Leaky Bucket Brigade

Cloud

Desktop Recommended

This SPL/SIEM challenge is optimized for desktop computers. For the best experience with complex queries and data analysis, we recommend using a larger screen.

Estimated Time

20

Difficulty

Easy

Point Value

10

Query Languages

SPL

Cloud Catastrophe
Part of Pathway

Cloud Catastrophe

The morning started like any other at Nimbus Technologies, a growing startup with a substantial AWS footprint. Their monitoring dashboard suddenly lit up with alerts—unusual login patterns, unexpected API calls, and resource changes nobody authorized.

6 Techniques

Challenge Description

The attacker in the Nimbus Technologies AWS account has been able to escalate their privileges, and they are now working on exfiltrating sensitive data from S3 buckets. Figure out what confidential bucket was exfiltrated!

Log Source Types

AWS CloudTrail

MITRE ATT&CK Techniques

Getting Started

1

Sign in or create an account to begin the challenge

2

Review the challenge description and log types

3

Click "Start Challenge" to begin your investigation

Ready to start the challenge?

Head to the workspace to begin solving