Group 5
- Osama Al-Bassam — 202161270
- Hussain Al-Abdullah — 202180710
- Mohammed Al-Refaei — 202012640
When it comes to work distribution we divided the project among us according to phases as the following:
- Phase 1: Setup & Initial Compromise — Hussain Al-Abdullah (202180710)
- Phase 2: SIEM Dashboard Analysis — Mohammed Al-Refaei (202012640), Hussain Al-Abdullah (202180710)
- Phase 3: Defensive Strategy & Validation — Osama Al-Bassam (202161270)
- Github Documentation and slides - Mohammed Al-Refaei (202012640)
During our project, we encountered several hurdles:
- Our initial setup used an ARM-based MacBook running Kali Linux, but the virtual machine’s allocated storage filled rapidly during installation. We expanded the disk capacity and reallocated resources before proceeding.
- Metasploitable3 exhibited compatibility issues in our environment, so we reverted to Metasploitable2 to maintain progress without further delay.
- When deploying Splunk Enterprise, we discovered it only supports x86 architectures. To address this, we switched to a Windows-based host and restarted the Splunk installation from scratch.