▸case-06 We are auditing our email domain security records to prevent external attackers from spoofing our company domain in phishing emails. Provide instructions for configuring SPF, DKIM, and DMARC DNS TXT records. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 An attacker gained administrative control over a mailbox and added delegate access permissions for a rogue user account to harvest incoming mail covertly. Which specific MITRE ATT&CK sub-technique ID covers adding delegate permissions to email accounts, and what is its official technique name? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 We want to write detection rules for inbox forwarding creation that can be converted automatically into Splunk SPL, Elastic EQL, and Microsoft Sentinel KQL. Which cross-platform detection rule format should be used for sharing these signatures? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 Threat intelligence indicates an active campaign where compromised accounts set up silent inbox rules to delete security alerts and forward financial communications. Run a threat hunt workflow across available logs to check if any user accounts in our tenant show this activity. Present the output outlining the hunt ID, technique ID, target host, user context, technical evidence details, assigned risk level, confidence score, and recommended next steps. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 During an executive account audit, analysts noticed an inbox rule set up on the CEO's mailbox that silently redirects messages containing 'wire transfer' or 'confidential' to an external domain. Which key scenario covers CEO email inbox rule exfiltration? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 We are structuring a threat hunt for malicious inbox rules across our enterprise. Security analysts are debating whether to jump straight into running KQL/SPL queries against log repositories or to start by formulating a testable hypothesis based on threat intelligence. What is the initial step in the standardized threat hunting workflow? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 During an investigation, we discovered an adversary pulling archived mailbox items remotely using IMAP/POP3 connections from an external IP address after obtaining user credentials. Identify the MITRE ATT&CK sub-technique ID specifically associated with remote email collection. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 We received an alert regarding a potential business email compromise where an inbox rule might have been configured to route internal executive messages to an outside webmail provider. Please conduct a threat hunt across our SIEM and EDR telemetry to verify whether email redirection or forwarding rules were injected. Format your findings with a Hunt ID, the ATT&CK technique code, affected hostname, user account context, log/network evidence gathered, risk rating, confidence level, and suggested containment steps. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 An analyst completed a hunt finding where an internal mailbox had a hidden rule forwarding all messages to a temporary webmail address. Generate the standardized hunt report summary block for host 'WORKSTATION-01' and user 'jdoe@corp.com'. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 Our team needs to write advanced threat hunting queries against Microsoft Defender for Endpoint telemetry to detect command-line inbox rule creation via PowerShell. What query language and platform tool pair is designed for this advanced hunting activity? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 An employee received a suspicious email containing an attached macro-enabled document (invoice.docm). We need to analyze this file to extract VBA code and determine if it drops a malware payload. Detail the static and dynamic analysis steps required. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 After correlating detected forwarding activity with an external command and control domain and identifying the compromised user account, what is the final step in the threat hunt workflow before closing the hunt ticket? | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 An analyst executed SIEM queries for email forwarding events and gathered 500 raw log hits. Many analysts confuse the step where query results are examined for anomalies with the subsequent step where true positives are separated from false positives using contextual analysis. What are these two sequential steps in order? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 Security monitoring alerted on a third-party OAuth application that requested broad Exchange Online scopes and created tenant-wide mail flow rules to exfiltrate sensitive messages. Which scenario category describes OAuth application abuse creating transport rules for data collection? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 Before launching an enterprise hunt for mailbox configuration changes, what central SIEM platforms are standard prerequisites for log data ingestion and correlation? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 A compromised user account had a rule created with conditions matching subject lines like 'Security Alert', 'Password Reset', or 'Multi-Factor Authentication' to move them immediately to Deleted Items. Which scenario describes this tactic? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 During our monthly purple team review, we need to search for unauthorized mail collection and forwarding setup across our cloud mail environment. Please investigate the telemetry for rogue inbox rules or added delegate permissions. Provide a structured summary report containing the Hunt identifier, technique reference, host and user involved, supporting evidence logs, risk severity, assessment confidence, and recommended remediation action. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 Our SIEM generated an alert for a high volume of Kerberos TGS-REQ ticket requests with RC4 encryption targeting service accounts from a domain-joined workstation. Please analyze this Kerberoasting activity (T1558.003) and provide remediation steps for service account security. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 We are setting up Windows Security Event Logging and SIEM ingestion to hunt for endpoint process activity related to mail client modifications. What detailed Windows process monitoring utility and configuration should be deployed on endpoints as a core prerequisite? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 We want to analyze centralized Exchange audit logs in our enterprise SIEM to find user account rule creation spikes over a 30-day window. Which SIEM platform and associated query language are specified for log analysis in this environment? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 When performing digital forensics on an endpoint suspected of hosting automated scripts that manipulate mail settings, which artifact collection tool is designated for endpoint hunting and forensic collection? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 An analyst has formulated the hypothesis that attackers are leveraging PowerShell scripts to add mailbox rules. Before writing any search queries, what workflow step requires determining which specific log feeds and EDR telemetry fields are needed? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |