Skip to main content

Training Operations

Hands-On SOC Training Operations

SOCSimulator training operations are free, browser-based cybersecurity investigation exercises. Each operation places you inside a realistic SIEM, XDR, or Firewall console to practice alert triage, threat detection, and incident response against scenarios mapped to the MITRE ATT&CK® framework.

128

Operations

898

Tasks

6

Tool Types

128 operations found

Building a Backdoor
PRO

Building a Backdoor

Velodraft Systems runs its release pipeline on a self-hosted TeamCity server that was left accessible from the internet on an unpatched build. An attacker exploited an authentication-bypass flaw to create a rogue administrator without credentials, harvested stored VCS secrets and cloud keys, then planted a malicious build step in the production release pipeline. When the next scheduled build fired, both CI build agents pulled and executed an implant that beaconed out to an attacker-controlled domain. Reconstruct the intrusion chain from the TeamCity audit trail and the build-agent XDR data.

50m·507 tasks
View Operation
The Backdoored Browser Extension: Following the C2 Beacon

The Backdoored Browser Extension: Following the C2 Beacon

A routine Chrome auto-update silently trojanized a productivity extension on a finance workstation at Halverson Logistics. The extension beaconed to an attacker C2 domain, harvested the analyst's session cookies and an API token, and exfiltrated them to a VULTR-hosted server. With no malware on disk, the proxy and firewall logs are the only trail. Walk them step by step to trace the beacon, the theft, and the exfiltration.

25m·256 tasks
View Operation
The One-Letter Vendor: Typosquat Invoice Thread Hijack
PRO

The One-Letter Vendor: Typosquat Invoice Thread Hijack

An accounts-payable team received what looked like a routine reply on an open invoice thread from a trusted supplier. It passed every mail gateway, because the From domain authenticated perfectly. The catch was four mailboxes in the CC field on a domain one letter off the real vendor, quietly hijacking the thread to redirect a six-figure payment to an attacker account. No malware, no account takeover, just mail authentication's blind spot. Work the headers, authentication results, and message traces to reconstruct the vendor-email-compromise fraud.

40m·507 tasks
View Operation
Trusted Tool, Hostile Hands: Atera RMM Foothold
PRO

Trusted Tool, Hostile Hands: Atera RMM Foothold

A phishing-delivered intrusion that weaponized a legitimate remote-monitoring tool instead of custom malware. A finance analyst was lured by a grant-program email whose link pointed at a file-sharing platform; the download was an MSI that silently installed the Atera agent, registered the endpoint to an attacker-controlled tenant, persisted as a Windows service, and beaconed to Atera's cloud over HTTPS. From the vendor console the operator ran PowerShell discovery and staged a follow-on implant, all over trusted infrastructure. Reconstruct the chain from email, SIEM, and endpoint XDR telemetry and classify the key ATT&CK techniques.

55m·507 tasks
View Operation
GoldPickaxe: The First iOS Trojan Stealing Your Face

GoldPickaxe: The First iOS Trojan Stealing Your Face

A mobile-first intrusion against a retail bank's managed iPhone fleet. A relationship officer is socially engineered into installing a fake government app through Apple TestFlight and trusting a rogue MDM profile, handing GoldFactory full control of the device. The GoldPickaxe.iOS trojan harvests identity documents and a facial-recognition video, intercepts SMS, and exfiltrates over three split channels: an RSA-encrypted HTTP API, a WebSocket command channel, and an RTMP face-video stream, all to enable AI face-swap fraud against the bank's facial verification. Reconstruct the chain from mobile-threat-defense, MDM, and perimeter firewall telemetry.

45m·507 tasks
View Operation
Shai-Hulud: Self-Replicating npm Post-Install Worm Harvesting CI/CD Secrets
PRO

Shai-Hulud: Self-Replicating npm Post-Install Worm Harvesting CI/CD Secrets

A routine dependency bump on a shared Linux CI runner pulls a trojanized npm package whose postinstall hook runs a bundled worm. The worm harvests GitHub, npm, and cloud credentials from the filesystem and the Instance Metadata Service, verifies them with TruffleHog, exfiltrates the loot to a free webhook dropbox, then reuses the stolen tokens to flip private repositories public as '-migration' clones, create a public Shai-Hulud loot repository, and republish itself into the organization's own packages. Reconstruct the self-replicating supply chain compromise from endpoint XDR and egress firewall telemetry, and classify the key ATT&CK techniques.

1h 15m·1508 tasks
View Operation
FortiJump: FortiManager Zero-Day Config Heist
PRO

FortiJump: FortiManager Zero-Day Config Heist

A FortiManager appliance is breached through an FGFM authentication bypass (the FortiJump zero-day): an attacker-controlled FortiManager registers itself as a trusted device, stages every managed FortiGate's configuration into a single hidden archive on the appliance, and exfiltrates it over HTTPS, stealing the fleet inventory and FortiOS256-hashed administrator passwords. Weeks later the operator re-registers and exfiltrates again to fresh infrastructure. With no malware on any firewall and no endpoint to inspect, reconstruct the entire heist from the appliance event log and perimeter firewall alone.

1h 15m·1507 tasks
View Operation
Org2Org: Scattered Spider's Okta Impersonation
PRO

Org2Org: Scattered Spider's Okta Impersonation

A help-desk social-engineering intrusion that abused Okta's inbound federation (Org2Org) to impersonate users across tenants. An operator phoned the IT service desk to reset a Super Administrator's MFA factors, re-enrolled the factor from an anonymizing proxy, and signed in to the Okta Admin Console as Super Admin. They granted Super Administrator to a second account for persistence, then stood up a second, attacker-controlled Identity Provider as an inbound-federation source and manipulated its username parameter to log in as real users with no victim password or MFA. Work the SIEM service-desk trail and the Okta System Log to reconstruct the chain and classify the trusted-relationship abuse.

1h 15m·1507 tasks
View Operation
Mounted and Loaded: ISO Container Delivery of the Bumblebee Loader

Mounted and Loaded: ISO Container Delivery of the Bumblebee Loader

An ISO image attachment hides a visible shortcut beside a hidden DLL. The user mounts the container and runs the shortcut, which executes the Bumblebee loader via rundll32 against a DLL export. Bumblebee injects into a signed Windows Mail binary through WMI, beacons HTTPS to a C2 cluster, then layers a Meterpreter stager and a Cobalt Strike beacon. The operator runs AdFind discovery, dumps LSASS with ProcDump, creates a rogue local admin, installs AnyDesk for fallback access, and moves laterally with a harvested domain administrator before the intrusion is contained pre-encryption. Reconstruct the kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.

1h·508 tasks
View Operation
Key Vault Contributor Privilege Escalation: Reading All Secrets via Access Policies
PRO

Key Vault Contributor Privilege Escalation: Reading All Secrets via Access Policies

A holder of the built-in Key Vault Contributor role abuses its Microsoft.KeyVault/vaults/write permission to write itself a full data-plane access policy on a production Azure Key Vault, then dumps every secret, key, and certificate it holds. Working purely from the cloud audit trail, correlate the control-plane access-policy change in the Azure Activity Log with the data-plane secret, key, and certificate reads in the Key Vault diagnostic log, identify the principal and what it stole, and classify the privilege-escalation and credential-access techniques.

40m·508 tasks
View Operation
Cookie Heist: AiTM Session Theft to Payment-Fraud BEC
PRO

Cookie Heist: AiTM Session Theft to Payment-Fraud BEC

An adversary-in-the-middle phishing intrusion that turns into payment fraud without any malware. A voicemail-themed email with an HTML attachment routes a finance analyst through a redirector to an Evilginx2 proxy, which relays her real Microsoft 365 sign-in and steals the post-MFA session cookie. The attacker replays the cookie from a foreign hosting IP, bypassing MFA, then reads her mailbox, creates an email-hiding inbox rule keyed on a vendor's domain, deletes the phishing mail, and replies inside a live invoice thread asking the vendor to wire payment to a new account. Work the Entra sign-in audit, the Exchange Online mailbox operations, and the email evidence to reconstruct the chain.

50m·507 tasks
View Operation
Illicit OAuth App-Consent Grant: Entra ID Impersonation Campaign

Illicit OAuth App-Consent Grant: Entra ID Impersonation Campaign

A mass illicit OAuth app-consent campaign against a maritime logistics tenant. Operators register multitenant Entra apps impersonating trusted SaaS brands (iLSMART, Adobe, DocuSign, OneDrive-2025) and send brand-themed consent lures from compromised supplier accounts. Victims who click are screened by a Tycoon antibot redirector into an adversary-in-the-middle relay that proxies the real Entra sign-in, harvests the password, and intercepts the MFA-approved token. The replayed token completes user-level consent grants to the impersonation apps, which read mailboxes over Microsoft Graph, and the attacker registers a new MFA method for durable persistence. Work the Email lures and the Entra consent, sign-in, Graph, and security-info audit to reconstruct the chain.

