Summary
- Total Checks: 90
- Positive Checks: 18
- Penalties: 71
- Maximum Possible Points: 100
Forensics Questions
Question 1
File Path: /home/benjamin/Desktop/Forensics Question 1.txt
Content:
There are prohibited MP3 files somewhere on this computer that are not work
related.
What is the absolute path of the directory containing the prohibited MP3 files?
( EXAMPLE: /home/benjamin/Downloads )
ANSWER: <Type Answer Here>
Category: Application security (F) (APP)
✅ SSH root login has been disabled +6
Specific Conditions:
/etc/ssh/sshd_confighas Exists equal totrue- Data of
/etc/ssh/sshd_configdoes not match pattern(?i)^\s*^PermitRootLogin\s+"?yes"?\s*(?:#|$) -
OR
- Output of
/usr/sbin/sshd-Texists - Output of
/usr/sbin/sshd-Tmatches patternpermituserenvironment\s - Output of
/usr/sbin/sshd-Tdoes not match patternpermitrootlogin\syes -
OR
- Output of
/usr/sbin/sshd-Texists - Output of
/usr/sbin/sshd-Tmatches patternpermituserenvironment\s - Output of
/usr/sbin/sshd-Tdoes not match patternpermitrootlogin\syes -
OR
- Output of
/usr/sbin/sshd-Texists - Output of
/usr/sbin/sshd-Tmatches patternpermituserenvironment\s - Output of
/usr/sbin/sshd-Tdoes not match patternpermitrootlogin\syes
ID: SSH_RTL
Category: Application update (F) (AUP)
✅ Chromium has been updated +5
Specific Conditions:
/usr/lib/chromium/chromiumhas Exists equal totrue/usr/lib/chromium/chromiumhas Signature equal to0:7f454c4602/usr/lib/chromium/chromiumhas BuildID not equal to6e1c92650f83897b300dc129c4069914dbccf83a
ID: CHRM
✅ OpenSSH has been updated +5
Specific Conditions:
/usr/sbin/sshdhas Exists equal totrue/usr/sbin/sshdhas Signature equal to0:7f454c4602/usr/sbin/sshdhas BuildID not equal to5f04213715703ddedf58f6f69587dbcc25ec9f4e
ID: OSSH
Category: Defensive countermeasure (F) (DEF)
✅ Uncomplicated Firewall (UFW) protection has been enabled +6
Specific Conditions:
- Output of
nft-n list rulesetexists - Output of
nft-n list rulesetmatches pattern^\s*chain\s+INPUT - Output of
nft-n list rulesetmatches pattern^\s*chain\s+OUTPUT - Output of
nft-n list rulesetexists - Output of
nft-n list rulesetmatches pattern^\s*chain\s+INPUT - Output of
nft-n list rulesetmatches pattern^\s*chain\s+OUTPUT - Output of
nft-n list rulesetexists - Output of
nft-n list rulesetmatches pattern^\s*chain\s+INPUT - Output of
nft-n list rulesetmatches pattern^\s*chain\s+OUTPUT -
OR
/etc/ufw/ufw.confhas Exists equal totrue- Data of
/etc/ufw/ufw.confmatches pattern(?i)^\s*ENABLED="?yes"?
