
EvilProxy AiTM: Indeed Redirect to M365 Cookie Theft
An executive at a logistics firm clicks a job-themed phishing link that abuses a recruiting platform's open redirect to reach an EvilProxy adversary-in-the-middle page. The page reverse-proxies the real Microsoft 365 sign-in, so the victim completes MFA against the attacker, who captures and replays the post-MFA session cookie. Work the email, web-proxy, DNS, Entra sign-in, and perimeter records to reconstruct the redirect chain, the relay infrastructure, and the MFA bypass.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Open the case
0Identity Protection escalated an executive account at Calderwood Logistics Group: a successful Microsoft 365 sign-in that satisfied MFA but originated from a network that does not belong to the company. The email, web-proxy, DNS, Entra sign-in, and perimeter records for the day are in front of you. Read the brief, then work the timeline from the lure to the stolen session.
Identify the compromised account
15One account drives the entire anomaly: it received the lure, its session authenticated from outside the corporate estate, and its mailbox was modified. Working from the identity sign-in records and the mail trail, identify the user principal whose session was taken over.
Trace the delivery redirect
15The lure link did not point straight at a malicious site. It pointed at a trusted third-party platform that quietly forwarded the browser elsewhere, which is why URL reputation let the click through. Identify the host the victim's browser first contacted when the link was clicked.
Pin the adversary-in-the-middle landing
15After the redirect, the browser landed on a page that looked like the Microsoft 365 sign-in but was not hosted by Microsoft. That page is the reverse proxy that relayed the real login. Identify the landing domain the victim authenticated against.
Locate the relay behind the session
15The lookalike sign-in domain resolves to the reverse-proxy infrastructure that sat between the victim and Microsoft, and that same external address is where the authenticated session came from. Identify the external IP behind the adversary-in-the-middle session.
Name the interception technique
15The defining move here is that the attacker positioned infrastructure between the victim and the real service, relaying the entire sign-in so they could capture what flowed through. Map that to its MITRE ATT&CK technique.
Classify how MFA was defeated
15MFA was satisfied during the sign-in, yet the attacker kept access afterward without being challenged again. For the report, classify the credential-access technique that explains how the attacker retained the authenticated session. Provide its MITRE ATT&CK identifier.
7 tasks · 90 points total
Training Tools
Email Console
Email header & content analysis
SIEM Console
Log analysis & SPL queries
Firewall Console
Network traffic analysis
Skills You'll Build
Requires foundational alert triage skills. Multiple data sources to correlate.
Prerequisites
- Basic understanding of security alerts
- Familiarity with Email concepts
- Familiarity with SIEM concepts
- Familiarity with Firewall concepts
Ready to investigate?
More Operations
View allIDAT Loader: Fake Chrome Update to Stealer
A fake Chrome update page convinced an estimator their browser was out of date, and one installer later their saved passwords and wallet data were on their way to an unknown host. Follow the chain from a drive-by MSI through msiexec, a signed application side-loading the IDAT Loader, process injection, and StealC and Lumma infostealers to a single command-and-control endpoint.
Finding Gozi: An Italian Malspam Infection
An accounts clerk at an Italian textile firm clicked an overdue-invoice link, downloaded a ZIP, and opened an Internet shortcut that reached out over SMB to pull a second-stage loader. PowerShell and rundll32 ran the Gozi banking trojan, and the workstation began beaconing to a rotating list of bare IP-literal hosts over plain HTTP. Trace the chain from a link-based lure through an SMB stage-2 fetch to the single command-and-control endpoint the trojan settled on, where it also shipped the stolen data.
Lazarus: ManageEngine RCE to QuiteRAT Espionage
An internet-facing ManageEngine ServiceDesk Plus appliance at Caldermoor Networks, a regional network and internet service provider, falls to the unauthenticated SAML RCE (CVE-2022-47966). Code runs as the appliance service account, which curls down a QuiteRAT first-stage implant, profiles the host and domain, installs itself as an auto-start Windows service, and beacons to a single HTTPS C2 that carries control and stolen data alike before pulling a CollectionRAT second stage. Work the ManageEngine web logs, the endpoint process tree, and the perimeter egress to reconstruct the intrusion. North-Korea-nexus actor.