Skip to main content
RDP Brute Force: Internet-Facing Server Login operation cover
BeginnerSIEM

RDP Brute Force: Internet-Facing Server Login

An internet-exposed Windows Server running RDP has been receiving a sustained brute-force campaign from an external address. After dozens of failed authentication events, one attempt succeeds and an interactive session is opened. Reconstruct the attack from the Windows Security event log, identify the source and target, and classify the technique.

25m
6 tasks
25 points
Free

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Spot the anomaly in authentication logs

20

The host VE-JUMP-01 is producing an unusual number of logon events. Before anything else, determine which external address is responsible for the authentication noise and what kind of logon it is attempting.

SOC{a.b.c.d}Hint available
2

Identify the target account

15

Every failed attempt in the burst names the same account. Determine which domain account was the target of the brute-force campaign.

SOC{firstname.lastname}Hint available
3

Confirm the logon type

15

Windows records why a logon succeeded or failed with a Logon Type code. Determine which Logon Type the attacker is using and what it means.

SOC{number}Hint available
4

Find the moment of compromise

20

After a long sequence of failures, one attempt finally succeeded. Pinpoint the timestamp of the first Event 4624 (successful logon) that arrived from the attacker's source IP.

SOC{hh:mm}Hint available
5

Identify the missing control

15

The attack succeeded because a standard defensive control was absent. Determine which specific Windows security setting, if configured, would have locked the account before the attacker found the correct password.

SOC{Policy Name}Hint available
6

Map the technique

15

Classify this attack pattern using the MITRE ATT&CK framework sub-technique that specifically describes guessing individual account passwords one by one until one works.

SOC{Txxxx.xxx}Hint available

6 tasks · 100 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Beginner

Ideal for newcomers to SOC operations. Guided investigation with clear indicators.

Prerequisites

  • No prior experience required
  • Familiarity with SIEM concepts

Ready to investigate?

More Operations

View all