Automated Malware Triage Pipeline
Build a fully automated malware analysis pipeline integrating Cuckoo Sandbox, MISP, and custom YARA rule generation.
Capstone Investigation
You are in a sandbox environment simulating real infrastructure. Complete ALL steps below in order. You must type commands from memory — no answer keys. Read output carefully — you'll be asked analysis questions based on what you see.
Step 1: Verify SIEM Health
Confirm Splunk is running and all Splunk daemons are healthy before beginning investigation.
💡 Check the status of the Splunk service using its CLI.
Step 2: Review Log Ingestion Sources
🔒 Complete previous steps to unlock
Step 3: Analysis: Identify Missing Log Source
🔒 Complete previous steps to unlock
Step 4: Enable Forwarder Reception
🔒 Complete previous steps to unlock
Step 5: Restart Splunk to Apply Changes
🔒 Complete previous steps to unlock
Step 6: Query Elasticsearch Cluster Health
🔒 Complete previous steps to unlock
Step 7: Analysis: Diagnose Cluster Status
🔒 Complete previous steps to unlock
Step 8: Analysis: Identify the Problem
🔒 Complete previous steps to unlock
Step 9: Check Elasticsearch Service Status
🔒 Complete previous steps to unlock
Step 10: Investigate Recent Security Alerts
🔒 Complete previous steps to unlock
Step 11: Analysis: Identify the Attacker
🔒 Complete previous steps to unlock
Step 12: Block the Attacker IP
🔒 Complete previous steps to unlock
Investigation Tips
- • Type 'help' for guidance and current step hints
- • Type 'objectives' to see your full mission
- • Read command output carefully — you'll be tested on it
- • Analysis questions require correct answers to proceed
- • No answer keys — you must know the commands
- • 3 wrong analysis answers reveals the hint
Task Status
Complete all 12 steps in order. Progress: 0/12.
