
Hide Your RDP
An internet-facing RDP server at a logistics firm is password-sprayed into, and within hours a RansomHub affiliate dumps credentials, pivots to the domain controller and backup servers, steals finance data over SFTP, and deploys ransomware. Work the authentication records, the endpoint process tree, and the perimeter traffic to reconstruct the intrusion end to end.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Find the account that fell to the spray
20An internet-facing RDP server generated a storm of failed remote logons across several staff accounts this morning, and one of those accounts then logged in successfully. Work the Windows authentication records and determine which single account the attacker sprayed into and used to gain the foothold.
Pin the foothold source
20The compromised account let an outsider in over RDP. Identify the external address that landed the successful remote logon, so it can be blocked and hunted across the estate.
Catch the directory theft
30Soon after the break-in, an account that has no business doing so asked the domain controller to hand over directory replication data. Identify the host where that domain-replication event was recorded.
Name the persistence agent
25With domain-admin credentials in hand, the operator reached the backup servers and installed software to keep a way back in. Identify the remote-management agent that was installed as a service for persistence.
Follow the data out
25Before the ransomware fired, finance data was copied out of the network. Identify the external host the stolen data was transferred to.
Classify the recovery sabotage
15Just before encryption, the operator made sure the victim could not roll back. Map that anti-recovery activity to the MITRE ATT&CK technique it represents.
6 tasks · 135 points total
Training Tools
Skills You'll Build
Requires foundational alert triage skills. Multiple data sources to correlate.
Prerequisites
- Basic understanding of security alerts
- Familiarity with SIEM concepts
- Familiarity with XDR concepts
- Familiarity with Firewall concepts
Ready to investigate?
More Operations
View allExchange ProxyShell: Domain-Wide Ransomware
An internet-facing Exchange server falls to ProxyShell, dropping ASPX web shells that run as SYSTEM. The attacker re-enables a built-in account, dumps LSASS with a Windows DLL, tunnels out with Plink and FRP, moves laterally over RDP, and encrypts the domain with its own BitLocker and DiskCryptor, no ransomware binary in sight. Work the Exchange logs, the endpoint process tree, and the perimeter traffic to reconstruct the intrusion.
Overnight on the DMZ Wiki
Quillon Software publishes its engineering wiki straight to the internet from the DMZ. Overnight the host picked up work nobody rostered: requests that never authenticated, shell activity under a service account, and outbound sessions from a server that normally only talks to its update mirrors. Work the web access logs, the Linux audit trail and the perimeter egress, and reconstruct what reached the host and what left it.
Brixton Foods: the directory answered a request it should have refused
A food manufacturer's help desk raised a ticket at lunchtime: an overnight production report had not written to the file share, and one workstation had been slow all morning. By the evening the share was unreadable and an administrator account nobody on the IT rota recognises had been busy on the domain controllers. You have the day's Windows Security feed and the endpoint telemetry for the estate. Reconstruct what the operator did between the first mailbox and the unreadable share, and name the accounts and hosts the response team has to act on.