
RDP Brute Force: Internet-Facing Server Login
An internet-exposed Windows Server running RDP has been receiving a sustained brute-force campaign from an external address. After dozens of failed authentication events, one attempt succeeds and an interactive session is opened. Reconstruct the attack from the Windows Security event log, identify the source and target, and classify the technique.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Spot the anomaly in authentication logs
20The host VE-JUMP-01 is producing an unusual number of logon events. Before anything else, determine which external address is responsible for the authentication noise and what kind of logon it is attempting.
Identify the target account
15Every failed attempt in the burst names the same account. Determine which domain account was the target of the brute-force campaign.
Confirm the logon type
15Windows records why a logon succeeded or failed with a Logon Type code. Determine which Logon Type the attacker is using and what it means.
Find the moment of compromise
20After a long sequence of failures, one attempt finally succeeded. Pinpoint the timestamp of the first Event 4624 (successful logon) that arrived from the attacker's source IP.
Identify the missing control
15The attack succeeded because a standard defensive control was absent. Determine which specific Windows security setting, if configured, would have locked the account before the attacker found the correct password.
Map the technique
15Classify this attack pattern using the MITRE ATT&CK framework sub-technique that specifically describes guessing individual account passwords one by one until one works.
6 tasks · 100 points total
Training Tools
Skills You'll Build
Ideal for newcomers to SOC operations. Guided investigation with clear indicators.
Prerequisites
- No prior experience required
- Familiarity with SIEM concepts
Ready to investigate?
More Operations
View allAccount Takeover: Impossible-Travel Sign-In
A finance analyst's Microsoft Entra account is accessed without MFA from Moldova 18 minutes after their normal London sign-in. Impossible travel confirmed. The unauthorized session reads the inbox via Graph and adds an external recovery address. Work the Entra audit trail to identify the attacker IP, the compromised mailbox, and the persistence mechanism.
Open SMB Share: Unauthorized Data Access
A finance file share on an internal Windows server was misconfigured to allow all domain users read access. A workstation account with no finance role connected over SMB and bulk-read payroll records, M&A strategy documents, and board materials. Reconstruct the session from Windows Security audit events and internal firewall logs.
VPN Brute Force: Credential Attack on the Remote-Access Portal
A password-spray campaign targets the Halcyon Freight SSL-VPN portal from two rotating source IPs, submitting credentials across many accounts to stay under per-account lockout thresholds. One account eventually matches. Reconstruct the spray, identify the compromised account and the operator IP that opened the active session, and trace the first move the attacker made over the tunnel.