Skip to main content
Overdue Invoice, Compromised Endpoint: Tracing a Finance Workstation Intrusion operation cover
BeginnerEmailSIEM

Overdue Invoice, Compromised Endpoint: Tracing a Finance Workstation Intrusion

A finance clerk at Brightwater Logistics worked through her inbox at her desk one Tuesday morning. Inside the hour her workstation, bwl-fin-wks-042, was running programs no accounts-payable machine has any business running and reaching hosts that have nothing to do with freight. You have the mail gateway records for her mailbox and the endpoint telemetry for that hour, and nothing else. Work the morning in order: establish what was delivered, what ran, what it left behind so that it would run again, and where it reported to.

25m
6 tasks
25 points
Free

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Brief: a finance workstation that stopped behaving like one

0

A finance clerk worked through her inbox this morning and, inside the hour, her workstation started producing endpoint events that no invoice review generates. Before you dig in, get oriented on how you are going to work it.

2

Establish what the message actually delivered

15

The gateway logged every message that reached the clerk's mailbox that morning. One of them did not carry a document; its attachment was a container. Name what the gateway recorded inside that container, exactly as it was written down.

SOC{name.ext}Hint available
3

Trace what the first stage put on disk

15

The program that ran next did not stay in memory. It decrypted a payload and put it on disk so that the next stage could be unpacked and run. Identify the file it created, by name.

SOC{name.ext}Hint available
4

Pin down how the malware survives a reboot

15

Marcus on the helpdesk needs to know exactly what to strip out so the infection does not come back at the next logon. Something in the chain arranged for that. Identify the name of the registry value it created.

SOC{value-name}Hint available
5

Identify where the host phoned home

15

Once persistence was in place, the same process reached out to the internet. Two external endpoints were contacted within six minutes of each other. Identify the domain the host reached first.

SOC{domain.tld}Hint available
6

Map the trigger to MITRE ATT&CK

10

Step back and label how this attack actually fired. Everything you have traced so far, from the first execution through persistence to the callouts, hangs off one earlier event. More than one ATT&CK technique is visible in the recap. You want the one that describes the pivot itself: not the one that got the message into the mailbox, not the interpreter the pivot handed off to, and not the one that kept the chain alive across a logoff. Name it, down to the sub-technique.

SOC{Txxxx.xxx}Hint available

6 tasks · 70 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
Email log analysis
SIEM log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Beginner

Ideal for newcomers to SOC operations. Guided investigation with clear indicators.

Prerequisites

  • No prior experience required
  • Familiarity with Email concepts
  • Familiarity with SIEM concepts

Ready to investigate?

More Operations

View all
BeginnerSIEMFirewall

The Template That Read the Disk

The file-transfer portal that Tideglow Logistics' partners upload to spent a morning returning host files it was never meant to publish, and finished it running an administrator session nobody had logged into. The root cause is CVE-2024-4040 in CrushFTP 10.6.0. Walk the access logs and firewall traffic step by step to trace how a client holding no credentials turned a request parameter into a read of the host, and that read into a takeover.

25m25 pts
BeginnerEmailXDR

OneNote Attachment to RAT: A Guided First Investigation

A logistics contracts employee at Glacierline Freight opens an attachment that arrived in her inbox and clicks a button inside it. Minutes later her workstation is running something that appears on no software inventory and is talking to a host that no business process uses. Walk the email gateway records, the file artifacts and the endpoint process tree one step at a time, and work out for yourself which message carried the delivery, what landed on disk, and what ran.

15m25 pts
BeginnerSIEMFirewall

Hijacked Discord Invite to ClickFix Loader: Tracing the Lure

A finance analyst at Halcyon Wealth Partners followed a recycled Discord invite that quietly redirected the browser to a fake verification page. They did what the page asked, and inside the hour the workstation was running a remote-access trojan alongside an info-stealer that shipped browser data straight out of the building. Walk the proxy, endpoint and firewall evidence step by step to trace the lure, the loader, the C2 beacon and the data theft.

15m25 pts