▸case-02 Our SOC team received threat intelligence about adversaries deploying image file execution options (IFEO) debugger backdoors and COM object hijacks. I need you to execute a threat hunting process for registry-based persistence in our environment. Provide the output structured with Hunt ID, MITRE technique, affected host, user account, telemetry evidence, risk level, confidence score, and recommended next actions. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 While analyzing registry modification queries, a hunter sees 100 hosts updating Run keys due to a Chrome enterprise update and 1 host updating a Run key from AppData\Local\Temp. Which workflow step involves distinguishing these benign baseline updates from genuine attacks? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-24 In what relative order should a threat hunter perform query execution against EDR platforms compared to result analysis in the hunt workflow? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 In the standard output format for hunt reports, which field specifies the operational actions to take, such as containment or monitoring? | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-23 Which SIEM platforms are explicitly recognized as primary log analysis destinations in the threat hunting setup? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 Why is detecting a registry write alone insufficient to confirm compromise, and what specific step in the hunt workflow connects host telemetry to execution logs and network traffic? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 During a purple team assessment, an engineer configured a Debugger string value under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options for sethc.exe. What MITRE ATT&CK technique code categorizes IFEO injection? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 We confirmed a malicious binary persistence entry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run pointing to C:\Users\Public\update.exe. Provide a PowerShell remediation script to remove the registry key, terminate the running process, and delete the payload file. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 A hunt on server FILE-SRV-01 revealed an unapproved edit modifying the Winlogon Shell value under account SYSTEM. Generate the completed threat hunt summary output block. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 During an incident response engagement, we dumped physical memory from a suspect host to analyze injected code in LSASS memory space using Volatility 3. Provide the Volatility plugin commands to inspect process memory and extract malicious code payloads. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 When our security operations team needs to collect deep endpoint artifacts and forensic evidence directly from Windows hosts during a hunt, which specialized artifact collection tool listed in the hunt tools table is designed for this purpose? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 A Defender for Endpoint query flagged an unexpected modification to the Winlogon Shell entry on domain controller DC-PROD-02. Please investigate this potential system-level persistence mechanism using our log sources and document your findings showing the hunt identifier, technique code, impacted system and user, correlated evidence, assessed risk level, confidence rating, and mitigation recommendations. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 We are building telemetry search rules for user-level auto-run startup keys added by malware after initial execution. What specific registry path under HKCU and what associated MITRE ATT&CK technique ID apply to standard Run key persistence? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 Our threat hunting unit wants to write detection rules that can be shared across heterogeneous SIEM and EDR tools including Splunk, MDE, and Elastic. Which detection rule standard listed in the toolset enables vendor-neutral rule writing? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 Telemetry on endpoint ENG-LAPTOP-15 indicated a user-level COM object InprocServer32 hijacking attempt for user mdev. Format the final hunt output block. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 A threat hunt identified malware adding a payload value to HKCU\Software\Microsoft\Windows\CurrentVersion\Run on endpoint WORKSTATION-12 for user jdoe. Produce the findings summary using the standard hunt report schema. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 We noticed suspicious registry modifications on host WORKSTATION-09 under the HKCU Run key following a phishing alert. Walk me through investigating this registry persistence attempt across our EDR and SIEM data, and give me a summary report including the Hunt ID, targeted technique, host name, user account context, evidence gathered, risk severity, confidence rating, and suggested containment steps. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 Our SIEM engineering team is verifying prerequisites before launching a registry hunt campaign. What specific endpoint log auditing utility must be configured and forwarded alongside Windows Security Event logs? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 When reviewing Sysmon telemetry ingested into a SIEM platform, which specific Sysmon event types record registry key creation and value modification events? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 Our Linux infrastructure team suspects an adversary established persistence on an Ubuntu web server using systemd timers or cron jobs. Outline the CLI commands and log files to inspect scheduled tasks and systemd service files on Linux. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 We want to start hunting for registry persistence mechanisms across our endpoint estate using Microsoft Defender. Should we immediately execute wide queries across all registry modifications, or what is the initial operational step in the hunt workflow? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 An adversary modified the Userinit string value under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon to execute a malicious payload at logon. What MITRE technique identifier corresponds to this persistence method? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 A hunt uncovered an IFEO key entry setting a Debugger binary for utilman.exe on host HOST-FIN-04. Provide the hunt output adhering strictly to the structured output template. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 Threat hunting telemetry flagged a non-admin account creating an InprocServer32 key path under HKCU\Software\Classes\CLSID to force a legitimate application to load a malicious DLL. What technique code classifies COM hijacking? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-25 What are the four valid severity options defined for the Risk Level field in the threat hunt output schema? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |