Salaheldinaz
Table of contents
KringleCon 2 (2019)

KringleCon 2 (2019)

To read the writeup please visit

https://kringlecon2.salaheldinaz.com/


🗺 Map

This a preview of a very high quality map for ELF University.

To zoom and check the details please download the full quality. click here:

Map


🏵 Objectives

Check the objectives in your badge, You will have the 6 objectives then unlock new objective by talking to the elves you find in the university:

ObjectiveTypeLocationTools
0/ Talk to Santa in the QuadTalkThe Quad
1/ Find the Turtle DovesExploreThe student union
2/ Unredact Threatening DocumentExploreThe Quad
3/ Windows Log Analysis: Evaluate Attack OutcomeLogs AnalysisThe event log dataDeepBlueCLI
4/ Windows Log Analysis: Determine Attacker TechniqueLogs AnalysisThe normalized Sysmon logsEQL
5/ Windows Log Analysis: Determine Compromised SystemLogs AnalysisZeek logsRITA
6/ SpunkSOCSplnuk ServerSplunk
7/ Get Access To The Steam TunnelsMultiMinty’s dorm roomMulti
8/ Bypassing the Frido Sleigh CAPTEHAMachine LearningfridosleighPython
9/ Retrieve Scraps of Paper from ServerSQL InjectionStudent PortalSqlmap
10/ Recover Cleartext DocumentReverse Engineeringelfscrow appIDA
11/ Open the Sleigh Shop DoorWeb DevCarteWeb Dev
12/ Filter Out Poisoned Sources of Weather DataLogs AnalysisSLEIGH ROUTE FINDER APIjq

🎗Helping the elves Challenges

As we walk around, we can find various challenges, and as we talk to the elves standing near them, we get some hints.

ChallengeTypeDirect UrlElfLocation
1 Escape EdEd editorLinkBushy EvergreenThe train station
2 Linux PathLinuxLinkSugarPlum MaryThe Hermey Hall
3 Xmas laser cheersPowershellLinkSparkle RedberryThe Laboratory
4 Splunk - The training questionsSOC - SplunkLinkProfessor BanasThe Laboratory
5 Mongo PilferMongoDBLinkHolly EvergreenNetwars Room
6 NyanshellLinux ShellLinkAlabaster SnowballThe Speaker UNpreparedness Room
7 Frosty KeypadKeypadLinkTangle CoalboxThe Quad
8 Holiday Hack trailWeb PentestLinkMinty CandycaneThe Dorm
9 Get Access To The Steam TunnelsKey BittingLink1 Link2KrampusMinty’s Room
10 GraylogLog AnalysisLinkPepper MinstixThe Dorm
11Smart BracesIptableslinkKent TinseltoothStudent Union
12 Zeek JSON AnalysisLog AnalysisLinkWunorse OpenslaeSleigh Shop

Resources

Virtual Machines I used:

Recording terminal: