Skip to main content
Night Shift at Veridian Specialty Chemicals operation cover
AdvancedSIEMXDRFirewallPRO

Night Shift at Veridian Specialty Chemicals

Veridian Specialty Chemicals runs one Windows domain from one site: an on-premises Exchange server in the DMZ, a domain controller, and a file, backup and SQL tier that carry the plant's process data. Between the small hours and the end of the following evening the estate logged work nobody rostered. A perimeter sensor fired against the mail host. Files appeared on servers where installers never run. Administrative sessions arrived from the wrong direction. A long outbound transfer left the server tier on a port nobody watches. None of it was escalated overnight. Work the SIEM event log, the XDR process telemetry and the perimeter firewall records, and establish what reached the estate, what it took with it, and what it left behind.

1h 40m
9 tasks
150 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Identify the first file the Exchange host should not have written

40

The Exchange server is behaving strangely. A perimeter sensor registered an anomaly against the OWA endpoint in the early hours, and endpoint logs show a file appearing where application binaries have no business writing. Establish the filename of that file.

Hint available
2

Confirm what was staged on the domain controller

45

After execution began on Exchange, activity moved to the domain controller. XDR process telemetry on that host shows a binary staged under ProgramData opening a protected system process. Confirm the SHA-256 of that binary.

Hint available
3

Identify the account used to spread across the estate

40

With domain credentials in hand, the operator moved from the domain controller to every high-value server. Pinpoint the domain account that appears across the RDP logon events on the file, backup and SQL servers in that window.

Hint available
4

Locate where the audit trail was erased

35

One host had its Windows Security event log cleared during the intrusion. Determine which host the log-clear event (Windows Security event 1102) was recorded on.

Hint available
5

Confirm the destination of the bulk outbound transfer

40

A large volume of data left the file server in a short window. The firewall recorded multiple large simultaneous outbound flows from that host. Identify the external IP address that received it.

Hint available
6

Map the pre-impact activity on the domain controller to ATT&CK

35

In the minutes before the file-rename burst on the share, two native Windows utilities ran on the domain controller. Find them, read their arguments, and give the ATT&CK technique id that the pair maps to.

Hint available
7

Reconstruct the initial-access technique

35

Establish how the operator got their first execution on the Exchange host, then give the ATT&CK technique id for that initial access.

Hint available
8

Classify the process-access step on the domain controller

40

Find the credential-access step on the domain controller and give the ATT&CK sub-technique id for it.

Hint available
9

Classify the terminal action on the file server

40

Find the terminal action on the file server and give the ATT&CK technique id for it.

Hint available

9 tasks · 350 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
XDR log analysis
Firewall log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Advanced

Complex multi-stage investigations. Realistic noise, ambiguous indicators, lateral movement.

Prerequisites

  • Basic understanding of security alerts
  • Experience with log analysis tools
  • Familiarity with SIEM concepts
  • Familiarity with XDR concepts
  • Familiarity with Firewall concepts

Ready to investigate?

More Operations

View all
AdvancedSIEMXDR

Cactus Ransomware: Qlik Sense Exploitation

An internet-facing Qlik Sense analytics server is exploited and turned into the launch point for a Cactus ransomware intrusion. Within a day the operator persists with a rogue remote-access agent, dumps domain-admin credentials from memory, pivots by RDP to the domain controller and backup servers, steals engineering data to cloud storage, and deploys ransomware. Work the Qlik web logs, the endpoint process tree and the perimeter traffic to reconstruct the intrusion end to end and tell the abuse apart from a heavy baseline of normal analytics and remote-access activity.

1h 30m150 pts
AdvancedSIEMXDR

Sandworm: Trojanized KMS Activator to DcRAT

A staff member at the energy provider Ridna Energo downloaded a free Microsoft KMS activation tool that turned out to be trojanized. Within minutes it dropped the BACKORDER loader, disabled Defender, proxy-loaded the DcRAT implant through rundll32, and opened an encrypted channel to a single anonymizing C2 node. Reconstruct the full espionage intrusion, from the lure download through credential theft, lateral movement, and exfiltration over command-and-control, across endpoint, network, and perimeter telemetry.

2h 5m150 pts
AdvancedSIEMXDR

Cobalt Strike and SOCKS: 11 Days to LockBit

An eleven-day, hands-on-keyboard intrusion that began with a phishing message and ended in enterprise-wide LockBit ransomware. The operator hid a Cobalt Strike beacon in a trusted Windows process, ran a pair of SOCKS proxies for pivoting, dumped LSASS and the Active Directory database, and exfiltrated data to a cloud share and FTP drops before encrypting the estate. Reconstruct the full kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.

1h 40m150 pts