Challenge category

forensics

16 distinct public Locinode forensics challenge families.

forensics

Starter: Read the Logs

★☆☆☆☆125 XP12 min

Learn to inspect a small incident log without downloading evidence onto your own computer.

forensics

PowerShell Breadcrumbs — Case AA4A

★★★☆☆450 XP25 minwindows

Northstar Medical Group is investigating its operations API after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

forensics

Wire Transfer — Case 8B64

★★☆☆☆300 XP17 min

Copperline Telecom is investigating its asset tracker after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

forensics

Two Timelines — Case D721

★★★☆☆450 XP25 min

Pine Ridge Utilities is investigating its dispatch console after a controlled training incident exposed a realistic weakness in a synthetic environment. Step in as the responder and follow the evidence.

forensics

Three Witnesses

★★★★★1000 XP45 min

Alder & Finch Legal is investigating its field-service dashboard after three independent evidence sources each preserve one part of a privileged request. Step in as the responder and follow the evidence.

forensics

Needle Stack

★★★☆☆450 XP20 min

Cedar Vale University is investigating its incident dashboard after web, application, and maintenance messages were merged into one evidence file during collection. Step in as the responder and follow the evidence.

forensics

Rebuild the Request

★★★★★1000 XP45 min

Summit Municipal IT is investigating its employee portal after incident evidence records a protected route in one file and the trusted request header in another. Step in as the responder and follow the evidence.

forensics

One Bad Line

★★★☆☆450 XP20 min

Copperline Telecom is investigating its reporting service after a JSON-lines audit export contains one privileged event hidden among routine records. Step in as the responder and follow the evidence.

forensics

Encoded Evidence

★★★☆☆450 XP20 min

Cedar Vale University is investigating its maintenance console after an evidence note contains one encoded field copied directly from application telemetry. Step in as the responder and follow the evidence.

forensics

Resolver Breadcrumb

★☆☆☆☆150 XP8 min

Stonebridge Property Services is investigating its incident dashboard after a resolver troubleshooting note records the path used immediately after an internal name lookup. Step in as the responder and follow the evidence.

forensics

Join the Dots

★★★★☆700 XP30 min

Summit Municipal IT is investigating its reporting service after one artifact contains a request identifier while another maps that identifier to a hidden route. Step in as the responder and follow the evidence.

forensics

Four Minute Window

★★★★☆700 XP30 min

Westgate Insurance is investigating its dispatch console after two logs overlap for only four minutes, and the sensitive request can be identified only by matching timestamps and request identifiers. Step in as the responder and follow the evidence.

forensics

Forwarded Evidence

★★☆☆☆300 XP12 min

Bluehaven Aviation is investigating its field-service dashboard after a proxy log records the original request path separately from the public path. Step in as the responder and follow the evidence.

forensics

Odd Browser

★☆☆☆☆150 XP8 min

Westgate Insurance is investigating its incident dashboard after a short access log contains one request made by an unusual automated client just before sensitive data was accessed. Step in as the responder and follow the evidence.

forensics

Chain of Custody

★★★★★ (6/7)1500 XP70 min

Ironwood Energy is investigating its field-service dashboard after a chain-of-custody package includes multiple transformed artifacts and one signed handoff note that ties them together. Step in as the responder and follow the evidence.

forensics

What Changed?

★★☆☆☆300 XP12 min

Pine Ridge Utilities is investigating its telemetry service after a before-and-after configuration diff shows one route added during the incident window. Step in as the responder and follow the evidence.