Skip to main content
Docker Hub Supply Chain: A Public Image on a Shared Build Runner operation cover
IntermediateXDRFirewallPRO

Docker Hub Supply Chain: A Public Image on a Shared Build Runner

A platform engineer pulls a public Docker Hub image advertised as a network scanning utility onto a shared Linux build-runner. Hours later the host is still pinned at full CPU with its build queue drained, nothing deployed and no data alarms raised. Reconstruct what the image actually did on the host from endpoint XDR and perimeter firewall telemetry, and classify the key ATT&CK techniques.

40m
7 tasks
50 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Incident brief

0

Orient yourself before pivoting into the data. This is a no-answer briefing checkpoint.

2

Identify the malicious image

45

Every later event traces back to one image pulled to the build-runner that morning. Identify it by its full repository and tag reference.

Hint available
3

Classify how the container itself was the attack

40

The malicious code did not arrive as a dropped binary; it arrived as the image. Identify the MITRE ATT&CK technique for running attacker logic by deploying a container.

Hint available
4

Name the miner process

40

Inside the container, one process is doing the actual mining. Identify the miner by the name it ran as.

Hint available
5

Recover the mining pool the miner connected to

45

The miner held a long-lived session to a public pool. Identify the pool it mined to.

Hint available
6

Classify the operator's objective

40

Name what the whole intrusion was for. Classify the impact technique the miner represents.

Hint available
7

Recover the attacker's wallet

45

Pin down the indicator that ties this build host to the operator's earnings. Provide the Monero wallet address the miner submitted shares for.

Hint available

7 tasks · 255 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
XDR log analysis
Firewall log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Intermediate

Requires foundational alert triage skills. Multiple data sources to correlate.

Prerequisites

  • Basic understanding of security alerts
  • Familiarity with XDR concepts
  • Familiarity with Firewall concepts

Ready to investigate?

More Operations

View all
IntermediateSIEMFirewall

Hidden in the Pixels: LSB Steganography Exfil From an Infected Endpoint

A LummaC2/Vidar-style infostealer smash-and-grab. A finance analyst was tricked by a fake CAPTCHA (ClickFix) into pasting an mshta command into the Run box, which staged hidden PowerShell, downloaded the Lumma stealer, and harvested browser credentials, cookies, and wallet artifacts. To smuggle the loot out, the operator LSB-encoded the stolen blob into an oversized PNG and uploaded it to a public image host, off the command-and-control channel. Reconstruct the chain from SIEM and perimeter firewall telemetry and classify the key ATT&CK techniques.

30m50 pts
IntermediateCloudEmail

Illicit OAuth App-Consent Grant: Entra ID Impersonation Campaign

A mass illicit OAuth app-consent campaign against a maritime logistics tenant. Operators register multitenant Entra apps impersonating trusted SaaS brands (iLSMART, Adobe, DocuSign, OneDrive-2025) and send brand-themed consent lures from compromised supplier accounts. Victims who click are screened by a Tycoon antibot redirector into an adversary-in-the-middle relay that proxies the real Entra sign-in, harvests the password, and intercepts the MFA-approved token. The replayed token completes user-level consent grants to the impersonation apps, which read mailboxes over Microsoft Graph, and the attacker registers a new MFA method for durable persistence. Work the Email lures and the Entra consent, sign-in, Graph, and security-info audit to reconstruct the chain.

40m50 pts
IntermediateEmailSIEM

Cookie Heist: AiTM Session Theft to Payment-Fraud BEC

An adversary-in-the-middle phishing intrusion that turns into payment fraud without any malware. A voicemail-themed email with an HTML attachment routes a finance analyst through a redirector to an Evilginx2 proxy, which relays her real Microsoft 365 sign-in and steals the post-MFA session cookie. The attacker replays the cookie from a foreign hosting IP, bypassing MFA, then reads her mailbox, creates an email-hiding inbox rule keyed on a vendor's domain, deletes the phishing mail, and replies inside a live invoice thread asking the vendor to wire payment to a new account. Work the Entra sign-in audit, the Exchange Online mailbox operations, and the email evidence to reconstruct the chain.

50m50 pts