Team Mint Security participated in the BOTS or BOSS of the SOC event which took place in Helsinki on the 13th of March. BOSS of the SOC is a Capture-the-flag (CTF) event using Splunk technology in an environment with a huge amount of data. The participants then uses Splunk to complete a variety of SOC-related questions and tasks.
BOTS is about the Blue Team
Unlike many other CTF events, BOSS of the SOC is about the Blue Team rather than the Red Team. This means you play on the defenders side of the table to find out about various cyber attacks instead of being the attacker. As the event progresses, the questions and challenges become more and more complicated. Many external sources of information and tools must be utilized. The correct answers may be hidden and found in a binary attachment inside a smtp stream. Of course you must first find the right smtp stream…
The team
The Mint team consisted of Teemu, Saku, Putsi and Thomas. In the team, only Putsi had any kind of previous CTF experience and only Teemu and Thomas had experience with Splunk longer than “a couple of weeks”. With typical Finnish modesty we arrived with a winning mindset, but when it turned out that there were a total of 14 registered teams – and some were even organized as primary and secondary teams- we had to back off just the slightest.
The event
Lessons learned
Read more about Splunk
Splunk Enterprise Architectural Decisions
So, you’ve got your Splunk Enterprise up and running and collecting data from some of your systems. A few dashboards have been created too and life is good. But perhaps, there could be more .
Minted by Splunk
Mint Security is a Splunk partner and a license reseller. In addition, Mint Security provides a vast range of überconsulting for Splunk. From a single server to clustered multisite setups with integrated SSO and 2FA.
Getting started with Splunk Enterprise
Splunk Enterprise is known as a de-facto do-it-all log collector, that in reality is fairly easy to start with, but can be complex to master.
SIEM, Splunk & Log Management
SIEM & Log Management in Brief Situational picture is one of the biggest “hype words” at the moment. Most simply, situational picture is an overview