Linux11: Hunting Failed Logins

Raw authentication logs are noisy. Filtering them fast using command pipelines is a core SOC skill

Objective

Learner can use pipes (|) to chain command output and apply simple filters

Mission

~/cases/case-1042/evidence/auth-dump.log contains mixed successful and failed login events across multiple hosts. Sarah needs the Session ID of the failed login attempt that occurred on app-srv-03 during the confirmed attack window (02:40–02:50 UTC)

Commands you may need to solve this lab

grep|cat

Questions

Machine Offline

Isolated container is offline

Click "Start Machine" to boot your sandbox instance and choose your preferred interface