Forum Discussion
ColeS
Bronze II
9 months agoThreat Research: Cobalt Strike C2 – SIEM Analysis - Question 4
Hello, I'm trying to solve Question 4 of the "Threat Research: Cobalt Strike C2 – SIEM Analysis" lab, I've solved every other question EXCEPT that one. "What's the earliest @timestamp for the retu...
- 9 months ago
Hey folks, I consulted with a colleague who finished the lab and got the answer with their advice. Format of the answer is HH.MM.SS (periods instead of colons), and they used event.created field instead of @timestamp. Also gotta check timezones ;)
The wording of the question is a bit misleading here, may want to address that?
BenMcCarthy
Immerser
9 months agoHi ColeS,
Thank you for sending your feedback! We have updated the task to ask for the event, created just as you pointed out! I have also chatted with the QA teams to ensure we are triple-checking for this type of error! I hope you enjoyed the lab, though :)
ColeS
Bronze II
9 months agoWas fun, thank you!