Skip to main content
ClickFix: The Fake CAPTCHA Trap operation cover
BeginnerSIEMXDRFirewall

ClickFix: The Fake CAPTCHA Trap

The ClickFix social engineering technique uses dialogue boxes containing fake error messages to trick victims into copying, pasting, and running malicious content. In this scenario, a user was targeted with a 'Verify You Are Human' CAPTCHA check that led to a significant endpoint compromise. You will analyze the 'paste-and-run' execution chain, investigate PowerShell activity initiated via the Windows Run dialog, and identify the deployment of an information stealer.

20m
5 tasks
25 points
Free

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

The ClickFix Trap

5

Before investigating the telemetry, understand HOW the attacker got their command to run. ClickFix never delivers a file the browser can block, so the command has to reach the Run dialog some other way. The endpoint agent recorded the page doing it. Read the telemetry below and name the Windows facility the page wrote the command into.

SOC{...}Hint available
2

Pinpoint the Loaded Malicious Library

10

You understand the ClickFix lure; now move to the endpoint. After the PowerShell command ran, the XDR file monitor on corp-wks-102 captured a burst of file activity, and one of those files is the malicious library that regasm.exe loaded into memory. Most entries are normal Windows and Office noise. Which file is the attacker's library?

SOC{...}Hint available
3

Trace the Payload Download to its Source IP

10

You have the malicious library; now find where it came from. The ClickFix PowerShell command pulled l6E.exe down from an external host before regasm.exe ever touched it. A domain name alone is not enough for a firewall block or a hunt across other hosts: you need the IP it resolved to. Review the SIEM network logs from corp-wks-102 and identify the server that delivered the payload.

SOC{...}Hint available
4

Unmask the Command-and-Control Destination

10

You know how the malware arrived and what it loaded. Now find where the stolen data went. After cleanuploader.exe read Anita's Chrome credential store, it opened an outbound channel that tries to look like normal Microsoft cloud traffic. Use the XDR process tree to place that process in the chain, then work the firewall logs to expose the true destination behind the disguise.

SOC{...}Hint available
5

Containment and Lessons Learned

5

You have reconstructed the entire ClickFix chain: lure, execution, the loaded library, the payload source, and the live C2 channel. The workstation is still online, still talking to the attacker, and carries a persistence key that will relaunch the malware. Review the summary and the persistence finding, then make the call: of the five containment actions offered, which one should you take FIRST?

SOC{...}Hint available

5 tasks · 40 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
XDR log analysis
Firewall log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Beginner

Ideal for newcomers to SOC operations. Guided investigation with clear indicators.

Prerequisites

  • No prior experience required
  • Familiarity with SIEM concepts
  • Familiarity with XDR concepts
  • Familiarity with Firewall concepts

Ready to investigate?

More Operations

View all
BeginnerSIEMFirewall

The Backdoored Browser Extension: Following the C2 Beacon

A routine Chrome auto-update silently trojanized a productivity extension on a finance workstation at Halverson Logistics. The extension beaconed to an attacker C2 domain, harvested the analyst's session cookies and an API token, and exfiltrated them to a VULTR-hosted server. With no malware on disk, the proxy and firewall logs are the only trail. Walk them step by step to trace the beacon, the theft, and the exfiltration.

25m25 pts
BeginnerSIEM

Credential Harvesting: The Lookalike Login

Investigate an adversary-in-the-middle (AiTM) credential phishing campaign that lured an employee to a lookalike Microsoft 365 login page. Working entirely from SIEM logs, you will identify the lookalike domain, reconstruct the multi-hop redirect chain through a compromised legitimate site, uncover a secondary phishing wave against another employee, and confirm account takeover in Azure AD sign-in logs via impossible travel and session-token replay. You finish by choosing the containment action that actually evicts an attacker holding a valid session token. Foundational skills for SOC analysts in lookalike-domain analysis and identity-centric incident response.

20m25 pts
BeginnerSIEM

QR Code Phishing: Scan to Compromise

In this scenario, you will investigate a modern 'Quishing' (QR phishing) attack that bypassed traditional email filters by hiding its payload inside an image. You will trace the full chain: a spoofed MFA-enrollment lure sent from purpose-built infrastructure, a redirect server that conceals the final destination, and an Evilginx-style adversary-in-the-middle page that stole an authenticated session cookie despite MFA. You will then follow the attacker's post-compromise moves (Graph API mailbox enumeration, SharePoint exfiltration, and a hidden inbox forwarding rule) and choose the containment action that actually evicts them.

15m25 pts