40m·507 tasks
View Operation
Storm-2949: Azure VM Run Command, VMAccess Backdoor, and Key Vault Secret Dump
PRO

Storm-2949: Azure VM Run Command, VMAccess Backdoor, and Key Vault Secret Dump

A hands-on-keyboard intrusion that turned one compromised cloud identity into control over an entire Azure estate. After seizing a finance user's account through self-service password reset abuse and attacker-owned MFA, the operator enumerated the tenant, escalated with an RBAC role assignment, harvested App Service publishing profiles, rewrote a Key Vault access policy and dumped every secret in four minutes, stole storage keys, and finished on a production VM using the VMAccess extension to mint a backdoor admin and Run Command to disable Defender and install ScreenConnect. Reconstruct the kill chain from the Azure cloud audit trail and the VM's endpoint XDR telemetry, and classify the key ATT&CK techniques.

1h 25m·1509 tasks
View Operation
OneClik: ClickOnce + AppDomainManager Injection with ETW Patching and AWS-Hidden C2
PRO

OneClik: ClickOnce + AppDomainManager Injection with ETW Patching and AWS-Hidden C2

A ClickOnce-delivered intrusion at an oil-and-gas operator that mirrors nation-state tradecraft. A spearphishing link served a Microsoft ClickOnce deployment that ran under the trusted dfsvc.exe, sideloaded a signed binary whose tampered .config used .NET AppDomainManager hijacking to load an attacker assembly at CLR startup, patched Event Tracing for Windows to blind the sensor, ran anti-debugging checks, and injected a Golang backdoor (RunnerBeacon) that hid its C2 behind AWS CloudFront and API Gateway. Reconstruct the chain from email, endpoint XDR, and cloud audit telemetry, and classify the key ATT&CK techniques.

1h 25m·1508 tasks
View Operation
Docker Hub Supply Chain: A Public Image on a Shared Build Runner
PRO

Docker Hub Supply Chain: A Public Image on a Shared Build Runner

A platform engineer pulls a public Docker Hub image advertised as a network scanning utility onto a shared Linux build-runner. Hours later the host is still pinned at full CPU with its build queue drained, nothing deployed and no data alarms raised. Reconstruct what the image actually did on the host from endpoint XDR and perimeter firewall telemetry, and classify the key ATT&CK techniques.

40m·507 tasks
View Operation
Hidden in the Pixels: LSB Steganography Exfil From an Infected Endpoint

Hidden in the Pixels: LSB Steganography Exfil From an Infected Endpoint

A LummaC2/Vidar-style infostealer smash-and-grab. A finance analyst was tricked by a fake CAPTCHA (ClickFix) into pasting an mshta command into the Run box, which staged hidden PowerShell, downloaded the Lumma stealer, and harvested browser credentials, cookies, and wallet artifacts. To smuggle the loot out, the operator LSB-encoded the stolen blob into an oversized PNG and uploaded it to a public image host, off the command-and-control channel. Reconstruct the chain from SIEM and perimeter firewall telemetry and classify the key ATT&CK techniques.

30m·507 tasks
View Operation
RapperBot: From SSH Brute-Force to DDoS and Hidden XMRig Mining
PRO

RapperBot: From SSH Brute-Force to DDoS and Hidden XMRig Mining

A Mirai-derived DDoS botnet brute-forces SSH on an internet-exposed Linux edge gateway, persists an attacker SSH key in root's authorized_keys, pulls a Bash stager, and drops a single merged binary that fuses the RapperBot DDoS client with an embedded XMRig Monero miner. The bot registers with a hardcoded C2 over a custom binary protocol, floods an external victim with UDP/TCP/HTTP traffic, and quietly mines Monero through two proxy pools hosted on the C2 IP itself. Reconstruct the chain from SIEM, endpoint XDR, and perimeter firewall telemetry.

1h·507 tasks
View Operation
Midnight Blizzard: Malicious Entra App Registration and Service Principal Abuse
PRO

Midnight Blizzard: Malicious Entra App Registration and Service Principal Abuse

A nation-state-style identity-plane intrusion that lives entirely in Microsoft Entra ID and Exchange Online. A low-and-slow password spray across rotating residential-proxy IPs lands on a legacy, no-MFA test account; from there the actor pivots into the application layer, creates a rogue user, registers a new malicious application and service principal, grants it the Office 365 Exchange Online full_access_as_app role plus EWS.AccessAsUser.All, adds a client secret for durable app-only access, and reads corporate mailboxes over Exchange Web Services with no user sign-in. Work the Entra sign-in audit, the application and service-principal lifecycle and role-assignment events, the credential change, and the EWS mailbox operations to reconstruct the chain and classify the key ATT&CK techniques.

1h 15m·1508 tasks
View Operation
RedTiger Stealer: GoFile + Discord-Webhook Exfiltration
PRO

RedTiger Stealer: GoFile + Discord-Webhook Exfiltration

A single-host smash-and-grab infostealer intrusion. An artist ran a PyInstaller-compiled executable disguised as a Roblox FPS-unlocker mod that was actually the open-source RedTiger stealer. In one short burst it unpacked to Temp, blackholed security-vendor domains in the hosts file, persisted via the Startup folder, injected JavaScript into the Discord client, and archived Discord tokens, browser credentials and cards, a crypto wallet, a webcam frame, and a screenshot. Exfiltration ran in two stages over legitimate cloud: the loot ZIP was uploaded to GoFile, then the download link plus victim recon was posted to a Discord webhook. Reconstruct the kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.

55m·507 tasks
View Operation
Consent Granted: Malicious OAuth App Mailbox BEC
PRO

Consent Granted: Malicious OAuth App Mailbox BEC

A consent-phishing intrusion where an adversary-in-the-middle proxy steals a finance analyst's Microsoft 365 session, then the attacker tricks her into granting a malicious multitenant OAuth application delegated mailbox permissions. The app gets its own client secret for durable access, reads her mailbox over Microsoft Graph, hides vendor replies with an inbox rule, and sends a fraudulent bank-detail-change reply into a live settlement thread. Work the Entra consent and permission-grant audit, the service-principal credential change, the Graph mailbox operations, and the email evidence to reconstruct the chain.

50m·507 tasks
View Operation
TRITON: Safety System Sabotage at a Petrochemical Plant
PRO

TRITON: Safety System Sabotage at a Petrochemical Plant

A nation-state-grade ICS intrusion that reaches the deepest protective layer of a petrochemical plant. An attacker reuses remote access to pivot from the DCS network onto a dual-homed Schneider Triconex SIS engineering workstation, transfers the TRITON attack framework (an executable masquerading as the legitimate Triconex Trilog viewer plus a bundled library and two controller payloads), and uses the proprietary TriStation protocol to reprogram a safety controller, until a failed validation check trips an unplanned emergency shutdown. Reconstruct the kill chain from SIEM, endpoint XDR, and firewall telemetry, and classify the ICS impact techniques.

1h 15m·1508 tasks
View Operation
HermeticWiper: Signed-Driver Destruction on the Eve of Invasion
PRO

HermeticWiper: Signed-Driver Destruction on the Eve of Invasion

A destructive, worm-assisted wiper operation run from inside an already-compromised Active Directory estate. An operator holding domain-administrator access pushed a binary signed to a code-signing identity to hosts over SMB, ran it as a service, and let it drop and load a legitimately signed EaseUS partition driver to reach the raw disk, overwrite the Master Boot Record, and shred the NTFS Master File Table. The crash-dump facility was disabled to slow forensics, a companion worm re-deployed the payload over SMB and WMI, and a decoy ransom note was dropped to misdirect responders. Reconstruct the destruction chain from SIEM, endpoint XDR, and firewall telemetry, and classify the key ATT&CK techniques.

1h 25m·1508 tasks
View Operation
Storm-0501: Azure Storage Account Key Abuse and Cloud Ransom

Storm-0501: Azure Storage Account Key Abuse and Cloud Ransom

A cloud-native ransomware operation against a hybrid Microsoft Entra ID tenant, delivered entirely through the Azure control plane with no encryptor binary. A synced non-human identity holding Global Administrator without MFA is reused to sign in, a federated-domain SAML backdoor is planted, the operator elevates to Owner over every subscription, lists the storage account keys, exfiltrates the freight archive with AzCopy, deletes snapshots, restore points and the Recovery Services vault, then re-encrypts the surviving storage with a customer-managed key in an attacker key vault and extorts over Teams. Reconstruct the chain from the Azure Activity Log, storage diagnostics, and Entra sign-in telemetry, classifying the key-theft and encryption-for-impact techniques.

1h 20m·1508 tasks
View Operation
GoldDigger: Accessibility-Abusing Banker Draining APAC Accounts
PRO

GoldDigger: Accessibility-Abusing Banker Draining APAC Accounts

A mobile-first banking-trojan intrusion on a corporate bring-your-own-device fleet. An employee searching for a government portal sideloaded a trojanized Android installer carrying the GoldDigger banker, granted it Accessibility Service, and the trojan then keylogged, painted fake bank-login overlays, intercepted SMS one-time-passcodes, and beaconed stolen data to a cluster of attacker command-and-control domains, enabling account-draining fraud. Reconstruct the kill chain from the mobile egress SIEM, the mobile threat-defense sensor, and the perimeter firewall, and classify the key ATT&CK mobile techniques.

1h·507 tasks
View Operation
Trigona Ransomware: Rclone-to-MEGA Cloud Exfiltration
PRO

Trigona Ransomware: Rclone-to-MEGA Cloud Exfiltration

A fast, RDP-only, hands-on-keyboard intrusion that went from a valid Administrator logon on an exposed RDP gateway to estate-wide Trigona ransomware in under three hours. The actor dropped a batch-script and Netscan toolkit, enumerated the network and file shares, pivoted over RDP, disabled Windows Defender by hand, exfiltrated file shares to MEGA cloud storage with a renamed rclone client, then staged and ran the Trigona encryptor over SMB. Reconstruct the full kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.

