Triage a correlated incident the way a Tier 2 analyst does
Operation NIGHTBLOOM has produced one Defender XDR incident spanning a mailbox, a Windows 11 endpoint and an on-premises service account. You have 75 minutes of analyst time: filter the queue to the real signal, prove the attack story, hunt for the rest of the blast radius, contain it under change control, and close it with a classification you could defend in an audit.
Required
i
This is a console replica, not Microsoft software.
The layout, page names and control labels model the 2026 Microsoft Defender portal at security.microsoft.com so the workflow transfers. No tenant is connected, no API is called, and every device, account, alert, file name and address below is synthetic. Product names are used only to describe the workflow; no Microsoft logo or trade dress is reproduced.
Alerting sources
What the tenant saw
High
Incident
INC-2291 · id 2291
Title
Suspicious PowerShell activity and mailbox rule creation on FIN-WKS-0421
First activity
2026-08-19 09:34:11Z
Last activity
2026-08-19 11:58:02Z
Detection sources
Defender for EndpointDefender for Office 365Defender for Identity
Intake & priority · 10 ptsConfirm the queue scope, set the priority you can defend, record the on-call owner.
2
Queue filtering & ownership · 15 ptsFilter to High severity, New status and the Endpoint source; claim the incident.
3
Attack story & blast radius · 20 ptsIdentify initial access, the correct ATT&CK technique set, and the pivot evidence.
4
Advanced hunting (KQL) · 15 ptsWrite a bounded, reproducible query that finds every host running the loader.
5
Contained response · 15 ptsIsolate, quarantine the artefact and collect evidence — in the right order, with approval.
6
Classification & closure · 15 ptsResolve with a true-positive classification, threat type, tags and a note that passes review.
7
Regulatory escalation decision · 10 ptsDecide which notification clocks apply to this entity and who owns each filing.
Objectives unlock in order — containment is locked until you have justified it in the hunt, exactly as a real change-advisory boundary works. Your score, notes and action log stay in this browser.
No real systemsNothing you click can isolate a laptop, delete a mail, or disable an account.
✓
No data leaves the pageNo sign-in, no API, no telemetry of your answers. Progress is localStorage only.
✓
No personal dataFree-text notes are redacted on export; enter nothing real. Domains use .example, addresses use RFC 5737 documentation ranges.
✓
No credential claimsThe evidence pack is a personal practice record, not a Microsoft certification.
Objective 2 · 15 pts
Incidents
The unified queue now receives alerts from Defender for Endpoint, Office 365, Identity, Cloud Apps, Purview DLP and Microsoft Sentinel analytics rules. Everything you do here is filter discipline: find the one incident that is genuinely active, and hand it an owner and a status.
Required
!
Three of these five incidents are noise you must prove, not assume.
A “Medium / New” row with a single alert can still be the real one, and a “High” row may be expected penetration-test traffic. Set the filters that answer the intake question, then select the incident whose entities overlap across at least two workloads.
Select one row. No rows selected
Incident ID
Title
Severity
Status
Service / detection source
Entities
Classification
Last activity
INC-2291
Suspicious PowerShell activity and mailbox rule creation on FIN-WKS-04216 alerts · automated investigation pending
High
New
Endpoint · Office 365 · Identity
1 device · 2 users · 1 mailbox
Not set
2026-08-19 11:58Z
INC-2288
Penetration test activity from the contracted red team2 alerts · scope: FIN-SEGMENT
High
New
Endpoint
1 device · 1 user
Exercise
2026-08-19 09:12Z
INC-2287
Suspicious sign-in after MFA prompt refused1 alert · impossible travel not confirmed
Medium
New
Identity
1 user
Not set
2026-08-19 07:44Z
INC-2285
Malware detected and already remediated by Defender Antivirus1 alert · auto-remediation succeeded
Medium
In progress
Endpoint
1 device · 1 file
Not set
2026-08-18 22:05Z
INC-2280
Vendor monitoring agent signed by an untrusted certificate3 alerts · software distribution
Low
New
Endpoint · Sentinel
12 devices
Known app
2026-08-18 16:30Z
5 incidents in the current time range·Queue modelled on the unified XDR queue, including Purview DLP and Sentinel sources
Summary pane
Priority assessment
Priority 28/100
The priority score in the queue is a triage aid, not a verdict. These are the factors the service published for INC-2291 — decide what they mean for your business.
↑
Active alert on a financially sensitive deviceFIN-WKS-0421 · Finance shared drive reachable
↑
Mailbox rule created after credential theft indicatorInbox rule “FIN-Mail-Junk” forwarding externally
–
No confirmed data egress volume1.4 MB to the C2 host; no large SharePoint download
↓
Device is not internet-facingNo inbound exposure; no external listener observed
Objective 2
Filter, then own it
Submit the queue state a reviewer would accept for INC-2291.
