← All Challenges
Phantom SOC
Forensics
200 pts
standard
Challenge Description
An intrusion occurred while the SOC dashboard stayed green. The attacker is suspected of tampering with detection content and API keys in the SIEM stack.
Identify:
- Compromised API key ID.
- Deleted detection rule ID.
- First host hidden by suppression.
- Source IP that performed tampering actions.
Flag format: HackCTF{...}
Files
Hints
Submit Flag
Login to submit a flag.