
Weaponized SVG: Embedded Code in an Image Attachment
A treasury analyst at a bank opens what looks like a SWIFT payment confirmation, clicks the button inside it, and no document ever appears. Minutes later her workstation is running code out of her own user profile and holding an encrypted session to a host it has never contacted before. Walk the mail gateway, the file artifacts and the endpoint process tree step by step, from the delivery that started it to the beacon that followed.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Brief: an image that was not just an image
0A treasury workstation started talking to an external host on its own this morning, minutes after the analyst opened what looked like a payment confirmation. Before you dig into the endpoint evidence, get oriented on how this attack began.
Trace the delivery to its sender
15Start at the mail gateway. Three messages reached Priya's mailbox in the same stretch of the morning, and one of them is the delivery that started this incident. Work out which record that is, then recover the address it was sent from.
Find the file that wrote a ZIP to disk
15Three files appeared in Priya's Downloads folder in the minutes around the click, and none of them is a payment confirmation. Read the file-monitor timeline and name the file the others came out of.
Follow the execution chain
15Priya extracted the archive and opened what was inside it. Read the process tree from larch-ws-0418 and name the process that executed that extracted file itself.
Name the command-and-control host
15Two outbound connections follow the loader in this window and they are not doing the same job. Identify the external host that the archive dropped into Priya's profile reached out to.
Classify the scripting technique
10Map the execution method to MITRE ATT&CK. Use the recap below to work out what the endpoint was actually asked to run, then name the technique ATT&CK assigns to it.
6 tasks · 70 points total
Training Tools
Email Console
Email header & content analysis
XDR Console
Endpoint detection & response
Skills You'll Build
Ideal for newcomers to SOC operations. Guided investigation with clear indicators.
Prerequisites
- No prior experience required
- Familiarity with Email concepts
- Familiarity with XDR concepts
Ready to investigate?
More Operations
View allFake Window, Real Loss: Browser-in-the-Browser Steam Phishing
A Counter-Strike 2 player on the community team at Voltline Interactive clicks a phishing email offering a free in-game case from a well-known esports team. The link leads to a scam site that paints a fake browser pop-up, complete with a fake Steam URL bar, entirely in HTML. The victim types their Steam credentials into the fake window and cannot sign in minutes later. Walk the email gateway and proxy logs step by step, from the lure to the moment the password left the browser.
Trusted Domain, Untrusted Destination: Open-Redirect Phishing
A finance clerk at Larkfield Mutual Assurance clicks a Release My Messages link in an Undelivered Mails phishing email. The link opens with a trusted brand domain that carries an open-redirect flaw, so it sails past URL filtering. Follow the 302 redirect through an attacker cushion server and a JavaScript hop to a spoofed Microsoft 365 login page, then catch the harvested credentials being replayed against the real tenant. Walk the mail gateway, web proxy, and sign-in logs step by step.
The Backdoored Browser Extension: Following the C2 Beacon
A routine Chrome auto-update silently trojanized a productivity extension on a finance workstation at Halverson Logistics. The extension beaconed to an attacker C2 domain, harvested the analyst's session cookies and an API token, and exfiltrated them to a VULTR-hosted server. With no malware on disk, the proxy and firewall logs are the only trail. Walk them step by step to trace the beacon, the theft, and the exfiltration.