# GitTheGate Lab

Q1) Using the "View Surrounding Documents" option, find the ID of the document that is 14 documents before (older) the id GDQOB3IBwJHf9VOW-r0Y?

```xquery
_id: GDQOB3IBwJHf9VOW-r0Y
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FqMz7dY9F5tVDCgptvU67%2FScreenshot(1).png?alt=media&#x26;token=cc327bf4-14f8-4c88-aa42-cebc20f80e39" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FeoQcy4pNWc3STg5kqTRi%2FScreenshot(2).png?alt=media&#x26;token=315d2720-3b73-4970-8569-73f28ac5b517" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FwNlIzitT1GsK8s20Et0o%2FScreenshot(3).png?alt=media&#x26;token=fe53b87b-50b4-4cbe-9b3e-45d15a0f6361" alt=""><figcaption></figcaption></figure>

Answer:  tzQOB3IBwJHf9VOW-Lyd

Q2) Using the "View Surrounding Documents" option, find the IP of the document that is 16 documents after (newer) the id vDQOB3IBwJHf9VOW-Lyd?

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2F1GFTUH20xr9fyQnPsfwa%2FScreenshot(4).png?alt=media&#x26;token=13859463-ddbf-448f-a8e8-f08f9ff8fba7" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2Fo9jPN1naLYlXeOy11sUu%2FScreenshot(5).png?alt=media&#x26;token=080e695e-c65a-4ca7-8853-22440974337b" alt=""><figcaption></figcaption></figure>

Answer:  191.189.39.130

Q3) How many requests have come from the IP address 2.49.53.218 between the 6th of May and the 13th of May? (time is in UTC)

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FDUI5uYBiOkkldqpj0XTP%2FScreenshot(6).png?alt=media&#x26;token=c886c4cb-eefb-4429-8c38-aac74ded4c2d" alt=""><figcaption></figcaption></figure>

```xquery
ip: 2.49.53.218
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FtlHmKJxM7ZpuVI2okAbx%2FScreenshot(7).png?alt=media&#x26;token=3ef53528-e9ca-4f47-8d94-09f8fe0b001f" alt=""><figcaption></figcaption></figure>

Answer:  7

Q4) What percentage of logs are from windows 8 machines on the 11th of May? (time is in UTC)

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FCP8lFt4ZhhhBFVg3tTJc%2FScreenshot(8).png?alt=media&#x26;token=4663ad4c-5cd8-49bf-8f8b-59f3e7b859c8" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FgRZB15pP5BamrIST68ie%2FScreenshot(9).png?alt=media&#x26;token=1e9f4635-713d-4dd5-8b51-ff33f7a9de8b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FAQEYWpMGdyNOJJMn48yz%2FScreenshot(10).png?alt=media&#x26;token=80ba4133-80b5-455a-a24a-5f43eb1f573c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2F0AwGDwyjqWdEvundCWBt%2FScreenshot(11).png?alt=media&#x26;token=9cb51d9a-241a-403e-9cbc-f4acb480ea9c" alt=""><figcaption></figcaption></figure>

Answer:  21.74%

Q5) How many 503 errors were there on the 8th of May? (time is in UTC)

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FJ5CNzup0adwmFR9LaE47%2FScreenshot(12).png?alt=media&#x26;token=c2283719-c226-436b-b4cd-d800fc4e9a30" alt=""><figcaption></figcaption></figure>

```
response: 503
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FVVzGGRpRO6yFTv60Do16%2FScreenshot(13).png?alt=media&#x26;token=cc8fc715-0dec-43fc-add2-58e3b29570de" alt=""><figcaption></figcaption></figure>

Answer:  8

Q6) How many connections to the host "[www.elastic.co](http://www.elastic.co)" were made on the 12th of May? (time is in UTC)

```xquery
host: www.elastic.co
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FbsCKPKzAGmQsvSSdXGRU%2FScreenshot(14).png?alt=media&#x26;token=51e50112-9f9f-4851-9bc5-6afada62d72e" alt=""><figcaption></figcaption></figure>

Answer:  82

Q7) What is the second most common extension of files being accessed on the 12th of May? (time is in UTC)

