Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-SOC2-LAB-006Hard
Browser LabLD-SOC2-LAB-006Hard22 min

Turn an Alert Into Intelligence

An alert fired on a finance workstation that opened an invoice-lure attachment and then beaconed out. Your CTI platform enriches the indicators against a synthetic actor profile. Read the enrichment, judge the attribution, and decide the next action.

What you will be able to do

  • Name the intelligence move that adds actor context to a raw alert.
  • Populate a Diamond Model vertex and judge attribution confidence.
  • Map the initial-access TTP and choose the proactive next action.
Threat IntelligenceIOC AnalysisT1566.001Phishing: Spearphishing AttachmentT1071.001Application Layer Protocol: Web Protocols

Sign in to start this lab.

Sign in