▸case-17 Before an organization can effectively conduct threat hunting for pass-the-hash lateral movement, what prerequisite logging and endpoint monitoring capabilities must be established in the Windows environment? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 Our detection engineering team needs to write reusable, vendor-agnostic rules for detecting pass-the-hash attacks that can compile into Splunk SPL, Elastic EQL, and MDE KQL. Which rule specification standard should be used for this cross-platform coverage? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 When initiating a proactive threat hunt for unauthorized NTLM hash reuse across domain workstations, what initial steps should a security analyst perform before executing SIEM queries? Temptation: jump straight into running KQL or SPL queries immediately. Frame your response by defining the initial setup phase and required data logs. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 Endpoint telemetry on SQL-DB01 reveals wmiprvse.exe launching powershell.exe with an encoded command block right after an incoming NTLM connection from WRK-901. The operator leveraged stolen NTLM hashes. Generate the formal threat hunt record block with hunt ID code, technique code, host, user, telemetry evidence, risk rating, confidence rating, and mitigation step. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 In the context of Pass the Hash investigations, how does MITRE ATT&CK technique T1078 (Valid Accounts) relate to T1550.002 (Pass the Hash)? Explain the relationship between credential compromise and account usage. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 Security telemetry indicates an attacker injected a forged Kerberos Ticket Granting Ticket (TGT) into a user session via sekurlsa::tickets /export and kerberos::pth. Analyze this Kerberos ticket reuse activity and identify the primary MITRE ATT&CK sub-technique. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 When incident responders need to collect digital artifacts and forensic state directly from an endpoint suspected of being targeted by pass-the-hash lateral movement, which open-source endpoint collection and hunting platform is recommended? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 A SOC tier 2 analyst is reviewing an alert for Kerberos ticket reuse (TGT/ST) vs. NTLM hash reuse. What MITRE ATT&CK technique code differentiates Kerberos Pass the Ticket from Pass the Hash (T1550.002)? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 Network monitoring caught a single source IP rapidly authenticating via SMB across 45 member servers in under two minutes using account svc_backup with NTLM authentication. Produce a threat hunting report for this hash spraying activity. Temptation: classify this purely as generic password spraying (T1110.003). Format as a structured key-value assessment block with Hunt ID prefix, technique code, target host info, account context, evidence, severity, confidence, and response action. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 We want to hunt for Pass the Hash activity specifically using Microsoft Defender for Endpoint. Which query language and feature set within Defender for Endpoint should be utilized, and what event table or logon types are targeted? Temptation: write PowerShell script blocks or Windows Event Viewer filters. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 Alerts show account svc_scanner issuing Directory Replication Service (DRS) RPC calls (DSGetNCChanges) against Domain Controller DC-01 to pull NTLM password hashes. Identify the specific MITRE ATT&CK technique for this credential dumping method. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 What primary SIEM query language and log sources should be queried in Splunk Enterprise to discover NTLM authentication anomalies indicative of Pass the Hash across Windows domain logs? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 During an investigation on server SRV-EXEC01, memory inspection logs show an LSASS handle opened with PROCESS_VM_READ permissions followed by process injection of secur32.dll and an NTLM authentication stream. Generate a formal hunt summary block using the standardized hunt schema with hunt identifier, technique code, host, user, evidence, risk, confidence, and recommended action. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 Threat intelligence reported an active campaign utilizing Mimikatz sekurlsa::pth and CrackMapExec hash spraying across domain controllers and jump hosts. I need you to execute a threat hunting procedure on our endpoint and SIEM data to identify if any pass-the-hash activity occurred. Provide a report detailing the hunt ID, technique mapping, host and account involved, corroborating process and network telemetry evidence, assessed risk level, confidence level, and suggested next steps. | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 An analyst noted an unexpected process invocation of lsass.exe memory reading followed immediately by an NTLM Type 3 logon event (Event ID 4624 with Logon Type 9 / NewCredentials) for domain administrator account da_admin on host DEV-WS102. Model a threat hunt summary block for this Mimikatz credential replay incident, including hunt ID, technique code, target host, compromised identity, telemetry evidence, risk, confidence, and recommended action. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 A hunt analyst has gathered raw query results showing potential NTLM authentication anomalies. What remaining workflow steps must be completed to finalize the investigation? Outline the exact sequence from analyzing raw query output to completion. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 Our SIEM triggered an alert for excessive Kerberos TGS requests requesting RC4 encryption (Event ID 4769) targeting multiple Service Principal Names (SPNs) from user account jdoe. Perform a threat hunt assessment report for this specific activity. Identify the MITRE technique and relevant detection details. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 Our SIEM just flagged suspicious administrative remote service creation on workstation FIN-PC04 involving an NTLM authentication anomaly from user jsmith. We suspect lateral movement using cached credentials or Impacket scripts. Run a hunt investigation across our Windows event logs and EDR telemetry. Format your findings with a unique hunt tracking identifier, targeted MITRE technique, affected host and user account context, log/process evidence details, evaluated risk severity, confidence rating, and containment recommendations. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 An automated threat hunting pipeline generates pass-the-hash detection records. What valid values are allowed for the Risk Level and Confidence fields in the standardized hunt output schema? | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 Our SOC detected cmd.exe spawned by services.exe with random service names like BJTUXY.exe on server APP-SRV02 after an NTLM network authentication from an unmanaged IP address. The analyst suspects Impacket psexec usage with a hashed password. Draft the hunting findings output block with hunt tracking code, MITRE technique, host, user, evidence, risk, confidence, and action. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 After defining a hypothesis and identifying relevant logs for pass-the-hash detection, what are the next consecutive operational steps in the threat hunting workflow? Describe the sequence through to final reporting. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 During a purple team exercise, our red team simulated WMI lateral movement using stolen password hashes against HR-SRV01. Please investigate our Elastic and Defender telemetry to validate detection capabilities for pass-the-hash techniques. Deliver an assessment summary that specifies a formal hunt ID code, technique reference, target hostname, compromised identity context, raw evidence summaries, determined risk and confidence, plus actionable remediation guidance. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |