Skip to main content
Overdue Invoice, Compromised Endpoint: Tracing a Finance Workstation Intrusion operation cover
BeginnerEmailSIEM

Overdue Invoice, Compromised Endpoint: Tracing a Finance Workstation Intrusion

A finance clerk at Brightwater Logistics worked through her inbox at her desk one Tuesday morning. Inside the hour her workstation, bwl-fin-wks-042, was running programs no accounts-payable machine has any business running and reaching hosts that have nothing to do with freight. You have the mail gateway records for her mailbox and the endpoint telemetry for that hour, and nothing else. Work the morning in order: establish what was delivered, what ran, what it left behind so that it would run again, and where it reported to.

25m
6 tasks
25 points
Free

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Brief: a finance workstation that stopped behaving like one

0

A finance clerk worked through her inbox this morning and, inside the hour, her workstation started producing endpoint events that no invoice review generates. Before you dig in, get oriented on how you are going to work it.

2

Establish what the message actually delivered

15

The gateway logged every message that reached the clerk's mailbox that morning. One of them did not carry a document; its attachment was a container. Name what the gateway recorded inside that container, exactly as it was written down.

SOC{name.ext}Hint available
3

Trace what the first stage put on disk

15

The program that ran next did not stay in memory. It decrypted a payload and put it on disk so that the next stage could be unpacked and run. Identify the file it created, by name.

SOC{name.ext}Hint available
4

Pin down how the malware survives a reboot

15

Marcus on the helpdesk needs to know exactly what to strip out so the infection does not come back at the next logon. Something in the chain arranged for that. Identify the name of the registry value it created.

SOC{value-name}Hint available
5

Identify where the host phoned home

15

Once persistence was in place, the same process reached out to the internet. Two external endpoints were contacted within six minutes of each other. Identify the domain the host reached first.

SOC{domain.tld}Hint available
6

Map the trigger to MITRE ATT&CK

10

Step back and label how this attack actually fired. Everything you have traced so far, from the first execution through persistence to the callouts, hangs off one earlier event. More than one ATT&CK technique is visible in the recap. You want the one that describes the pivot itself: not the one that got the message into the mailbox, not the interpreter the pivot handed off to, and not the one that kept the chain alive across a logoff. Name it, down to the sub-technique.

SOC{Txxxx.xxx}Hint available

6 tasks · 70 points total

Training Tools

Email Console

Email header & content analysis

SIEM Console

Log analysis & SPL queries

Skills You'll Build

Investigate realistic security alerts
Email log analysis
SIEM log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Beginner

Ideal for newcomers to SOC operations. Guided investigation with clear indicators.

Prerequisites

  • No prior experience required
  • Familiarity with Email concepts
  • Familiarity with SIEM concepts

Ready to investigate?

More Operations

View all
BeginnerSIEMFirewall

Hijacked Discord Invite to ClickFix Loader: Tracing the Lure

A finance analyst at Halcyon Wealth Partners followed a recycled Discord invite that quietly redirected the browser to a fake verification page. They did what the page asked, and inside the hour the workstation was running a remote-access trojan alongside an info-stealer that shipped browser data straight out of the building. Walk the proxy, endpoint and firewall evidence step by step to trace the lure, the loader, the C2 beacon and the data theft.

15m25 pts
BeginnerEmailSIEM

Fake Window, Real Loss: Browser-in-the-Browser Steam Phishing

A Counter-Strike 2 player on the community team at Voltline Interactive clicks a phishing email offering a free in-game case from a well-known esports team. The link leads to a scam site that paints a fake browser pop-up, complete with a fake Steam URL bar, entirely in HTML. The victim types their Steam credentials into the fake window and cannot sign in minutes later. Walk the email gateway and proxy logs step by step, from the lure to the moment the password left the browser.

25m25 pts
BeginnerEmailXDR

Weaponized SVG: Embedded Code in an Image Attachment

A treasury analyst at a bank opens what looks like a SWIFT payment confirmation, clicks the button inside it, and no document ever appears. Minutes later her workstation is running code out of her own user profile and holding an encrypted session to a host it has never contacted before. Walk the mail gateway, the file artifacts and the endpoint process tree step by step, from the delivery that started it to the beacon that followed.

25m25 pts