1h·507 tasks
View Operation
Staged and Gone: Rclone Bulk Upload to MEGA From a File Server
PRO

Staged and Gone: Rclone Bulk Upload to MEGA From a File Server

A pre-ransomware bulk data-exfiltration investigation. After a perimeter foothold and hands-on command and control, the operator pivoted to a Windows file share server, recovered a domain-administrator password from a plaintext file, staged finance data into a single archive, and bulk-uploaded it to a MEGA cloud remote with a renamed rclone client over HTTPS before any encryptor ran. The organization also runs rclone legitimately on its backup server, so the challenge is separating the sanctioned job from the theft. Reconstruct the staging-then-upload chain from SIEM and perimeter firewall telemetry.

55m·507 tasks
View Operation
Trusted Domain, Untrusted Destination: Open-Redirect Phishing

Trusted Domain, Untrusted Destination: Open-Redirect Phishing

A finance clerk at Larkfield Mutual Assurance clicks a Release My Messages link in an Undelivered Mails phishing email. The link opens with a trusted brand domain that carries an open-redirect flaw, so it sails past URL filtering. Follow the 302 redirect through an attacker cushion server and a JavaScript hop to a spoofed Microsoft 365 login page, then catch the harvested credentials being replayed against the real tenant. Walk the mail gateway, web proxy, and sign-in logs step by step.

25m·256 tasks
View Operation
Weaponized SVG: Embedded Code in an Image Attachment

Weaponized SVG: Embedded Code in an Image Attachment

A treasury analyst at a bank opens what looks like a SWIFT payment confirmation, clicks the button inside it, and no document ever appears. Minutes later her workstation is running code out of her own user profile and holding an encrypted session to a host it has never contacted before. Walk the mail gateway, the file artifacts and the endpoint process tree step by step, from the delivery that started it to the beacon that followed.

25m·256 tasks
View Operation
Fake Window, Real Loss: Browser-in-the-Browser Steam Phishing

Fake Window, Real Loss: Browser-in-the-Browser Steam Phishing

A Counter-Strike 2 player on the community team at Voltline Interactive clicks a phishing email offering a free in-game case from a well-known esports team. The link leads to a scam site that paints a fake browser pop-up, complete with a fake Steam URL bar, entirely in HTML. The victim types their Steam credentials into the fake window and cannot sign in minutes later. Walk the email gateway and proxy logs step by step, from the lure to the moment the password left the browser.

25m·256 tasks
View Operation
Overdue Invoice, Compromised Endpoint: Tracing a Finance Workstation Intrusion

Overdue Invoice, Compromised Endpoint: Tracing a Finance Workstation Intrusion

A finance clerk at Brightwater Logistics worked through her inbox at her desk one Tuesday morning. Inside the hour her workstation, bwl-fin-wks-042, was running programs no accounts-payable machine has any business running and reaching hosts that have nothing to do with freight. You have the mail gateway records for her mailbox and the endpoint telemetry for that hour, and nothing else. Work the morning in order: establish what was delivered, what ran, what it left behind so that it would run again, and where it reported to.

25m·256 tasks
View Operation
Hijacked Discord Invite to ClickFix Loader: Tracing the Lure

Hijacked Discord Invite to ClickFix Loader: Tracing the Lure

A finance analyst at Halcyon Wealth Partners followed a recycled Discord invite that quietly redirected the browser to a fake verification page. They did what the page asked, and inside the hour the workstation was running a remote-access trojan alongside an info-stealer that shipped browser data straight out of the building. Walk the proxy, endpoint and firewall evidence step by step to trace the lure, the loader, the C2 beacon and the data theft.

15m·257 tasks
View Operation
Anatsa Banker: The Trojan Hiding in a Google Play PDF Reader

Anatsa Banker: The Trojan Hiding in a Google Play PDF Reader

A relationship manager at Larkfield Mutual installs a five-star PDF and QR reader from the Google Play store onto her managed Android handset. It is an Anatsa (TeaBot) dropper: it stages a DEX payload disguised as an app update, sidesteps sandbox checks, downloads the final banking trojan, and abuses the Accessibility service to overlay a fake bank login. Walk the EMM/MDM and web-proxy logs step by step to trace the install, the staged downloads, the C2 callback, and the final payload.

20m·256 tasks
View Operation
OneNote Attachment to RAT: A Guided First Investigation

OneNote Attachment to RAT: A Guided First Investigation

A logistics contracts employee at Glacierline Freight opens an attachment that arrived in her inbox and clicks a button inside it. Minutes later her workstation is running something that appears on no software inventory and is talking to a host that no business process uses. Walk the email gateway records, the file artifacts and the endpoint process tree one step at a time, and work out for yourself which message carried the delivery, what landed on disk, and what ran.

15m·256 tasks
View Operation
Exposed .git Folder: Scanning the Web for Secrets

Exposed .git Folder: Scanning the Web for Secrets

A public web server at Larkspur Logistics was deployed straight from a git checkout, leaving its .git directory exposed to the Internet. Following the EMERALDWHALE playbook, an attacker pulled /.git/config, stole the GitHub token baked into the clone URL, cloned the private repository, and found a hard-coded AWS key inside that handed them the cloud account. Walk the access, GitHub, and CloudTrail logs step by step to trace one misconfiguration into a full credential-theft chain.

25m·257 tasks
View Operation
Lingering in the Background: BITS Job Used for Download and Persistence
PRO

Lingering in the Background: BITS Job Used for Download and Persistence

A teller workstation was cleaned by antivirus, yet the operator's foothold survived. The malware had abused the Background Intelligent Transfer Service: a self-contained BITS job with a SetNotifyCmdLine notification command re-downloads a payload and re-launches it with regsvr32 every time a transfer completes, then deletes its tracks, leaving only the job entry inside the service state database. Reconstruct the persistence loop from BITS-Client operational events, Sysmon process lineage, and endpoint XDR telemetry, prove it outlived the file-based cleanup, and classify the key ATT&CK techniques.

45m·507 tasks
View Operation
FluBot: The Parcel-Delivery Text That Spreads Itself

FluBot: The Parcel-Delivery Text That Spreads Itself

A managed Android handset at Larkfield Mutual is infected by FluBot after the employee taps a smishing SMS impersonating a DHL parcel-delivery notice. The fake tracking page talks the user into installing an app and granting it Accessibility and SMS permissions; from there the trojan turns the phone into a sender, harvesting the contact list, texting the same lure onward and intercepting bank 2FA codes, while keeping a command channel the perimeter firewall never blocked. Walk the mobile telemetry and firewall logs step by step to trace the lure, the sideload, the contact theft, the SMS worm, and the hidden C2.

15m·256 tasks
View Operation
From OneNote to RansomNote: A .one Attachment to Nokoyawa Ransomware
PRO

From OneNote to RansomNote: A .one Attachment to Nokoyawa Ransomware

A phishing email carrying a malicious OneNote (.one) attachment delivered the IcedID loader, which beaconed quietly for weeks before the operator launched Cobalt Strike, enumerated Active Directory with AdFind, installed AnyDesk for redundancy, moved laterally over RDP, exfiltrated data over SFTP, and deployed Nokoyawa ransomware on the backup and file servers. Reconstruct the full kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.

2h·508 tasks
View Operation
Public by Default: Sensitive Files Pulled From an Open Azure Blob Container
PRO

Public by Default: Sensitive Files Pulled From an Open Azure Blob Container

A sensitive-data exposure caused entirely by a storage misconfiguration. A developer set a production Azure Blob container's public access level to anonymous, an external actor swept the *.blob.core.windows.net namespace and found it, listed it with an unauthenticated List Blobs call, then bulk-downloaded the exports — including a config file with a SQL connection string and a nightly database backup — with AzCopy over anonymous HTTPS. Reconstruct the exposure from Azure Storage diagnostic logs and SIEM corroboration, classifying the discovery and collection techniques, in a case where nothing failed and no credential was ever used.

40m·507 tasks
View Operation
The Template That Read the Disk

The Template That Read the Disk

The file-transfer portal that Tideglow Logistics' partners upload to spent a morning returning host files it was never meant to publish, and finished it running an administrator session nobody had logged into. The root cause is CVE-2024-4040 in CrushFTP 10.6.0. Walk the access logs and firewall traffic step by step to trace how a client holding no credentials turned a request parameter into a read of the host, and that read into a takeover.

25m·256 tasks
View Operation
Lazarus: ManageEngine RCE to QuiteRAT Espionage

Lazarus: ManageEngine RCE to QuiteRAT Espionage

An internet-facing ManageEngine ServiceDesk Plus appliance at Caldermoor Networks, a regional network and internet service provider, falls to the unauthenticated SAML RCE (CVE-2022-47966). Code runs as the appliance service account, which curls down a QuiteRAT first-stage implant, profiles the host and domain, installs itself as an auto-start Windows service, and beacons to a single HTTPS C2 that carries control and stolen data alike before pulling a CollectionRAT second stage. Work the ManageEngine web logs, the endpoint process tree, and the perimeter egress to reconstruct the intrusion. North-Korea-nexus actor.

