SIGNAL/NOISE
terminal access environment · version 0.2
Türkçe

You run the attack. Then you triage the alerts.

A realistic security game. The terminal is simulated but the commands are literally real: nmap, hydra, ssh, curl, grep. No invented syntax, and every flag it accepts does something.

Here is the difference. When you finish a job the game sits you down in that night's SOC. The queue in front of you holds the rows you left, mixed in with the office's ordinary traffic. Which one is you?

red phase · terminalSN-0028
berkay@kit:~$ nmap 10.13.37.0/24
Starting Nmap 7.94 ( https://nmap.org )

Nmap scan report for 10.13.37.20
Host is up (0.00060s latency).
PORT     STATE SERVICE
22/tcp   open  ssh
80/tcp   open  http
3306/tcp open  mysql

Nmap scan report for 10.13.37.44
Host is up (0.00084s latency).
PORT     STATE SERVICE
22/tcp   open  ssh
8080/tcp open  http

  [port scan · trace +5]
You have the live machines. Which one is
interesting? Look at their ports.
  ✓ objective complete · +60 xp
blue phase · shift console5 rows
The same evening, on the night shift of
the SOC the client outsources to.
Something in this queue is yours.

TIME      RULE    LV  SOURCE
13:04:11  5501    3   10.0.0.4
          PAM: session opened (cron)
13:11:39  31101   5   10.0.0.211
          Web server 400 error code
13:20:00  100010  5   10.13.37.5
          Many connections to closed ports
13:20:05  100012  6   10.13.37.5
          Service banner probing pattern
13:52:02  5402    3   10.0.0.4
          Successful sudo to ROOT

One source in this queue mapped the
block. What is its address?

Both blocks are the game's real output, taken from the first contract. The thing that produced those two blue rows is the scan on the left.

Play →

Runs in the browser, no account needed. The first contract takes fifteen minutes.