Skip to main content
EvilProxy AiTM: Indeed Redirect to M365 Cookie Theft operation cover
IntermediateEmailSIEMFirewall

EvilProxy AiTM: Indeed Redirect to M365 Cookie Theft

An executive at a logistics firm clicks a job-themed phishing link that abuses a recruiting platform's open redirect to reach an EvilProxy adversary-in-the-middle page. The page reverse-proxies the real Microsoft 365 sign-in, so the victim completes MFA against the attacker, who captures and replays the post-MFA session cookie. Work the email, web-proxy, DNS, Entra sign-in, and perimeter records to reconstruct the redirect chain, the relay infrastructure, and the MFA bypass.

45m
7 tasks
50 points
Free

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Open the case

0

Identity Protection escalated an executive account at Calderwood Logistics Group: a successful Microsoft 365 sign-in that satisfied MFA but originated from a network that does not belong to the company. The email, web-proxy, DNS, Entra sign-in, and perimeter records for the day are in front of you. Read the brief, then work the timeline from the lure to the stolen session.

2

Identify the compromised account

15

One account drives the entire anomaly: it received the lure, its session authenticated from outside the corporate estate, and its mailbox was modified. Working from the identity sign-in records and the mail trail, identify the user principal whose session was taken over.

SOC{user@domain.tld}Hint available
3

Trace the delivery redirect

15

The lure link did not point straight at a malicious site. It pointed at a trusted third-party platform that quietly forwarded the browser elsewhere, which is why URL reputation let the click through. Identify the host the victim's browser first contacted when the link was clicked.

SOC{host.domain.tld}Hint available
4

Pin the adversary-in-the-middle landing

15

After the redirect, the browser landed on a page that looked like the Microsoft 365 sign-in but was not hosted by Microsoft. That page is the reverse proxy that relayed the real login. Identify the landing domain the victim authenticated against.

SOC{host.domain.tld}Hint available
5

Locate the relay behind the session

15

The lookalike sign-in domain resolves to the reverse-proxy infrastructure that sat between the victim and Microsoft, and that same external address is where the authenticated session came from. Identify the external IP behind the adversary-in-the-middle session.

SOC{a.b.c.d}Hint available
6

Name the interception technique

15

The defining move here is that the attacker positioned infrastructure between the victim and the real service, relaying the entire sign-in so they could capture what flowed through. Map that to its MITRE ATT&CK technique.

SOC{Txxxx}Hint available
7

Classify how MFA was defeated

15

MFA was satisfied during the sign-in, yet the attacker kept access afterward without being challenged again. For the report, classify the credential-access technique that explains how the attacker retained the authenticated session. Provide its MITRE ATT&CK identifier.

SOC{Txxxx}Hint available

7 tasks · 90 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
Email log analysis
SIEM log analysis
Firewall log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Intermediate

Requires foundational alert triage skills. Multiple data sources to correlate.

Prerequisites

  • Basic understanding of security alerts
  • Familiarity with Email concepts
  • Familiarity with SIEM concepts
  • Familiarity with Firewall concepts

Ready to investigate?

More Operations

View all
IntermediateSIEMXDR

IDAT Loader: Fake Chrome Update to Stealer

A fake Chrome update page convinced an estimator their browser was out of date, and one installer later their saved passwords and wallet data were on their way to an unknown host. Follow the chain from a drive-by MSI through msiexec, a signed application side-loading the IDAT Loader, process injection, and StealC and Lumma infostealers to a single command-and-control endpoint.

1h50 pts
IntermediateSIEMFirewall

Finding Gozi: An Italian Malspam Infection

An accounts clerk at an Italian textile firm clicked an overdue-invoice link, downloaded a ZIP, and opened an Internet shortcut that reached out over SMB to pull a second-stage loader. PowerShell and rundll32 ran the Gozi banking trojan, and the workstation began beaconing to a rotating list of bare IP-literal hosts over plain HTTP. Trace the chain from a link-based lure through an SMB stage-2 fetch to the single command-and-control endpoint the trojan settled on, where it also shipped the stolen data.

50m50 pts
IntermediateSIEMXDR

Lazarus: ManageEngine RCE to QuiteRAT Espionage

An internet-facing ManageEngine ServiceDesk Plus appliance at Caldermoor Networks, a regional network and internet service provider, falls to the unauthenticated SAML RCE (CVE-2022-47966). Code runs as the appliance service account, which curls down a QuiteRAT first-stage implant, profiles the host and domain, installs itself as an auto-start Windows service, and beacons to a single HTTPS C2 that carries control and stolen data alike before pulling a CollectionRAT second stage. Work the ManageEngine web logs, the endpoint process tree, and the perimeter egress to reconstruct the intrusion. North-Korea-nexus actor.

55m50 pts