Spray ‘n’ Pray
is a multi-host intrusion scenario that simulates a simple privilege escalation from a workstation compromise to a server admin compromise via a brute force attack.
The intrusion starts with an already compromised workstation, and teams are tasked with extracting key information from the SIEM and retrieving files from the compromised endpoints to help understand the scope of the attack.
Throughout the scenario, teams will hunt for:
  • Suspicious file downloads
  • Brute Force password attacks
  • Lateral Movement
  • Living off the Land attacks
  • OS Credential Dumping
Screenshot 2025-12-01 at 12