Skip to main content
Scattered Spider: Identity-First Attack Chain operation cover
AdvancedSIEMXDRPRO

Scattered Spider: Identity-First Attack Chain

Investigate a high-sophistication intrusion by UNC3944 (Scattered Spider). This scenario simulates a multi-stage attack starting from social engineering and MFA fatigue, progressing through the exploitation of unmanaged edge devices, and culminating in a 'Bring Your Own Vulnerable Driver' (BYOVD) technique to blind kernel-level security agents. Analysts must correlate identity providers, cloud sign-ins, and deep endpoint forensics to reconstruct the timeline and identify the breakout speed of this financially motivated threat actor.

1h 30m
10 tasks
150 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Investigating Lateral Movement and Credential Dumping

10

The actor used service-based access to reach corp-srv-ad01 and run credential-dumping tooling against the domain database. Review the XDR timeline around Domain Controller access and identify the Impacket script responsible for the credential dump.

Hint available
2

Fingerprinting the Vulnerable Driver (BYOVD)

10

kdmapper.exe was used to manually map an unsigned, vulnerable driver into the kernel, a Bring-Your-Own-Vulnerable-Driver (BYOVD) technique to bypass Driver Signature Enforcement. On corp-wks-8821, identify the SHA-256 hash of the vulnerable driver file that was dropped to disk and loaded.

Hint available
3

Uncovering Kernel-Level Persistence Artifacts

10

A mapper process on corp-wks-8821 is loading a driver into kernel memory. Review the command line and resulting file artifacts in the driver-loading phase to identify the driver being manually mapped.

Hint available
4

Investigating Execution Anomalies on corp-wks-8821

10

A high-severity alert was triggered when a user account, claudia.vance, executed a process that attempted to bypass local security controls. Analysts must review the event descriptions within the XDR Timeline to determine which interpreter was invoked to facilitate this activity.

Hint available
5

Investigating Kernel-Level Persistence on corp-wks-8821

10

An alert triggered for potential driver manual mapping on corp-wks-8821. Review the process tree for services.exe to find the malicious binary executed by the SYSTEM account that attempted to bypass security controls.

Hint available
6

Investigating Kernel-Level Persistence via Driver Loading

10

The adversary successfully executed kdmapper.exe on the corp-wks-8821 workstation to bypass driver signature enforcement. You must determine the exact name of the malicious driver file that was dropped and executed during this sequence to establish the extent of kernel-level compromise.

Hint available
7

Tracing the Origin of the Kernel-Mode Driver Load

10

During later driver-mapper activity on corp-wks-8821, SIEM records include the telemetry provider that reported the process start. Examine the event metadata and determine which source or log provider reported the activity.

Hint available
8

Unusual DNS Resolution on corp-wks-8821

10

The workstation generated a DNS query tied to driver-mapper activity. Review SIEM DNS events from that phase and determine the queried domain.

Hint available
9

Investigating Suspicious Beaconing Activity

10

Shortly after suspicious execution on corp-wks-8821, the host opened outbound traffic to unauthorized infrastructure. Analyze endpoint network activity to determine the destination used for command-and-control or exfiltration staging.

Hint available
10

Phishing Reconstruction: Identifying the Initial Entry Document

10

An alert triggered for suspicious driver loading via kdmapper.exe, but we need to trace the execution chain back to the start. Analyze the SIEM event messages for host corp-wks-8821 to find which productivity application was used to launch the initial stage of the attack.

Hint available

10 tasks · 100 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
XDR log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Advanced

Complex multi-stage investigations. Realistic noise, ambiguous indicators, lateral movement.

Prerequisites

  • Basic understanding of security alerts
  • Experience with log analysis tools
  • Familiarity with SIEM concepts
  • Familiarity with XDR concepts

Ready to investigate?

More Operations

View all
BeginnerSIEMFirewall

The Template That Read the Disk

The file-transfer portal that Tideglow Logistics' partners upload to spent a morning returning host files it was never meant to publish, and finished it running an administrator session nobody had logged into. The root cause is CVE-2024-4040 in CrushFTP 10.6.0. Walk the access logs and firewall traffic step by step to trace how a client holding no credentials turned a request parameter into a read of the host, and that read into a takeover.

25m25 pts
BeginnerEmailXDR

OneNote Attachment to RAT: A Guided First Investigation

A logistics contracts employee at Glacierline Freight opens an attachment that arrived in her inbox and clicks a button inside it. Minutes later her workstation is running something that appears on no software inventory and is talking to a host that no business process uses. Walk the email gateway records, the file artifacts and the endpoint process tree one step at a time, and work out for yourself which message carried the delivery, what landed on disk, and what ran.

15m25 pts
BeginnerSIEMFirewall

Hijacked Discord Invite to ClickFix Loader: Tracing the Lure

A finance analyst at Halcyon Wealth Partners followed a recycled Discord invite that quietly redirected the browser to a fake verification page. They did what the page asked, and inside the hour the workstation was running a remote-access trojan alongside an info-stealer that shipped browser data straight out of the building. Walk the proxy, endpoint and firewall evidence step by step to trace the lure, the loader, the C2 beacon and the data theft.

15m25 pts