Investigate realistic cybersecurity attack scenarios
An internet-facing RDP server (RDP-BR-01) recorded over 3,000 failed login attempts against the Administrator account over the weekend, followed by one successful authentication early Monday morning.
Accounts payable clerk nramirez received an email appearing to come from a long-time vendor requesting an update to their bank routing number. The email came from a domain one character off from the real vendor domain. nramirez updated the payment record and a $42,000 invoice was paid to the new account before finance flagged it.
EDR flagged 600+ file rename events on FILE-SRV-04 within 8 minutes. No ransom note yet. The activity began 90 minutes after a suspicious macro-enabled attachment was opened by user tholt in the accounting department.
A sales rep, kbennett, who submitted a resignation two days ago, exported the entire customer contact database (14,000 records) from the CRM at 9:47 PM — well outside normal working hours.
WAF logs show repeated requests to the customer login endpoint containing SQL syntax patterns (' OR '1'='1, UNION SELECT). The requests originate from a single external IP and began escalating in complexity over 40 minutes.
A researcher notified the company that a storage bucket containing employee payroll exports was set to public-read. Access logs show downloads from three external IPs over the past 10 days before the bucket was locked down.
The employee SSO login page recorded 6,800 login attempts in 12 minutes using breached credential pairs. 11 accounts had matching passwords and were successfully authenticated before rate limiting kicked in.
A third-party inventory management agent pushed an unsigned update to 9 warehouse terminals at 2:15 AM. By morning, 6 of those terminals began beaconing to an unfamiliar external IP.
A standard user account rjohnson was added to the Domain Admins group at 10:05 PM on a weeknight by the admin_legacy service account. No change management ticket exists for this modification. The admin_legacy account has not been used in 7 months.
Workstation WS-042, belonging to the compromised jsmith account, transferred 2.3GB of data to external IP 198.51.100.50 over HTTPS. The transfer took 45 minutes. Normal daily upload for this user is under 50MB. This workstation was previously flagged for C2 beaconing.
A public-facing web server WEB01 running Apache 2.4.49 has a critical path traversal vulnerability (CVE-2021-41773) with known exploits available in the wild. The server hosts customer-facing applications and has not been patched.
Workstation WS-042 begins making repeated outbound HTTPS connections to IP 203.0.113.99 at exactly 60-second intervals. This pattern is consistent with Command & Control (C2) beaconing behavior. The same workstation was previously flagged for suspicious PowerShell execution.
After the jsmith account was compromised via brute force, the attacker logged into workstation WS-042 and executed encoded PowerShell commands. The commands attempted to download a remote payload from an external server and establish persistence.
During a routine vulnerability scan, it was discovered that the management interface of the primary firewall FW01 is accessible from the internet on port 8443 using a self-signed certificate. Additionally, brute force login attempts have been detected against this interface.
User mwilliams in the Finance department received a phishing email that appeared to come from IT Support requesting a password reset. The user clicked the link and entered credentials on a fake O365 login page. Two hours later, a login was detected from Lagos, Nigeria.
A user account belonging to jsmith receives multiple failed login attempts from external IP 185.220.101.45, followed by a successful login. The IP is known to be associated with a Tor exit node. After login, suspicious PowerShell commands are executed on the workstation.