▸case-08 We want to start a threat hunt for insider credential misuse across our Windows domain endpoints. What is the initial operational step required before gathering data or executing SIEM queries in a hypothesis-driven hunting workflow? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 Review this Java Spring MVC controller endpoint for security bugs: `@GetMapping("/user") public User getUser(@RequestParam String id) { return jdbcTemplate.queryForObject("SELECT * FROM users WHERE id = " + id, User.class); }`. Identify the vulnerability and show how to fix it using parameterized queries. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 An employee accessed an AWS S3 bucket containing confidential engineering blueprints and downloaded 50 GB of data to a local workstation without authorization. Which specific MITRE ATT&CK technique ID corresponds to acquiring sensitive data directly from cloud storage objects? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 We noticed that a domain administrator account logged into an off-limits HR network share at 2 AM without an active maintenance ticket. I need an investigation executed to determine if this account activity represents an unauthorized insider threat. Format the resulting report with a hunting case ID, ATT&CK technique code, host name, account context, compiled log/process evidence, overall risk rating, confidence level, and recommended containment steps. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 During an insider threat investigation, after query results are analyzed and false positives are filtered out in validation, what analysis step connects the isolated finding to broader threat actor TTPs and attack chains? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-23 What is the final step in a standard hypothesis-driven threat hunting workflow after activity correlation across attack chains is completed? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 Our HR system flagged a software developer who recently submitted their resignation and is suddenly transferring large batches of repository archives to personal web storage. Can you run an insider threat hunt across our endpoint telemetry and SIEM logs to investigate this potential exfiltration? Please structure your final analysis to include a hunt tracking ID, the mapped MITRE technique, target host, user account context, key evidence, risk evaluation, confidence score, and suggested mitigation actions. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 Construct an automated Ansible playbook snippet to update all security patch packages on Ubuntu 22.04 LTS web servers using the apt module. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 Our network firewall is receiving thousands of SYN packets per minute from remote IP 198.51.100.45 targeting exposed SSH ports on host edge-gw-01. Generate a Cisco ASA firewall CLI command set to permanently drop all inbound traffic from this IP address on the perimeter interface. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 When setting up a SIEM environment to hunt for insider threats on Windows enterprise hosts, what key operating system log forwarding feature must be enabled in addition to Sysmon? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 Service account svc-sql-reporting was used to execute bulk SELECT queries against employee PII tables outside its normal batch execution window. Format the hunt analysis block using the standard key-value output template. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 A external contractor on machine WS-DEV-08 was observed uploading proprietary source code archives to a personal cloud storage bucket. Summarize the incident findings using our standard hunt tracking report template, providing the exact MITRE ATT&CK code for cloud data staging/exfiltration. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 We need to author detection rules for insider data stage-and-ship behaviors that can be shared across both our Elastic Security and Splunk SIEM environments without rewriting them from scratch. What cross-platform detection rule specification format should be used? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 We confirmed a high-risk insider threat event where a system engineer copied IP databases to personal cloud storage. Produce the hunt tracking summary block, ensuring the risk level field uses standard severity tiers. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 An enterprise developer submitted formal notice of resignation and immediately began downloading thousands of proprietary repository zip files. Create the standard hunt record block for this event, assigning host DEV-LAPTOP-12 and user corp\jdoe. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 After formulating a hypothesis about an IT administrator abusing elevated privileges to access sensitive HR shares, what step should immediately follow data source identification before analyzing query results? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 An insider logged into active domain accounts using legitimate credentials obtained from compromised system files to traverse internal shares. Which MITRE ATT&CK technique ID covers the use of valid accounts? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 A departing marketing director uploaded customer CRM databases to an external web-based file transfer site via HTTPS POST requests. Which MITRE ATT&CK technique code represents exfiltration over a web service? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 An automated database service account was detected executing unusual bulk export queries against sensitive financial tables from an unfamiliar desktop IP. Hunt across our Windows security logs and SIEM data to determine if this service account is being abused. Present the findings using a standard summary containing the hunt tracking reference, technique ID, host details, user/account context, log evidence, risk level, confidence assessment, and recommended next steps. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 Provide the final output block for an insider threat hunt on host WS-FIN-04 involving account corp\bsmith. The recommended action must select from standard response categories. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 Our SOC team needs an open-source endpoint tool to pull forensic artifacts, process memory, and MFT records directly from a remote host suspected of insider source code theft. Which artifact collection and threat hunting tool fulfills this requirement? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 To detect detailed process execution trees, command-line parameters, and network connections on Windows endpoints for insider threat hunting, what specialized Microsoft system monitoring service should be deployed alongside standard Event Forwarding? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 A network administrator used domain admin rights to access confidential compensation spreadsheets on the HR server HR-FS01.corp at 3 AM. Format the threat hunt outcome according to our standardized key-value block format. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |