Active Threat Hunt: SPECTER-STORM
Ingest emergency IoCs, query the SIEM, and triage a potential state-sponsored supply chain compromise within a defense contractor's network.
Deploy into high-fidelity environments // earn cryptographically signed credentials.
Ingest emergency IoCs, query the SIEM, and triage a potential state-sponsored supply chain compromise within a defense contractor's network.
During advance work for a visiting government official, the EP team uncovers a credible physical threat at the primary venue. Coordinate with local LE and venue management to adjust tactics and secure the perimeter.
Analyze industrial protocol traffic and IoT firmware to detect and contain unauthorized CIP commands originating from environmental sensors in a critical oil refinery.
Navigate a corporate crisis at Velox Technologies LLC where high employee turnover and escalating phishing susceptibility require a complete overhaul of security onboarding and compliance mapping.
Conduct forensic threat modeling and secure code review on a proposed cloud-native citizen tax portal to identify complex business logic flaws and SAST misconfigurations before deployment.
Investigate suspicious checkout anomalies by auditing GraphQL endpoints, reviewing JavaScript frontend code, and validating XSS mitigations.
Defend Crestline SecureOps Corp's isolated logistics planning servers from an active internal network pivot and PowerShell-based domain enumeration attack originating from a compromised vendor account.
Investigate unauthorized system changes and logical access anomalies discovered during a SOC 2 Type II readiness ITGC audit at Altis SecurePay Inc.
Investigate privileged access anomalies and verify HR background check compliance to secure SOC 2 Type II readiness ahead of an external audit.
Investigate anomalous API traffic originating from a hardened bastion host, right-size CIEM permissions, and tune SIEM rules to prevent unauthorized financial transactions.
Investigate severe CPU spikes across global Point-of-Sale terminals, utilizing EDR, memory forensics, and SIEM correlation to uncover a supply chain compromise.
Investigate unauthorized after-hours physical access by analyzing BMS logs, SCADA physical tampering evidence, and reverse-engineering IoT smart locks.
Investigate anomalous encrypted tunnels, deploy Python automation to sever malicious connections, architect a Zero Trust enclave, and author CMMC-compliant security policies to prevent recurrence.
Respond to an automated cyber assault targeting cloud-native infrastructure by enforcing AWS SCPs, leveraging CSPM for attack surface identification, and deploying CWPP runtime controls.
Investigate a compromised CI/CD pipeline, remediate malicious Kubernetes IaC manifests, and enforce least privilege in cloud IAM policies.
Investigate severe configuration drift in a production web fleet. Determine if the drift is a threat actor breach or an errant deployment script from a vendor, and apply infrastructure hardening to restore the immutable baseline.
Analyze anomalous outbound container traffic, isolate the workload using CWPP, and revoke an over-provisioned service principal via CIEM to halt lateral movement.
Investigate an incomplete offboarding script execution that left a terminated senior engineer with active GCP BeyondCorp tokens and physical RFID access to a classified lab.
Investigate compromised executive protection routes, suspected surveillance detection route (SDR) failures, and tactical radio breaches during a VIP tour in a volatile region.
Contain a rogue multi-region AWS deployment by securing IaC templates, hardening Linux AMIs, and enforcing strict GovCloud SCP boundaries.
Respond to an accidental IT/OT network bridge during maintenance, restore segmentation, and strictly enforce LOTO protocols to ensure engineering safety.
Analyze SIEM logs and perform malware analysis to identify patient zero and extract containment IoCs following a ransomware deployment on a clinical file share.
Investigate a high-severity impossible travel alert where a senior physician's physical badge and cloud identity are simultaneously authenticated from geographically impossible locations.
Following a near-miss data exfiltration by a departing contractor, overhaul human risk protocols, update Acceptable Use Policies, and design a targeted security awareness module in collaboration with HR and Legal.
A ransomware strain is spreading through the legacy IoT network of a critical healthcare facility. Analysts must perform PCAP analysis, implement Zero Trust policies, and automate IOC ingestion to halt the infection.
Investigate anomalous internal traffic indicative of lateral movement, analyze PCAPs using Python, and enforce a Zero Trust micro-segmentation policy to secure the fintech gateway.