55m·506 tasks
View Operation
QakBot bb02: Trace the Loader DLL to its C2

QakBot bb02: Trace the Loader DLL to its C2

A purchasing coordinator opened a phishing email, downloaded a password-protected archive, and ran a shortcut on the disk image hidden inside it. A signed Windows utility quietly registered a QakBot DLL, and the workstation started beaconing to addresses nobody recognized. Trace the bb02 wave from a phishing link through an ISO and the loader DLL handoff to the single TLS command-and-control endpoint the bot settled on.

30m·256 tasks
View Operation
Bumblebee Returns: The Voicemail VBA Macro

Bumblebee Returns: The Voicemail VBA Macro

An accounts-payable clerk opened a voicemail-notification email, followed a OneDrive link, and a Word macro quietly pulled a loader onto the host. Follow the chain from a sender-spoofed phishing message through a VBA macro, PowerShell, and signed-binary proxy execution to the Bumblebee loader's TLS command-and-control.

30m·257 tasks
View Operation
Finding Gozi: An Italian Malspam Infection
PRO

Finding Gozi: An Italian Malspam Infection

An accounts clerk at an Italian textile firm clicked an overdue-invoice link, downloaded a ZIP, and opened an Internet shortcut that reached out over SMB to pull a second-stage loader. PowerShell and rundll32 ran the Gozi banking trojan, and the workstation began beaconing to a rotating list of bare IP-literal hosts over plain HTTP. Trace the chain from a link-based lure through an SMB stage-2 fetch to the single command-and-control endpoint the trojan settled on, where it also shipped the stolen data.

50m·506 tasks
View Operation
Three Gangs, One Affiliate: A Pre-Ransomware Intrusion
PRO

Three Gangs, One Affiliate: A Pre-Ransomware Intrusion

A five-day, hands-on-keyboard intrusion run by a single affiliate whose tooling overlaps with three ransomware operations, caught and evicted before any encryptor ran. The operator delivered a trojanized desktop utility, ran two parallel command channels, dumped LSASS, enumerated the domain, and exfiltrated a collection archive over FTP. Reconstruct the full pre-ransomware kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.

1h 40m·15011 tasks
View Operation
EvilProxy AiTM: Indeed Redirect to M365 Cookie Theft

EvilProxy AiTM: Indeed Redirect to M365 Cookie Theft

An executive at a logistics firm clicks a job-themed phishing link that abuses a recruiting platform's open redirect to reach an EvilProxy adversary-in-the-middle page. The page reverse-proxies the real Microsoft 365 sign-in, so the victim completes MFA against the attacker, who captures and replays the post-MFA session cookie. Work the email, web-proxy, DNS, Entra sign-in, and perimeter records to reconstruct the redirect chain, the relay infrastructure, and the MFA bypass.

45m·507 tasks
View Operation
Storm-0408: Malvertising Drops Lumma via GitHub
PRO

Storm-0408: Malvertising Drops Lumma via GitHub

An after-hours visit to a pirated sports stream feeds a corporate workstation through a malvertising redirect chain that pulls a dropper from an abused public code-hosting service. A hidden PowerShell loader sets Run-key persistence and fetches the Lumma infostealer and a NetSupport RAT, which run through signed .NET living-off-the-land binaries to dodge application control. Lumma steals the browser credential store and exfiltrates it over HTTPS. Correlate proxy, Windows, XDR, and firewall telemetry to rebuild the chain from the ad redirect to the exfiltration endpoint and hand the team the indicators to contain it.

1h 35m·1509 tasks
View Operation
IDAT Loader: Fake Chrome Update to Stealer
PRO

IDAT Loader: Fake Chrome Update to Stealer

A fake Chrome update page convinced an estimator their browser was out of date, and one installer later their saved passwords and wallet data were on their way to an unknown host. Follow the chain from a drive-by MSI through msiexec, a signed application side-loading the IDAT Loader, process injection, and StealC and Lumma infostealers to a single command-and-control endpoint.

1h·506 tasks
View Operation
Vidar: Fake Notepad++ Malvertising to Data Theft
PRO

Vidar: Fake Notepad++ Malvertising to Data Theft

A developer searched for a popular code editor, clicked a paid search ad, and ran an installer that was not the real thing. Follow the chain from a typosquatted landing page through a dynamic-DNS payload host to the Vidar stealer's dead-drop C2 resolution, then pin down the single hosting address that carried both the stolen data and the malware's orders.

50m·506 tasks
View Operation
StealC: Cheat Tool to Emptied Wallet

StealC: Cheat Tool to Emptied Wallet

A gamer chasing a free aimbot ran a fake cheat-tool installer, and within the hour the PC was beaconing to the internet and pinning its CPU. Follow the trail from a search-driven lure and an abused download through StealC's Run-key persistence and credential, wallet, clipboard, and screenshot theft to its HTTP exfiltration and a second-stage cryptojacker.

20m·256 tasks
View Operation
IcedID Botnet to Dagon Locker Ransomware
PRO

IcedID Botnet to Dagon Locker Ransomware

A banking-trojan infection that smouldered for twenty-nine days before erupting into domain-wide Dagon Locker ransomware. A fake document portal served a JScript dropper that installed IcedID; weeks later the operator handed off to a Cobalt Strike beacon over a separate channel, pushed it across the estate through a Group Policy scheduled task, ran AdFind discovery, dumped domain credentials by replicating the directory (DCSync), moved over SMB administrative shares, exfiltrated to AWS S3 with Rclone, and deployed the encryptor while deleting shadow copies. Reconstruct the full kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.

1h·5010 tasks
View Operation
GootLoader: SEO Poisoning to Domain Control

GootLoader: SEO Poisoning to Domain Control

A paralegal searching for a contract template clicked a poisoned search result and a quiet endpoint script alert turned into a domain controller compromise by nightfall. Follow the chain from a drive-by ZIP through an obfuscated JavaScript loader, scheduled-task and Run-key persistence, a Cobalt Strike beacon, and a SystemBC proxy to the domain controller.

1h·507 tasks
View Operation
Emotet Revival: Triage the November Loader

Emotet Revival: Triage the November Loader

An operations coordinator opened a thread-hijacked remittance spreadsheet and enabled its macro. A trusted Windows utility quietly fetched a loader from a compromised website, and the workstation started beaconing to addresses nobody recognized. Trace the rebuilt November Emotet loader from a hijacked mail thread through a regsvr32 download-and-register, an encrypted epoch command-and-control pool, and a Cobalt Strike second stage.

1h·507 tasks
View Operation
Fake IP Scanner to BlackCat Ransomware
PRO

Fake IP Scanner to BlackCat Ransomware

A multi-day, hands-on-keyboard intrusion that began with a malvertising lure for a popular network scanning utility and ended in enterprise-wide BlackCat ransomware. The trojanized installer side-loaded a malicious library to stage Sliver and Cobalt Strike, the operator dumped credentials living-off-the-land, moved laterally over SMB, exfiltrated data with a renamed Restic client to a dedicated host, then deleted shadow copies and encrypted the estate. Reconstruct the full kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.

1h 45m·1508 tasks
View Operation
PaperCut RCE to Bl00dy Ransomware
PRO

PaperCut RCE to Bl00dy Ransomware

Bl00dy ransomware actors exploited an unauthenticated access-control flaw (CVE-2023-27350) on an internet-facing PaperCut MF/NG print-management server, ran code as the application service account, staged a TrueBot loader and a Cobalt Strike beacon, installed Atera and AnyDesk for hands-on remote access, moved laterally over RDP, tunnelled the file share out through a Tor helper, and deployed the Bl00dy encryptor fleet-wide. Reconstruct the intrusion from SIEM, endpoint XDR, and perimeter firewall telemetry and classify the key ATT&CK techniques.

1h·508 tasks
View Operation
Cobalt Strike and SOCKS: 11 Days to LockBit
PRO

Cobalt Strike and SOCKS: 11 Days to LockBit

An eleven-day, hands-on-keyboard intrusion that began with a phishing message and ended in enterprise-wide LockBit ransomware. The operator hid a Cobalt Strike beacon in a trusted Windows process, ran a pair of SOCKS proxies for pivoting, dumped LSASS and the Active Directory database, and exfiltrated data to a cloud share and FTP drops before encrypting the estate. Reconstruct the full kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.

1h 40m·1509 tasks
View Operation
FortiOS Bypass to Hunters International Ransomware

FortiOS Bypass to Hunters International Ransomware

Operators consistent with the Hunters International ransomware group abuse a FortiOS super-admin authentication bypass on an internet-facing FortiGate, plant rogue accounts, pivot over the SSL-VPN tunnel by RDP, sweep the network with Advanced IP and Port Scanner, and push roughly 6.8 GB of share data to a single external host over SFTP before running the encrypter. Work the FortiGate edge, the directory records, the perimeter egress, and the endpoint process tree to reconstruct the intrusion from entry to encryption.

30m·256 tasks
View Operation
Fighting Ursa: Car-for-Sale Lure to HeadLace

Fighting Ursa: Car-for-Sale Lure to HeadLace

A diplomatic attache clicked a link offering a discounted vehicle for sale, and a trusted Windows program started behaving like malware. Follow the chain from a spearphishing link through an abused web-service redirector and a staged archive to a side-loaded HeadLace loader running under a legitimate signed binary.