Objective 3 · 20 pts
Suspicious PowerShell activity and mailbox rule creation on FIN-WKS-0421
HighNewINC-22916 alertsCorrelated by shared device + userT1566.001T1059.001
Required
Alerts grouped into this incident by shared entities and overlapping time.
Timestamp
Category
Title
Severity
Source
Status
2026-08-19 09:34Z
Malicious email link
Payload delivered through a link in a phishing emailURL reputation changed to malicious 09:31Z · delivery: Allow (not detected at time)
Medium
Office 365
Pending AIR
2026-08-19 09:41Z
Defense evasion
PowerShell downloaded a file from a remote serverpowershell.exe -nop -w hidden -enc <base64> · parent excel.exe
High
Endpoint
Active
2026-08-19 09:44Z
Persistence
New startup file created in the user’s Start-up foldersvch0st.exe copied to %APPDATA%\Microsoft\Windows\Start Menu\Programs\StartUp
Medium
Endpoint
Active
2026-08-19 10:02Z
Collection
Mailbox audit: new inbox rule created and forwarded externallyRule “FIN-Mail-Junk” · forward-to n1ghtbloom@relay-secure.example · delete-action enabled
High
Office 365
Active
2026-08-19 10:19Z
Lateral movement
Unusual SMB access to a share from a workstation account\\FS-FIN01\Finance · 1.4 MB read · first time observed for this pair
High
Identity
Active
2026-08-19 11:58Z
Command & control
Outbound connection to a domain registered 3 days agologin-contoso.secure-mail.example · registered 2026-08-16 · 4 beacons
Medium
Endpoint
Active
Hostile / attacker-controlledPivot assetGraph is a static model of the correlated alerts — it is not a live rendering of an environment.
09:33:41ZEmail delivered · no detonation verdict yet
Attachment-less link message to 41 recipients; 3 clicked within 90 seconds. Defender for Office 365 network protection did not block: the domain was 3 days old and previously clean.
09:41:22Zpowershell.exe spawned by excel.exe with an encoded command
ASR rule “Block JavaScript or VBScript from launching downloaded executable content” was in audit on this device group, so nothing was blocked.
09:41:25ZDownload of svch0st.exe from 203.0.113.64
RFC 5737 documentation address used deliberately by this lab; in a real case, record the address in your evidence and never paste it into a ticketing system that logs third parties.
09:44:10ZCopy to the user Start-up folder + Run key value
Persistence is user-scoped, so re-imaging the profile is as effective as re-imaging the disk.
10:02:00ZInbox rule FIN-Mail-Junk created
Rule deletes inbound mail containing “invoice” and forwards to relay-secure.example. This is the alert that tells you the mailbox, not just the device, is compromised.
10:19:36ZSMB read of \\FS-FIN01\Finance (1.4 MB)
Authenticated as svc_backup from a workstation — the account is configured “cannot be delegated” but is not marked sensitive and can log on interactively.
11:58:02ZFour C2 beacons, then silence
No further beacon after 11:58Z. Absence of beaconing is not evidence of removal — check the sensor state on the device before you believe it.
Device
FIN-WKS-0421
OS
Windows 11 23H2
Exposure
Group: FIN-WKS (medium)
Sensor
Healthy · v10.26.08
Onboarded
2025-04-11
Isolated
No
TD state
Investigate
Account
mira.solanki
Risk
High · confirmed compromised
MFA
Registered · phishing-resistant no
Tokens
Active on 2 devices
Last logon
2026-08-19 09:29Z
Roles
User · Finance-Share-Owner
Identity risk state and endpoint telemetry point at the same device — that correlation is what makes this a single incident.
Service account
svc_backup
Type
On-premises · sync’d
Password age
812 days
Constraints
Kerberos delegation allowed
Logon right
Allow log on locally — yes
!
Root-cause candidate
A service account with interactive logon rights and an 812-day password is a standing exposure, not an artifact of this attack.
Go hunt
Built-in queries offered for these entities
1
All Activity — device FIN-WKS-0421All telemetry for the device in a bounded window.
2
Related Alerts — user mira.solankiAlerts across workloads involving the account.
3
File observed on other devices — svch0st.exeThe blast-radius query. Run it yourself in the hunt tab.
Evidence
What must be preserved before you click anything
✓
ReportId / alertId of each alertThey are the join key back to the raw event.
✓
SHA-256 of the loader + its first-seen timeRecorded, not shared publicly, from a quarantined copy.
✓
Investigation package, collected before isolation endsOnce the sensor is offline you cannot get it.
✓
Mailbox audit record for the rule (creation + deletion)Export the O365 management log entry, not a screenshot.
Objective 4 · 15 pts
Advanced hunting
You are proving blast radius, not going shopping. The question you must answer with a query: which other devices in the last 14 days have run the same loader? KQL-Lite in this lab executes for real — a wrong filter returns the wrong row count and the objective will tell you so.