Respond to a severe forklift accident at a logistics hub. Secure the loading bay, navigate the electronic key management system to retrieve trauma kits, and apply life-saving hemorrhage control while managing site security.
Respond to a critical physical access control failure trapping personnel in a restricted hospital zone. Secure the BMS, audit SCADA interfaces, and execute emergency LOTO protocols.
Conduct a forensic audit of a new healthcare REST API for BOLA vulnerabilities, execute Software Composition Analysis (SCA), and prioritize CVEs using SSVC.
An unannounced late-night delivery truck arrives at a critical water treatment facility. The user must intercept the driver, audit the manifest, and ensure the master key control box remains secure.
Conduct a post-mortem forensic audit following a successful red team bypass of GCP BeyondCorp controls via dormant zombie accounts.
Contain an active lateral movement campaign pivoting from Azure AD corporate environments to GCP SCADA telemetry processing environments.
Investigate and prioritize critical vulnerabilities in the NEXUS-GRID payment gateway codebase before the release candidate is compiled.
Conduct comprehensive SCA and DAST triage on Ultralink Technologies' SaaS platform, auditing internal REST APIs for authorization flaws linked to third-party integrations from Stratos Enterprises LLC.
Manage an escalating unpermitted protest outside a corporate administrative center. Coordinate CCTV monitoring, deploy physical barriers, and execute verbal de-escalation tactics against a hostile splinter group attempting to breach the main gate.
A forensic investigation into a missing master key ring at a Sigma StoreFront LLC distribution center, requiring CCTV analysis and immediate lockdown procedures.
Investigate a critical insider leak compromising the travel itinerary and venue security of a controversial public figure.
A high-threat tactical response scenario where operators must navigate an active ambush, perform Tactical Emergency Casualty Care (TECC) under fire, and extract a VIP from a compromised urban zone.
A macro-enabled attachment bypasses the SEG at a fintech firm. Analysts must triage the phishing vector, analyze the payload, and isolate the endpoint via EDR before lateral movement compromises the SWIFT gateway.
An active assumed-breach scenario where an unauthorized actor is utilizing offensive PowerShell techniques from a compromised vendor subnet to pivot toward an isolated medical records enclave.
Investigate anomalous SSH exfiltration on a government server by analyzing Splunk logs, interrogating suspects, and triaging lateral movement.
Coordinate tactical radio communications and execute surveillance detection routes to protect a high-profile medical researcher from hostile corporate interception.
Investigate massive entitlement sprawl and unauthorized privilege escalation across a multi-cloud environment following a recent audit. Use CIEM to identify zombie accounts, engineer granular IAM policies, and implement AWS SCPs.
A suspicious email claiming to be a mandatory policy update targets the HR department. Analysts must triage the threat, utilize tactical intelligence feeds, and prevent a ransomware outbreak threatening patient genomic data.
Validate the security posture of Solara Commerce AG's upcoming holiday promotional site. Identify and triage DAST findings, intercept web traffic, and confirm XSS and SQLi vulnerabilities before launch.
Track and contain an authorized red team simulating an insider threat using PowerShell to pivot toward a restricted HR subnet.
Secure newly deployed automated mixing vats at Dendron InfraOps GmbH by hardening PLCs, securing physical SCADA interfaces, and enforcing rigorous Lock-Out Tag-Out (LOTO) protocols during an active cyber-physical incident.
Investigate anomalous PII data flows and third-party KYC vendor baseline failures during a major NIST CSF implementation at a cryptocurrency exchange.
Investigate a critical intelligence leak concerning the CEO's high-risk travel itinerary and secure the operational footprint before arrival.
A major retail distribution center's refrigeration units are failing simultaneously due to a compromised BMS. Isolate the HVAC controllers to prevent millions in perishable goods loss.
Investigate erratic behavior in a healthcare provider's automated medication dispensing system. Intercept MQTT/DNP3 traffic, perform IoT security testing, and lead OT incident response to eradicate malware without disrupting critical patient care.
A high-level corporate motorcade is ambushed. Operators must execute emergency driving, neutralize the threat, apply TECC to casualties, and manage law enforcement liaison.
An executive protection detail is ambushed via IED en route to a remote critical infrastructure site. The EP agent must repel attackers, administer TECC, and coordinate extraction.
