Skip to main content
The Template That Read the Disk operation cover
BeginnerSIEMFirewall

The Template That Read the Disk

The file-transfer portal that Tideglow Logistics' partners upload to spent a morning returning host files it was never meant to publish, and finished it running an administrator session nobody had logged into. The root cause is CVE-2024-4040 in CrushFTP 10.6.0. Walk the access logs and firewall traffic step by step to trace how a client holding no credentials turned a request parameter into a read of the host, and that read into a takeover.

25m
6 tasks
25 points
Free

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Brief: when a file server reads its own secrets

0

The file-transfer portal our partners upload to started serving files that have nothing to do with file transfer this morning. Before tracing it, get oriented on the class of flaw you are about to walk through.

2

Spot the template-injection payload

20

Several requests that morning were not asking for files the portal owns. One of them actually read a file off the host. Find it in the access log and submit the exact string that was placed in that request's path parameter.

SOC{<TAG>/path</TAG>}Hint available
3

Find the file that gave up the session tokens

15

Reading a host file proved the attacker could reach outside the portal's own area. The next read went after something far more useful to them. Name the file that was pulled.

SOC{filename.ext}Hint available
4

Trace where the admin session was replayed from

15

Not every request that morning came from the same place. Submit the address that was using the stolen session.

SOC{a.b.c.d}Hint available
5

Name the account the attacker became

10

Once the stolen session was replayed, the portal itself answered the question of whose session it was. Read the evidence and name that account.

SOC{username}Hint available
6

Map the initial access to MITRE ATT&CK

10

Step back from the individual requests and label how the attacker first got in. Give the ATT&CK technique ID for that first step.

SOC{Txxxx}Hint available

6 tasks · 70 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
Firewall log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Beginner

Ideal for newcomers to SOC operations. Guided investigation with clear indicators.

Prerequisites

  • No prior experience required
  • Familiarity with SIEM concepts
  • Familiarity with Firewall concepts

Ready to investigate?

More Operations

View all
BeginnerSIEMFirewall

QakBot bb02: Trace the Loader DLL to its C2

A purchasing coordinator opened a phishing email, downloaded a password-protected archive, and ran a shortcut on the disk image hidden inside it. A signed Windows utility quietly registered a QakBot DLL, and the workstation started beaconing to addresses nobody recognized. Trace the bb02 wave from a phishing link through an ISO and the loader DLL handoff to the single TLS command-and-control endpoint the bot settled on.

30m25 pts
BeginnerSIEMFirewall

FluBot: The Parcel-Delivery Text That Spreads Itself

A managed Android handset at Larkfield Mutual is infected by FluBot after the employee taps a smishing SMS impersonating a DHL parcel-delivery notice. The fake tracking page talks the user into installing an app and granting it Accessibility and SMS permissions; from there the trojan turns the phone into a sender, harvesting the contact list, texting the same lure onward and intercepting bank 2FA codes, while keeping a command channel the perimeter firewall never blocked. Walk the mobile telemetry and firewall logs step by step to trace the lure, the sideload, the contact theft, the SMS worm, and the hidden C2.

15m25 pts
BeginnerSIEMFirewall

Exposed .git Folder: Scanning the Web for Secrets

A public web server at Larkspur Logistics was deployed straight from a git checkout, leaving its .git directory exposed to the Internet. Following the EMERALDWHALE playbook, an attacker pulled /.git/config, stole the GitHub token baked into the clone URL, cloned the private repository, and found a hard-coded AWS key inside that handed them the cloud account. Walk the access, GitHub, and CloudTrail logs step by step to trace one misconfiguration into a full credential-theft chain.

25m25 pts