Practice guided SIEM investigations with step-by-step scoring and completion tracking
Each scenario simulates a real-world security incident. You'll be guided through the investigation step-by-step, just like a professional SOC analyst.
The helpdesk received a complaint from user jsmith claiming they were locked out of their account this morning. IT confirmed the account lockout policy triggers after 5 failed attempts. Your job is to investigate whether this was a user error or an external brute-force attack. NOTE: The 'Successful Login' events you may see in the logs are from jsmith's legitimate workstation (192.168.1.45) during normal business hours — before and after the attack. The attacker IP (185.220.101.47) never succeeded.
An automated alert flagged a successful login at 3:14 AM for user mrodriguez. This user works in the New York office (9–5 EST) and has never logged in outside business hours. The login came from IP 91.108.4.18, geolocated to Bucharest, Romania. Earlier that same day at 8:52 AM, mrodriguez had a normal login from 203.0.113.22 (NYC). Investigate whether this is a compromised credential.
A DLP (Data Loss Prevention) system flagged an unusual outbound transfer from a finance workstation. Before the transfer, a user named pwalker downloaded several ZIP files from an external file-sharing service during business hours. IT is asking whether this is a policy violation or potential data theft. Investigate the download and what happened afterward.
A newly deployed switch (SWITCH-FLOOR3) was discovered still using factory default credentials (admin/admin). A network scan from IT Asset Management found an external port scan targeting the device's management interface on 192.168.10.50. Determine if the device has been accessed by an unauthorized party.
The SOC received an alert: user cmorgan is receiving repeated MFA push notifications but says they are NOT trying to log in. This is an MFA fatigue attack — the attacker obtained cmorgan's password (likely via a previous breach) and is spamming MFA requests hoping the user accidentally approves one. Investigate whether any approval occurred.
HR submitted a termination ticket for employee bwilson (IT department) last Monday. The offboarding checklist shows their account was disabled in Active Directory. However, this morning the VPN logs show a successful connection from an IP geolocated to bwilson's home ISP. Investigate whether the account was fully disabled and whether any internal access occurred.
An internet-facing Windows Server 2016 (RDP-SRV-EXT) was left exposed on port 3389 without a VPN requirement. Over the weekend, an automated scanner identified it and performed a brute force attack. The account 'Administrator' was successfully compromised. By Monday morning, ransomware had been manually deployed. This is a classic 'big game hunting' initial access technique.
Azure AD Identity Protection fired an alert: 'Unusual sign-in activity — password spray detected.' Unlike brute force (many passwords against one account), password spray uses ONE common password against MANY accounts — staying below per-account lockout thresholds. The attacker tried 'Summer2024!' against 200 accounts and succeeded on 6. Identify the 6 compromised accounts and what was accessed.
Three employees in the Finance department (tbaker, lwilliams, and kpatel) received a spear-phishing email impersonating Microsoft 365 IT support, asking them to 're-verify' their credentials. Two of them (tbaker and lwilliams) clicked the link and entered their passwords into a fake login page. kpatel did not click. Within 20 minutes of the credential harvest, the attacker used those credentials from IP 185.130.44.108 to log in. Trace the full attack chain.
Your EDR tool flagged WKSTN-DEV-07 (used by dchen) making outbound connections to 104.21.44.72 every 300 seconds (5 minutes exactly). This regularity is the hallmark of automated C2 beaconing malware. The infection likely started when dchen opened a malicious macro-enabled Word document sent via email 3 days ago. The malware has been dormant until today. Confirm the C2 channel, identify execution method, and check for lateral spread.
HR notified the SOC that rthompson submitted their resignation 2 weeks ago with a last day of this Friday. The DLP system flagged a large file transfer from rthompson's workstation yesterday evening. Review the activity to determine if rthompson is stealing company data before departure — a common insider threat pattern known as 'data hoarding before exit'.
The accounts payable team received an email appearing to be from CFO glopez requesting an urgent wire transfer to a new vendor. The email passed SPF checks but came from a lookalike domain. AP clerk nfoster authenticated to the finance portal to process the transfer. The SOC was notified when the wire gateway flagged an unusual destination account. Trace the full BEC incident.
The SOC received an alert about svcReporting (a service account used for nightly report generation) executing commands outside its normal 2 AM window. At 11:34 AM, this account ran PowerShell commands on three different workstations. Service accounts should only run automated tasks — any interactive or out-of-schedule activity is suspicious.
A third-party IT management agent (MonitorPro v4.2.1) deployed on all company workstations pushed a silent update at 03:00 AM last night. By 09:15 AM, EDR began flagging unusual outbound connections from 12 machines that received the update. Threat intelligence reports that MonitorPro's update server was compromised and the update package was backdoored.
An alert fired on the Domain Controller (DC-01): an unusual number of Kerberos Service Ticket (TGS) requests were made by user hmartin within a 2-minute window. Normal users request 1-3 service tickets per session. hmartin requested 47 tickets across multiple service accounts. This pattern is consistent with Kerberoasting — extracting service account password hashes for offline cracking.
A security researcher notified the company that an S3 bucket named 'corp-backup-2024' was publicly accessible and contained employee PII and financial records. The bucket was created by developer fyang 3 months ago. Today, unusual download activity from an external IP was detected against the company's storage infrastructure before it was locked down.
