Key Party Gone Wrong

Cloud

Estimated Time

15

Difficulty

Easy

Point Value

10

Query Languages

SPL

Cloud Catastrophe
Part of Pathway

Cloud Catastrophe

The morning started like any other at Nimbus Technologies, a growing startup with a substantial AWS footprint. Their monitoring dashboard suddenly lit up with alerts—unusual login patterns, unexpected API calls, and resource changes nobody authorized.

6 Techniques

Challenge Description

You've identified the user that's been compromised in Nimbus Technologies. Now, we need to identify any persistence that has been established so when you revoke access, they can't get back in.

Log Source Types

AWS CloudTrail

MITRE ATT&CK Techniques

Getting Started

1

Sign in or create an account to begin the challenge

2

Review the challenge description and log types

3

Click "Start Challenge" to begin your investigation

Ready to start the challenge?

Head to the workspace to begin solving