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FYf6oduFCu1utNWjfB5I1%2FScreenshot(15).png?alt=media&#x26;token=82fdde51-24b3-468a-9d38-c89ab6f27bb9" alt=""><figcaption></figcaption></figure>

Answer:  .gz

Q8) Find the first IP address to connect to the host elastic-elastic-elastic.org on the 12th of May. (time is in UTC)

```xquery
host: "elastic-elastic-elastic.org"
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2F9nOY8YD35TQBXj2eZwPj%2FScreenshot(17).png?alt=media&#x26;token=0b885ac6-6674-4685-8a0b-f3f369ea548d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2Fl8F76xFXoew8DNVZ5QNX%2FScreenshot(18).png?alt=media&#x26;token=0b20a0a0-6646-406d-b1d1-507f1af68872" alt=""><figcaption></figcaption></figure>

Answer:  114.246.225.218

Q9) What was the username used that failed to log in on the 15th of May at 10:44 pm? (time is in UTC)

```xquery
event.type: "authentication_failure"
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2F7AIzGNm7pJuJGQ4y0lG0%2FScreenshot(19).png?alt=media&#x26;token=1ef97461-cba4-4f68-af35-841066d6d348" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FpZ4LDzIK0gkXaXupJtQA%2FScreenshot(20).png?alt=media&#x26;token=71855a65-3ec2-40ae-a6b1-6182321e1b6f" alt=""><figcaption></figcaption></figure>

Answer:  deploy

Q10) According to the logs, which vulnerable version of Kibana was identified as running in the stack?

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2Fk8HOkeYf6sD0nv2BvSxZ%2FScreenshot(21).png?alt=media&#x26;token=dc165e61-fd8f-4dc4-b445-2f4850db1d07" alt=""><figcaption></figcaption></figure>

Answer:  7.6.2

Q11) Using current data in the auditbeat index, what is the name of the elasticsearch node? (one word)

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FjZ9CRBBoGYLR7GYEOs7w%2FScreenshot(22).png?alt=media&#x26;token=71008588-6cc1-40bb-991d-2272b72a68b0" alt=""><figcaption></figcaption></figure>

Answer:  elkstack

Q12) What is the name of the beat to collect windows logs? (one word)

Answer:  winlogbeat

Q13) What is the name of the beat that sends network data? (one word)

Answer: packetbeat

**Q14)** How many fields are in the auditbeat-\* index pattern?

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FCf6l3gUQ3GEhcx9bq7Gx%2FScreenshot(23).png?alt=media&#x26;token=4f59d5f5-0974-49dd-b484-ce784f93f1c8" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2F0O7OrJxbTlT7GCkq4dzU%2FScreenshot(24).png?alt=media&#x26;token=59645e10-21cc-4bd2-90bc-8d781f6f1f87" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FJkpgulFldCcrxHbc896e%2FScreenshot(25).png?alt=media&#x26;token=f813e75e-7b3e-44d4-baac-98a14c4abe07" alt=""><figcaption></figcaption></figure>

Answer:  437

Q15) On the 14th of May, how many failed authentication attempts did the host server receive? (time is in UTC)

```xquery
event.type: authentication_failure
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FlFmptVCK83dVcfkJhJvW%2FScreenshot(26).png?alt=media&#x26;token=0e908707-04bb-4853-9faa-cd543ebbf6a3" alt=""><figcaption></figcaption></figure>

Answer:  762

Q16) On the 13th and 14th of May, how many bytes were received by the source IP 159.89.203.214 (time is in UTC)

```xquery
source.ip: "159.89.203.214"
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2Fv59YNuCbIK9pT45ad9E1%2FScreenshot(27).png?alt=media&#x26;token=cd581213-5afb-4daa-a804-87a056d45bde" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FI4dkORjU9doHlEPNobh7%2FScreenshot(28).png?alt=media&#x26;token=f5382e0c-68cc-425f-8e18-7befd5c5be94" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2Fhj7YWRWAVVzJazaCvghJ%2FScreenshot(29).png?alt=media&#x26;token=aadfddce-05d5-4a0a-b476-d64a87a3d3f9" alt=""><figcaption></figcaption></figure>

Answer:  492,919

Q17) What username did they crack?

```xquery
event.type: 'authentication_success'
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FBkpQIZGCeHBS6cHHUtmI%2FScreenshot(30).png?alt=media&#x26;token=97ec9064-8d09-4816-a97c-3892f2936d4e" alt=""><figcaption></figcaption></figure>

```xquery
event.type: 'authentication_failure'
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FoN77jaWqkGNIfcwnNRT6%2FScreenshot(31).png?alt=media&#x26;token=e28ef67f-4fe6-4580-9695-60f043bac385" alt=""><figcaption></figcaption></figure>

Answer:  johnny

Q18)  What host was attacked?

