Proactive Threat HuntAdvancedFree, no sign-up
The Slow Drip
A case from the Threat Hunting Lab
Briefing
No alert has fired. A sector intelligence advisory says peers of a fictional financial firm were quietly breached by an actor who favours signed tooling, disguised persistence and deliberately slow beaconing. You get four weeks of telemetry from a handful of treasury workstations and five hypotheses. Pick the ones worth testing, query the corpus, prove or disprove each, and write the detection that would actually hold.
878 events10 log sourcesabout 60 min
Solve this case
Opens the lab with this case selected. Graded in the browser; nothing to install.
What you will practise
- Hypothesis-driven hunting instead of alert-driven triage
- Finding low-and-slow activity without a volume threshold
- Telling legitimate scheduled and signed activity from abuse of it
- Mapping findings to techniques and writing a durable detection
Maps to these certifications
GCIAGCIHCySA+GCFA
Log sources in the corpus
EDR · Task Scheduler · Proxy · DNS · Windows Security · NetFlow · Email Gateway · Asset Inventory · Badge System · IAM
How a case works
- Read the briefing: the alert as the analyst received it, the environment and the time window.
- Work the console: search, filter and pivot across every source; open raw lines; pin evidence.
- Fill the investigation form and write a short executive summary. Hints are available and cost points.
- Get graded per item with the evidence behind each answer, then share your result card.