Your customer-facing login portal (PORTAL-01) experienced a sudden spike of 4,300 login attempts in 8 minutes. The attempts use valid email formats but slightly different passwords — consistent with a credential stuffing attack using a leaked password database. 38 of those attempts succeeded.
FinOps flagged an unexpected 340% increase in cloud compute costs this month. Upon investigation, 8 cloud workload instances show CPU utilization consistently at 95-100%. This pattern is consistent with cryptomining malware using company cloud resources to mine cryptocurrency at the company's expense. Developer clee deployed these instances 3 weeks ago.
Over the past 72 hours, security sensors have detected a pattern of low-and-slow reconnaissance across the network. The attacker is deliberately staying under alert thresholds — scanning slowly, using legitimate tools, and impersonating service accounts to blend in. A port scan was detected from an internal IP (WKSTN-MKTG-11, user: jfoster) suggesting this machine has been compromised and is now the attacker's beachhead. The attacker appears to be targeting the Domain Controller (DC-01) and a high-value file server (FILE-SERVER-02). You have no hints — reconstruct the full attack.
At 14:23 today, the SOC received an automated critical alert: 847 file modification events on FILE-SERVER-01 within a 10-minute window. No ransom note has appeared yet, but the pattern matches pre-encryption staging — the attacker is enumerating and modifying file ACLs before encryption begins. The initial vector appears to be a suspicious download by agarcia 2 hours earlier. You have approximately 20 minutes before encryption begins. Act fast.
A critical zero-day vulnerability in the company's customer-facing web application was disclosed at 09:00 today. By 09:47, your IDS detected anomalous traffic patterns consistent with exploitation of this vulnerability against WEB-SRV-01. The attacker appears to have chained the web exploit with a post-exploitation framework. No patches are available yet. This is a live active exploitation scenario — investigate the full chain and recommend compensating controls.
At 22:47, an off-hours alert fired: a non-domain-controller machine (WKSTN-IT-11) performed a Directory Replication Service (DRS) request against DC-01. DCSync is a technique where an attacker mimics a domain controller to request ALL password hashes from a legitimate DC — effectively dumping the entire Active Directory password database. The attacker has likely already escalated to domain admin. You have no hints.
A healthcare provider's EMR (Electronic Medical Records) system went offline at 06:12 AM. Staff found a ransom note. Threat intel identifies the group as using double extortion — they exfiltrate patient data BEFORE encrypting, then threaten both the ransom and public data release. This is a HIPAA breach scenario. The initial vector appears to be a phishing email to EMR administrator gpatil 48 hours ago. You have no hints.
IT Director mstone was placed on a Performance Improvement Plan (PIP) two weeks ago. Yesterday evening, several critical production systems experienced simultaneous outages. Initial investigation suggests intentional sabotage — firewall rules deleted, database services stopped, and AD group policies modified. mstone has domain admin rights and knows the infrastructure intimately. You have no hints.
EDR detected an anomaly: several standard Windows tools (certutil.exe, regsvr32.exe, mshta.exe) were used in an unusual sequence on WKSTN-DEV-22 (user: dlee, a developer). These are legitimate Windows utilities — but when chained, they form a fileless attack chain that downloads and executes malicious code entirely in memory, leaving no files on disk for antivirus to detect. No AV alerts fired. You have no hints.
Users on the remote access VPN are reporting that internal sites are intermittently resolving to wrong IP addresses. The SOC suspects DNS hijacking targeting the VPN split tunnel configuration. VPN-GW-02 is processing DNS queries for both internal and external domains. An attacker may have poisoned the DNS cache on this gateway, redirecting internal auth traffic to a credential harvesting server.
Users in Building 3 are reporting intermittent connection drops and credential re-prompts for internal applications. Network team detected an ARP cache poisoning attack on VLAN 30 — a device (unauthorized laptop, MAC: 00:11:22:33:44:55) is impersonating the default gateway, intercepting traffic between workstations and the firewall. The attacker is harvesting credentials from unencrypted authentication traffic.
An anomalous alert fired for the company's Microsoft 365 environment: a registered OAuth application ('DataSync Helper') was granted unusually broad permissions by user epark, and has since been making API calls from an IP address in Singapore. OAuth token theft via malicious app consent is an increasingly common attack against cloud environments. No malware was involved — the user was tricked into granting permissions to a malicious third-party app.
Three R&D employees (nlee, kchen, sgupta) clicked links to a job portal site (jobboard-tech.net) shared in a Slack message. This site was compromised to serve a browser exploit targeting unpatched Chrome versions — a drive-by download silently installed a backdoor. The site targets R&D employees specifically, suggesting targeted industrial espionage. You have no hints.
The SOC detected an anomaly in Kerberos authentication: a Golden Ticket was issued with an unusually long validity (10 years) from DC-01. A Golden Ticket attack occurs when an attacker obtains the KRBTGT account hash (Active Directory's secret ticket-signing key) and forges Kerberos tickets granting access to ANY resource in the domain — indefinitely. This is the most severe Active Directory attack possible. You have no hints.