LIVE NEWSROOM · --:-- · May 30, 2026
A LIBRARY FOR SECURITY RESEARCHERS

Splunk Basics – Did you SIEM?: TryHackMe Walkthrough

Post on X LinkedIn
Splunk Basics – Did you SIEM?: TryHackMe Walkthrough

It’s almost Christmas in Wareville, and the team of The Best Festival Company (TBFC) is busy preparing for the big celebration. Everything is running smoothly until the (Splunk SIEM SOC dashboard flashes red. A ransom message suddenly appears: 

The message comes from King Malhare, the jealous ruler of HopSec Island, who’s tired of Easter being forgotten. He’s sent his Bandit Bunnies to attack TBFC’s systems and turn Christmas into his new holiday, EAST-mas.

With McSkidy missing and the network under attack, the TBFC SOC team will utilize Splunk to determine how the ransomware infiltrated the system and prevent King Malhare’s plan from being compromised before Christmas.

// 01 Learning Objectives

  • Ingest and interpret custom log data in SIEM
  • Create and apply custom field extractions
  • Use Search Processing Language (SPL) to filter and refine search results
  • Conduct an investigation within Splunk to uncover key insights

// 02 Connecting to the Machine

Before moving forward, review the questions in the connection card below.

Room Link

// 03 Task 2 Log Analysis with Splunk

What is the attacker IP found attacking and compromising the web server?

index=main sourcetype=web_traffic

Answer: 198.51.100.55

Which day was the peak traffic in the logs? (Format: YYYY-MM-DD)

Answer: 2025-10-12

What is the count of Havij user_agent events found in the logs?

Answer: 993

How many path traversal attempts to access sensitive files on the server were observed?

Splunk Basics - Did you SIEM?: TryHackMe Walkthrough

Answer: 658

Examine the firewall logs. How many bytes were transferred to the C2 server IP from the compromised web server?

Splunk Basics - Did you SIEM?: TryHackMe Walkthrough 1

Answer: 126167

If you enjoyed today’s room, check out the Incident Handling With Splunk room to learn more about analyzing logs with Splunk.

Answer: No Answer

For any query contact us at contact@cipherssecurity.com

    TE
    Team Ciphers Security

    The Ciphers Security editorial team — practitioners covering daily threat intel, CVE deep-dives, and hands-on cybersecurity research. About us →

    Previous Enumeration & Brute Force: TryHackMe Walkthrough Next AI in Security - old sAInt nick: TryHackMe Walkthrough

    Latest News

    How to Automate Compliance Evidence Collection (Drata & Vanta 2026) Learn how to automate compliance evidence collection in 2026 using Drata or Vanta — step-by-step setup for AWS, Git… Best CNAPP Platforms 2026: Multi-Cloud Enterprise Buyer's Guide Best CNAPP platforms 2026: Wiz, Prisma Cloud, CrowdStrike, Orca, Lacework, Sysdig, Aqua, and Defender ranked for mu… Druva vs Rubrik vs Cohesity: Immutable Backup for Ransomware Recovery 2026 Compare Druva vs Rubrik vs Cohesity immutable backup for ransomware recovery 2026: architecture, RTO/RPO, pricing, … Drata vs Vanta vs Tugboat Logic: Compliance Automation Comparison 2026 Compare Drata vs Vanta vs Tugboat Logic on pricing, framework breadth, integrations, and time to audit-ready for SO… JINX-0164 Targets Crypto Firms with macOS Malware and CI/CD Hijacking JINX-0164 targets crypto firms with AUDIOFIX macOS malware via fake LinkedIn recruiters and CI/CD supply chain pois… CSPM vs CWPP: Choosing the Right Cloud Security Tool in 2026 CSPM vs CWPP cloud security 2026 guide: compare Wiz, Prisma Cloud, Lacework, and Defender for Cloud with a decision… FBI USB Insider Threat Alert: DLP Policy and Detection Controls FBI USB insider threat alert: Silent Ransom Group sends operatives to insert USB drives at law firms. Enterprise DL… Best Vulnerability Management Tools for Enterprise Security Teams in 2026 Evaluate the best vulnerability management tools enterprise 2026: Tenable, Qualys, Rapid7, Wiz, and Falcon Spotligh…
    Scroll to Top
    Ad