new
Enterprise
Defensive
New Threat Range Scenario: CertForge
CertForge is a compromised small company following a public WingFTP foothold.
The incident response team faces a critical security challenge after alerts reveal signs of a coordinated intrusion across public-facing Linux services and the internal Windows domain. They must quickly determine which events represent genuine attacker activity and which are expected administrator or deployment actions.
Your team must defend CertForge by:
- Triaging alerts and separating genuine compromise from routine administrator and deployment activity
- Reconstructing the attack chain from the public-facing WEB01 server into the internal Active Directory environment
- Investigating suspicious Linux, Jenkins, Windows, certificate services, and SMB activity
- Detecting AD CS ESC1 abuse and unauthorized Administrator access to DC01
- Identifying credential dumping, DCSync activity, persistence, and sensitive file collection
- Assessing the impact across compromised systems and escalating high-confidence findings
