HTB: LogJammer Writeup

LogJammer - HackTheBox Writeup

Machine Information

AttributeDetails
NameLogJammer
TypeHTB Sherlock — DFIR / Windows Event Log Forensics
OSWindows (log artifacts only, no live host)
DifficultyEasy
Sherlock ID557
PointsN/A
Release DateN/A
Authord3vn0mi

Machine Rating

⭐⭐☆☆☆ (2/5)

Difficulty Assessment:

  • Enumeration: ⭐⭐☆☆☆
  • Real-world: ⭐⭐⭐⭐☆
  • CVE: ☆☆☆☆☆
  • CTF-like: ⭐⭐⭐☆☆

Summary

LogJammer is a beginner-friendly DFIR Sherlock built around a bundle of five Windows Event Log (.evtx) exports handed off by “Forela-Security.” The scenario is a post-compromise triage exercise: reconstruct an intrusion timeline purely from Security.evtx, System.evtx, Windows Firewall With Advanced Security/Firewall.evtx, Microsoft-Windows-Windows Defender/Operational.evtx, and Powershell-Operational.evtx. The twelve questions walk an analyst from the attacker’s initial interactive logon, through a Metasploit-flavored outbound firewall rule, a scheduled task used for persistence/execution, a SharpHound recon tool download that Defender caught and quarantined, and finally a PowerShell hash-verification command the operator ran to confirm the tool’s integrity. Two deliberate decoys are seeded in the logs — an unrelated msf.dll Meterpreter detection from 17 days prior, and log-clearing events on the wrong date — to test whether the analyst is actually correlating timestamps rather than pattern-matching on keywords.

TL;DR: Pull the Sherlock archive → extract with 7-Zip and the Sherlock password → parse each .evtx with a Rust-backed EVTX parser → correlate Security 4624 (logon) → Firewall 2004 (Metasploit C2 bypass rule, outbound) → Security 4719/4698 (audit policy change + scheduled task HTB-AUTOMATION running Automation-HTB.ps1) → Defender 1116/1117 (SharpHound flagged and quarantined) → PowerShell 4104 (Get-FileHash on the payload) → System 104 (Firewall log cleared) to answer all 12 tasks and reach 100% ownership.


Reconnaissance

Artifact Acquisition

The Sherlock instance provided in this run shipped with a truncated Powershell-Operational.evtx (0 bytes), so the actual evidence bundle had to be pulled directly from HTB rather than relied on locally:

# Resolve the Sherlock by name, then pull its signed download link via the internal HTB API client
from lib.htb_api import HTBClient
c = HTBClient()
sherlock = c._request('GET', 'sherlocks?keyword=logjammer') # locate sid
sid = 557
link = c.sherlock_download_link(sid) # returns a presigned S3 URL
name, data = c.download(link['url']) # fetch the archive bytes

The archive is a standard Sherlock zip, protected with the well-known Sherlock distribution password:

Terminal window
# Extract the evidence bundle
mkdir -p arts
7z x -phacktheblue -oarts logjammer.zip -y
find arts -type f

This yielded five real .evtx files under arts/Event-Logs/:

  • Security.evtx
  • System.evtx
  • Powershell-Operational.evtx
  • Windows Defender %4 Operational.evtx
  • Windows Firewall With Advanced Security %4 Firewall.evtx

Parsing Setup

Native Windows Event Viewer tooling wasn’t available in the analysis environment, so events were parsed with the Rust-backed evtx Python bindings, which handle the binary XML record format directly:

Terminal window
pip install evtx
from evtx import PyEvtxParser
# Every log was walked the same way: parse, filter by EventID substring, then
# regex the rendered XML for the fields relevant to each task question.
parser = PyEvtxParser('arts/Event-Logs/Security.evtx')
for record in parser.records():
xml = record['data']
if '<EventID>4624</EventID>' in xml:
print(record['event_record_id'], xml)

Vulnerability / Incident Indicators Identified

  • Interactive (Type 2) logon establishing the attacker’s session on the host.
  • An inbound Windows Firewall rule change permitting outbound Metasploit C2 traffic.
  • A security audit-policy change event (4719) touching the “Other Object Access Events” subcategory.
  • A scheduled task (4698) created for command execution/persistence.
  • SharpHound (BloodHound’s collector) downloaded and flagged by Windows Defender as HackTool:MSIL/SharpHound!MSR.
  • A PowerShell 4104 script-block log showing the operator hashing their own tooling.
  • A firewall-channel log clear (System 104) — the attacker’s cleanup step.

