Skip to main content
UNC6384: Captive-Portal PlugX Implant operation cover
BeginnerSIEMXDRFirewall

UNC6384: Captive-Portal PlugX Implant

A diplomat's managed laptop on an untrusted conference network has its captive-portal check hijacked and is steered to a page posing as a security update. The download is a signed Canon utility paired with a malicious DLL: running the trusted binary side-loads the DLL, which runs PlugX in memory, beacons to a single HTTPS host, and sets a Run key. Reconstruct the chain from the proxy, Sysmon, endpoint, and firewall evidence.

30m
7 tasks
25 points
Free

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Orient on the traveling-laptop alert

0

A diplomat's managed laptop on a conference network started making outbound connections that do not match the user's normal traffic, minutes after a captive-portal sign-in. Before pivoting through the evidence, get oriented on what you are looking at and which surfaces hold the answers.

2

Find where the captive-portal check was redirected

15

The intrusion began when the laptop's connectivity check was tampered with on the untrusted network. Trace the proxy and DNS records from the connectivity probe to the attacker page and identify the host the browser was steered to.

SOC{host.domain.tld}Hint available
3

Identify the malicious DLL that was sideloaded

15

The attacker page delivered a bundle built around a trusted, signed application. The dangerous component is not the signed executable but the file loaded beside it. Use the endpoint and Sysmon evidence to name it.

SOC{filename.ext}Hint available
4

Classify the execution technique

15

Put a name to how the attacker got code to run inside a trusted, signed process. Map the technique you just reconstructed to MITRE ATT&CK.

SOC{Txxxx.xxx}Hint available
5

Pin down the command-and-control host

15

Once loaded, the implant ran in memory and reached out to its operator. Separate that callback from ordinary encrypted browsing and identify the single external host it used.

SOC{a.b.c.d}Hint available
6

Locate the persistence mechanism

15

The actor wanted the foothold to survive a reboot. Using the Sysmon and endpoint records, identify the registry value the loader wrote so it would relaunch automatically.

SOC{ValueName}Hint available
7

Classify how the data left the machine

15

Wrap up by mapping the exfiltration to MITRE ATT&CK. The implant did not build a separate upload site: the data left over the channel it was already using.

SOC{Txxxx}Hint available

7 tasks · 90 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
XDR log analysis
Firewall log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Beginner

Ideal for newcomers to SOC operations. Guided investigation with clear indicators.

Prerequisites

  • No prior experience required
  • Familiarity with SIEM concepts
  • Familiarity with XDR concepts
  • Familiarity with Firewall concepts

Ready to investigate?

More Operations

View all
BeginnerSIEMFirewall

The Template That Read the Disk

The file-transfer portal that Tideglow Logistics' partners upload to spent a morning returning host files it was never meant to publish, and finished it running an administrator session nobody had logged into. The root cause is CVE-2024-4040 in CrushFTP 10.6.0. Walk the access logs and firewall traffic step by step to trace how a client holding no credentials turned a request parameter into a read of the host, and that read into a takeover.

25m25 pts
BeginnerEmailXDR

OneNote Attachment to RAT: A Guided First Investigation

A logistics contracts employee at Glacierline Freight opens an attachment that arrived in her inbox and clicks a button inside it. Minutes later her workstation is running something that appears on no software inventory and is talking to a host that no business process uses. Walk the email gateway records, the file artifacts and the endpoint process tree one step at a time, and work out for yourself which message carried the delivery, what landed on disk, and what ran.

15m25 pts
BeginnerSIEMFirewall

Hijacked Discord Invite to ClickFix Loader: Tracing the Lure

A finance analyst at Halcyon Wealth Partners followed a recycled Discord invite that quietly redirected the browser to a fake verification page. They did what the page asked, and inside the hour the workstation was running a remote-access trojan alongside an info-stealer that shipped browser data straight out of the building. Walk the proxy, endpoint and firewall evidence step by step to trace the lure, the loader, the C2 beacon and the data theft.

15m25 pts