
DPRK Fake IT Worker: Insider Access and Exfiltration
A fraudulent remote software engineer embedded under a stolen identity gains network access on their first day and immediately begins collecting source code, architecture documentation and cloud secrets. The session originates entirely from a single hosting-range ASN, persists through AnyDesk and ngrok tunnels, and ends with a dual-channel exfiltration via Rclone and AzCopy. Reconstruct the full chain from Azure AD audit events, VPN and endpoint telemetry.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Map the access origin
20Every alert from this session points to an unusual source. Before tracing the operative's actions, establish where all the malicious connections originate at the network level.
Name the identity pivot
20Once inside Azure AD, the operative did not stop there. The cloud audit log shows access to source-code and documentation platforms that were not directly authenticated -- they inherited trust from the initial login.
Track the remote-access implant
25The operative did not rely solely on the VPN for continued access. The endpoint telemetry on the jump server shows a remote-access tool was installed silently from the SSH session -- giving the operator a channel that does not depend on the VPN tunnel staying open.
Find the exfiltration endpoint
25The operative staged repository archives locally and then transferred them off the network. Pinpoint the external address that received the bulk transfer.
Identify the cloud staging account
25In parallel with the endpoint-based exfil, the operative used a cloud transfer tool to upload a compressed source archive to an Azure storage account that does not belong to any known project. Identify that storage account name.
Hash the exfil binary
30One of the three unsigned binaries dropped to ProgramData was the tool responsible for the bulk exfiltration. Retrieve its SHA-256 hash from the endpoint telemetry.
Correlate the impossible travel
30One cloud alert flagged an impossible-travel event for the operative's account. Two sessions for the same account were authenticated from geographically inconsistent IPs within a window too short for legitimate travel. Identify the anomalous IP that triggered that alert.
Expose the persistence tunnel
30Beyond AnyDesk, the operative ran a second tunnel that routes incoming connections through an external cloud relay service. This tunnel survives VPN disconnection and lets the operator re-enter the network without re-authenticating to any corporate service. Identify the domain the tunnel connects to.
Reconstruct the exfil path
35The operator configured Rclone to transfer data to a named remote and a specific path on that remote. Both are visible in the command-line arguments in the process telemetry. Reproduce the full rclone destination argument exactly.
9 tasks · 240 points total
Training Tools
SIEM Console
Log analysis & SPL queries
Cloud Console
Cloud infrastructure logs
XDR Console
Endpoint detection & response
Skills You'll Build
Complex multi-stage investigations. Realistic noise, ambiguous indicators, lateral movement.
Prerequisites
- Basic understanding of security alerts
- Experience with log analysis tools
- Familiarity with SIEM concepts
- Familiarity with Cloud concepts
- Familiarity with XDR concepts
Ready to investigate?
More Operations
View allRhysida Ransomware: Healthcare Network Intrusion
A Rhysida ransomware affiliate phishes a healthcare staff member's VPN credentials and exploits a stale MFA exemption to breach a regional medical center. Using a Cobalt Strike beacon and built-in Windows tools, the attacker extracts all domain credentials, exfiltrates patient records for double extortion, and deploys the encryptor estate-wide. Trace the kill chain from the first failed VPN login to the final ransom note.
UNC3886: vCenter RCE to ESXi Persistence (CVE-2023-34048)
Orbivex Aerospace runs its virtualisation estate on a vCenter Server appliance and three ESXi hypervisors, with the vCenter HTTPS management interface published to the internet. The platform team opened a ticket during the morning shift: the appliance had logged a management daemon terminating on a fatal signal and restarting, and the hypervisor integrity summary listed package and startup-file entries the change record does not account for. Work the vCenter, ESXi and firewall telemetry and establish what reached the estate, how it moved between the management plane and the hypervisors, and how far it got.
Salt Typhoon: Telecom Carrier Espionage
An Axiom Carrier Services edge router is behaving in ways its change record cannot explain: management sessions from addresses that should never reach it, a configuration change with no ticket behind it, and egress the estate never authorised. Work a full day of router syslog and perimeter firewall traffic and reconstruct what happened to the device, in order.