It's always worth pointing put these signposts for others to follow up. If it has been then no harm no foul, but if it was missed due to the mountain of data to trawl through then it's an invaluable reference.
If I ever get my hands on the pcap files I will create some tutorials and pointers on how to isolate data streams and interpret the results. My wireshark filters with 30-50 terms are frightening ;)
Someone from the audience on day two did mention looking into the IIS logs. It was when they were going over the forensic image. I'm sure they're looking at it.
Dayum Anon!
Great catch!
What do you want to bet that someone on the red team already caught this?
It's always worth pointing put these signposts for others to follow up. If it has been then no harm no foul, but if it was missed due to the mountain of data to trawl through then it's an invaluable reference.
If I ever get my hands on the pcap files I will create some tutorials and pointers on how to isolate data streams and interpret the results. My wireshark filters with 30-50 terms are frightening ;)
Someone from the audience on day two did mention looking into the IIS logs. It was when they were going over the forensic image. I'm sure they're looking at it.