Forum Discussion
ColeS
Bronze II
9 months agoThreat Research: Cobalt Strike C2 – SIEM Analysis - Question 4
Hello, I'm trying to solve Question 4 of the "Threat Research: Cobalt Strike C2 – SIEM Analysis" lab, I've solved every other question EXCEPT that one. "What's the earliest @timestamp for the retu...
- 9 months ago
Hey folks, I consulted with a colleague who finished the lab and got the answer with their advice. Format of the answer is HH.MM.SS (periods instead of colons), and they used event.created field instead of @timestamp. Also gotta check timezones ;)
The wording of the question is a bit misleading here, may want to address that?
TillyCorless
Community Manager
9 months agoHi ColeS
Thanks for the question and sharing where you think you might need some assistance. Let me speak to the lab author and get back to you, unless any member of the community has completed this lab and can offer some advice in the meantime!