Skip to main content
Scattered Spider: Identity-First Attack Chain operation cover
AdvancedSIEMXDRPRO

Scattered Spider: Identity-First Attack Chain

Investigate a high-sophistication intrusion by UNC3944 (Scattered Spider). This scenario simulates a multi-stage attack starting from social engineering and MFA fatigue, progressing through the exploitation of unmanaged edge devices, and culminating in a 'Bring Your Own Vulnerable Driver' (BYOVD) technique to blind kernel-level security agents. Analysts must correlate identity providers, cloud sign-ins, and deep endpoint forensics to reconstruct the timeline and identify the breakout speed of this financially motivated threat actor.

1h 30m
10 tasks
150 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Investigating Lateral Movement and Credential Dumping

10

The actor used service-based access to reach corp-srv-ad01 and run credential-dumping tooling against the domain database. Review the XDR timeline around Domain Controller access and identify the Impacket script responsible for the credential dump.

Hint available
2

Fingerprinting the Vulnerable Driver (BYOVD)

10

kdmapper.exe was used to manually map an unsigned, vulnerable driver into the kernel, a Bring-Your-Own-Vulnerable-Driver (BYOVD) technique to bypass Driver Signature Enforcement. On corp-wks-8821, identify the SHA-256 hash of the vulnerable driver file that was dropped to disk and loaded.

Hint available
3

Uncovering Kernel-Level Persistence Artifacts

10

A mapper process on corp-wks-8821 is loading a driver into kernel memory. Review the command line and resulting file artifacts in the driver-loading phase to identify the driver being manually mapped.

Hint available
4

Investigating Execution Anomalies on corp-wks-8821

10

A high-severity alert was triggered when a user account, claudia.vance, executed a process that attempted to bypass local security controls. Analysts must review the event descriptions within the XDR Timeline to determine which interpreter was invoked to facilitate this activity.

Hint available
5

Investigating Kernel-Level Persistence on corp-wks-8821

10

An alert triggered for potential driver manual mapping on corp-wks-8821. Review the process tree for services.exe to find the malicious binary executed by the SYSTEM account that attempted to bypass security controls.

Hint available
6

Investigating Kernel-Level Persistence via Driver Loading

10

The adversary successfully executed kdmapper.exe on the corp-wks-8821 workstation to bypass driver signature enforcement. You must determine the exact name of the malicious driver file that was dropped and executed during this sequence to establish the extent of kernel-level compromise.

Hint available
7

Tracing the Origin of the Kernel-Mode Driver Load

10

During later driver-mapper activity on corp-wks-8821, SIEM records include the telemetry provider that reported the process start. Examine the event metadata and determine which source or log provider reported the activity.

Hint available
8

Unusual DNS Resolution on corp-wks-8821

10

The workstation generated a DNS query tied to driver-mapper activity. Review SIEM DNS events from that phase and determine the queried domain.

Hint available
9

Investigating Suspicious Beaconing Activity

10

Shortly after suspicious execution on corp-wks-8821, the host opened outbound traffic to unauthorized infrastructure. Analyze endpoint network activity to determine the destination used for command-and-control or exfiltration staging.

Hint available
10

Phishing Reconstruction: Identifying the Initial Entry Document

10

An alert triggered for suspicious driver loading via kdmapper.exe, but we need to trace the execution chain back to the start. Analyze the SIEM event messages for host corp-wks-8821 to find which productivity application was used to launch the initial stage of the attack.

Hint available

10 tasks · 100 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
XDR log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Advanced

Complex multi-stage investigations. Realistic noise, ambiguous indicators, lateral movement.

Prerequisites

  • Basic understanding of security alerts
  • Experience with log analysis tools
  • Familiarity with SIEM concepts
  • Familiarity with XDR concepts

Ready to investigate?

More Operations

View all
AdvancedSIEMXDR

Fake Zoom to Ransomware: The Social Engineering Pipeline

In this advanced SOC simulation, you will investigate a multi-stage intrusion that began with a drive-by download of a trojanized Zoom installer. The attack progressed through several stages of loader execution, including d3f@ckloader and IDAT loader, eventually leading to the deployment of high-end C2 frameworks like Cobalt Strike and Brute Ratel. You must trace the attacker's path from the initial web-based compromise, through lateral movement via RDP tunneling and proxy tools, to the final mass-deployment of BlackSuit ransomware via enterprise management software. This scenario is based on real-world 2025 threat intelligence and requires deep analysis of SIEM, XDR, and Firewall telemetry to reconstruct the full kill chain.

1h 40m150 pts
AdvancedSIEMFirewall

The Half-Second Tell

A Linux hosting fleet quietly picks up an affected xz-utils / liblzma 5.6.1 build, and the SSH daemon's login path is no longer its own. There is no crash and no malware drop, only a shared object whose hash moved, an sshd that forks a shell it never should, a half-second of extra login latency, and a root key the fleet never issued. Work the package, file-integrity, auth, and perimeter records to surface the subtle host artifacts of CVE-2024-3094 and scope the affected version.

1h 15m150 pts
AdvancedSIEMFirewall

Trust, Forged: The Monitoring-Platform Backdoor

A trusted, signed plugin in Greyford's network monitoring platform was backdoored upstream. From a silent defense-tamper on the monitoring server, follow a low-and-slow DGA-over-DNS beacon under a single attacker apex, a CNAME redirect to a staged C2, and finally the theft of on-prem token-signing trust that forges SAML tokens into anomalous, MFA-less cloud sign-ins. The DNS resolver log is your sharpest blade.

1h 35m150 pts