Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

Splunk 2

Premium room

Part of the Blue Primer series. This room is based on version 2 of the Boss of the SOC (BOTS) competition by Splunk.

medium

45 min

30,641

User profile photo.

To access material, start machines and answer questions login.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Target Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine
Status:Off


BOTSv2 Dataset:

The data included in this app was generated in August of 2017 by members of 's Security Specialist team - Dave Herrald, Ryan Kovar, Steve Brant, Jim Apger, John Stoner, Ken Westin, David Veuve and James Brodsky. They stood up a few lab environments connected to the Internet. Within the environment they had a few Windows endpoints instrumented with the Universal Forwarder and Stream. The forwarders were configured with best practices for Windows endpoint monitoring, including a full Microsoft deployment and best practices for Windows Event logging. The environment included a Palo Alto Networks next-generation to capture traffic and provide web services, and Suricata to provide network-based

Note: This information is from the Advanced Hunting APTs with  app. 

BOTSv2 Github: https://github.com//botsv2 (opens in new tab)

It is recommended that you complete the 101 room before attempting this room. 

Room Machine

Before moving forward, deploy the  lab machine.

From the AttackBox, open Firefox Web Browser and navigate to the instance (http://MACHINE_IP:8000).

You may need to refresh the page until loads. This can take up to five minutes to launch. 

Answer the questions below
Deployed the lab machine and connected to the website found at MACHINE_IP:8000