Skip to main content
VPN Brute Force: Credential Attack on the Remote-Access Portal operation cover
BeginnerSIEMFirewall

VPN Brute Force: Credential Attack on the Remote-Access Portal

A password-spray campaign targets the Halcyon Freight SSL-VPN portal from two rotating source IPs, submitting credentials across many accounts to stay under per-account lockout thresholds. One account eventually matches. Reconstruct the spray, identify the compromised account and the operator IP that opened the active session, and trace the first move the attacker made over the tunnel.

25m
6 tasks
25 points
Free

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Identify the attack pattern in the VPN logs

15

Something unusual is happening at the remote-access portal this morning. Before the team escalates, establish what kind of activity you are looking at.

SOC{Txxxx.xxx}Hint available
2

Determine how many accounts were targeted

10

The spray hit more than one account. Establish the exact count of distinct account names that appear in the failure events from the 185.159.0.0/24 block.

SOC{number}Hint available
3

Find the account where the spray succeeded

15

One account in the target list had a password that matched. Identify it.

SOC{firstname.lastname}Hint available
4

Identify the IP that opened the active session

15

After the spray found a working credential, the attacker shifted to a different IP to establish the actual VPN session. Find that source address.

SOC{a.b.c.d}Hint available
5

Trace the movement over the tunnel

20

Within minutes of gaining VPN access, the attacker began probing inside the network. Determine which internal host they attempted to reach and over which protocol.

SOC{HOSTNAME}Hint available
6

Classify the access technique

15

The attacker used legitimate stolen credentials to gain access through the VPN portal. Map this to the MITRE ATT&CK technique for using valid accounts to authenticate to external services.

SOC{Txxxx}Hint available

6 tasks · 90 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
Firewall log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Beginner

Ideal for newcomers to SOC operations. Guided investigation with clear indicators.

Prerequisites

  • No prior experience required
  • Familiarity with SIEM concepts
  • Familiarity with Firewall concepts

Ready to investigate?

More Operations

View all