Showing posts with label PCAP. Show all posts
Showing posts with label PCAP. Show all posts

Thursday, November 12, 2015

Spy Hunter Holiday Challenge 2015

This holiday season I have created another network forensics challenge for the community to try and solve. This scenario called “Spy Hunter – Operation Ares” is the second in a series that follows the questionable activities of Insider1.

All solutions should be submitted to me at Jordan 2175 with no space at Google’s mail service no later than December 20th, 2015. Winners will be announced in January. Entries will be rated based on completeness and overall explanation of what happened and how.

Please NOTE I will NOT accept any documents in PDF or Word format.  Only plain text email and documents, something readable by pine, vim or emacs, will be accepted. By submitting a solution you grant me the right to list your name on this blog.

Good Luck.

PDF: https://drive.google.com/file/d/0By0KeB0IEqeTNnd1WUFHQmt0TzQ/view?usp=sharing&resourcekey=0-B6SOqOuNK2Eh4vV7HrWp8w
MD5 (SpyHunter-Operation_Ares-ver1.pdf) = 5b428889accb3f7760c4418bb5b5b629

PCAP: https://drive.google.com/file/d/0By0KeB0IEqeTaHZDdWhMNUR2T00/view?usp=sharing&resourcekey=0-_GJ38BPGpaVsArQGJSiZ6w
MD5 (SpyHunter-Operation_Ares-ver1.pcap.zip) = 02aa6ab22bd628e819ace4d3df669caf

Official solution information will be available to full-time faculty members teaching courses in digital forensics or cyber security at accredited academic institutions.

Thursday, January 8, 2015

Tools for editing PCAP files

I wrote a new command line tool to rebase PCAP files and edit their layer2 and layer3 addresses. This tool is smart enough to edit corresponding ARP packets and understands 802.1Q tagged frames and Q-in-Q double tagged frames.  It should easily compile with Go v1.4 on MacOSX and Linux (it may also compile on Windows though I can not test that). You can get it on GitHub at: https://github.com/jordan2175/rewritecap

Results of the 2014 Holiday Spy Hunter Network Forensics Challenge

I hope everyone had a great holiday season and enjoyed working through the challenge. After reading through loads of really great submissions, the top 3 reports, being 90+% complete, were from:

  1. Peter VanBuskirk
  2. Matthew Edmondson
  3. Rich Cassara 

A round of virtual congratulations is in order for these three and everyone else that submitted solutions. For those of you that have been asking, the next challenge should be ready by midyear.

Wednesday, November 5, 2014

Spy Hunter Holiday Challenge 2014

This holiday season I have created a network forensics challenge for the community to try and solve. This scenario, called “Spy Hunter – Operation Hermes” is the first in a new series I am going to create and publish here at My War With Entropy.

All solutions should be submitted to me at Jordan 2175 with no space at Google’s mail service no later than December 20th, 2014. Winners will be announced in January. Entries will be rated based on completeness and overall explanation of what happened and how.

Please NOTE I will NOT accept any documents in PDF or Word format.  Only plain text email and documents, something readable by pine, vim or emacs, will be accepted. By submitting a solution you grant me the right to list your name on this blog.

Good Luck.

PDF: https://drive.google.com/file/d/0By0KeB0IEqeTX0ZYWTJqRWpXdlU/view?usp=sharing&resourcekey=0-A60aXqHU_Bml20VruR2iIg
MD5 (SpyHunter-Operation_Hermes-ver1.pdf) = 6d2bb7d0ab0d83ba2da8a1142deca758

PCAP: https://drive.google.com/file/d/0By0KeB0IEqeTVl9DRUpSU1lYclk/view?usp=sharing&resourcekey=0-YR30-ma8qjCx_2gS91rJeA
MD5 (SpyHunter-Operation_Hermes-ver1.pcap.zip) = de20687a9287dcf66ddf40d699915994

Official solution information will be available to full-time faculty members teaching courses in digital forensics or cyber security at accredited academic institutions.