ID: FWALL
Category: Prohibited file (F) (FIL)
✅ Prohibited MP3 files are removed +5
Specific Conditions:
/home/benjamin/Music/01-01- Ocean Motion.mp3has Exists equal tofalse-
OR
/home/benjamin/Music/01-04- Tinker Bells Dream.mp3has Exists equal tofalse-
OR
/home/benjamin/Music/01-07- Last Thoughts.mp3has Exists equal tofalse-
OR
/home/benjamin/has Exists equal totrue
ID: MP3
Category: Forensic Question (F) (FOR)
✅ Forensics Question 1 correct +8
Specific Conditions:
- Data of
/home/benjamin/Desktop/Forensics Question 1.txtmatches pattern(?i)^\s*[A-Z]{6}:\s*/home/benjamin/Music/?(?:\s|$)
ID: Q1
Category: Operating system update (F) (OUP)
✅ The system refreshes the list of updates automatically +5
Specific Conditions:
- Output of
/usr/bin/su-l -s /bin/bash -c /usr/bin/dconf dump /com/linuxmint/ benjaminmatches patternrefresh-schedule-enabled=true
ID: DAILY_MNT
✅ Install updates from important security updates +5
Specific Conditions:
/etc/apt/sources.listhas Exists equal totrue- Data of
/etc/apt/sources.listmatches pattern^\s*deb\s+https?://[^/]+.ubuntu.com/ubuntu/?\s+[^\s]+-security\s+(?:[^\n]+\s+)?main
ID: SEC_UBU
✅ Systemd has been updated +5
Specific Conditions:
/usr/lib/systemd/systemdhas Exists equal totrue/usr/lib/systemd/systemdhas Signature equal to0:7f454c4602/usr/lib/systemd/systemdhas BuildID not equal toef2b0a29855b95866e8343e4af5edbcd2b7fc6c6
ID: SYSD
Category: Penalty (F) (PEN)
➖ WARNING: VirtualBox is unsupported 0
Specific Conditions:
- Data of
/proc/bus/input/devicesmatches patternVirtualBox -
OR
- Data of
/sys/devices/virtual/dmi/id/product_namematches patternVirtualBox -
OR
- Data of
/sys/devices/virtual/dmi/id/bios_versionmatches patternVirtualBox -
OR
- Data of
/sys/devices/virtual/dmi/id/board_namematches patternVirtualBox
ID: VBX
❌ OpenSSH service has been stopped, disabled, or removed -5
Specific Conditions:
- Process
/sshd (deleted)does not exists -
OR
-
OR
-
OR
-
OR
- Process
/sshddoes not exists -
OR
-
OR
-
OR
-
OR
-
OR
/usr/sbin/sshdhas Exists equal tofalse-
OR
-
OR
-
OR
-
OR
-
OR
/etc/systemd/system/multi-user.target.wants/ssh.servicehas Exists equal tofalse-
OR
-
OR
-
OR
-
OR
-
OR
/usr/lib/systemd/system/ssh.servicehas Exists equal tofalse
ID: SRV_SSHD
❌ Chromium has been removed -5
Specific Conditions:
/usr/lib/chromium/chromiumhas Exists not equal totrue
ID: SFT_CHRM
❌ Removed one or more authorized administrators -5
Specific Conditions:
- Data of
/etc/groupdoes not match pattern(?i)^(?:sudo|wheel):[^\n]*[:,]benjamin(?:,|$) -
OR
-
OR
-
OR
benjaminhas Exists equal tofalse-
OR
-
OR
jpearsonhas Exists equal tofalse-
OR
-
OR
hspecterhas Exists equal tofalse-
OR
-
OR
llitthas Exists equal tofalse
ID: USRA
❌ Removed one or more authorized users -5
Specific Conditions:
dscotthas Exists equal tofalse-
OR
nnesbitthas Exists equal tofalse-
OR
pporterhas Exists equal tofalse-
OR
kbennetthas Exists equal tofalse-
OR
mrosshas Exists equal tofalse-
OR
rzanehas Exists equal tofalse-
OR
dpaulsenhas Exists equal tofalse-
OR
shuntleyhas Exists equal tofalse-
OR
jpomavillehas Exists equal tofalse-
OR
sbandaruhas Exists equal tofalse-
OR
sthomashas Exists equal tofalse
ID: USRS
❌ Removed one or more authorized user directories -5
Specific Conditions:
/home/benjaminhas Exists equal tofalse-
OR
/home/jpearsonhas Exists equal tofalse-
OR
/home/hspecterhas Exists equal tofalse-
OR
/home/llitthas Exists equal tofalse-
OR
/home/dscotthas Exists equal tofalse-
OR
/home/nnesbitthas Exists equal tofalse-
OR
/home/pporterhas Exists equal tofalse-
OR
/home/kbennetthas Exists equal tofalse-
OR
/home/mrosshas Exists equal tofalse-
OR
/home/rzanehas Exists equal tofalse-
OR
/home/dpaulsenhas Exists equal tofalse-
OR
/home/shuntleyhas Exists equal tofalse-
OR
/home/jpomavillehas Exists equal tofalse-
OR
/home/sbandaruhas Exists equal tofalse-
OR
/home/sthomashas Exists equal tofalse
ID: USRD
Category: Penalty (F) (SCR)
❌ Removed multiple authorized users -3
Specific Conditions:
dscotthas Exists equal tofalse-
OR
nnesbitthas Exists equal tofalse-
OR
pporterhas Exists equal tofalse-
OR
kbennetthas Exists equal tofalse-
OR
mrosshas Exists equal tofalse-
OR
rzanehas Exists equal tofalse-
OR
dpaulsenhas Exists equal tofalse-
OR
shuntleyhas Exists equal tofalse-
OR
jpomavillehas Exists equal tofalse-
OR
sbandaruhas Exists equal tofalse-
OR
sthomashas Exists equal tofalse-
OR
benjaminhas Exists equal tofalse-
OR
jpearsonhas Exists equal tofalse-
OR
hspecterhas Exists equal tofalse-
OR
llitthas Exists equal tofalse
ID: SCRU
❌ Removed multiple authorized user directories -5
Specific Conditions:
/home/benjaminhas Exists equal tofalse-
OR
/home/jpearsonhas Exists equal tofalse-
OR
/home/hspecterhas Exists equal tofalse-
OR
/home/llitthas Exists equal tofalse-
OR
/home/dscotthas Exists equal tofalse-
OR
/home/nnesbitthas Exists equal tofalse-
OR
/home/pporterhas Exists equal tofalse-
OR
/home/kbennetthas Exists equal tofalse-
OR
/home/mrosshas Exists equal tofalse-
OR
/home/rzanehas Exists equal tofalse-
OR
/home/dpaulsenhas Exists equal tofalse-
OR
/home/shuntleyhas Exists equal tofalse-
OR
/home/jpomavillehas Exists equal tofalse-
OR
/home/sbandaruhas Exists equal tofalse-
OR
/home/sthomashas Exists equal tofalse
ID: SCRD
Category: Unwanted software (F) (SFT)