Initial Foothold

(No live exploitation occurs in this Sherlock — “Initial Foothold” here maps to identifying the attacker’s initial access event in the log timeline.)

Task 1 — Initial Logon Time

Filtering Security.evtx for Event ID 4624 (successful logon) and reading the LogonType field pinpointed the attacker’s session start:

for r in parser.records():
if '<EventID>4624</EventID>' in r['data'] and '<Data Name="LogonType">2</Data>' in r['data']:
print(r['data']) # interactive logon, TimeCreated in the record header

Answer: 27/03/2023 14:37:09

Task 2/3 — Metasploit C2 Firewall Rule

Windows Firewall With Advanced Security/Firewall.evtx Event ID 2004 (rule added) named the rule itself and carried a Direction field:

for r in PyEvtxParser('arts/Event-Logs/Firewall.evtx').records():
if '<EventID>2004</EventID>' in r['data']:
print(r['data']) # <Data Name="RuleName">Metasploit C2 Bypass</Data>, Direction=2

Answers: Rule name Metasploit C2 Bypass; Direction=2 → Outbound

Task 4 — Audit Policy Change

Security 4719 recorded which subcategory of auditing was altered, keyed by GUID %%12804:

for r in sec_parser.records():
if '<EventID>4719</EventID>' in r['data']:
print(r['data']) # SubcategoryId %%12804 → "Other Object Access Events"

Answer: Other Object Access Events

Task 5/6/7 — Scheduled Task Persistence

Security 4698 (a scheduled task was created) held the task name and the full <Command>/<Arguments> used to run the attacker’s PowerShell script:

for r in sec_parser.records():
if '<EventID>4698</EventID>' in r['data']:
print(r['data'])
Task Name : \HTB-AUTOMATION
Command : C:\Users\CyberJunkie\Desktop\Automation-HTB.ps1
Arguments : -A cyberjunkie@hackthebox.eu

Answers: Task HTB-AUTOMATION; script C:\Users\CyberJunkie\Desktop\Automation-HTB.ps1; args -A cyberjunkie@hackthebox.eu


Privilege Escalation

(No privilege escalation occurs against a live host in this challenge — the equivalent phase here is identifying tooling/persistence and the operator’s own verification/cleanup actions.)

Task 8/9/10 — SharpHound Detection & Quarantine (Windows Defender)

Windows Defender/Operational.evtx Event IDs 1116 (threat detected) and 1117 (action taken) named the tool and its on-disk path. Notably, the log also contains a decoy: 25+ much older Trojan:Win64/Meterpreter.B detections against an msf.dll from 17 days prior — those had to be excluded by timestamp correlation, since the question is specifically about a reconnaissance tool, not the earlier Meterpreter payload:

for r in PyEvtxParser('arts/Event-Logs/Defender.evtx').records():
if '<EventID>1116</EventID>' in r['data'] or '<EventID>1117</EventID>' in r['data']:
if 'SharpHound' in r['data']:
print(r['data'])
Threat Name : HackTool:MSIL/SharpHound!MSR
Path : C:\Users\CyberJunkie\Downloads\SharpHound-v1.1.0.zip
Action : Quarantine

Answers: Tool Sharphound; path C:\Users\CyberJunkie\Downloads\SharpHound-v1.1.0.zip; action Quarantine

Task 11 — Operator’s Hash Verification

Powershell-Operational.evtx Event ID 4104 (PowerShell ScriptBlock logging) captured the exact command the operator ran to verify the payload’s integrity after downloading it:

for r in PyEvtxParser('arts/Event-Logs/Powershell-Operational.evtx').records():
if '<EventID>4104</EventID>' in r['data'] and 'FileHash' in r['data']:
print(r['data'])

