
Account Takeover: Impossible-Travel Sign-In
A finance analyst's Microsoft Entra account is accessed without MFA from Moldova 18 minutes after their normal London sign-in. Impossible travel confirmed. The unauthorized session reads the inbox via Graph and adds an external recovery address. Work the Entra audit trail to identify the attacker IP, the compromised mailbox, and the persistence mechanism.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Locate the unauthorized entry point
15One identity authenticated twice to Exchange Online within 18 minutes from locations on opposite sides of Europe. The second sign-in is the attacker. Identify the source IP behind that unauthorized session.
Establish the travel gap
10The impossible-travel alert fires on the time between two sign-ins for the same account. Determine exactly how many minutes elapsed between the legitimate London logon and the attacker's sign-in.
Trace the mailbox access
15After establishing a session, the attacker immediately queried the victim's inbox via Microsoft Graph. Identify the account whose mailbox was targeted.
Find the persistence move
20Before ending the session, the attacker modified the compromised account in a way that outlasts a password reset. Identify the specific account attribute that was changed.
Classify the initial access
15Map the technique by which the attacker gained entry to the Entra tenant to its MITRE ATT&CK sub-technique.
Classify the mailbox collection
10The attacker read the victim's inbox through Microsoft Graph. Identify the MITRE ATT&CK technique that describes this action.
6 tasks · 85 points total
Training Tools
Cloud Console
Cloud infrastructure logs
SIEM Console
Log analysis & SPL queries
Skills You'll Build
Ideal for newcomers to SOC operations. Guided investigation with clear indicators.
Prerequisites
- No prior experience required
- Familiarity with Cloud concepts
- Familiarity with SIEM concepts
Ready to investigate?
More Operations
View allMalicious npm Package: Postinstall Infostealer
A developer at a software company runs a routine npm install and the terminal returns clean. Less than a minute later the web proxy records a large outbound upload from that workstation. Work the process tree, the file activity and the outbound traffic to reconstruct what the install actually did.
RDP Brute Force: Internet-Facing Server Login
An internet-exposed Windows Server running RDP has been receiving a sustained brute-force campaign from an external address. After dozens of failed authentication events, one attempt succeeds and an interactive session is opened. Reconstruct the attack from the Windows Security event log, identify the source and target, and classify the technique.
Open SMB Share: Unauthorized Data Access
A finance file share on an internal Windows server was misconfigured to allow all domain users read access. A workstation account with no finance role connected over SMB and bulk-read payroll records, M&A strategy documents, and board materials. Reconstruct the session from Windows Security audit events and internal firewall logs.