https://tryhackme.com/room/loggingforaccountability
Created by: tryhackme
I continue my learning of Splunk and logging with this room. This room showcases the importance of accountability when it comes to the incident response. THM also brings up the the Identification, Authentication, Authorization, and Accountability (IAAA) model. Per THM, “IAAA stands for Identification, Authentication, Authorization, and Accountability. It is a security principle that is used to protect systems and data. IAAA ensures that only authorized users can access a system and that their actions can be tracked.”
Make sure you have prior Splunk knowledge as the end task has you use Splunk with no tips on search filters.
Task 2 has a couple of importance links: https://attack.mitre.org/ and https://www.microsoft.com/en-us/security/blog/2007/09/11/stride-chart/. They also link to another room which I plan on doing: https://tryhackme.com/room/auditingandmonitoringse.
“A user being held accountable for their actions, as proven by logs, is known as what?”
This use of accountability is more formally known as non-repudiation and contributes to many threat models, such as the STRIDE model(opens in new tab). Non-repudiation means that an individual cannot contest an action, the opposite of repudiation, where an individual disputes an action.”
Task 3 covers Log Ingestion and Storage. It covers storage of data for compliance. For example, the PCI DSS standard is an example where the data must be stored for a year, in that case cold storage, where the data would be on low cost drives they aren’t running continuous. Accountability, non-repudiation, and regulations all go hand in hand with storing data for compliance.
“SIEMs are typically architected with three components used for searching, indexing, and load-balancing; these components are commonly known as the search head, indexer, and forwarder, respectively.
In this room, our objective is accountability, so we will focus primarily on the indexer and how data arrives from a device to the indexer; this process is commonly known as data ingestion.
Types of data ingestion include: Agent/fowarder, Port-fowarding, Syslog, Upload.”
“What component of an SIEM is responsible for searching data?”
search head
“How many years must all audit data be stored to be PCI DSS compliant?”
1 year.
On to Task 4, Types of Logs and Data Sources.
“Many log sources exist to collect data efficiently with as much relevant information as possible. In this task, we will outline a few of the most common log sources and how they may be used in the incident response process.

“A change log is an example of what log source?”
Manual
“An application log is an example of what log source?”
Automated
On to a brief room, Task 5, Using Logs Effectively. Logs are important when it comes to the SIEM and the blue team!
“As briefly introduced in task four, using multiple log types and sources is beneficial for validating logs and creating a complete story of an incident. This concept is more formally known as correlation or building a relationship between two things: logs and data. For example, if a user performed a suspicious action (created a DLL file on the disk), a browser application log could be used to correlate their browser search history with their behavior. If they were searching for a specific installer or troubleshooting process, it may explain the suspicious action. If email logs showed a potential phishing attempt directly followed by the suspicious action, it could cause more investigation. Data enrichment can also be included in correlation efforts.”
In Task 6, Improving Incident Response with Accountability, we get to launch and work in Splunk!
“How many total events are indexed by Splunk?”

“How many events were indexed from April 15th to 16th 2022?”

“How many events are associated with the user “James”?”

“What utility was used in the oldest event associated with “James”?”

“What event ID followed process creation events associated with “James”?”
