
COMING SOONBeginner
RDP Brute Force: Internet-Facing Server Login
An internet-exposed Windows Server running RDP has been receiving a sustained brute-force campaign from an external address. After dozens of failed authentication events, one attempt succeeds and an interactive session is opened. Reconstruct the attack from the Windows Security event log, identify the source and target, and classify the technique.
25m
6 tasks
25 points
FreeLaunches in 3 days
Aug 18, 2026
Create your free accountTuesday, August 18, 2026 at 9:00 AM
Be ready the moment it drops, free.
Training Tools
SIEM
What you'll investigate
6 objectives unlock when this operation goes live.
1Spot the anomaly in authentication logs
2Identify the target account
3Confirm the logon type
4Find the moment of compromise
5Identify the missing control
6Map the technique
Be first when it launches
Create your free account now. The moment this operation goes live on Aug 18, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.
Get Started Free