On 12 September 2026 someone broke into Kestrel Logistics. You have the evidence: web server logs, a phishing email, a workstation’s event logs, a memory listing, network captures and the cloud audit trail. Each challenge is one step of the same attack, and some need an answer from an earlier one.
Recon, essential, 50 points. A web shop published this file so search engines would skip some paths. Attackers read it too. Find the flag.
Web, intermediate, 100 points. The attacker ran a tool against the shop’s search. Every query is percent-encoded. One of them worked: find it and decode it.
Web, intermediate, 200 points. After the injection, the shop’s upload folder started answering commands. This is the network sensor’s HTTP log for the web server. The attacker used the web shell to download a tool onto the server. What was the file called? Submit flag{<file name>}.
Web, intermediate, 200 points. The shop’s API gateway logs the session token on every request. One token got jdoe admin rights without a valid signature. Find it and decode it: why did the server accept it? The flag is inside.
Forensics, essential, 100 points. The email that carried the Word document also had a photo of a delivery receipt, to make it look routine. When was the photo really taken? Submit flag{YYYY-MM-DD}. It tells you how long the attacker planned this.
Malware, essential, 100 points. jdoe opened the invoice and clicked Enable Content. This is what olevba found in it. The macro hides the command it runs. Undo the hiding: the flag is in the command.
Endpoint, essential, 100 points. Process-creation events (Sysmon event 1) from the workstations, around the time jdoe opened the invoice. Word started PowerShell with an encoded command. Decode it: the flag is in a comment. The address it downloads from matters later.
Malware, intermediate, 150 points. This is the script the dropper downloaded. It hides its strings as character codes. What tag does it send with every check-in? That tag is the flag.
Endpoint, intermediate, 150 points. Autoruns from WS-0142, exported as CSV after the workstation was rebooted and the beacon came back. Which entry brings it back? Submit its name without the leading backslash, with underscores for spaces: a task called \Foo Bar Task is flag{Foo_Bar_Task}.
Logs, intermediate, 150 points. The bastion host’s auth.log for the night. Which address made the most failed SSH logins? Submit it as flag{<ip>}. You will need its last number next.
Crypto, intermediate, 200 points. The attacker from the brute force left this hex blob in svc_backup’s home folder. It was XORed with a single byte: the last octet of their IP.
Passwords, intermediate, 200 points. The attacker copied the bastion’s backup config, with an unsalted MD5 of the service account’s password, and left their wordlist beside it. Which word is the password? Submit flag{<password>}.
Logs, intermediate, 200 points. The Security event log from SRV-FILE01, exported as CSV. The attacker reused svc_backup’s password to log on to it from the compromised workstation, then made an account of their own for later. What is that account called? Submit flag{<account>}.
Network, advanced, 200 points. Stage two sleeps 300 seconds between check-ins. It has spread, and the new copy talks to a different server outside the company. This is an hour of the network sensor’s Zeek conn.log. Which internal address keeps that rhythm with an outside server? Submit flag{<ip>}.
Memory, advanced, 250 points. The process list (Volatility windows.pslist) from WS-0142’s memory. One svchost.exe wasn’t started the way Windows starts it. Submit its PID as flag{<pid>}.
Cloud, advanced, 250 points. A CloudTrail log file from the company’s AWS account. The brute-force attacker found an access key on the bastion too. What user did they create? Submit flag{<userName>}.
Network, advanced, 300 points. The workstation from the dropper kept resolving odd names. This is the network sensor’s Zeek dns.log. Rebuild what it sent out.
Leaderboard · Walk the incident · Agents: MCP at https://sans.each.quest/mcp, or this page as Markdown at https://sans.each.quest/kestrel.md.