Skip to main content
DPRK Fake IT Worker: Insider Access and Exfiltration operation cover
AdvancedSIEMCloudXDRPRO

DPRK Fake IT Worker: Insider Access and Exfiltration

A fraudulent remote software engineer embedded under a stolen identity gains network access on their first day and immediately begins collecting source code, architecture documentation and cloud secrets. The session originates entirely from a single hosting-range ASN, persists through AnyDesk and ngrok tunnels, and ends with a dual-channel exfiltration via Rclone and AzCopy. Reconstruct the full chain from Azure AD audit events, VPN and endpoint telemetry.

1h 25m
9 tasks
150 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Map the access origin

20

Every alert from this session points to an unusual source. Before tracing the operative's actions, establish where all the malicious connections originate at the network level.

Hint available
2

Name the identity pivot

20

Once inside Azure AD, the operative did not stop there. The cloud audit log shows access to source-code and documentation platforms that were not directly authenticated -- they inherited trust from the initial login.

Hint available
3

Track the remote-access implant

25

The operative did not rely solely on the VPN for continued access. The endpoint telemetry on the jump server shows a remote-access tool was installed silently from the SSH session -- giving the operator a channel that does not depend on the VPN tunnel staying open.

Hint available
4

Find the exfiltration endpoint

25

The operative staged repository archives locally and then transferred them off the network. Pinpoint the external address that received the bulk transfer.

Hint available
5

Identify the cloud staging account

25

In parallel with the endpoint-based exfil, the operative used a cloud transfer tool to upload a compressed source archive to an Azure storage account that does not belong to any known project. Identify that storage account name.

Hint available
6

Hash the exfil binary

30

One of the three unsigned binaries dropped to ProgramData was the tool responsible for the bulk exfiltration. Retrieve its SHA-256 hash from the endpoint telemetry.

Hint available
7

Correlate the impossible travel

30

One cloud alert flagged an impossible-travel event for the operative's account. Two sessions for the same account were authenticated from geographically inconsistent IPs within a window too short for legitimate travel. Identify the anomalous IP that triggered that alert.

Hint available
8

Expose the persistence tunnel

30

Beyond AnyDesk, the operative ran a second tunnel that routes incoming connections through an external cloud relay service. This tunnel survives VPN disconnection and lets the operator re-enter the network without re-authenticating to any corporate service. Identify the domain the tunnel connects to.

Hint available
9

Reconstruct the exfil path

35

The operator configured Rclone to transfer data to a named remote and a specific path on that remote. Both are visible in the command-line arguments in the process telemetry. Reproduce the full rclone destination argument exactly.

Hint available

9 tasks · 240 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
Cloud log analysis
XDR log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Advanced

Complex multi-stage investigations. Realistic noise, ambiguous indicators, lateral movement.

Prerequisites

  • Basic understanding of security alerts
  • Experience with log analysis tools
  • Familiarity with SIEM concepts
  • Familiarity with Cloud concepts
  • Familiarity with XDR concepts

Ready to investigate?

More Operations

View all
AdvancedSIEMXDR

Rhysida Ransomware: Healthcare Network Intrusion

A Rhysida ransomware affiliate phishes a healthcare staff member's VPN credentials and exploits a stale MFA exemption to breach a regional medical center. Using a Cobalt Strike beacon and built-in Windows tools, the attacker extracts all domain credentials, exfiltrates patient records for double extortion, and deploys the encryptor estate-wide. Trace the kill chain from the first failed VPN login to the final ransom note.

1h 30m150 pts
AdvancedSIEMXDR

UNC3886: vCenter RCE to ESXi Persistence (CVE-2023-34048)

Orbivex Aerospace runs its virtualisation estate on a vCenter Server appliance and three ESXi hypervisors, with the vCenter HTTPS management interface published to the internet. The platform team opened a ticket during the morning shift: the appliance had logged a management daemon terminating on a fatal signal and restarting, and the hypervisor integrity summary listed package and startup-file entries the change record does not account for. Work the vCenter, ESXi and firewall telemetry and establish what reached the estate, how it moved between the management plane and the hypervisors, and how far it got.

1h 20m150 pts
AdvancedSIEMFirewall

Salt Typhoon: Telecom Carrier Espionage

An Axiom Carrier Services edge router is behaving in ways its change record cannot explain: management sessions from addresses that should never reach it, a configuration change with no ticket behind it, and egress the estate never authorised. Work a full day of router syslog and perimeter firewall traffic and reconstruct what happened to the device, in order.

1h 30m150 pts