Analyst Tier 2
Free to learnPro rangesIncident Response
Where triage becomes response. A single alert is rarely the whole story, and this stage is about reconstructing the intrusion behind it across hosts and time, deciding what to contain first, and telling the full story of what happened once it's over.
What this stage covers
- The incident lifecycle: detection, triage, containment, eradication, recovery
- Reconstructing a multi-stage intrusion from scattered telemetry
- Deciding containment order under time pressure
What you should be able to do
- Pivot across hosts and log sources to rebuild an attack chain
- Identify patient zero and the blast radius around it
- Prioritise containment when everything looks urgent
The path through it
Work these in order. Every page is free to read and needs no account.
Ranges in this stage
Live networks, breached for real, graded automatically.
Operation Silverfish
IntermediateA phished workstation leads to AD recon, a Kerberoasted service account, lateral movement to the file server, and payroll exfiltration. Reconstruct it from Elastic and contain patient zero.
~40 min · Available now
Operation Nightjar
IntermediateA helpdesk ticket, no alert, and an unfamiliar name in Domain Admins. Work backwards through four hosts to reconstruct how it got there -- and find the evidence the attacker tried to destroy but did not.
~60 min · Available now
Operation Locust
AdvancedA malicious file execution opens into host discovery, a scheduled task for persistence, credentials pulled from LSASS, lateral movement over WinRM, and DNS command-and-control used to carry the data out. A longer chain than Silverfish, with the exfiltration hidden in traffic that looks routine.
Available now
Every technique these stages touch is written up in the TTP Catalog, which spans all three tiers rather than belonging to any one of them.