Skip to main content
Medusa RaaS: VPN access to enterprise encryption operation cover
AdvancedSIEMXDRFirewallPRO

Medusa RaaS: VPN access to enterprise encryption

A regional healthcare provider is breached through its internet-facing SSL-VPN, and within a shift a Medusa affiliate harvests domain credentials, pivots to the domain controller and backup servers, persists with a rogue remote-management agent hidden among the estate's legitimate ones, steals patient data to cloud storage, and deploys ransomware. Work the VPN authentication records, the endpoint process tree, and the perimeter traffic to reconstruct the intrusion end to end and tell the abuse apart from a heavy baseline of normal remote-management activity.

1h 35m
7 tasks
150 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Find the account that opened the door

25

The SSL-VPN portal logged a burst of failed authentications across several staff accounts this morning, and one of those accounts then established a tunnel. Work the VPN appliance records and determine which single account the attacker authenticated as to gain the foothold.

Hint available
2

Pin the entry address

25

The compromised account let an outsider establish a VPN tunnel. Identify the external address that landed the successful tunnel, so it can be blocked and hunted across the estate.

Hint available
3

Catch the credential theft

30

Once on a management host, the operator pulled tooling and harvested credentials from memory. Identify the host where a process was seen reading the credential store to obtain a privileged account.

Hint available
4

Separate the rogue remote-management agent

30

This estate is managed by an MSP and runs several legitimate remote-management products all day. After the lateral move, the operator installed one more agent for persistence that does not belong. Identify the remote-management agent the attacker installed.

Hint available
5

Follow the patient data out

30

Before the ransomware fired, data was copied out of the network for extortion. Identify the external host the stolen data was transferred to.

Hint available
6

Classify the recovery sabotage

20

Just before encryption, the operator made sure the victim could not roll back. Map that anti-recovery activity to the MITRE ATT&CK technique it represents.

Hint available
7

Read the impact signature

25

When the encryptor ran, it rewrote the patient-record files. Identify the file extension the encryptor appended to every file it encrypted, the on-disk signature that confirms the strain.

Hint available

7 tasks · 185 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
XDR log analysis
Firewall log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Advanced

Complex multi-stage investigations. Realistic noise, ambiguous indicators, lateral movement.

Prerequisites

  • Basic understanding of security alerts
  • Experience with log analysis tools
  • Familiarity with SIEM concepts
  • Familiarity with XDR concepts
  • Familiarity with Firewall concepts

Ready to investigate?

More Operations

View all
AdvancedSIEMXDR

Volt Typhoon: living-off-the-land in critical infrastructure

No malware, no ransomware, no payload to scan for, just native Windows binaries used in an abnormal sequence and a stolen administrator credential. A stealth operator plants a tiny web shell on a water utility's internet-facing host, dumps LSASS with a signed system DLL, routes C2 through a compromised home router, and exports the entire Active Directory database off the domain controller before clearing the logs. Work the Windows Security log, the endpoint process tree, and the perimeter traffic to separate the living-off-the-land activity from a heavy baseline of legitimate admin work.

1h 30m150 pts
AdvancedSIEMXDR

Qilin: Veeam credential abuse to ESXi hypervisor encryption

A Qilin operator exploits a manufacturing firm's SSL-VPN edge, recovers stored credentials from an internet-facing backup server, steals a domain-admin token, self-propagates over SMB to vCenter, exfiltrates data over an encrypted tunnel, clears the Windows logs, and encrypts the ESXi datastores after mass-powering-off the guests. Work the FortiGate and Windows logs, the endpoint process tree, the perimeter traffic, and the vCenter/ESXi records to reconstruct the path from the edge to the hypervisor.

1h 35m150 pts
AdvancedSIEMXDR

Play (Playcrypt): FortiOS + Exchange to Double Extortion

Operators consistent with the Play ransomware group abuse a valid SSL-VPN account and exploit a published Exchange server, run AdFind and Grixba, disable the endpoint defenses, beacon out with Cobalt Strike and SystemBC, move laterally over RDP, archive Finance and HR data with WinRAR, and upload roughly 9.6 GB to a file-sharing service before deleting shadow copies and running an intermittent-encryption impact stage. Work the FortiGate edge, Exchange web logs, the endpoint process tree, the perimeter egress, and the extortion email to reconstruct the full double-extortion intrusion.

1h 45m150 pts