Catch DNS-tunneling exfiltration

Solve in your browser

Edit the files below. The Objectives tick green live as you work. Hit Check when they all pass and your verified proof page is issued automatically.

Objectives

  • Met: The rule parses (match, group_by, threshold, window_seconds)
  • Not met: The rule alerts on the tunneling domain
  • Not met: The busy CI host's legitimate lookups don't trigger an alert

1 of 3 objectives met.

Objectives update live as you edit. Hitting Check commits your proof.

No account needed to explore. When you're ready, browse the rest of the challenges or sign in to save a solve as a verified proof.