Skip to main content
Edge Device Exploitation: VPN Zero-Day operation cover
IntermediateSIEMXDRFirewall

Edge Device Exploitation: VPN Zero-Day

Investigate a breach targeting exposed edge security appliances. In this scenario, an attacker exploits Ivanti Connect Secure CVE-2025-22457 to obtain unauthenticated code execution, spawns a shell from the gateway web process, retrieves a Linux payload, and attempts to preserve access using edge-device service abuse patterns similar to FortiGate SSL-VPN post-exploitation tradecraft. Analyze SIEM, XDR, and firewall evidence to identify the spawned shell, suspicious domain, local sync script, and defensive block policy.

55m
8 tasks
50 points
Free

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Pinpointing the Sensor That Paged the SOC

5

Your shift opens with a perimeter security alert: an exploit attempt was flagged against the internet-facing gateway corp-ivnt-gw-01 from an external IP. Before tracing the attacker, establish provenance; pivot to the SIEM panel, locate the exploit-detection event, and determine which internal monitoring system raised it (the value recorded in its log source field).

SOC{...}Hint available
2

Confirming Code Execution on the Gateway

10

With the detecting sensor confirmed, pivot to what the exploit actually achieved. During the gateway compromise the exposed web service was driven to spawn a process it should never launch, a clear sign the adversary obtained command execution. Work the XDR process hierarchy for corp-ivnt-gw-01 and identify the name of that anomalous child process.

SOC{...}Hint available
3

Recovering the Implant Staged on the Gateway

5

Having confirmed the interpreter the exploit spawned, follow what it did next. That process reached out to external infrastructure and wrote a file to the gateway's disk: the attacker's first-stage implant. Using the XDR file artifacts and the suspicious process command line on corp-ivnt-gw-01, identify the exact filename written to disk.

SOC{...}Hint available
4

Identifying the Implant's Callback Host

5

The implant on the gateway did not act alone; shortly after it landed, an outbound HTTP request left the environment toward attacker-controlled infrastructure. A SIEM network-proxy event was flagged high severity against the usual informational noise. Inspect that flagged proxy event and determine the external domain the internal host tried to reach.

SOC{...}Hint available
5

Crediting the Control That Stopped the Callback

10

You now know where the gateway implant tried to phone home. The good news: the perimeter held. When the gateway shell attempted a follow-up connection back to that same external host, an automated firewall policy denied the session. Inspect the firewall panel, locate the blocked outbound session, and name the defensive policy that stopped it.

SOC{...}Hint available
6

Hunting the Attacker's Foothold on the Gateway

5

Containment bought time, but an adversary who exploited the gateway will try to survive a reboot. An alert fired for potential persistence on corp-ivnt-gw-01: the init system was seen spawning a long-running service process that should not be a direct child of init. Examine the XDR process hierarchy for the gateway and submit the full command line used to launch that persistent service.

SOC{...}Hint available
7

Tracing the Pivot Onto the LDAP Server

5

With the gateway foothold mapped, widen the scope inward. During host triage of the directory server srv-ldap-01, a root cron entry was found running a local shell script shortly after the edge-device compromise, a likely lateral-movement or staging step deeper in the network. Review the relevant SIEM cron message and identify the name of the script that was executed.

SOC{...}Hint available
8

Resolving the Follow-On Activity on the DevOps Workstation

5

The investigation's final thread leads off the perimeter and onto an internal endpoint. Several days after the gateway was compromised, follow-on activity surfaced on the developer workstation wks-devops-01: an operator launched a PowerShell script tied to edge-configuration work. Walk the XDR process ancestry back to that PowerShell execution and determine the exact filename of the script that was run.

SOC{...}Hint available

8 tasks · 50 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
XDR log analysis
Firewall log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Intermediate

Requires foundational alert triage skills. Multiple data sources to correlate.

Prerequisites

  • Basic understanding of security alerts
  • Familiarity with SIEM concepts
  • Familiarity with XDR concepts
  • Familiarity with Firewall concepts

Ready to investigate?

More Operations

View all
BeginnerSIEMFirewall

The Template That Read the Disk

The file-transfer portal that Tideglow Logistics' partners upload to spent a morning returning host files it was never meant to publish, and finished it running an administrator session nobody had logged into. The root cause is CVE-2024-4040 in CrushFTP 10.6.0. Walk the access logs and firewall traffic step by step to trace how a client holding no credentials turned a request parameter into a read of the host, and that read into a takeover.

25m25 pts
BeginnerEmailXDR

OneNote Attachment to RAT: A Guided First Investigation

A logistics contracts employee at Glacierline Freight opens an attachment that arrived in her inbox and clicks a button inside it. Minutes later her workstation is running something that appears on no software inventory and is talking to a host that no business process uses. Walk the email gateway records, the file artifacts and the endpoint process tree one step at a time, and work out for yourself which message carried the delivery, what landed on disk, and what ran.

15m25 pts
BeginnerSIEMFirewall

Hijacked Discord Invite to ClickFix Loader: Tracing the Lure

A finance analyst at Halcyon Wealth Partners followed a recycled Discord invite that quietly redirected the browser to a fake verification page. They did what the page asked, and inside the hour the workstation was running a remote-access trojan alongside an info-stealer that shipped browser data straight out of the building. Walk the proxy, endpoint and firewall evidence step by step to trace the lure, the loader, the C2 beacon and the data theft.

15m25 pts