File yang digunakan/diberikan dalam Challenge ini berupa custom sigma rules & windows event logs.
┌──(glmx㉿kali)-[~/Desktop/Packet Cyclone]
└─$ tree
.
├── Logs
│ ├── Application.evtx
│ ├── HardwareEvents.evtx
│ ├── Internet Explorer.evtx
│ ├── Key Management Service.evtx
│ ├── Microsoft-Client-Licensing-Platform%4Admin.evtx
│ ├── Microsoft-Windows-AAD%4Operational.evtx
│ ├── Microsoft-Windows-AppModel-Runtime%4Admin.evtx
│ ├── Microsoft-Windows-AppReadiness%4Admin.evtx
│ ├── Microsoft-Windows-AppReadiness%4Operational.evtx
│ ├── Microsoft-Windows-AppXDeployment%4Operational.evtx
│ ├── Microsoft-Windows-AppXDeploymentServer%4Operational.evtx
│ ├── Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx
│ ├── Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx
│ ├── Microsoft-Windows-Application-Experience%4Program-Compatibility-Troubleshooter.evtx
│ ├── Microsoft-Windows-Application-Experience%4Program-Inventory.evtx
│ ├── Microsoft-Windows-Application-Experience%4Program-Telemetry.evtx
│ ├── Microsoft-Windows-Application-Experience%4Steps-Recorder.evtx
│ ├── Microsoft-Windows-AppxPackaging%4Operational.evtx
│ ├── Microsoft-Windows-Audio%4CaptureMonitor.evtx
│ ├── Microsoft-Windows-Audio%4Operational.evtx
│ ├── Microsoft-Windows-Audio%4PlaybackManager.evtx
│ ├── Microsoft-Windows-Authentication User Interface%4Operational.evtx
│ ├── Microsoft-Windows-Biometrics%4Operational.evtx
│ ├── Microsoft-Windows-BitLocker%4BitLocker Management.evtx
│ ├── Microsoft-Windows-Bits-Client%4Operational.evtx
│ ├── Microsoft-Windows-CloudStore%4Operational.evtx
│ ├── Microsoft-Windows-CodeIntegrity%4Operational.evtx
│ ├── Microsoft-Windows-Containers-BindFlt%4Operational.evtx
│ ├── Microsoft-Windows-Containers-Wcifs%4Operational.evtx
│ ├── Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx
│ ├── Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx
│ ├── Microsoft-Windows-Crypto-DPAPI%4Operational.evtx
│ ├── Microsoft-Windows-Crypto-NCrypt%4Operational.evtx
│ ├── Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx
│ ├── Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Operational.evtx
│ ├── Microsoft-Windows-DeviceSetupManager%4Admin.evtx
│ ├── Microsoft-Windows-DeviceSetupManager%4Operational.evtx
│ ├── Microsoft-Windows-Dhcp-Client%4Admin.evtx
│ ├── Microsoft-Windows-Dhcpv6-Client%4Admin.evtx
│ ├── Microsoft-Windows-Diagnosis-DPS%4Operational.evtx
│ ├── Microsoft-Windows-Diagnosis-PLA%4Operational.evtx
│ ├── Microsoft-Windows-Diagnosis-Scheduled%4Operational.evtx
│ ├── Microsoft-Windows-Diagnosis-Scripted%4Admin.evtx
│ ├── Microsoft-Windows-Diagnosis-Scripted%4Operational.evtx
│ ├── Microsoft-Windows-Diagnostics-Performance%4Operational.evtx
│ ├── Microsoft-Windows-DiskDiagnosticDataCollector%4Operational.evtx
│ ├── Microsoft-Windows-FileHistory-Core%4WHC.evtx
│ ├── Microsoft-Windows-GroupPolicy%4Operational.evtx
│ ├── Microsoft-Windows-HelloForBusiness%4Operational.evtx
│ ├── Microsoft-Windows-HotspotAuth%4Operational.evtx
│ ├── Microsoft-Windows-IKE%4Operational.evtx
│ ├── Microsoft-Windows-Kernel-Boot%4Operational.evtx
│ ├── Microsoft-Windows-Kernel-EventTracing%4Admin.evtx
│ ├── Microsoft-Windows-Kernel-PnP%4Configuration.evtx
│ ├── Microsoft-Windows-Kernel-PnP%4Driver Watchdog.evtx
│ ├── Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx
│ ├── Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx
│ ├── Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx
│ ├── Microsoft-Windows-Kernel-WHEA%4Errors.evtx
│ ├── Microsoft-Windows-Kernel-WHEA%4Operational.evtx
│ ├── Microsoft-Windows-Known Folders API Service.evtx
│ ├── Microsoft-Windows-LanguagePackSetup%4Operational.evtx
│ ├── Microsoft-Windows-LiveId%4Operational.evtx
│ ├── Microsoft-Windows-MUI%4Admin.evtx
│ ├── Microsoft-Windows-MUI%4Operational.evtx
│ ├── Microsoft-Windows-ModernDeployment-Diagnostics-Provider%4Admin.evtx
│ ├── Microsoft-Windows-ModernDeployment-Diagnostics-Provider%4Autopilot.evtx
│ ├── Microsoft-Windows-ModernDeployment-Diagnostics-Provider%4ManagementService.evtx
│ ├── Microsoft-Windows-NCSI%4Operational.evtx
│ ├── Microsoft-Windows-NetworkProfile%4Operational.evtx
│ ├── Microsoft-Windows-Ntfs%4Operational.evtx
│ ├── Microsoft-Windows-Ntfs%4WHC.evtx
│ ├── Microsoft-Windows-Partition%4Diagnostic.evtx
