Skip to main content
Play (Playcrypt): FortiOS + Exchange to Double Extortion operation cover
AdvancedSIEMXDRFirewallEmailPRO

Play (Playcrypt): FortiOS + Exchange to Double Extortion

Operators consistent with the Play ransomware group abuse a valid SSL-VPN account and exploit a published Exchange server, run AdFind and Grixba, disable the endpoint defenses, beacon out with Cobalt Strike and SystemBC, move laterally over RDP, archive Finance and HR data with WinRAR, and upload roughly 9.6 GB to a file-sharing service before deleting shadow copies and running an intermittent-encryption impact stage. Work the FortiGate edge, Exchange web logs, the endpoint process tree, the perimeter egress, and the extortion email to reconstruct the full double-extortion intrusion.

1h 45m
7 tasks
150 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Pin the way in

20

Overnight, the perimeter saw a remote-access session that did not behave like a normal staff connection. Work the FortiGate edge and VPN authentication records and isolate the external address behind the SSL-VPN session that authenticated without the account's usual second factor.

Hint available
2

Confirm the second door

20

The same operator did not rely on the VPN alone, the published mail server was hit in parallel. Identify the internal host that was driven to spawn a shell from its web application after the Exchange backend was reached.

Hint available
3

Catch the blinding

25

Before going loud, the operator made sure the endpoint defenses would not get in the way. Examine the beachhead process tree and endpoint records and identify the privileged account that disabled protection and was later reused to move through the estate.

Hint available
4

Spot the quiet account

20

The crew left themselves a durable way back in using an account that should never be active. Identify the built-in Windows account that was re-enabled and added to Administrators on the domain controller.

Hint available
5

Follow the data out

25

The most important fact for the business is that data left the building before anything was locked. Reconstruct the egress from the file server and report the external address the stolen archives were uploaded to.

Hint available
6

Read the demand

20

Hours after the data left, the business received a message confirming the breach and setting terms. From the email evidence, identify the sender address the operators used to make contact.

Hint available
7

Name the impact technique

15

Only after the data had been stolen were the files locked, and they were locked in a way built for speed. Map the final encryption stage to its MITRE ATT&CK technique.

Hint available

7 tasks · 145 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
XDR log analysis
Firewall log analysis
Email log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Advanced

Complex multi-stage investigations. Realistic noise, ambiguous indicators, lateral movement.

Prerequisites

  • Basic understanding of security alerts
  • Experience with log analysis tools
  • Familiarity with SIEM concepts
  • Familiarity with XDR concepts
  • Familiarity with Firewall concepts
  • Familiarity with Email concepts

Ready to investigate?

More Operations

View all
AdvancedSIEMXDR

Qilin: Veeam credential abuse to ESXi hypervisor encryption

A Qilin operator exploits a manufacturing firm's SSL-VPN edge, recovers stored credentials from an internet-facing backup server, steals a domain-admin token, self-propagates over SMB to vCenter, exfiltrates data over an encrypted tunnel, clears the Windows logs, and encrypts the ESXi datastores after mass-powering-off the guests. Work the FortiGate and Windows logs, the endpoint process tree, the perimeter traffic, and the vCenter/ESXi records to reconstruct the path from the edge to the hypervisor.

1h 35m150 pts
AdvancedSIEMXDR

BianLian: Exfiltration-Based Extortion

A threat actor with a valid domain account and no MFA to stop them lands on an internet-facing RDP jump host, spends the morning living off the land, dumps credentials from LSASS, and spends the afternoon moving approximately 47 GB of engineering documents out of the network through a cloud-sync utility pointed at storage they control. No files are encrypted; the leverage is the stolen data itself. Reconstruct the full chain from initial RDP spray to log wipe.

1h 55m150 pts
AdvancedSIEMXDR

Rhysida Ransomware: Healthcare Network Intrusion

A Rhysida ransomware affiliate phishes a healthcare staff member's VPN credentials and exploits a stale MFA exemption to breach a regional medical center. Using a Cobalt Strike beacon and built-in Windows tools, the attacker extracts all domain credentials, exfiltrates patient records for double extortion, and deploys the encryptor estate-wide. Trace the kill chain from the first failed VPN login to the final ransom note.

1h 30m150 pts