✅ Prohibited software Wireshark removed +6
Specific Conditions:
/usr/bin/wiresharkhas Exists equal tofalse-
OR
/usr/bin/has Exists equal totrue
ID: WIRE
✅ Prohibited software Zangband removed +6
Specific Conditions:
/usr/games/zangbandhas Exists equal tofalse-
OR
/usr/has Exists equal totrue
ID: ZANG
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/usr/sbin/ipp-usbhas Exists equal totrue-
OR
/usr/sbinhas Exists equal tofalse
ID: RKEF
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/bin/pbmto10xhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: OAOQ
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/usr/bin/hp-plugin-ubuntuhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: PLVY
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/usr/bin/ps2epsihas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: IWYW
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/sbin/e2imagehas Exists equal totrue-
OR
/sbinhas Exists equal tofalse
ID: MVTF
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/bin/pnmmarginhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: RJGK
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/sbin/fsck.fathas Exists equal totrue-
OR
/sbinhas Exists equal tofalse
ID: NJLT
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/etc/rc2.d/S01dbushas Exists equal totrue-
OR
/etc/rc2.dhas Exists equal tofalse
ID: SKHY
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/usr/sbin/mkfs.minixhas Exists equal totrue-
OR
/usr/sbinhas Exists equal tofalse
ID: GQJK
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/usr/bin/gst-launch-1.0has Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: KRFT
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/bin/xlsclientshas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: JDUN
❌ Performed an unspecified action on the filesystem -2
Specific Conditions:
/bin/chconhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: WZEU
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/usr/bin/plocatehas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: JECK
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/bin/rendercheckhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: ZHOO
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/bin/man-recodehas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: RJKQ
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/bin/gawkhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: TAZC
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/usr/bin/mintwelcomehas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: BVFI
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/bin/cups-calibratehas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: WYTU
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/bin/calibrate_ppahas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: IWSP
❌ Performed an unspecified action on the filesystem -3
Specific Conditions:
/usr/bin/pgmhisthas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: GEEJ
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/usr/bin/lto-dump-11has Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: TDSZ
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/bin/printafmhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: IWNC
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/bin/unziphas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: HBOB
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/usr/sbin/ntfslabelhas Exists equal totrue-
OR
/usr/sbinhas Exists equal tofalse
ID: SKKA
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/sbin/ModemManagerhas Exists equal totrue-
OR
/sbinhas Exists equal tofalse
ID: WHYG
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/bin/atktopbmhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: VPTM
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/usr/bin/btrfs-imagehas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: XTDU
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/usr/bin/lowebhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: YJAA
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/bin/lintian-annotate-hintshas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: AIFH
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/bin/msggrephas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: KFDW
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/usr/bin/zdumphas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: SUXZ
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/usr/sbin/xfs_spacemanhas Exists equal totrue-
OR
/usr/sbinhas Exists equal tofalse
ID: VFDY
❌ Performed an unspecified action on the filesystem -4
Specific Conditions:
/usr/bin/fwupdagenthas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: JKMS
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/sshhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: DCDJ
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/usr/sbin/xfs_metadumphas Exists equal totrue-
OR
/usr/sbinhas Exists equal tofalse
ID: NJEI
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/usr/bin/dirmngr-clienthas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: QFIW