30m·256 tasks
View Operation
Sandworm: Trojanized KMS Activator to DcRAT
PRO

Sandworm: Trojanized KMS Activator to DcRAT

A staff member at the energy provider Ridna Energo downloaded a free Microsoft KMS activation tool that turned out to be trojanized. Within minutes it dropped the BACKORDER loader, disabled Defender, proxy-loaded the DcRAT implant through rundll32, and opened an encrypted channel to a single anonymizing C2 node. Reconstruct the full espionage intrusion, from the lure download through credential theft, lateral movement, and exfiltration over command-and-control, across endpoint, network, and perimeter telemetry.

2h 5m·15010 tasks
View Operation
UNC6384: Captive-Portal PlugX Implant

UNC6384: Captive-Portal PlugX Implant

A diplomat's managed laptop on an untrusted conference network has its captive-portal check hijacked and is steered to a page posing as a security update. The download is a signed Canon utility paired with a malicious DLL: running the trusted binary side-loads the DLL, which runs PlugX in memory, beacons to a single HTTPS host, and sets a Run key. Reconstruct the chain from the proxy, Sysmon, endpoint, and firewall evidence.

30m·257 tasks
View Operation
Copyright Lure to Rhadamanthys Stealer

Copyright Lure to Rhadamanthys Stealer

A procurement officer opened a copyright-infringement notice, followed a shortened link, and ran a signed PDF reader out of a Downloads folder. Follow the chain from a CDN-fronted delivery domain through a DLL search-order hijack and a Run-key autostart to the Rhadamanthys stealer's single command-and-control channel, where the beacon and the stolen data ride together.

45m·506 tasks
View Operation
Fake Browser Update to Atomic macOS Stealer

Fake Browser Update to Atomic macOS Stealer

A freelance designer's personal Mac is lured by a ClearFake 'your browser is out of date' prompt into downloading a fake Safari update. The bundled app is Atomic macOS Stealer: it phishes the login password, raids the keychain and browser stores, and uploads the loot to a single host over the same channel it uses to communicate. Reconstruct the chain from the macOS endpoint telemetry and the web filter.

25m·256 tasks
View Operation
VPN Brute Force: Credential Attack on the Remote-Access Portal

VPN Brute Force: Credential Attack on the Remote-Access Portal

A password-spray campaign targets the Halcyon Freight SSL-VPN portal from two rotating source IPs, submitting credentials across many accounts to stay under per-account lockout thresholds. One account eventually matches. Reconstruct the spray, identify the compromised account and the operator IP that opened the active session, and trace the first move the attacker made over the tunnel.

25m·256 tasks
View Operation
Open SMB Share: Unauthorized Data Access

Open SMB Share: Unauthorized Data Access

A finance file share on an internal Windows server was misconfigured to allow all domain users read access. A workstation account with no finance role connected over SMB and bulk-read payroll records, M&A strategy documents, and board materials. Reconstruct the session from Windows Security audit events and internal firewall logs.

25m·256 tasks
View Operation
RDP Brute Force: Internet-Facing Server Login

RDP Brute Force: Internet-Facing Server Login

An internet-exposed Windows Server running RDP has been receiving a sustained brute-force campaign from an external address. After dozens of failed authentication events, one attempt succeeds and an interactive session is opened. Reconstruct the attack from the Windows Security event log, identify the source and target, and classify the technique.

25m·256 tasks
View Operation
Account Takeover: Impossible-Travel Sign-In

Account Takeover: Impossible-Travel Sign-In

A finance analyst's Microsoft Entra account is accessed without MFA from Moldova 18 minutes after their normal London sign-in. Impossible travel confirmed. The unauthorized session reads the inbox via Graph and adds an external recovery address. Work the Entra audit trail to identify the attacker IP, the compromised mailbox, and the persistence mechanism.

25m·256 tasks
View Operation
Golden Ticket: Forged Kerberos TGT Persistence
PRO

Golden Ticket: Forged Kerberos TGT Persistence

A threat actor who already extracted the krbtgt hash from a domain workstation forged Kerberos TGTs offline and used them to access any domain resource without re-touching the domain controller. The telltale signs are RC4-encrypted TGS requests with no preceding AS-REQ and a domain controller that starts beaconing outbound. Reconstruct the full chain from LSASS extraction to C2 beacon using Windows Security events and XDR process telemetry.

40m·507 tasks
View Operation
Cisco IOS XE Web UI: Implant and Rogue Admin (CVE-2023-20198)

Cisco IOS XE Web UI: Implant and Rogue Admin (CVE-2023-20198)

The Cisco IOS XE Web UI management interface on AXFORD-RTR-01 was inadvertently exposed to the internet. An attacker exploited CVE-2023-20198 to create an unauthenticated privilege-15 local account, then chained CVE-2023-20273 to drop a Lua implant on the device flash filesystem. The implant hooked the HTTP server and beaconed to an external C2 address. Reconstruct the full compromise chain from the router syslog and the perimeter firewall.

40m·506 tasks
View Operation
Night Shift at Veridian Specialty Chemicals
PRO

Night Shift at Veridian Specialty Chemicals

Veridian Specialty Chemicals runs one Windows domain from one site: an on-premises Exchange server in the DMZ, a domain controller, and a file, backup and SQL tier that carry the plant's process data. Between the small hours and the end of the following evening the estate logged work nobody rostered. A perimeter sensor fired against the mail host. Files appeared on servers where installers never run. Administrative sessions arrived from the wrong direction. A long outbound transfer left the server tier on a port nobody watches. None of it was escalated overnight. Work the SIEM event log, the XDR process telemetry and the perimeter firewall records, and establish what reached the estate, what it took with it, and what it left behind.

1h 40m·1509 tasks
View Operation
Spring4Shell: Class-Loader RCE to Webshell (CVE-2022-22965)

Spring4Shell: Class-Loader RCE to Webshell (CVE-2022-22965)

An internet-facing Java Spring MVC application is compromised through CVE-2022-22965 (Spring4Shell), a class-loader manipulation flaw that turns Tomcat's own logging system into a webshell writer. Working from the Tomcat access logs and the perimeter firewall, trace the exploit request, identify what landed on disk, follow the operator's command sessions, and catch the pivot to an internal backend service.

40m·506 tasks
View Operation
Cactus Ransomware: Qlik Sense Exploitation
PRO

Cactus Ransomware: Qlik Sense Exploitation

An internet-facing Qlik Sense analytics server is exploited and turned into the launch point for a Cactus ransomware intrusion. Within a day the operator persists with a rogue remote-access agent, dumps domain-admin credentials from memory, pivots by RDP to the domain controller and backup servers, steals engineering data to cloud storage, and deploys ransomware. Work the Qlik web logs, the endpoint process tree and the perimeter traffic to reconstruct the intrusion end to end and tell the abuse apart from a heavy baseline of normal analytics and remote-access activity.

1h 30m·1508 tasks
View Operation
Salt Typhoon: Telecom Carrier Espionage
PRO

Salt Typhoon: Telecom Carrier Espionage

An Axiom Carrier Services edge router is behaving in ways its change record cannot explain: management sessions from addresses that should never reach it, a configuration change with no ticket behind it, and egress the estate never authorised. Work a full day of router syslog and perimeter firewall traffic and reconstruct what happened to the device, in order.

1h 30m·1508 tasks
View Operation
UNC3886: vCenter RCE to ESXi Persistence (CVE-2023-34048)
PRO

UNC3886: vCenter RCE to ESXi Persistence (CVE-2023-34048)

Orbivex Aerospace runs its virtualisation estate on a vCenter Server appliance and three ESXi hypervisors, with the vCenter HTTPS management interface published to the internet. The platform team opened a ticket during the morning shift: the appliance had logged a management daemon terminating on a fatal signal and restarting, and the hypervisor integrity summary listed package and startup-file entries the change record does not account for. Work the vCenter, ESXi and firewall telemetry and establish what reached the estate, how it moved between the management plane and the hypervisors, and how far it got.

1h 20m·1509 tasks
View Operation
DPRK Fake IT Worker: Insider Access and Exfiltration
PRO

DPRK Fake IT Worker: Insider Access and Exfiltration

A fraudulent remote software engineer embedded under a stolen identity gains network access on their first day and immediately begins collecting source code, architecture documentation and cloud secrets. The session originates entirely from a single hosting-range ASN, persists through AnyDesk and ngrok tunnels, and ends with a dual-channel exfiltration via Rclone and AzCopy. Reconstruct the full chain from Azure AD audit events, VPN and endpoint telemetry.

1h 25m·1509 tasks
View Operation
Rhysida Ransomware: Healthcare Network Intrusion
PRO

Rhysida Ransomware: Healthcare Network Intrusion

A Rhysida ransomware affiliate phishes a healthcare staff member's VPN credentials and exploits a stale MFA exemption to breach a regional medical center. Using a Cobalt Strike beacon and built-in Windows tools, the attacker extracts all domain credentials, exfiltrates patient records for double extortion, and deploys the encryptor estate-wide. Trace the kill chain from the first failed VPN login to the final ransom note.

1h 30m·1507 tasks
View Operation
BianLian: Exfiltration-Based Extortion
PRO

BianLian: Exfiltration-Based Extortion

A threat actor with a valid domain account and no MFA to stop them lands on an internet-facing RDP jump host, spends the morning living off the land, dumps credentials from LSASS, and spends the afternoon moving approximately 47 GB of engineering documents out of the network through a cloud-sync utility pointed at storage they control. No files are encrypted; the leverage is the stolen data itself. Reconstruct the full chain from initial RDP spray to log wipe.