Answer: Get-FileHash -Algorithm md5 .\Desktop\Automation-HTB.ps1

Task 12 — Anti-Forensics: Log Clearing

System.evtx Event ID 104 (log cleared) exposed which channel was wiped and when. This task also had a built-in decoy: a Security 1102 clear plus 14 Sysmon-channel (also logged under 104) clears from 24 March, three days before the actual intrusion timeline established in Task 1. Only the entry matching the 27 March timeframe was the correct answer:

print('== System 104 ==')
for r in PyEvtxParser('arts/Event-Logs/System.evtx').records():
if '<EventID>104</EventID>' in r['data']:
print(r['data']) # Channel field distinguishes Security/Sysmon/Firewall clears

Answer: Microsoft-Windows-Windows Firewall With Advanced Security/Firewall


Attack Chain Summary

Interactive logon (Security 4624, 27/03/2023 14:37:09)
↓
Firewall rule "Metasploit C2 Bypass" added, Outbound (Firewall 2004)
↓
Audit policy tampered — Other Object Access Events (Security 4719)
↓
Scheduled task "HTB-AUTOMATION" created to run Automation-HTB.ps1 -A cyberjunkie@hackthebox.eu (Security 4698)
↓
SharpHound-v1.1.0.zip downloaded → detected as HackTool:MSIL/SharpHound!MSR → Quarantined (Defender 1116/1117)
↓
Operator runs Get-FileHash -Algorithm md5 on Automation-HTB.ps1 to verify tooling (PowerShell 4104)
↓
Firewall log channel cleared for anti-forensics (System 104)

Tools Used

ToolPurpose
HTB internal API client (lib.htb_api.HTBClient)Located the Sherlock by keyword, resolved the presigned download link, fetched the archive
7z (p7zip)Extracted the password-protected Sherlock zip (hacktheblue)
evtx (Rust-backed Python bindings)Parsed all five .evtx files into rendered XML records
Python (re, string filtering)Filtered records by Event ID and extracted field values from rendered XML
HTB Sherlock task-answer APISubmitted the 12 task answers and confirmed 100% ownership

Key Learnings

Techniques Practiced

  • Parsing native .evtx binary format without Windows tooling, using a cross-platform Rust-backed library
  • Correlating multiple event log channels (Security, System, Firewall, Defender, PowerShell-Operational) into a single incident timeline
  • Recognizing key forensic Event IDs: 4624 (logon), 4719 (audit policy change), 4698 (scheduled task creation), 1116/1117 (Defender detection/action), 4104 (PowerShell script block), 104 (log cleared)
  • Identifying and discarding decoy artifacts by timestamp correlation rather than keyword matching alone

Lessons Learned

  1. Timestamps are the tie-breaker, not keywords. Both major decoys in this Sherlock (the older msf.dll Meterpreter detections and the 24 March log clears) look superficially like valid answers if you pattern-match on “malware detected” or “log cleared” without anchoring everything to the actual intrusion window established by the first logon event.
  2. 4698’s <Command>/<Arguments> fields are gold for attacker attribution. Scheduled task creation events log the full command line, which directly ties persistence mechanisms back to specific script paths and operator-supplied arguments.
  3. Windows Defender’s own quarantine action (1117) is as evidentiary as the detection (1116). Confirming what happened to a flagged file (quarantined vs. allowed) matters as much as knowing it was flagged.
  4. Anti-forensics leaves its own trail. Event ID 104 in the System channel records exactly which log channel was cleared and when — attackers clearing logs to cover their tracks generate the very evidence needed to prove they were there.
  5. When a provided artifact is corrupted (0-byte file), re-fetch from the source rather than guessing at contents — re-pulling the archive via the HTB API and re-extracting with the correct Sherlock password recovered the complete, analyzable evidence set.

Proof of Ownership

Sherlocks have no flag-submission mechanic; ownership is confirmed via the task-answer API returning full completion:

Sherlock: LogJammer (sid 557)
Tasks completed: 12/12
is_owned: true
progress: 100%