HTB: LogJammer Writeup
LogJammer - HackTheBox Writeup
Machine Information
| Attribute | Details |
|---|---|
| Name | LogJammer |
| Type | HTB Sherlock — DFIR / Windows Event Log Forensics |
| OS | Windows (log artifacts only, no live host) |
| Difficulty | Easy |
| Sherlock ID | 557 |
| Points | N/A |
| Release Date | N/A |
| Author | d3vn0mi |
Machine Rating
⭐⭐☆☆☆ (2/5)
Difficulty Assessment:
- Enumeration: ⭐⭐☆☆☆
- Real-world: ⭐⭐⭐⭐☆
- CVE: ☆☆☆☆☆
- CTF-like: ⭐⭐⭐☆☆
Summary
LogJammer is a beginner-friendly DFIR Sherlock built around a bundle of five Windows Event Log (.evtx) exports handed off by “Forela-Security.” The scenario is a post-compromise triage exercise: reconstruct an intrusion timeline purely from Security.evtx, System.evtx, Windows Firewall With Advanced Security/Firewall.evtx, Microsoft-Windows-Windows Defender/Operational.evtx, and Powershell-Operational.evtx. The twelve questions walk an analyst from the attacker’s initial interactive logon, through a Metasploit-flavored outbound firewall rule, a scheduled task used for persistence/execution, a SharpHound recon tool download that Defender caught and quarantined, and finally a PowerShell hash-verification command the operator ran to confirm the tool’s integrity. Two deliberate decoys are seeded in the logs — an unrelated msf.dll Meterpreter detection from 17 days prior, and log-clearing events on the wrong date — to test whether the analyst is actually correlating timestamps rather than pattern-matching on keywords.
TL;DR: Pull the Sherlock archive → extract with 7-Zip and the Sherlock password → parse each .evtx with a Rust-backed EVTX parser → correlate Security 4624 (logon) → Firewall 2004 (Metasploit C2 bypass rule, outbound) → Security 4719/4698 (audit policy change + scheduled task HTB-AUTOMATION running Automation-HTB.ps1) → Defender 1116/1117 (SharpHound flagged and quarantined) → PowerShell 4104 (Get-FileHash on the payload) → System 104 (Firewall log cleared) to answer all 12 tasks and reach 100% ownership.
Reconnaissance
Artifact Acquisition
The Sherlock instance provided in this run shipped with a truncated Powershell-Operational.evtx (0 bytes), so the actual evidence bundle had to be pulled directly from HTB rather than relied on locally:
# Resolve the Sherlock by name, then pull its signed download link via the internal HTB API clientfrom lib.htb_api import HTBClientc = HTBClient()
sherlock = c._request('GET', 'sherlocks?keyword=logjammer') # locate sidsid = 557
link = c.sherlock_download_link(sid) # returns a presigned S3 URLname, data = c.download(link['url']) # fetch the archive bytesThe archive is a standard Sherlock zip, protected with the well-known Sherlock distribution password:
# Extract the evidence bundlemkdir -p arts7z x -phacktheblue -oarts logjammer.zip -yfind arts -type fThis yielded five real .evtx files under arts/Event-Logs/:
Security.evtxSystem.evtxPowershell-Operational.evtxWindows Defender %4 Operational.evtxWindows Firewall With Advanced Security %4 Firewall.evtx
Parsing Setup
Native Windows Event Viewer tooling wasn’t available in the analysis environment, so events were parsed with the Rust-backed evtx Python bindings, which handle the binary XML record format directly:
pip install evtxfrom evtx import PyEvtxParser
# Every log was walked the same way: parse, filter by EventID substring, then# regex the rendered XML for the fields relevant to each task question.parser = PyEvtxParser('arts/Event-Logs/Security.evtx')for record in parser.records(): xml = record['data'] if '<EventID>4624</EventID>' in xml: print(record['event_record_id'], xml)Vulnerability / Incident Indicators Identified
- Interactive (Type 2) logon establishing the attacker’s session on the host.
- An inbound Windows Firewall rule change permitting outbound Metasploit C2 traffic.