1h 55m·1509 tasks
View Operation
LLMNR and NBT-NS Poisoning: NTLM Relay to SMB
PRO

LLMNR and NBT-NS Poisoning: NTLM Relay to SMB

A workstation on the Vantara Solutions network mistyped a file server name. DNS had no answer. Windows broadcast the query over LLMNR -- and something on the network answered. Reconstruct the poisoning, the credential capture, and the relay that followed using SIEM events, endpoint telemetry, and a raw packet capture.

40m·507 tasks
View Operation
BazarCall: Callback Phishing to Remote Access
PRO

BazarCall: Callback Phishing to Remote Access

An accounts-payable coordinator received a spoofed subscription invoice with no attachment and no link -- just a phone number to call. The call center talked her into installing a remote-management tool, and from there the operator moved fast: enumeration, a persistence scheduled task, a Cobalt Strike stager, and a pivot attempt toward the domain controller. Reconstruct the chain from the lure email through the RMM session and the second-stage beacon.

55m·506 tasks
View Operation
AsyncRAT: Malvertising to Trojanized Installer
PRO

AsyncRAT: Malvertising to Trojanized Installer

An IT admin searching for a remote management tool clicks a paid search advertisement and downloads what appears to be a legitimate installer. The ZIP contains an AutoIt-compiled fake setup executable that drops a PowerShell loader, which fetches AsyncRAT from a staging server. The RAT establishes persistence via a scheduled task and beacons to a C2 server. Correlate web proxy records, Windows event logs, XDR file and process artifacts, and firewall egress traffic to trace the full chain from malvertising lure to active command-and-control.

45m·507 tasks
View Operation
DarkGate via Microsoft Teams: External Message Lure

DarkGate via Microsoft Teams: External Message Lure

An IT helpdesk coordinator at a logistics firm receives an urgent Teams chat from an external IT support account. The message links to a VBS script disguised as a VPN update. Running it kicks off a silent MSI install that drops a renamed AutoIt3 loader, which decrypts DarkGate in memory, registers a scheduled task for persistence, and begins beaconing to an HTTPS C2 server. Trace the chain from the Teams lure through the loader to the active backdoor.

50m·507 tasks
View Operation
AWS S3 Ransomware: SSE-C Encryption (Codefinger)
PRO

AWS S3 Ransomware: SSE-C Encryption (Codefinger)

Client deliverables and backups at a professional-services firm are silently re-encrypted overnight using a legitimate AWS storage feature. No malware runs on any host. Working through CloudTrail, piece together how stolen service-account keys were used to install a countdown clock and lock every object behind a key only the attacker holds.

40m·507 tasks
View Operation
Exposed Kubernetes API: Cryptojacking the Cluster
PRO

Exposed Kubernetes API: Cryptojacking the Cluster

Three EKS worker nodes started pegging their CPUs overnight. The Kubernetes API server was reachable from the internet with anonymous access enabled, and an automated attacker used it to deploy a privileged DaemonSet on every node, escape the container to the host, drop a Monero miner, and steal the node IAM credentials. Work the cluster audit log, host records, perimeter egress, and CloudTrail to reconstruct the full intrusion chain.

55m·506 tasks
View Operation
GCP Service Account Key Abuse: IAM Privilege Escalation
PRO

GCP Service Account Key Abuse: IAM Privilege Escalation

A developer committed a GCP service account JSON key to a public repository and an attacker found it within hours. Work the GCP Cloud Audit Logs to trace how the leaked credential was turned into a full IAM privilege escalation and a bulk download of the production secrets vault.

45m·507 tasks
View Operation
Entra ID Device Code Phishing: Token Theft

Entra ID Device Code Phishing: Token Theft

A Microsoft 365 user at a financial services firm receives a convincing phishing email asking her to enter a device code at the legitimate Microsoft devicelogin page. The code completes the attacker's OAuth request, handing over a valid token. Working through Entra sign-in logs, Graph audit events, and the email trail, trace how the token was stolen and what the attacker read from the victim's mailbox.

45m·507 tasks
View Operation
AWS Exposed Access Key: Enumeration to Data Access
PRO

AWS Exposed Access Key: Enumeration to Data Access

A deployment service account's AWS access key landed in a public GitHub repository. By the time the secret-scanning alert fired, an attacker had already validated the credential and was working through the account: mapping IAM identities, pulling financial exports from S3, and launching compute-optimized instances to mine cryptocurrency at the victim's expense. Work the CloudTrail audit trail and the SIEM to reconstruct the full chain.

45m·507 tasks
View Operation
Jenkins Arbitrary File Read: CVE-2024-23897 to RCE

Jenkins Arbitrary File Read: CVE-2024-23897 to RCE

The Jenkins controller at Vetrina Systems is running a version vulnerable to CVE-2024-23897 -- an args4j parser flaw that lets the CLI read any file from the server filesystem before authentication completes. An attacker used it to steal the Jenkins master key and credential store, decrypted stored service-account passwords offline, then authenticated and ran Groovy code through the Script Console to drop a persistent payload and pivot to connected build agents. Work from the SIEM access logs and XDR process evidence to trace every step from the first CLI probe to the reverse shell.

45m·507 tasks
View Operation
Zimbra Webmail RCE: Archive Exploit to Mailbox Theft
PRO

Zimbra Webmail RCE: Archive Exploit to Mailbox Theft

A law firm Zimbra Collaboration server was compromised through a path traversal flaw in the cpio helper invoked during inbound email scanning (CVE-2022-41352). A crafted archive delivered over SMTP caused cpio to drop a JSP webshell directly into the Zimbra web root, giving the actor persistent server-side execution. They then used Zimbra's own CLI tooling to export targeted attorney mailboxes and exfiltrate the data. Reconstruct the chain from the mail delivery through the webshell activity to the data leaving the network.

45m·507 tasks
View Operation
Cleo Harmony MFT: Cl0p Data Theft at Vantex Logistics

Cleo Harmony MFT: Cl0p Data Theft at Vantex Logistics

A Cleo Harmony managed file transfer server in the Vantex Logistics DMZ started reaching external systems it does not normally contact and running processes the change record does not explain. Reconstruct what happened from the Cleo web logs, the Windows event logs, the resolver and the perimeter firewall.

50m·507 tasks
View Operation
Ivanti Connect Secure: Auth Bypass to Webshell

Ivanti Connect Secure: Auth Bypass to Webshell

An internet-facing Ivanti Connect Secure VPN appliance has been exploited through a pair of chained zero-days: an authentication bypass and a command injection. A webshell is now resident on the appliance, credentials have been stolen from the system configuration, and the attacker has pivoted inward. Work from the SIEM access logs, the Linux host audit trail, and the XDR process tree to reconstruct the chain from the first bypass request to the internal pivot.

55m·507 tasks
View Operation
Malicious npm Package: Postinstall Infostealer

Malicious npm Package: Postinstall Infostealer

A developer at a software company runs a routine npm install and the terminal returns clean. Less than a minute later the web proxy records a large outbound upload from that workstation. Work the process tree, the file activity and the outbound traffic to reconstruct what the install actually did.

25m·256 tasks
View Operation
Remcos RAT: Malicious Invoice Attachment

Remcos RAT: Malicious Invoice Attachment

An accounts-payable employee at Harwell Logistics opens what looks like an overdue supplier invoice, and minutes later her workstation is holding a persistent outbound session to an address outside the company on a port nothing else uses. Walk the mail gateway records, the endpoint file artifacts and the process tree in order, pulling one indicator out of each surface until the delivery, the loader, the execution chain and the implant are all named, then close the case with an ATT&CK label.

25m·256 tasks
View Operation
Apache Path Traversal: CVE-2021-41773 to RCE

Apache Path Traversal: CVE-2021-41773 to RCE

An Apache 2.4.49 web server at Kestrel Analytics is targeted via CVE-2021-41773. An attacker uses percent-encoded path traversal to read /etc/passwd, confirms mod_cgi is enabled, and escalates to remote code execution. Walk the access logs and firewall traffic step by step to trace the traversal, the RCE, and the webshell that was left behind.

25m·256 tasks
View Operation
WordPress Plugin RCE: Webshell on a Vulnerable Site

WordPress Plugin RCE: Webshell on a Vulnerable Site

A media company's WordPress server is compromised after an attacker exploits an unpatched file-upload plugin to drop a PHP webshell into the public uploads directory. Work through the Apache access logs and IDS alerts step by step, tracing the probe, the upload bypass, and the command execution that followed.

25m·257 tasks
View Operation
Tomcat Manager Abuse: Weak Credentials to Webshell

Tomcat Manager Abuse: Weak Credentials to Webshell

An Apache Tomcat server at a retail company has its Manager web application exposed with default credentials. An attacker authenticates, deploys a malicious WAR webshell, runs OS commands through it, and drops a cryptocurrency miner. Walk the Tomcat access logs from the first 401 to the mining pool connection.