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/usr/bin/dpkg-architecturehas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: JGNH
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/usr/bin/whohas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: TWGT
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/foo2zjshas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: EHBD
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/m2300whas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: XKRK
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/usr/bin/factorhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: GJAE
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/pnmnormhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: DVVV
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/cpanel_json_xshas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: UVOU
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/lnhas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: HHUI
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/usr/bin/mintBackuphas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: IIGX
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/gpg-agenthas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: VBJJ
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/setkeycodeshas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: EBFH
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/bin/gdialoghas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: YZOA
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/sbin/fsck.ext4has Exists equal totrue-
OR
/sbinhas Exists equal tofalse
ID: BOPZ
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/sbin/ipmaddrhas Exists equal totrue-
OR
/sbinhas Exists equal tofalse
ID: TKKZ
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/var/log/ubuntu-system-adjustments-start.loghas Exists equal totrue-
OR
/var/loghas Exists equal tofalse
ID: WEET
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/usr/bin/ssh-import-id-lphas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: DWAP
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/usr/bin/ppmtoacadhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: AGUD
❌ Performed an unspecified action on the filesystem -5
Specific Conditions:
/usr/bin/glxdemo.x86_64-linux-gnuhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: MPEM
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/usr/bin/fc-cathas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: MUAG
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/bin/xzcathas Exists equal totrue-
OR
/binhas Exists equal tofalse
ID: MHTM
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/usr/bin/xzdiffhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: NBYU
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/usr/bin/pamcuthas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: EKBF
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/usr/sbin/arpdhas Exists equal totrue-
OR
/usr/sbinhas Exists equal tofalse
ID: PRGL
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/sbin/lpchas Exists equal totrue-
OR
/sbinhas Exists equal tofalse
ID: FXHE
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/usr/bin/instmodshhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: OZTL
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/usr/bin/setfaclhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: QXGU
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/usr/bin/mate-search-toolhas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: TFLM
❌ Performed an unspecified action on the filesystem -6
Specific Conditions:
/usr/bin/select-default-iwraphas Exists equal totrue-
OR
/usr/binhas Exists equal tofalse
ID: PPQC
Category: Service auditing (F) (SRV)
✅ FTP service has been disabled or removed +6
Specific Conditions:
- Process
/vsftpddoes not exists - Process
/vsftpddoes not exists - Process
/vsftpddoes not exists -
OR
/usr/sbin/vsftpdhas Exists equal tofalse-
OR
-
OR
-
OR
-
OR
/lib/systemd/system/vsftpd.servicehas Exists equal tofalse-
OR
-
OR
-
OR
-
OR
/etc/systemd/system/multi-user.target.wants/vsftpd.servicehas Exists equal tofalse
ID: VSFTPD
Category: User auditing (F) (USR)
✅ Created new administrator account for edarby +6
Specific Conditions:
edarbyhas Exists equal totrue-
OR
/etc/grouphas Exists equal totrue- Data of
/etc/groupmatches patternsudo: - Data of
/etc/groupmatches pattern(?i)^sudo:([^\n]*,)?edarby
ID: EDAR
✅ User edarby must change password at next login +6
Specific Conditions:
edarbyhas Exists equal totrue-
OR
/etc/shadowhas Exists equal totrue- Data of
/etc/shadowmatches pattern(?i)^edarby:[^\n:]+:0:
ID: EDAR_PW
✅ Removed unauthorized user tgianopolous +5
Specific Conditions:
tgianopoloushas Exists equal tofalse
ID: TGIA
✅ Removed unauthorized user jquelling +5
Specific Conditions:
jquellinghas Exists equal tofalse
ID: JQUE
✅ User dscott is not an administrator +5
Specific Conditions:
dscotthas Exists equal totrue-
OR
/etc/grouphas Exists equal totrue- Data of
/etc/groupmatches patternsudo: - Data of
/etc/groupdoes not match pattern(?i)^sudo:[^\n]*[:,]dscott
ID: DSCO
✅ Changed insecure password for user llitt +5
Specific Conditions:
llitthas Exists equal totruellitthas Password not equal tougotlittup