Forensic Cybersecurity Investigation
Budget: ₹600 – ₹1,500 INR
Project Overview
We are seeking an experienced cybersecurity professional to conduct a forensic investigation of a suspected website compromise.
The environment includes:
• Website hosted on AWS EC2
• Application stack: WordPress or Node.js (to be confirmed)
• Nature of application: primarily static content with limited dynamic functionality
An incident occurred a few weeks ago. The objective is to determine:
• The likely attack vector
• A timeline of events
• Whether the compromise originated from:
• External attacker
• Insider activity
• Compromised credentials
⸻
Available Data
The following data sources are available:
• EC2 instance logs:
• Access logs (Apache/Nginx)
• Error logs
• System logs (subject to availability)
• AWS logs:
• CloudTrail logs
Note: No forensic snapshot was taken at incident time. Investigation will rely on available logs and current system state.
⸻
Scope of Work
The selected expert will be responsible for:
1. Log Analysis
• Analyze access, error, and system logs
• Identify anomalies such as unusual endpoints, payloads, or access patterns
2. AWS CloudTrail Investigation
• Review API activity for:
• Unauthorized access
• IAM misuse / privilege escalation
• Suspicious geographic access
3. Timeline Reconstruction
• Build a correlated, multi-source timeline across:
• Application logs
• System logs
• CloudTrail
4. Attack Vector Identification
• Determine likely entry point:
• Web vulnerabilities (plugins, APIs, misconfigurations)
• Credential compromise
• Infrastructure misconfiguration
5. Attribution Assessment
• Provide a reasoned assessment of:
• Insider vs external actor
• Include:
• Supporting indicators
• Confidence level
• Assumptions and limitations
6. Persistence & Impact Analysis
• Check for:
• Backdoors / web shells
• Unauthorized users / SSH keys
• Suspicious cron jobs or processes
• File modifications
7. Remediation Recommendations
• Provide clear, actionable steps for:
• Immediate containment
• Long-term hardening
⸻
Deliverables
The final output should include:
1. Executive Incident Summary
2. Detailed Timeline of Events
3. Attack Vector Analysis
4. Attribution Assessment (with confidence levels)
5. Indicators of Compromise (IOCs)
6. Remediation & Hardening Recommendations
⸻
Required Skills
• Proven experience in Digital Forensics & Incident Response (DFIR)
• Hands-on expertise with:
• AWS CloudTrail analysis
• Linux system forensics
• Experience investigating:
• Web application attacks (WordPress / Node.js)
• Strong understanding of:
• Log correlation techniques
• IAM security and access patterns
• Web attack methodologies
⸻
Preferred Qualifications
• Prior experience with cloud breach investigations
• Relevant certifications (preferred, not mandatory):
• GCFA / GCIA / GCIH
• AWS Security Specialty
• Experience working with incomplete or partially available logs
⸻
Engagement & Payment Approach (Outcome-Oriented)
This engagement is outcome-driven, with a focus on quality and completeness of investigation rather than effort alone.
• A small upfront payment will be made to initiate the engagement.
• The major portion of compensation is linked to the quality and depth of deliverables, including:
• Structured and correlated timeline
• Evidence-backed attack vector analysis
• Well-reasoned attribution assessment
• Clear and actionable recommendations
Clarification
• We recognize that definitive attribution may not always be possible due to limitations in logs or evidence.
• Evaluation will therefore be based on:
• Depth and rigor of analysis
• Cross-correlation of multiple data sources
• Logical consistency and defensibility of conclusions
• Transparency in assumptions and limitations
⸻
Engagement Model
• Short-term, fixed-scope project
• Remote engagement
• NDA required prior to data sharing
• Interim review checkpoint may be included before final submission
⸻
Screening Questions (Mandatory)
Please include responses to the following:
1. Describe a similar AWS + web application incident you have investigated
2. How do you reconstruct a timeline using CloudTrail and server logs?
3. How do you differentiate between insider activity and credential compromise?
4. What common attack vectors would you evaluate first (WordPress / Node)?
5. How do you handle investigations with incomplete logs?
⸻
Important Notes
• This is a forensic investigation, not a penetration test
• Emphasis is on structured methodology and reasoning, not just tools
• Submissions demonstrating clear investigation thinking (timeline correlation, hypothesis testing, multi-source validation) will be prioritized
We are seeking an experienced cybersecurity professional to conduct a forensic investigation of a suspected website compromise.