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2F320x59XuxC93mvgPL8fD%2FScreenshot(33).png?alt=media&#x26;token=f32db481-3413-492f-b96a-9d0cd48e50b4" alt=""><figcaption></figcaption></figure>

Answer:  sshbox

Q19) How many were failed attempts made on the machine?

```xquery
event.type: 'authentication_failure'
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2Fgw5BsJ2uBQbFODlHHbDE%2FScreenshot(34).png?alt=media&#x26;token=3c235969-f784-40f5-92f7-8413caf54b57" alt=""><figcaption></figcaption></figure>

Answer:  12523

Q20) What time was the last failed attempted login?

```xquery
event.type: 'authentication_failure' and host.name: 'sshbox'
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FaHUmIkpnvYXMqarWrXgt%2FScreenshot(35).png?alt=media&#x26;token=39827b3e-f5e3-4551-b718-e5135094c252" alt=""><figcaption></figcaption></figure>

Answer:  11:39:31

Q21) What time did the attacker successfully login?

Based on the scenario, the attack is believed to have occurred on May 25th between 9:00 AM and 11:30 AM.

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2Fnq8ISrxqI22pGOYlGzYt%2FScreenshot(36).png?alt=media&#x26;token=adfa354a-8d69-4016-80d5-542b313701b0" alt=""><figcaption></figcaption></figure>

Answer:  11:50:13

Q22) What tool did the attacker use to get the exploit onto the machine?

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2F03N1nW19hj72Sr7Tcpo4%2FScreenshot(38).png?alt=media&#x26;token=cff237d3-e660-4b71-b45a-daad6a0cc383" alt=""><figcaption></figcaption></figure>

Answer:  git

Q23) Shortly after getting the exploit on the machine, the attacker used vim to create a file. What is the name of that file?

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2F4PVmH5fsnOyQ4plbMvPd%2FScreenshot(39).png?alt=media&#x26;token=824cb1ef-0ff5-4074-a03e-f9289463073a" alt=""><figcaption></figcaption></figure>

Answer:  ElasticCTFisFun!

Q24) What is the filename of the exploit that was run?

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2F9EFjmqoal5vudGO3faNq%2FScreenshot(40).png?alt=media&#x26;token=6611859d-05b0-4317-8245-c612ef2200d9" alt=""><figcaption></figcaption></figure>

Answer:  CVE-2019-7609-kibana-rce.py

Q25) What is the first ID of the log that shows the exploit being run?

```xquery
agent.hostname:"sshbox"  and *CVE-2019-7609-kibana-rce.py*
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2FlCBL5wEawY59tpyOcDos%2FScreenshot(41).png?alt=media&#x26;token=1f26a518-22f9-44bf-ad12-fc76bed56666" alt=""><figcaption></figcaption></figure>

Answer:  \_SHbS3IBCEolQs9lAD3z

Q26) What parameter turned the script from testing to exploiting?

From this link:  <https://github.com/LandGrey/CVE-2019-7609>

Answer:  --shell

Q27) Determining the destination IP is key to tracing the attacker’s actions. What is the destination IP address where the malicious shell was sent?

```xquery
agent.hostname:"sshbox"  and process.name:"nc"
```

<figure><img src="https://2537271824-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIswWWP3l0rGuQmG2WUcr%2Fuploads%2Fn2uRGSqHNNiuG43BElb0%2FScreenshot(42).png?alt=media&#x26;token=3f3d5868-b65e-417d-bf67-3c7a2f348436" alt=""><figcaption></figcaption></figure>

Answer:  10.116.0.2

Q28) Identifying new users is vital to uncovering unauthorized access. What was the name of the user they created?

```xquery
process.name: useradd 
```

<figure><img src="broken-reference" alt=""><figcaption></figcaption></figure>

Answer:  Thanks4Playing
