Skip to main content
Cookie Heist: AiTM Session Theft to Payment-Fraud BEC operation cover
IntermediateEmailSIEMCloudPRO

Cookie Heist: AiTM Session Theft to Payment-Fraud BEC

An adversary-in-the-middle phishing intrusion that turns into payment fraud without any malware. A voicemail-themed email with an HTML attachment routes a finance analyst through a redirector to an Evilginx2 proxy, which relays her real Microsoft 365 sign-in and steals the post-MFA session cookie. The attacker replays the cookie from a foreign hosting IP, bypassing MFA, then reads her mailbox, creates an email-hiding inbox rule keyed on a vendor's domain, deletes the phishing mail, and replies inside a live invoice thread asking the vendor to wire payment to a new account. Work the Entra sign-in audit, the Exchange Online mailbox operations, and the email evidence to reconstruct the chain.

50m
7 tasks
50 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Incident brief

0

Orient yourself before pivoting into the data. This is a no-answer briefing checkpoint.

2

Locate the compromised identity

35

One cloud account signed in twice within minutes, once normally and once from abroad. Identify the account that was taken over.

Hint available
3

Pin the cookie-replay source

35

The MFA bypass came from reusing a stolen session, not a password. Identify the external IP that replayed the session cookie.

Hint available
4

Find the email-hiding inbox rule

35

The attacker hid the vendor's replies so the fraud could proceed. Identify the sender domain the malicious inbox rule keys on.

Hint available
5

Recover the fraudulent account details

30

The attacker's end goal was a redirected wire. Identify the IBAN inserted into the vendor invoice thread.

Hint available
6

Classify the MFA-bypass technique

35

Name how the attacker defeated MFA. Map the stolen, replayed session to its MITRE ATT&CK technique.

Hint available
7

Classify the email-hiding technique

35

Name what the inbox rule was for. Map the rule that buries the vendor's replies to its MITRE ATT&CK technique.

Hint available

7 tasks · 205 points total

Training Tools

Email Console

Email header & content analysis

SIEM Console

Log analysis & SPL queries

Cloud Console

Cloud infrastructure logs

Skills You'll Build

Investigate realistic security alerts
Email log analysis
SIEM log analysis
Cloud log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Intermediate

Requires foundational alert triage skills. Multiple data sources to correlate.

Prerequisites

  • Basic understanding of security alerts
  • Familiarity with Email concepts
  • Familiarity with SIEM concepts
  • Familiarity with Cloud concepts

Ready to investigate?

More Operations

View all
IntermediateXDRFirewall

Docker Hub Supply Chain: A Public Image on a Shared Build Runner

A platform engineer pulls a public Docker Hub image advertised as a network scanning utility onto a shared Linux build-runner. Hours later the host is still pinned at full CPU with its build queue drained, nothing deployed and no data alarms raised. Reconstruct what the image actually did on the host from endpoint XDR and perimeter firewall telemetry, and classify the key ATT&CK techniques.

40m50 pts
IntermediateSIEMFirewall

GoldPickaxe: The First iOS Trojan Stealing Your Face

A mobile-first intrusion against a retail bank's managed iPhone fleet. A relationship officer is socially engineered into installing a fake government app through Apple TestFlight and trusting a rogue MDM profile, handing GoldFactory full control of the device. The GoldPickaxe.iOS trojan harvests identity documents and a facial-recognition video, intercepts SMS, and exfiltrates over three split channels: an RSA-encrypted HTTP API, a WebSocket command channel, and an RTMP face-video stream, all to enable AI face-swap fraud against the bank's facial verification. Reconstruct the chain from mobile-threat-defense, MDM, and perimeter firewall telemetry.

45m50 pts
IntermediateXDRSIEM

Trusted Tool, Hostile Hands: Atera RMM Foothold

A phishing-delivered intrusion that weaponized a legitimate remote-monitoring tool instead of custom malware. A finance analyst was lured by a grant-program email whose link pointed at a file-sharing platform; the download was an MSI that silently installed the Atera agent, registered the endpoint to an attacker-controlled tenant, persisted as a Windows service, and beaconed to Atera's cloud over HTTPS. From the vendor console the operator ran PowerShell discovery and staged a follow-on implant, all over trusted infrastructure. Reconstruct the chain from email, SIEM, and endpoint XDR telemetry and classify the key ATT&CK techniques.

55m50 pts