The environment includes:
• Website hosted on AWS EC2
• Application stack: WordPress or Node.js (to be confirmed)
• Nature of application: primarily static content with limited dynamic functionality
An incident occurred a few weeks ago. The objective is to determine:
• The likely attack vector
• A timeline of events
• Whether the compromise originated from:
• External attacker
• Insider activity
• Compromised credentials
⸻
Available Data
The following data sources are available:
• EC2 instance logs:
• Access logs (Apache/Nginx)
• Error logs
• System logs (subject to availability)
• AWS logs:
• CloudTrail logs
Note: No forensic snapshot was taken at incident time. Investigation will rely on available logs and current system state.
⸻
Scope of Work
The selected expert will be responsible for:
1. Log Analysis
• Analyze access, error, and system logs
• Identify anomalies such as unusual endpoints, payloads, or access patterns
2. AWS CloudTrail Investigation
• Review API activity for:
• Unauthorized access
• IAM misuse / privilege escalation
• Suspicious geographic access
3. Timeline Reconstruction
• Build a correlated, multi-source timeline across:
• Application logs
• System logs
• CloudTrail
4. Attack Vector Identification
• Determine likely entry point:
• Web vulnerabilities (plugins, APIs, misconfigurations)
• Credential compromise
• Infrastructure misconfiguration
5. Attribution Assessment
• Provide a reasoned assessment of:
• Insider vs external actor
• Include:
• Supporting indicators
• Confidence level
• Assumptions and limitations
6. Persistence & Impact Analysis
• Check for:
• Backdoors / web shells
• Unauthorized users / SSH keys
• Suspicious cron jobs or processes
• File modifications
7. Remediation Recommendations
• Provide clear, actionable steps for:
• Immediate containment
• Long-term hardening
⸻
Deliverables
The final output should include:
1. Executive Incident Summary
2. Detailed Timeline of Events
3. Attack Vector Analysis
4. Attribution Assessment (with confidence levels)
5. Indicators of Compromise (IOCs)
6. Remediation & Hardening Recommendations
⸻
Required Skills
• Proven experience in Digital Forensics & Incident Response (DFIR)
• Hands-on expertise with:
• AWS CloudTrail analysis
• Linux system forensics
• Experience investigating:
• Web application attacks (WordPress / Node.js)
• Strong understanding of:
• Log correlation techniques
• IAM security and access patterns
• Web attack methodologies
⸻
Preferred Qualifications
• Prior experience with cloud breach investigations
• Relevant certifications (preferred, not mandatory):
• GCFA / GCIA / GCIH
• AWS Security Specialty
• Experience working with incomplete or partially available logs
⸻
Engagement & Payment Approach (Outcome-Oriented)
This engagement is outcome-driven, with a focus on quality and completeness of investigation rather than effort alone.
• A small upfront payment will be made to initiate the engagement.
• The major portion of compensation is linked to the quality and depth of deliverables, including:
• Structured and correlated timeline
• Evidence-backed attack vector analysis
• Well-reasoned attribution assessment
• Clear and actionable recommendations
Clarification
• We recognize that definitive attribution may not always be possible due to limitations in logs or evidence.
• Evaluation will therefore be based on:
• Depth and rigor of analysis
• Cross-correlation of multiple data sources
• Logical consistency and defensibility of conclusions
• Transparency in assumptions and limitations
⸻
Engagement Model
• Short-term, fixed-scope project
• Remote engagement
• NDA required prior to data sharing
• Interim review checkpoint may be included before final submission
⸻
Screening Questions (Mandatory)
Please include responses to the following:
1. Describe a similar AWS + web application incident you have investigated
2. How do you reconstruct a timeline using CloudTrail and server logs?
3. How do you differentiate between insider activity and credential compromise?
4. What common attack vectors would you evaluate first (WordPress / Node)?
5. How do you handle investigations with incomplete logs?
⸻
Important Notes
• This is a forensic investigation, not a penetration test
• Emphasis is on structured methodology and reasoning, not just tools
• Submissions demonstrating clear investigation thinking (timeline correlation, hypothesis testing, multi-source validation) will be prioritized