SANS Holiday Hack Challenge 2019
KringleCon 2 - Objective 12 12) Filter Out Poisoned Sources of Weather Data Difficulty: 🎄🎄🎄🎄 (4/5) Use the data supplied in the Zeek JSON logs to identify the IP addresses of attackers poisoning Santa's flight mapping software. Block the 100 offending sources of information to guide Santa's sleigh through the attack. Submit the Route ID ("RID") success value that you're given. For hints on achieving this objective, please visit the Sleigh Shop and talk with Wunorse Openslae. Wunorse Openslae Wunorse Openslae here, just looking at some Zeek logs. I'm pretty sure one of these connections is a malicious C2 channel... Do you think you could take a look? I hear a lot of C2 channels have very long connection times. Please use jq to find the longest connection in this data set. We have to kick out any and all grinchy activity! So this is the part we do the cranpi Terminal..., the terminal was made f...