About

Campaign Overview

Setting: Wareville, home of The Best Festival Company (TBFC)
Event: SOCMAS - the annual cyber security celebration
Threat Level: Critical
Purpose: Each mission teaches essential cybersecurity skills while uncovering clues about King Malhare's conspiracy to corrupt Christmas into EASTMAS


The Antagonist: King Malhare

Origin: HopSec Island
Motivation: Jealousy over Easter being overlooked; seeks to rebrand Christmas as EAST-mas
Operatives: Sir Carrotbane, Bandit Bunnies, and HopSec Island operatives
Endgame: EASTMAS - a corrupted version of the festival designed to sabotage TBFC operations and hold Wareville hostage


Plot Progression

Act 1: The Glitches

Act 2: Escalation & Kidnapping

Act 3: Investigation & Defense


Key Investigation Targets & Findings

Primary Investigation: tbfc-web01

System Type: Linux server processing Christmas wishlists
Attack: Eggstrike malware infiltration
Evidence Location: /home/socmas/2025/eggstrike.sh
Critical Forensic Techniques:

Evidence Trail


Challenge Categories

1. Forensic Investigation & Log Analysis

2. Red Team & Social Engineering

3. System Forensics & File Analysis


Access Credentials

Username: mcskidy
Password: AoC2025!
Connection: ssh mcskidy@[machine_ip]
Note: Machine IP changes upon each start

Learning Outcomes

Each challenge reinforces essential cybersecurity competencies:


The Stakes


Revision #8
Created 2025-12-01 16:09:56 UTC by David Rizzo
Updated 2025-12-03 17:02:30 UTC by David Rizzo