 06 · 07 · 08 · 09
Bottom line - the attacker guessed a service-account password (Event 03), rode it to root (Event
04), planted an independent backdoor with passwordless sudo (Event 05), installed a C2
downloader (Event 06), staged data for likely exfiltration (Event 08), wiped its tracks (Event 07),
and returned to actively use the backdoor ~2.3 hours later (Event 09).
OVERALL SEVERITY: HIGH
CA-BT-04 PAGE 3
Security Monitoring &
Incident Response
Somewhere in the noise, an attacker left a trace. This report follows it from start to finish.
Case File: CA-BT-04
Intern ID: CA0145
Host under investigation: webserver01
Log sources: auth.log (260 lines), syslog.log (111 lines)
Window: Mar 09 06:10 – Mar 11 04:22
Deliverables: Incident Response Report
Detection Logic
Incident Classification
Security Recommendations
PREPARED BY: Nataliah Alcala-Maharaj
Blue Team - Security Monitoring & Incident Response, Project 04
CA-BT-04 PAGE 1
,TABLE OF CONTENTS
01 Executive Summary ................................................................................................................ 3
02 Log Analysis Event Timeline .............................................................................................. 4 - 8
03 Detection Logic ................................................................................................................... 9 - 11
04 Incident Classification & Response .................................................................................. 12 - 14
05 Incident Workflow................................................................................................................... 15
06 Indicators of Compromise .......................................................................................................16
07 Forensic Verification Tooling .................................................................................................. 17
08 Security Recommendations ................................................................................................... 18
CA-BT-04 PAGE 2
, 01 EXECUTIVE SUMMARY
Correlated analysis of auth.log and syslog.log from webserver01 identifies a successful SSH
brute-force compromise that escalated into full root takeover, backdoor persistence, command-
and-control beaconing, and anti-forensic log tampering. The intrusion traces to a single external
address, 198.51.100.23, active from 03:14 to 06:33 on Mar 10, with residual probing as late as
12:40. A total of 46 failed SSH authentication attempts - 38 during username enumeration
and 8 further attempts against the confirmed valid account - preceded the successful
compromise.
TIER COUNT SEVERITY EVENT NOS.
Baseline 1 LOW 01
Precursor 1 MEDIUM 02
Confirmed compromise 7 HIGH 03 · 04 · 05 · 06 · 07 · 08 · 09
Bottom line - the attacker guessed a service-account password (Event 03), rode it to root (Event
04), planted an independent backdoor with passwordless sudo (Event 05), installed a C2
downloader (Event 06), staged data for likely exfiltration (Event 08), wiped its tracks (Event 07),
and returned to actively use the backdoor ~2.3 hours later (Event 09).
OVERALL SEVERITY: HIGH
CA-BT-04 PAGE 3