
Night Shift at Veridian Specialty Chemicals
Veridian Specialty Chemicals runs one Windows domain from one site: an on-premises Exchange server in the DMZ, a domain controller, and a file, backup and SQL tier that carry the plant's process data. Between the small hours and the end of the following evening the estate logged work nobody rostered. A perimeter sensor fired against the mail host. Files appeared on servers where installers never run. Administrative sessions arrived from the wrong direction. A long outbound transfer left the server tier on a port nobody watches. None of it was escalated overnight. Work the SIEM event log, the XDR process telemetry and the perimeter firewall records, and establish what reached the estate, what it took with it, and what it left behind.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Identify the first file the Exchange host should not have written
40The Exchange server is behaving strangely. A perimeter sensor registered an anomaly against the OWA endpoint in the early hours, and endpoint logs show a file appearing where application binaries have no business writing. Establish the filename of that file.
Confirm what was staged on the domain controller
45After execution began on Exchange, activity moved to the domain controller. XDR process telemetry on that host shows a binary staged under ProgramData opening a protected system process. Confirm the SHA-256 of that binary.
Identify the account used to spread across the estate
40With domain credentials in hand, the operator moved from the domain controller to every high-value server. Pinpoint the domain account that appears across the RDP logon events on the file, backup and SQL servers in that window.
Locate where the audit trail was erased
35One host had its Windows Security event log cleared during the intrusion. Determine which host the log-clear event (Windows Security event 1102) was recorded on.
Confirm the destination of the bulk outbound transfer
40A large volume of data left the file server in a short window. The firewall recorded multiple large simultaneous outbound flows from that host. Identify the external IP address that received it.
Map the pre-impact activity on the domain controller to ATT&CK
35In the minutes before the file-rename burst on the share, two native Windows utilities ran on the domain controller. Find them, read their arguments, and give the ATT&CK technique id that the pair maps to.
Reconstruct the initial-access technique
35Establish how the operator got their first execution on the Exchange host, then give the ATT&CK technique id for that initial access.
Classify the process-access step on the domain controller
40Find the credential-access step on the domain controller and give the ATT&CK sub-technique id for it.
Classify the terminal action on the file server
40Find the terminal action on the file server and give the ATT&CK technique id for it.
9 tasks · 350 points total
Training Tools
Skills You'll Build
Complex multi-stage investigations. Realistic noise, ambiguous indicators, lateral movement.
Prerequisites
- Basic understanding of security alerts
- Experience with log analysis tools
- Familiarity with SIEM concepts
- Familiarity with XDR concepts
- Familiarity with Firewall concepts
Ready to investigate?
More Operations
View allCactus Ransomware: Qlik Sense Exploitation
An internet-facing Qlik Sense analytics server is exploited and turned into the launch point for a Cactus ransomware intrusion. Within a day the operator persists with a rogue remote-access agent, dumps domain-admin credentials from memory, pivots by RDP to the domain controller and backup servers, steals engineering data to cloud storage, and deploys ransomware. Work the Qlik web logs, the endpoint process tree and the perimeter traffic to reconstruct the intrusion end to end and tell the abuse apart from a heavy baseline of normal analytics and remote-access activity.
Sandworm: Trojanized KMS Activator to DcRAT
A staff member at the energy provider Ridna Energo downloaded a free Microsoft KMS activation tool that turned out to be trojanized. Within minutes it dropped the BACKORDER loader, disabled Defender, proxy-loaded the DcRAT implant through rundll32, and opened an encrypted channel to a single anonymizing C2 node. Reconstruct the full espionage intrusion, from the lure download through credential theft, lateral movement, and exfiltration over command-and-control, across endpoint, network, and perimeter telemetry.
Cobalt Strike and SOCKS: 11 Days to LockBit
An eleven-day, hands-on-keyboard intrusion that began with a phishing message and ended in enterprise-wide LockBit ransomware. The operator hid a Cobalt Strike beacon in a trusted Windows process, ran a pair of SOCKS proxies for pivoting, dumped LSASS and the Active Directory database, and exfiltrated data to a cloud share and FTP drops before encrypting the estate. Reconstruct the full kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.