
Scattered Spider: Identity-First Attack Chain
Investigate a high-sophistication intrusion by UNC3944 (Scattered Spider). This scenario simulates a multi-stage attack starting from social engineering and MFA fatigue, progressing through the exploitation of unmanaged edge devices, and culminating in a 'Bring Your Own Vulnerable Driver' (BYOVD) technique to blind kernel-level security agents. Analysts must correlate identity providers, cloud sign-ins, and deep endpoint forensics to reconstruct the timeline and identify the breakout speed of this financially motivated threat actor.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Investigating Lateral Movement and Credential Dumping
10The actor used service-based access to reach corp-srv-ad01 and run credential-dumping tooling against the domain database. Review the XDR timeline around Domain Controller access and identify the Impacket script responsible for the credential dump.
Fingerprinting the Vulnerable Driver (BYOVD)
10kdmapper.exe was used to manually map an unsigned, vulnerable driver into the kernel, a Bring-Your-Own-Vulnerable-Driver (BYOVD) technique to bypass Driver Signature Enforcement. On corp-wks-8821, identify the SHA-256 hash of the vulnerable driver file that was dropped to disk and loaded.
Uncovering Kernel-Level Persistence Artifacts
10A mapper process on corp-wks-8821 is loading a driver into kernel memory. Review the command line and resulting file artifacts in the driver-loading phase to identify the driver being manually mapped.
Investigating Execution Anomalies on corp-wks-8821
10A high-severity alert was triggered when a user account, claudia.vance, executed a process that attempted to bypass local security controls. Analysts must review the event descriptions within the XDR Timeline to determine which interpreter was invoked to facilitate this activity.
Investigating Kernel-Level Persistence on corp-wks-8821
10An alert triggered for potential driver manual mapping on corp-wks-8821. Review the process tree for services.exe to find the malicious binary executed by the SYSTEM account that attempted to bypass security controls.
Investigating Kernel-Level Persistence via Driver Loading
10The adversary successfully executed kdmapper.exe on the corp-wks-8821 workstation to bypass driver signature enforcement. You must determine the exact name of the malicious driver file that was dropped and executed during this sequence to establish the extent of kernel-level compromise.
Tracing the Origin of the Kernel-Mode Driver Load
10During later driver-mapper activity on corp-wks-8821, SIEM records include the telemetry provider that reported the process start. Examine the event metadata and determine which source or log provider reported the activity.
Unusual DNS Resolution on corp-wks-8821
10The workstation generated a DNS query tied to driver-mapper activity. Review SIEM DNS events from that phase and determine the queried domain.
Investigating Suspicious Beaconing Activity
10Shortly after suspicious execution on corp-wks-8821, the host opened outbound traffic to unauthorized infrastructure. Analyze endpoint network activity to determine the destination used for command-and-control or exfiltration staging.
Phishing Reconstruction: Identifying the Initial Entry Document
10An alert triggered for suspicious driver loading via kdmapper.exe, but we need to trace the execution chain back to the start. Analyze the SIEM event messages for host corp-wks-8821 to find which productivity application was used to launch the initial stage of the attack.
10 tasks · 100 points total
Training Tools
Skills You'll Build
Complex multi-stage investigations. Realistic noise, ambiguous indicators, lateral movement.
Prerequisites
- Basic understanding of security alerts
- Experience with log analysis tools
- Familiarity with SIEM concepts
- Familiarity with XDR concepts
Ready to investigate?
More Operations
View allThe Template That Read the Disk
The file-transfer portal that Tideglow Logistics' partners upload to spent a morning returning host files it was never meant to publish, and finished it running an administrator session nobody had logged into. The root cause is CVE-2024-4040 in CrushFTP 10.6.0. Walk the access logs and firewall traffic step by step to trace how a client holding no credentials turned a request parameter into a read of the host, and that read into a takeover.
OneNote Attachment to RAT: A Guided First Investigation
A logistics contracts employee at Glacierline Freight opens an attachment that arrived in her inbox and clicks a button inside it. Minutes later her workstation is running something that appears on no software inventory and is talking to a host that no business process uses. Walk the email gateway records, the file artifacts and the endpoint process tree one step at a time, and work out for yourself which message carried the delivery, what landed on disk, and what ran.
Hijacked Discord Invite to ClickFix Loader: Tracing the Lure
A finance analyst at Halcyon Wealth Partners followed a recycled Discord invite that quietly redirected the browser to a fake verification page. They did what the page asked, and inside the hour the workstation was running a remote-access trojan alongside an info-stealer that shipped browser data straight out of the building. Walk the proxy, endpoint and firewall evidence step by step to trace the lure, the loader, the C2 beacon and the data theft.