25m·256 tasks
View Operation
Play (Playcrypt): FortiOS + Exchange to Double Extortion
PRO

Play (Playcrypt): FortiOS + Exchange to Double Extortion

Operators consistent with the Play ransomware group abuse a valid SSL-VPN account and exploit a published Exchange server, run AdFind and Grixba, disable the endpoint defenses, beacon out with Cobalt Strike and SystemBC, move laterally over RDP, archive Finance and HR data with WinRAR, and upload roughly 9.6 GB to a file-sharing service before deleting shadow copies and running an intermittent-encryption impact stage. Work the FortiGate edge, Exchange web logs, the endpoint process tree, the perimeter egress, and the extortion email to reconstruct the full double-extortion intrusion.

1h 45m·1507 tasks
View Operation
Qilin: Veeam credential abuse to ESXi hypervisor encryption
PRO

Qilin: Veeam credential abuse to ESXi hypervisor encryption

A Qilin operator exploits a manufacturing firm's SSL-VPN edge, recovers stored credentials from an internet-facing backup server, steals a domain-admin token, self-propagates over SMB to vCenter, exfiltrates data over an encrypted tunnel, clears the Windows logs, and encrypts the ESXi datastores after mass-powering-off the guests. Work the FortiGate and Windows logs, the endpoint process tree, the perimeter traffic, and the vCenter/ESXi records to reconstruct the path from the edge to the hypervisor.

1h 35m·1507 tasks
View Operation
Medusa RaaS: VPN access to enterprise encryption
PRO

Medusa RaaS: VPN access to enterprise encryption

A regional healthcare provider is breached through its internet-facing SSL-VPN, and within a shift a Medusa affiliate harvests domain credentials, pivots to the domain controller and backup servers, persists with a rogue remote-management agent hidden among the estate's legitimate ones, steals patient data to cloud storage, and deploys ransomware. Work the VPN authentication records, the endpoint process tree, and the perimeter traffic to reconstruct the intrusion end to end and tell the abuse apart from a heavy baseline of normal remote-management activity.

1h 35m·1507 tasks
View Operation
Volt Typhoon: living-off-the-land in critical infrastructure
PRO

Volt Typhoon: living-off-the-land in critical infrastructure

No malware, no ransomware, no payload to scan for, just native Windows binaries used in an abnormal sequence and a stolen administrator credential. A stealth operator plants a tiny web shell on a water utility's internet-facing host, dumps LSASS with a signed system DLL, routes C2 through a compromised home router, and exports the entire Active Directory database off the domain controller before clearing the logs. Work the Windows Security log, the endpoint process tree, and the perimeter traffic to separate the living-off-the-land activity from a heavy baseline of legitimate admin work.

1h 30m·1507 tasks
View Operation
Trust, Forged: The Monitoring-Platform Backdoor

Trust, Forged: The Monitoring-Platform Backdoor

A trusted, signed plugin in Greyford's network monitoring platform was backdoored upstream. From a silent defense-tamper on the monitoring server, follow a low-and-slow DGA-over-DNS beacon under a single attacker apex, a CNAME redirect to a staged C2, and finally the theft of on-prem token-signing trust that forges SAML tokens into anomalous, MFA-less cloud sign-ins. The DNS resolver log is your sharpest blade.

1h 35m·1507 tasks
View Operation
The Half-Second Tell
PRO

The Half-Second Tell

A Linux hosting fleet quietly picks up an affected xz-utils / liblzma 5.6.1 build, and the SSH daemon's login path is no longer its own. There is no crash and no malware drop, only a shared object whose hash moved, an sshd that forks a shell it never should, a half-second of extra login latency, and a root key the fleet never issued. Work the package, file-integrity, auth, and perimeter records to surface the subtle host artifacts of CVE-2024-3094 and scope the affected version.

1h 15m·1508 tasks
View Operation
AD CS ESC1: Certificate Template Abuse to Domain Admin
PRO

AD CS ESC1: Certificate Template Abuse to Domain Admin

An ordinary user becomes a Domain Admin without stealing a password. A misconfigured certificate template lets the enrollee supply the subject, so the user requests a certificate whose Subject Alternative Name names a Domain Admin, and the CA issues it. The forged certificate is then used for PKINIT to authenticate as that admin. Work the certificate-authority records, the endpoint process tree, and the domain controller's Kerberos logs to reconstruct the escalation.

50m·505 tasks
View Operation
Phishing foothold → domain compromise
PRO

Phishing foothold → domain compromise

A finance user at Vendt Aerospace opened a mail attachment mid-morning, and within the hour an administrative account was signing in to a server it had no business reaching. Work the domain controller's authentication records and the endpoint process telemetry, separate the intrusion from an estate that produces plenty of traffic that looks similar, and reconstruct how the operator got from one workstation to the directory.

40m·506 tasks
View Operation
Brixton Foods: the directory answered a request it should have refused
PRO

Brixton Foods: the directory answered a request it should have refused

A food manufacturer's help desk raised a ticket at lunchtime: an overnight production report had not written to the file share, and one workstation had been slow all morning. By the evening the share was unreadable and an administrator account nobody on the IT rota recognises had been busy on the domain controllers. You have the day's Windows Security feed and the endpoint telemetry for the estate. Reconstruct what the operator did between the first mailbox and the unreadable share, and name the accounts and hosts the response team has to act on.

50m·505 tasks
View Operation
Overnight on the DMZ Wiki

Overnight on the DMZ Wiki

Quillon Software publishes its engineering wiki straight to the internet from the DMZ. Overnight the host picked up work nobody rostered: requests that never authenticated, shell activity under a service account, and outbound sessions from a server that normally only talks to its update mirrors. Work the web access logs, the Linux audit trail and the perimeter egress, and reconstruct what reached the host and what left it.

50m·506 tasks
View Operation
Hide Your RDP
PRO

Hide Your RDP

An internet-facing RDP server at a logistics firm is password-sprayed into, and within hours a RansomHub affiliate dumps credentials, pivots to the domain controller and backup servers, steals finance data over SFTP, and deploys ransomware. Work the authentication records, the endpoint process tree, and the perimeter traffic to reconstruct the intrusion end to end.

1h·506 tasks
View Operation
Exchange ProxyShell: Domain-Wide Ransomware
PRO

Exchange ProxyShell: Domain-Wide Ransomware

An internet-facing Exchange server falls to ProxyShell, dropping ASPX web shells that run as SYSTEM. The attacker re-enables a built-in account, dumps LSASS with a Windows DLL, tunnels out with Plink and FRP, moves laterally over RDP, and encrypts the domain with its own BitLocker and DiskCryptor, no ransomware binary in sight. Work the Exchange logs, the endpoint process tree, and the perimeter traffic to reconstruct the intrusion.

1h·506 tasks
View Operation
Zerologon DC takeover → ransomware
PRO

Zerologon DC takeover → ransomware

An unprivileged phishing foothold becomes a domain-wide ransomware outbreak in hours. The attacker abuses the Zerologon flaw to reset a domain controller's machine-account password, pivots controller-to-controller, and encrypts the estate after gutting the backups. Work the Windows Security log, the endpoint process tree, and the perimeter traffic to reconstruct the takeover.

55m·505 tasks
View Operation
Frozen Assets: The Snowflake Tenant Heist

Frozen Assets: The Snowflake Tenant Heist

A retailer's Snowflake tenant is accessed with a contractor credential lifted from an infostealer log. With no MFA and no network policy to stop it, the actor logs in from VPN-exit IPs, recons with anomalous tooling, and bulk-exfiltrates an entire customer table. Work the Snowflake audit trail to reconstruct the theft.

1h·506 tasks
View Operation
Daemon in the Dark

Daemon in the Dark

A Linux Docker host quietly started mining crypto overnight. Its container-engine API was open to the internet, and an automated intruder used it to launch a host-mounting container, drop the Kinsing malware and an XMRig miner, kill the defenses, and try to spread. Work the host, perimeter, and cloud trails to reconstruct the intrusion.

30m·255 tasks
View Operation
Purchase Order, Poisoned

Purchase Order, Poisoned

A sales coordinator opened a malspam 'purchase order' and a finance workstation went quiet, then started talking to the internet. Follow the chain from a sender-spoofed email through an Equation Editor exploit, a rundll32 loader, Run-key persistence, and a hollowed system process to the FormBook stealer's HTTP command-and-control.

30m·256 tasks
View Operation
Transfer Denied: The MOVEit Web Shell

Transfer Denied: The MOVEit Web Shell

An internet-facing MOVEit Transfer server is breached through an unauthenticated SQL injection. A stealthy web shell, gated by a secret header, enumerates and steals stored files and plants a rogue account. Work the web request logs to reconstruct the data theft.

30m·256 tasks
View Operation
Kernel Thread Impostor

Kernel Thread Impostor

An internet-exposed Linux node falls to an SSH password brute force, and within seconds the Outlaw (Dota3) toolkit drops a hidden cryptominer disguised as a kernel thread. Work the auth logs, process records, and perimeter traffic to reconstruct the break-in, the persistence, and the mining.

25m·256 tasks
View Operation
Wide Open

Wide Open

An Elasticsearch node that should have stayed on the internal network had its API exposed to the internet on port 9200 with no authentication. Scanners found it within hours; one actor ran code on the host and dropped a cryptominer, another wiped every index and left a ransom note. Reconstruct the chain from the Linux host logs and the perimeter firewall.

25m·256 tasks
View Operation
Open Bucket, Open Books

Open Bucket, Open Books

A payments vendor's S3 bucket of bank-mandate PDFs was quietly made world-readable. Anonymous outsiders listed and bulk-downloaded the data with no credentials. Work the cloud audit trail to reconstruct the exposure and the theft.

