
Medusa RaaS: VPN access to enterprise encryption
A regional healthcare provider is breached through its internet-facing SSL-VPN, and within a shift a Medusa affiliate harvests domain credentials, pivots to the domain controller and backup servers, persists with a rogue remote-management agent hidden among the estate's legitimate ones, steals patient data to cloud storage, and deploys ransomware. Work the VPN authentication records, the endpoint process tree, and the perimeter traffic to reconstruct the intrusion end to end and tell the abuse apart from a heavy baseline of normal remote-management activity.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Find the account that opened the door
25The SSL-VPN portal logged a burst of failed authentications across several staff accounts this morning, and one of those accounts then established a tunnel. Work the VPN appliance records and determine which single account the attacker authenticated as to gain the foothold.
Pin the entry address
25The compromised account let an outsider establish a VPN tunnel. Identify the external address that landed the successful tunnel, so it can be blocked and hunted across the estate.
Catch the credential theft
30Once on a management host, the operator pulled tooling and harvested credentials from memory. Identify the host where a process was seen reading the credential store to obtain a privileged account.
Separate the rogue remote-management agent
30This estate is managed by an MSP and runs several legitimate remote-management products all day. After the lateral move, the operator installed one more agent for persistence that does not belong. Identify the remote-management agent the attacker installed.
Follow the patient data out
30Before the ransomware fired, data was copied out of the network for extortion. Identify the external host the stolen data was transferred to.
Classify the recovery sabotage
20Just before encryption, the operator made sure the victim could not roll back. Map that anti-recovery activity to the MITRE ATT&CK technique it represents.
Read the impact signature
25When the encryptor ran, it rewrote the patient-record files. Identify the file extension the encryptor appended to every file it encrypted, the on-disk signature that confirms the strain.
7 tasks · 185 points total
Training Tools
Skills You'll Build
Complex multi-stage investigations. Realistic noise, ambiguous indicators, lateral movement.
Prerequisites
- Basic understanding of security alerts
- Experience with log analysis tools
- Familiarity with SIEM concepts
- Familiarity with XDR concepts
- Familiarity with Firewall concepts
Ready to investigate?
More Operations
View allVolt Typhoon: living-off-the-land in critical infrastructure
No malware, no ransomware, no payload to scan for, just native Windows binaries used in an abnormal sequence and a stolen administrator credential. A stealth operator plants a tiny web shell on a water utility's internet-facing host, dumps LSASS with a signed system DLL, routes C2 through a compromised home router, and exports the entire Active Directory database off the domain controller before clearing the logs. Work the Windows Security log, the endpoint process tree, and the perimeter traffic to separate the living-off-the-land activity from a heavy baseline of legitimate admin work.
Qilin: Veeam credential abuse to ESXi hypervisor encryption
A Qilin operator exploits a manufacturing firm's SSL-VPN edge, recovers stored credentials from an internet-facing backup server, steals a domain-admin token, self-propagates over SMB to vCenter, exfiltrates data over an encrypted tunnel, clears the Windows logs, and encrypts the ESXi datastores after mass-powering-off the guests. Work the FortiGate and Windows logs, the endpoint process tree, the perimeter traffic, and the vCenter/ESXi records to reconstruct the path from the edge to the hypervisor.
Play (Playcrypt): FortiOS + Exchange to Double Extortion
Operators consistent with the Play ransomware group abuse a valid SSL-VPN account and exploit a published Exchange server, run AdFind and Grixba, disable the endpoint defenses, beacon out with Cobalt Strike and SystemBC, move laterally over RDP, archive Finance and HR data with WinRAR, and upload roughly 9.6 GB to a file-sharing service before deleting shadow copies and running an intermittent-encryption impact stage. Work the FortiGate edge, Exchange web logs, the endpoint process tree, the perimeter egress, and the extortion email to reconstruct the full double-extortion intrusion.