Skip to main content
RDP Brute Force: Internet-Facing Server Login operation cover
COMING SOONBeginner

RDP Brute Force: Internet-Facing Server Login

An internet-exposed Windows Server running RDP has been receiving a sustained brute-force campaign from an external address. After dozens of failed authentication events, one attempt succeeds and an interactive session is opened. Reconstruct the attack from the Windows Security event log, identify the source and target, and classify the technique.

25m
6 tasks
25 points
Free

Launches in 3 days

Aug 18, 2026

Tuesday, August 18, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops, free.

Training Tools

SIEM

What you'll investigate

6 objectives unlock when this operation goes live.

1Spot the anomaly in authentication logs
2Identify the target account
3Confirm the logon type
4Find the moment of compromise
5Identify the missing control
6Map the technique

Be first when it launches

Create your free account now. The moment this operation goes live on Aug 18, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free