25m·254 tasks
View Operation
Scattered Spider: Identity-First Attack Chain
PRO

Scattered Spider: Identity-First Attack Chain

Investigate a high-sophistication intrusion by UNC3944 (Scattered Spider). This scenario simulates a multi-stage attack starting from social engineering and MFA fatigue, progressing through the exploitation of unmanaged edge devices, and culminating in a 'Bring Your Own Vulnerable Driver' (BYOVD) technique to blind kernel-level security agents. Analysts must correlate identity providers, cloud sign-ins, and deep endpoint forensics to reconstruct the timeline and identify the breakout speed of this financially motivated threat actor.

1h 30m·15010 tasks
View Operation
Fake Zoom to Ransomware: The Social Engineering Pipeline

Fake Zoom to Ransomware: The Social Engineering Pipeline

In this advanced SOC simulation, you will investigate a multi-stage intrusion that began with a drive-by download of a trojanized Zoom installer. The attack progressed through several stages of loader execution, including d3f@ckloader and IDAT loader, eventually leading to the deployment of high-end C2 frameworks like Cobalt Strike and Brute Ratel. You must trace the attacker's path from the initial web-based compromise, through lateral movement via RDP tunneling and proxy tools, to the final mass-deployment of BlackSuit ransomware via enterprise management software. This scenario is based on real-world 2025 threat intelligence and requires deep analysis of SIEM, XDR, and Firewall telemetry to reconstruct the full kill chain.

1h 40m·15010 tasks
View Operation
Black Basta: Email Bomb to Encryption
PRO

Black Basta: Email Bomb to Encryption

Investigate a Black Basta-style ransomware intrusion that begins with email bombing and Microsoft Teams impersonation, escalates through Quick Assist remote control, establishes BackConnect-style command and control through OneDrive DLL side-loading, exfiltrates data with WinSCP, and ends in ransomware encryption. Correlate SIEM, XDR, and firewall telemetry carefully: external C2 IPs identify adversary infrastructure, while internal srcIp values identify compromised hosts. Note: there is no separate email console in this operation - all mail-gateway telemetry for the email-bombing wave lives in the SIEM logs (source: email-gateway), alongside Windows, IDS, EDR, and Azure AD events.

1h 35m·15010 tasks
View Operation
Akira Ransomware: Full Kill Chain IR
PRO

Akira Ransomware: Full Kill Chain IR

The intrusion began with a search engine advertisement and ended with the deployment of Akira ransomware. This scenario covers the full 2025 threat landscape, emphasizing identity-based compromise, MFA bypass via AiTM kits, and rapid lateral movement toward Active Directory. Analysts must navigate a complex environment of Windows workstations, Domain Controllers, and Cisco VPN infrastructure to reconstruct the timeline from initial access to data exfiltration and final encryption.

2h·15010 tasks
View Operation
Edge Device Exploitation: VPN Zero-Day

Edge Device Exploitation: VPN Zero-Day

Investigate a breach targeting exposed edge security appliances. In this scenario, an attacker exploits Ivanti Connect Secure CVE-2025-22457 to obtain unauthenticated code execution, spawns a shell from the gateway web process, retrieves a Linux payload, and attempts to preserve access using edge-device service abuse patterns similar to FortiGate SSL-VPN post-exploitation tradecraft. Analyze SIEM, XDR, and firewall evidence to identify the spawned shell, suspicious domain, local sync script, and defensive block policy.

55m·508 tasks
View Operation
Search Engine Poisoning: From a Sponsored Result to the Domain Controller

Search Engine Poisoning: From a Sponsored Result to the Domain Controller

An analyst at a mid-sized logistics firm searched for a routine software update, clicked the sponsored result at the top of the page, and went back to work. Five days later the SOC is holding a workstation, a file server and a domain controller whose telemetry nobody has read yet. You have the SIEM and the endpoint console for those five days, and most of what is in them is an ordinary week. Reconstruct what the click actually started, follow it off the workstation, and put names to the files and the account behind the activity that does not belong.

1h·508 tasks
View Operation
CI/CD Pipeline Hijack: GitHub Actions Compromise

CI/CD Pipeline Hijack: GitHub Actions Compromise

Investigate the March 2025 GitHub Actions supply-chain compromise involving tj-actions/changed-files and reviewdog/action-setup. A compromised action version tag caused Linux CI runners to execute malicious payload logic and expose CI/CD secrets in workflow logs using double-base64 encoding. Analyze SIEM and XDR telemetry to identify the affected action, runner identity, payload execution, detection source, and secret-exposure pattern, then decide which artifacts are malicious versus benign threat-intelligence lookups.

50m·508 tasks
View Operation
Cloud Identity Under Siege

Cloud Identity Under Siege

Nine days of telemetry from a cloud-first Azure estate: Entra ID sign-ins, Windows endpoints, a Kubernetes cluster, an Azure Function and the storage accounts behind them all report into one SIEM. Something inside that window does not fit the shape the estate normally has. Work the SIEM, XDR, firewall and cloud panels together, pin each observation to a host and a principal you can name, and rebuild the sequence from the records themselves.

1h·508 tasks
View Operation
Kerberoasting: Service Ticket to Domain Admin
PRO

Kerberoasting: Service Ticket to Domain Admin

In this scenario, you will investigate a high-speed identity-based attack. Starting from an edge device exploitation, an adversary moves laterally to a domain-joined workstation and targets Active Directory. You must analyze SIEM logs for Kerberos ticket anomalies (RC4 encryption), correlate XDR process trees for Impacket usage, and identify the 'malware-free' techniques used to escalate privileges to Domain Admin.

55m·508 tasks
View Operation
Finance Mailbox Takeover at MegaCorp Logistics

Finance Mailbox Takeover at MegaCorp Logistics

A finance analyst at MegaCorp Logistics reported that colleagues were receiving replies to messages she never sent, and her account was disabled while the investigation runs. You have the SIEM feed and the endpoint XDR telemetry for the workstation estate and the mail platform, covering the week around the report. Reconstruct what happened: which host produced the endpoint evidence, what its browser reached, how the account was taken over, and what was left behind on the mail platform so the containment plan is complete.

45m·508 tasks
View Operation
Cobalt Strike: Beacon Detection
PRO

Cobalt Strike: Beacon Detection

In this scenario, a threat actor has gained a foothold in a corporate environment. You will serve as a SOC Analyst tasked with identifying the initial infection vector, tracing lateral movement, and uncovering the final objectives of the intrusion. This room focuses on detecting beacon traffic, process injection patterns, and the hands-on-keyboard activity that precedes encryption. You will utilize SIEM logs and XDR telemetry to reconstruct the attack timeline and identify critical Indicators of Compromise (IOCs).

1h·508 tasks
View Operation
MFA Fatigue: The Notification Flood

MFA Fatigue: The Notification Flood

In this guided walkthrough, you will step into the shoes of a SOC analyst investigating a modern identity-based attack. The threat landscape in 2026 has shifted: adversaries are no longer just 'breaking in'; they are logging in. You will analyze real-time identity signals, correlate disparate log sources across a hybrid cloud environment, and identify the markers of an MFA fatigue attack used by the FlowerStorm phishing kit. This scenario highlights the critical importance of behavioral analysis over simple IOC matching in an era of malware-free intrusions and compromised human identities.

30m·256 tasks
View Operation
QR Code Phishing: Scan to Compromise

QR Code Phishing: Scan to Compromise

In this scenario, you will investigate a modern 'Quishing' (QR phishing) attack that bypassed traditional email filters by hiding its payload inside an image. You will trace the full chain: a spoofed MFA-enrollment lure sent from purpose-built infrastructure, a redirect server that conceals the final destination, and an Evilginx-style adversary-in-the-middle page that stole an authenticated session cookie despite MFA. You will then follow the attacker's post-compromise moves (Graph API mailbox enumeration, SharePoint exfiltration, and a hidden inbox forwarding rule) and choose the containment action that actually evicts them.

15m·256 tasks
View Operation
Credential Harvesting: The Lookalike Login

Credential Harvesting: The Lookalike Login

Investigate an adversary-in-the-middle (AiTM) credential phishing campaign that lured an employee to a lookalike Microsoft 365 login page. Working entirely from SIEM logs, you will identify the lookalike domain, reconstruct the multi-hop redirect chain through a compromised legitimate site, uncover a secondary phishing wave against another employee, and confirm account takeover in Azure AD sign-in logs via impossible travel and session-token replay. You finish by choosing the containment action that actually evicts an attacker holding a valid session token. Foundational skills for SOC analysts in lookalike-domain analysis and identity-centric incident response.

20m·257 tasks
View Operation
ClickFix: The Fake CAPTCHA Trap

ClickFix: The Fake CAPTCHA Trap

The ClickFix social engineering technique uses dialogue boxes containing fake error messages to trick victims into copying, pasting, and running malicious content. In this scenario, a user was targeted with a 'Verify You Are Human' CAPTCHA check that led to a significant endpoint compromise. You will analyze the 'paste-and-run' execution chain, investigate PowerShell activity initiated via the Windows Run dialog, and identify the deployment of an information stealer.

20m·255 tasks
View Operation

Start Training Free

Create your free account and start investigating real-world attack scenarios. Track your progress, earn points, and build job-ready SOC analyst skills.

Get Started Free