- A security audit-policy change event (4719) touching the “Other Object Access Events” subcategory.
- A scheduled task (4698) created for command execution/persistence.
- SharpHound (BloodHound’s collector) downloaded and flagged by Windows Defender as
HackTool:MSIL/SharpHound!MSR. - A PowerShell 4104 script-block log showing the operator hashing their own tooling.
- A firewall-channel log clear (System 104) — the attacker’s cleanup step.
Initial Foothold
(No live exploitation occurs in this Sherlock — “Initial Foothold” here maps to identifying the attacker’s initial access event in the log timeline.)
Task 1 — Initial Logon Time
Filtering Security.evtx for Event ID 4624 (successful logon) and reading the LogonType field pinpointed the attacker’s session start:
for r in parser.records(): if '<EventID>4624</EventID>' in r['data'] and '<Data Name="LogonType">2</Data>' in r['data']: print(r['data']) # interactive logon, TimeCreated in the record headerAnswer: 27/03/2023 14:37:09
Task 2/3 — Metasploit C2 Firewall Rule
Windows Firewall With Advanced Security/Firewall.evtx Event ID 2004 (rule added) named the rule itself and carried a Direction field:
for r in PyEvtxParser('arts/Event-Logs/Firewall.evtx').records(): if '<EventID>2004</EventID>' in r['data']: print(r['data']) # <Data Name="RuleName">Metasploit C2 Bypass</Data>, Direction=2Answers: Rule name Metasploit C2 Bypass; Direction=2 → Outbound
Task 4 — Audit Policy Change
Security 4719 recorded which subcategory of auditing was altered, keyed by GUID %%12804:
for r in sec_parser.records(): if '<EventID>4719</EventID>' in r['data']: print(r['data']) # SubcategoryId %%12804 → "Other Object Access Events"Answer: Other Object Access Events
Task 5/6/7 — Scheduled Task Persistence
Security 4698 (a scheduled task was created) held the task name and the full <Command>/<Arguments> used to run the attacker’s PowerShell script:
for r in sec_parser.records(): if '<EventID>4698</EventID>' in r['data']: print(r['data'])Task Name : \HTB-AUTOMATIONCommand : C:\Users\CyberJunkie\Desktop\Automation-HTB.ps1Arguments : -A cyberjunkie@hackthebox.euAnswers: Task HTB-AUTOMATION; script C:\Users\CyberJunkie\Desktop\Automation-HTB.ps1; args -A cyberjunkie@hackthebox.eu
Privilege Escalation
(No privilege escalation occurs against a live host in this challenge — the equivalent phase here is identifying tooling/persistence and the operator’s own verification/cleanup actions.)
Task 8/9/10 — SharpHound Detection & Quarantine (Windows Defender)
Windows Defender/Operational.evtx Event IDs 1116 (threat detected) and 1117 (action taken) named the tool and its on-disk path. Notably, the log also contains a decoy: 25+ much older Trojan:Win64/Meterpreter.B detections against an msf.dll from 17 days prior — those had to be excluded by timestamp correlation, since the question is specifically about a reconnaissance tool, not the earlier Meterpreter payload:
for r in PyEvtxParser('arts/Event-Logs/Defender.evtx').records(): if '<EventID>1116</EventID>' in r['data'] or '<EventID>1117</EventID>' in r['data']: if 'SharpHound' in r['data']: print(r['data'])Threat Name : HackTool:MSIL/SharpHound!MSRPath : C:\Users\CyberJunkie\Downloads\SharpHound-v1.1.0.zipAction : QuarantineAnswers: Tool Sharphound; path C:\Users\CyberJunkie\Downloads\SharpHound-v1.1.0.zip; action Quarantine
Task 11 — Operator’s Hash Verification
Powershell-Operational.evtx Event ID 4104 (PowerShell ScriptBlock logging) captured the exact command the operator ran to verify the payload’s integrity after downloading it:
for r in PyEvtxParser('arts/Event-Logs/Powershell-Operational.evtx').records(): if '<EventID>4104</EventID>' in r['data'] and 'FileHash' in r['data']: print(r['data'])Answer: Get-FileHash -Algorithm md5 .\Desktop\Automation-HTB.ps1
Task 12 — Anti-Forensics: Log Clearing
