Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-SOC1-LAB-012Medium
Browser LabLD-SOC1-LAB-012Medium20 min

First Moves on a Confirmed Incident

EDR has CONFIRMED a compromise on WS-042: a finance user clicked a phishing link, PowerShell ran, and the host is beaconing to an external controller right now. The user has access to the payment system. The incident is real — your job is the first moves. Make each response decision in the right order: what to preserve, how to contain without destroying evidence, what NOT to do yet, and how urgently to escalate.

What you will be able to do

  • Preserve volatile evidence before acting
  • Choose a containment that stops the attacker without destroying evidence
  • Respect the response order and escalate with the right urgency
Incident TriageAnalyst ReportingT1566.002Phishing: Spearphishing LinkT1071.001Application Layer Protocol: Web Protocols

Sign in to start this lab.

Sign in