Process tree from hell
A Sysmon stream with a chain that looks like execution from a temp folder. The candidate has the raw events.
Whether they correlate parent and child before they raise.
- · a real Linux box in the browser
- · kubectl, docker, terraform, jq, yq
- · cluster, repo and cloud creds pre-wired
- · auto-checks running in the background
- · every keystroke + every command
- · terminal + screen recording
- · auto-graded pass/fail per check
