Email-Borne IntrusionBeginnerFree, no sign-up
Invoice From a Stranger
A case from the Incident Investigation Lab
Briefing
An endpoint detection fires on a finance workstation at a fictional healthcare company in the middle of a normal working morning. Nobody has reported anything. You get the whole day of logs from seven sources and one question: is the detection real, and if so, how did it start, where did it spread and what left the building? Reconstruct the chain from the first email to the last byte out.
312 events7 log sourcesabout 40 min
Solve this case
Opens the lab with this case selected. Graded in the browser; nothing to install.
What you will practise
- Pivoting across Windows, Sysmon, proxy, DNS, firewall, EDR and mail-gateway logs
- Separating one attack chain from a day of benign activity
- Reading raw log lines for the detail the summary column hides
- Writing an executive summary a manager can act on
Maps to these certifications
Security+CySA+BTL1SC-200GCIH
Log sources in the corpus
Windows Security · Sysmon · EDR · Proxy · DNS · Firewall · Email Gateway
How a case works
- Read the briefing: the alert as the analyst received it, the environment and the time window.
- Work the console: search, filter and pivot across every source; open raw lines; pin evidence.
- Fill the investigation form and write a short executive summary. Hints are available and cost points.
- Get graded per item with the evidence behind each answer, then share your result card.