
Docker Hub Supply Chain: A Public Image on a Shared Build Runner
A platform engineer pulls a public Docker Hub image advertised as a network scanning utility onto a shared Linux build-runner. Hours later the host is still pinned at full CPU with its build queue drained, nothing deployed and no data alarms raised. Reconstruct what the image actually did on the host from endpoint XDR and perimeter firewall telemetry, and classify the key ATT&CK techniques.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Incident brief
0Orient yourself before pivoting into the data. This is a no-answer briefing checkpoint.
Identify the malicious image
45Every later event traces back to one image pulled to the build-runner that morning. Identify it by its full repository and tag reference.
Classify how the container itself was the attack
40The malicious code did not arrive as a dropped binary; it arrived as the image. Identify the MITRE ATT&CK technique for running attacker logic by deploying a container.
Name the miner process
40Inside the container, one process is doing the actual mining. Identify the miner by the name it ran as.
Recover the mining pool the miner connected to
45The miner held a long-lived session to a public pool. Identify the pool it mined to.
Classify the operator's objective
40Name what the whole intrusion was for. Classify the impact technique the miner represents.
Recover the attacker's wallet
45Pin down the indicator that ties this build host to the operator's earnings. Provide the Monero wallet address the miner submitted shares for.
7 tasks · 255 points total
Training Tools
Skills You'll Build
Requires foundational alert triage skills. Multiple data sources to correlate.
Prerequisites
- Basic understanding of security alerts
- Familiarity with XDR concepts
- Familiarity with Firewall concepts
Ready to investigate?
More Operations
View allHidden in the Pixels: LSB Steganography Exfil From an Infected Endpoint
A LummaC2/Vidar-style infostealer smash-and-grab. A finance analyst was tricked by a fake CAPTCHA (ClickFix) into pasting an mshta command into the Run box, which staged hidden PowerShell, downloaded the Lumma stealer, and harvested browser credentials, cookies, and wallet artifacts. To smuggle the loot out, the operator LSB-encoded the stolen blob into an oversized PNG and uploaded it to a public image host, off the command-and-control channel. Reconstruct the chain from SIEM and perimeter firewall telemetry and classify the key ATT&CK techniques.
Illicit OAuth App-Consent Grant: Entra ID Impersonation Campaign
A mass illicit OAuth app-consent campaign against a maritime logistics tenant. Operators register multitenant Entra apps impersonating trusted SaaS brands (iLSMART, Adobe, DocuSign, OneDrive-2025) and send brand-themed consent lures from compromised supplier accounts. Victims who click are screened by a Tycoon antibot redirector into an adversary-in-the-middle relay that proxies the real Entra sign-in, harvests the password, and intercepts the MFA-approved token. The replayed token completes user-level consent grants to the impersonation apps, which read mailboxes over Microsoft Graph, and the attacker registers a new MFA method for durable persistence. Work the Email lures and the Entra consent, sign-in, Graph, and security-info audit to reconstruct the chain.
Cookie Heist: AiTM Session Theft to Payment-Fraud BEC
An adversary-in-the-middle phishing intrusion that turns into payment fraud without any malware. A voicemail-themed email with an HTML attachment routes a finance analyst through a redirector to an Evilginx2 proxy, which relays her real Microsoft 365 sign-in and steals the post-MFA session cookie. The attacker replays the cookie from a foreign hosting IP, bypassing MFA, then reads her mailbox, creates an email-hiding inbox rule keyed on a vendor's domain, deletes the phishing mail, and replies inside a live invoice thread asking the vendor to wire payment to a new account. Work the Entra sign-in audit, the Exchange Online mailbox operations, and the email evidence to reconstruct the chain.