│ ├── Microsoft-Windows-PowerShell%4Admin.evtx
│ ├── Microsoft-Windows-PowerShell%4Operational.evtx
│ ├── Microsoft-Windows-Privacy-Auditing%4Operational.evtx
│ ├── Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx
│ ├── Microsoft-Windows-Provisioning-Diagnostics-Provider%4Admin.evtx
│ ├── Microsoft-Windows-Provisioning-Diagnostics-Provider%4AutoPilot.evtx
│ ├── Microsoft-Windows-Provisioning-Diagnostics-Provider%4ManagementService.evtx
│ ├── Microsoft-Windows-PushNotification-Platform%4Admin.evtx
│ ├── Microsoft-Windows-PushNotification-Platform%4Operational.evtx
│ ├── Microsoft-Windows-ReadyBoost%4Operational.evtx
│ ├── Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx
│ ├── Microsoft-Windows-RestartManager%4Operational.evtx
│ ├── Microsoft-Windows-SMBClient%4Operational.evtx
│ ├── Microsoft-Windows-SMBServer%4Audit.evtx
│ ├── Microsoft-Windows-SMBServer%4Connectivity.evtx
│ ├── Microsoft-Windows-SMBServer%4Operational.evtx
│ ├── Microsoft-Windows-SMBServer%4Security.evtx
│ ├── Microsoft-Windows-Security-Mitigations%4KernelMode.evtx
│ ├── Microsoft-Windows-Security-Mitigations%4UserMode.evtx
│ ├── Microsoft-Windows-Security-SPP-UX-Notifications%4ActionCenter.evtx
│ ├── Microsoft-Windows-SettingSync%4Debug.evtx
│ ├── Microsoft-Windows-SettingSync%4Operational.evtx
│ ├── Microsoft-Windows-Shell-ConnectedAccountState%4ActionCenter.evtx
│ ├── Microsoft-Windows-Shell-Core%4ActionCenter.evtx
│ ├── Microsoft-Windows-Shell-Core%4AppDefaults.evtx
│ ├── Microsoft-Windows-Shell-Core%4LogonTasksChannel.evtx
│ ├── Microsoft-Windows-Shell-Core%4Operational.evtx
│ ├── Microsoft-Windows-ShellCommon-StartLayoutPopulation%4Operational.evtx
│ ├── Microsoft-Windows-SmbClient%4Audit.evtx
│ ├── Microsoft-Windows-SmbClient%4Connectivity.evtx
│ ├── Microsoft-Windows-SmbClient%4Security.evtx
│ ├── Microsoft-Windows-StateRepository%4Operational.evtx
│ ├── Microsoft-Windows-StateRepository%4Restricted.evtx
│ ├── Microsoft-Windows-Storage-Storport%4Health.evtx
│ ├── Microsoft-Windows-Storage-Storport%4Operational.evtx
│ ├── Microsoft-Windows-StorageSpaces-Driver%4Diagnostic.evtx
│ ├── Microsoft-Windows-StorageSpaces-Driver%4Operational.evtx
│ ├── Microsoft-Windows-StorageSpaces-ManagementAgent%4WHC.evtx
│ ├── Microsoft-Windows-Store%4Operational.evtx
│ ├── Microsoft-Windows-Storsvc%4Diagnostic.evtx
│ ├── Microsoft-Windows-Sysmon%4Operational.evtx
│ ├── Microsoft-Windows-TWinUI%4Operational.evtx
│ ├── Microsoft-Windows-TZSync%4Operational.evtx
│ ├── Microsoft-Windows-TaskScheduler%4Maintenance.evtx
│ ├── Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx
│ ├── Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx
│ ├── Microsoft-Windows-Time-Service%4Operational.evtx
│ ├── Microsoft-Windows-UAC%4Operational.evtx
│ ├── Microsoft-Windows-UniversalTelemetryClient%4Operational.evtx
│ ├── Microsoft-Windows-User Device Registration%4Admin.evtx
│ ├── Microsoft-Windows-User Profile Service%4Operational.evtx
│ ├── Microsoft-Windows-UserPnp%4ActionCenter.evtx
│ ├── Microsoft-Windows-UserPnp%4DeviceInstall.evtx
│ ├── Microsoft-Windows-VPN%4Operational.evtx
│ ├── Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx
│ ├── Microsoft-Windows-WER-PayloadHealth%4Operational.evtx
│ ├── Microsoft-Windows-WFP%4Operational.evtx
│ ├── Microsoft-Windows-WMI-Activity%4Operational.evtx
│ ├── Microsoft-Windows-Wcmsvc%4Operational.evtx
│ ├── Microsoft-Windows-WebAuthN%4Operational.evtx
│ ├── Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx
│ ├── Microsoft-Windows-WinRM%4Operational.evtx
│ ├── Microsoft-Windows-Windows Defender%4Operational.evtx
│ ├── Microsoft-Windows-Windows Defender%4WHC.evtx
│ ├── Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx
│ ├── Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx
│ ├── Microsoft-Windows-Windows Firewall With Advanced Security%4FirewallDiagnostics.evtx
│ ├── Microsoft-Windows-WindowsBackup%4ActionCenter.evtx
│ ├── Microsoft-Windows-WindowsSystemAssessmentTool%4Operational.evtx
│ ├── Microsoft-Windows-WindowsUpdateClient%4Operational.evtx
│ ├── Microsoft-Windows-Winlogon%4Operational.evtx
│ ├── Microsoft-Windows-WorkFolders%4WHC.evtx
│ ├── Security.evtx
│ ├── Setup.evtx
│ ├── System.evtx
│ └── Windows PowerShell.evtx
└── sigma_rules
├── rclone_config_creation.yaml
└── rclone_execution.yaml