
Overdue Invoice, Compromised Endpoint: Tracing a Finance Workstation Intrusion
A finance clerk at Brightwater Logistics worked through her inbox at her desk one Tuesday morning. Inside the hour her workstation, bwl-fin-wks-042, was running programs no accounts-payable machine has any business running and reaching hosts that have nothing to do with freight. You have the mail gateway records for her mailbox and the endpoint telemetry for that hour, and nothing else. Work the morning in order: establish what was delivered, what ran, what it left behind so that it would run again, and where it reported to.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Brief: a finance workstation that stopped behaving like one
0A finance clerk worked through her inbox this morning and, inside the hour, her workstation started producing endpoint events that no invoice review generates. Before you dig in, get oriented on how you are going to work it.
Establish what the message actually delivered
15The gateway logged every message that reached the clerk's mailbox that morning. One of them did not carry a document; its attachment was a container. Name what the gateway recorded inside that container, exactly as it was written down.
Trace what the first stage put on disk
15The program that ran next did not stay in memory. It decrypted a payload and put it on disk so that the next stage could be unpacked and run. Identify the file it created, by name.
Pin down how the malware survives a reboot
15Marcus on the helpdesk needs to know exactly what to strip out so the infection does not come back at the next logon. Something in the chain arranged for that. Identify the name of the registry value it created.
Identify where the host phoned home
15Once persistence was in place, the same process reached out to the internet. Two external endpoints were contacted within six minutes of each other. Identify the domain the host reached first.
Map the trigger to MITRE ATT&CK
10Step back and label how this attack actually fired. Everything you have traced so far, from the first execution through persistence to the callouts, hangs off one earlier event. More than one ATT&CK technique is visible in the recap. You want the one that describes the pivot itself: not the one that got the message into the mailbox, not the interpreter the pivot handed off to, and not the one that kept the chain alive across a logoff. Name it, down to the sub-technique.
6 tasks · 70 points total
Training Tools
Email Console
Email header & content analysis
SIEM Console
Log analysis & SPL queries
Skills You'll Build
Ideal for newcomers to SOC operations. Guided investigation with clear indicators.
Prerequisites
- No prior experience required
- Familiarity with Email concepts
- Familiarity with SIEM concepts
Ready to investigate?
More Operations
View allHijacked Discord Invite to ClickFix Loader: Tracing the Lure
A finance analyst at Halcyon Wealth Partners followed a recycled Discord invite that quietly redirected the browser to a fake verification page. They did what the page asked, and inside the hour the workstation was running a remote-access trojan alongside an info-stealer that shipped browser data straight out of the building. Walk the proxy, endpoint and firewall evidence step by step to trace the lure, the loader, the C2 beacon and the data theft.
Fake Window, Real Loss: Browser-in-the-Browser Steam Phishing
A Counter-Strike 2 player on the community team at Voltline Interactive clicks a phishing email offering a free in-game case from a well-known esports team. The link leads to a scam site that paints a fake browser pop-up, complete with a fake Steam URL bar, entirely in HTML. The victim types their Steam credentials into the fake window and cannot sign in minutes later. Walk the email gateway and proxy logs step by step, from the lure to the moment the password left the browser.
Weaponized SVG: Embedded Code in an Image Attachment
A treasury analyst at a bank opens what looks like a SWIFT payment confirmation, clicks the button inside it, and no document ever appears. Minutes later her workstation is running code out of her own user profile and holding an encrypted session to a host it has never contacted before. Walk the mail gateway, the file artifacts and the endpoint process tree step by step, from the delivery that started it to the beacon that followed.