Defensive Report

Blue Team: Summary of Operations

Table of Contents

Network Topology

The following machines were identified on the network:

Description of Targets

The target of this attack was: Target 1 |192.168.1.110.

Target 1 is an Apache web server and has SSH enabled, so ports 80 and 22 are possible ports of entry for attackers. As such, the following alerts have been implemented:

Monitoring the Targets

Traffic to these services should be carefully monitored. To this end, we have implemented the alerts below:

HTTP Request Size Monitor

Alert 1 is implemented as follows:

Excessive HTTP Errors

Alert 2 is implemented as follows:

CPU Usage Monitor

Alert 3 is implemented as follows:


Revision #1
Created 2025-12-08 18:17:31 UTC by David Rizzo
Updated 2025-12-08 18:17:31 UTC by David Rizzo