Conduct a time-critical pre-integration WAN penetration test against Helios SecureOps SA to identify and safely exploit legacy vulnerabilities before network integration.
Investigate a sophisticated credential stuffing attack during peak Black Friday operations by correlating UEBA alerts, Azure Conditional Access logs, and physical turnstile data.
Investigate unapproved SCADA architecture changes, enforce Purdue model segmentation, and harden PLCs at a regional water treatment facility.
Respond to anomalous Modbus traffic originating from an engineering workstation at a defense manufacturing plant. Identify malicious payloads, execute safe OT incident response, and harden targeted HMIs without halting the assembly line.
Evaluate OT network upgrades at Redline UtilityCo PLC, focusing on NIST CSF implementation, ITGC backup testing, and SCADA data mapping amidst suspected unauthorized vendor access.
Investigate a massive spike in public-facing S3 buckets following a cloud architecture update. Tune SIEM alerts to filter legitimate auditor traffic and engineer strict IAM policies to secure the exposed fintech data.
Execute an authorized red team engagement against Parallax PipeCore BV's corporate IT boundary to validate OT segmentation controls using advanced Nmap scanning and Metasploit.
Investigate a tailgating incident and forced-door alarm while managing a concurrent medical emergency.
Provide close protection for the Praxis ClinTech LLC CEO in a bustling hospital environment. Execute SDR, use tactical radio comms, and de-escalate an aggressive confrontation from an Apex GenomicVault SA affiliate.
Secure the CI/CD pipeline and tune SIEM rules during a live CWPP integration to prevent false positives and block a malicious deployment.
Conduct a dynamic application security test on the new Stratos CapitalLink payment portal, intercepting traffic to identify SQLi and XSS vulnerabilities before launch.
Evaluate a new cloud EHR vendor and map PHI data flows to uncover a critical compliance failure aligned with the NIST CSF.
Execute authenticated vulnerability scans, advanced Nmap fingerprinting, and non-disruptive Metasploit validation against Sigma AuditCore BV's external infrastructure.
Execute a dynamic patrol and crowd management response to a localized fire alarm at a major healthcare campus, mitigating bottlenecks and contractor interference.
Investigate anomalous outbound traffic from a critical SCADA gateway. Utilize Splunk SPL, analyze PCAP data, and perform memory forensics to identify data exfiltration and uncover the root cause.
Secure a hybrid cloud SCADA migration from unauthorized vendor access by hardening Linux control nodes and enforcing Zero Trust Architecture.
Perform PASTA threat modeling and SQLi validation on a modernized SCADA web interface during an active database exposure incident.
Investigate a suspected pivot from newly installed IoT smart cameras into an isolated SCADA network at a defense contractor R&D lab.
Investigate a highly targeted spear-phishing campaign against corporate executives, detonate suspicious attachments, and trace the blast radius using Splunk SPL.
During a chaotic night shift, GSOC operators must filter false alarms, track an active intruder via CCTV, and vector physical patrols across the Vortex ClearVault campus.
A massive crowd breaches the primary barricades during a holiday sale event at Stratos LogiPath Corp, resulting in a trampled shopper suffering cardiac arrest. Contain the crowd, de-escalate hostile shoppers, and perform life-saving CPR/AED deployment.
Conduct a STRIDE threat modeling session, implement SAST gates, and deploy SCA to secure a defense logistics application from a compromised vendor library.
Execute a rapid DAST and manual proxy assessment on a pre-production CRM, identifying critical SQLi and DOM XSS vulnerabilities before deployment.
An EDR alert triggers on a trading floor workstation at Praxis SecurePay SA, indicating suspicious PowerShell execution. Analysts must investigate endpoint telemetry, analyze network traffic for C2 beacons, and cross-reference tactical threat intel feeds to contain the breach.
Respond to an active cross-cloud exfiltration attempt where a rogue service account is bypassing GCP BeyondCorp IAP to steal high-frequency trading algorithms.
Investigate a critical Third-Party Risk Management (TPRM) failure during a major e-commerce expansion, mapping vendor SOC 2 anomalies to internal compliance frameworks.
Respond to an agitated individual bypassing visitor management to access a restricted Emergency Department ward, triggering access alarms. De-escalate the conflict and secure the facility.