System.evtx Event ID 104 (log cleared) exposed which channel was wiped and when. This task also had a built-in decoy: a Security 1102 clear plus 14 Sysmon-channel (also logged under 104) clears from 24 March, three days before the actual intrusion timeline established in Task 1. Only the entry matching the 27 March timeframe was the correct answer:
print('== System 104 ==')for r in PyEvtxParser('arts/Event-Logs/System.evtx').records(): if '<EventID>104</EventID>' in r['data']: print(r['data']) # Channel field distinguishes Security/Sysmon/Firewall clearsAnswer: Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
Attack Chain Summary
Interactive logon (Security 4624, 27/03/2023 14:37:09) ↓Firewall rule "Metasploit C2 Bypass" added, Outbound (Firewall 2004) ↓Audit policy tampered — Other Object Access Events (Security 4719) ↓Scheduled task "HTB-AUTOMATION" created to run Automation-HTB.ps1 -A cyberjunkie@hackthebox.eu (Security 4698) ↓SharpHound-v1.1.0.zip downloaded → detected as HackTool:MSIL/SharpHound!MSR → Quarantined (Defender 1116/1117) ↓Operator runs Get-FileHash -Algorithm md5 on Automation-HTB.ps1 to verify tooling (PowerShell 4104) ↓Firewall log channel cleared for anti-forensics (System 104)Tools Used
| Tool | Purpose |
|---|---|
HTB internal API client (lib.htb_api.HTBClient) | Located the Sherlock by keyword, resolved the presigned download link, fetched the archive |
7z (p7zip) | Extracted the password-protected Sherlock zip (hacktheblue) |
evtx (Rust-backed Python bindings) | Parsed all five .evtx files into rendered XML records |
Python (re, string filtering) | Filtered records by Event ID and extracted field values from rendered XML |
| HTB Sherlock task-answer API | Submitted the 12 task answers and confirmed 100% ownership |
Key Learnings
Techniques Practiced
- Parsing native
.evtxbinary format without Windows tooling, using a cross-platform Rust-backed library - Correlating multiple event log channels (Security, System, Firewall, Defender, PowerShell-Operational) into a single incident timeline
- Recognizing key forensic Event IDs: 4624 (logon), 4719 (audit policy change), 4698 (scheduled task creation), 1116/1117 (Defender detection/action), 4104 (PowerShell script block), 104 (log cleared)
- Identifying and discarding decoy artifacts by timestamp correlation rather than keyword matching alone
Lessons Learned
- Timestamps are the tie-breaker, not keywords. Both major decoys in this Sherlock (the older
msf.dllMeterpreter detections and the 24 March log clears) look superficially like valid answers if you pattern-match on “malware detected” or “log cleared” without anchoring everything to the actual intrusion window established by the first logon event. - 4698’s
<Command>/<Arguments>fields are gold for attacker attribution. Scheduled task creation events log the full command line, which directly ties persistence mechanisms back to specific script paths and operator-supplied arguments. - Windows Defender’s own quarantine action (1117) is as evidentiary as the detection (1116). Confirming what happened to a flagged file (quarantined vs. allowed) matters as much as knowing it was flagged.
- Anti-forensics leaves its own trail. Event ID 104 in the System channel records exactly which log channel was cleared and when — attackers clearing logs to cover their tracks generate the very evidence needed to prove they were there.
- When a provided artifact is corrupted (0-byte file), re-fetch from the source rather than guessing at contents — re-pulling the archive via the HTB API and re-extracting with the correct Sherlock password recovered the complete, analyzable evidence set.
Proof of Ownership
Sherlocks have no flag-submission mechanic; ownership is confirmed via the task-answer API returning full completion:
Sherlock: LogJammer (sid 557)Tasks completed: 12/12is_owned: trueprogress: 100%