Defender XDR series · Lab 1 of 5 · Advanced

Triage a correlated incident the way a Tier 2 analyst does

Operation NIGHTBLOOM has produced one Defender XDR incident spanning a mailbox, a Windows 11 endpoint and an on-premises service account. You have 75 minutes of analyst time: filter the queue to the real signal, prove the attack story, hunt for the rest of the blast radius, contain it under change control, and close it with a classification you could defend in an audit.

Required
This is a console replica, not Microsoft software.

The layout, page names and control labels model the 2026 Microsoft Defender portal at security.microsoft.com so the workflow transfers. No tenant is connected, no API is called, and every device, account, alert, file name and address below is synthetic. Product names are used only to describe the workflow; no Microsoft logo or trade dress is reproduced.

Alerting sources

What the tenant saw

High
Incident
INC-2291 · id 2291
Title
Suspicious PowerShell activity and mailbox rule creation on FIN-WKS-0421
First activity
2026-08-19 09:34:11Z
Last activity
2026-08-19 11:58:02Z
Detection sources
Defender for Endpoint Defender for Office 365 Defender for Identity
Alerts
6 correlated · 4 pending Air
Entities
1 device · 2 accounts · 1 mailbox · 1 file · 2 URLs
Blast radius
medium · 1 of 3 shared-service hosts reached
Confirmed true threat Needs analyst judgement Simulated / safe
Objectives · 100 points

Seven controls you must evidence

  • Intake & priority · 10 ptsConfirm the queue scope, set the priority you can defend, record the on-call owner.
  • Queue filtering & ownership · 15 ptsFilter to High severity, New status and the Endpoint source; claim the incident.
  • Attack story & blast radius · 20 ptsIdentify initial access, the correct ATT&CK technique set, and the pivot evidence.
  • Advanced hunting (KQL) · 15 ptsWrite a bounded, reproducible query that finds every host running the loader.
  • Contained response · 15 ptsIsolate, quarantine the artefact and collect evidence — in the right order, with approval.
  • Classification & closure · 15 ptsResolve with a true-positive classification, threat type, tags and a note that passes review.
  • Regulatory escalation decision · 10 ptsDecide which notification clocks apply to this entity and who owns each filing.

Objectives unlock in order — containment is locked until you have justified it in the hunt, exactly as a real change-advisory boundary works. Your score, notes and action log stay in this browser.

Standards used by this lab

Every step maps to a control

FrameworkControlWhere it is graded
NIST SP 800-61r3Preparation · Detection & analysis · Containment · Post-incidentAll seven objectives
MITRE ATT&CK v17T1566.001, T1059.001, T1114.002, T1021.002Attack story, hunt
ISO/IEC 27035-2Scope decision, evidence, escalationEscalation decision
NIS2 Art. 23 / DORA Art. 1924h · 72h · 1-month / 4h clocksEscalation decision
GDPR Art. 3372h to the supervisory authorityEscalation decision
WCAG 2.2 AAKeyboard, contrast, live regions, focus orderConsole usability
Ground rules

What this lab will never do

  • No real systemsNothing you click can isolate a laptop, delete a mail, or disable an account.
  • No data leaves the pageNo sign-in, no API, no telemetry of your answers. Progress is localStorage only.
  • No personal dataFree-text notes are redacted on export; enter nothing real. Domains use .example, addresses use RFC 5737 documentation ranges.
  • No credential claimsThe evidence pack is a personal practice record, not a Microsoft certification.
Objective 1 · 10 pts

Intake: record the priority you can defend

Required
Intake acknowledgements

The queue is already 5 incidents deep and the shift changes in 40 minutes. Prioritising is a decision, not a feeling — write it down.