Required
blast-radius.kql
1
Query not run yet·Time range: last 14 days · scope: all devices (simulated)
Objective 4
Submit the blast-radius query
Required
Requirements, checked automatically: run against DeviceProcessEvents, bound the window with ago() or datetime(), match the loader name case-insensitively, and return exactly the three affected devices. No take 1 shortcuts, no where 1 == 1.
Not graded · recommended
Second-order checks
Once your first query is accepted, run these against the same dataset to complete the analyst habit:
a
Persistence per deviceDeviceRegistryEvents | where Timestamp > ago(14d) | where RegistryKey has 'CurrentVersion\\Run' | summarize Devices = dcount(DeviceName) by InitiatingProcessFileName
b
Same C2 domain, different devicesDeviceNetworkEvents | where Timestamp > ago(14d) | where RemoteUrl contains 'secure-mail.example' | summarize by DeviceName, RemoteIP
c
Who else got the mailEmailEvents | where Timestamp > ago(14d) | where SenderFromAddress has 'n1ghtbloom' | summarize Recipients = count() by RecipientEmailAddress
Objective 5 · 15 pts · gated by Objective 4
Contain without breaking the business
High-impact actions are reversible but not free. In a real tenant, response actions on high-value assets can be restricted, and every action requires a justification that the Action Center records. Order matters: evidence collected after isolation can be unrecoverable.
Locked
!
Clicking an action before the approval fields are complete is recorded as a control violation.
The lab will let you do it — so you can see what an auditor sees. Reset and redo it properly; the violation stays in your log as a learning artefact, not a mark of shame.
Change control
Authorisation to act
Action pane
Execute the containment sequence
6 steps
In the real portal these live under Take action on the device page, Manage user on the identity page and Action center. Click them in the order NIST SP 800-61r3 containment guidance and evidence preservation demand.
Two of these are out of order or out of scope for this stage and must not be clicked yet: imaging (eradication decision, not yours alone) and “Action center” (it is your verification step, done last). The validator enforces the first six in order and rejects the rest.
Objective 6 · 15 pts
Classify, tag and resolve
Classification is how a SOC learns. Get it wrong and you teach the correlation engine, the alert-tuning rules and your own metrics to lie. Everything on this page is a real field in the Defender portal’s Manage incident flyout.
Required
Manage incident
Resolution form
Required
Consequence
What your choices change
Choice
Effect in a real tenant
True positive + Multi-staged activity
Feeds correlation tuning; keeps the incident in MTTR metrics; unlocks the “reported by customer” signal.
False positive
Reduces effective detection coverage in Secure Score reporting and may drive someone to suppress a rule that was right.
Informational, expected activity
Appropriate for red-team exercises within scope — such as INC-2288, not this one.
No tags
Next quarter you cannot count how many finance-impacting incidents you handled. Tags are cheap search.
Resolution note with no owner
The “what we are changing” item silently never happens. Auditors call this an open finding.
Self-check
Before you submit
?
Did you leave “False-positive reason” blank?Filling it while classifying as a true positive is the most common data-quality defect in incident queues.
?
Is the open item on a named human?“IT will look at it” is not an owner.
?
Would you paste this note into a regulator’s evidence pack?If it contains a customer name, a hash or a full UPN, no.
Objective 7 · 10 pts
Which clock is running?
A Tier 2 analyst is not the notifier — but you are the person who tells the incident commander which obligations are triggered and how fast they tick. Get this wrong and the legal deadline is missed while everyone is busy being technical.
Required
!
Synthetic scenario, real obligations.
Contoso-RCW is modelled here as an EU-based credit institution that also processes personal data — so DORA applies as lex specialis and NIS2 does not double-report the same incident for that entity. Verify against your own counsel: national transposition differs, and some member states count in working days.
Objective 7
Record the escalation decision
Required
All objectives evidenced
Your completion record
Lab complete
Reference
Lab guide, marking scheme and standing rules
Everything an instructor or auditor needs about this lab is on this page, and it is also in LAB_GUIDE.md next to the lab files.
Walkthrough
Recommended path
Home. Read the briefing; note which detection sources correlate. Nothing to submit.
Incidents queue. Set Severity = High, Status = New, Source = Defender for Endpoint, then select INC-2291. Assign it to yourself and set In progress. Justify against INC-2288.
Incident page. Read the alert titles before the graph. Tick only techniques an alert supports, pick the initial access vector, the mailbox pivot and the correct reading of the beacon silence.
Advanced hunting. Write a bounded query over DeviceProcessEvents. Run it, look at the row count, then validate. If you get 1 row you filtered on the known device; if you get 3 you found the others.
Response. Fill the change-control fields and the checklist first, then execute: package → isolate → quarantine file → block hash → revoke sessions → reset credentials. Imaging waits for the eradication decision.
Resolve. Status Resolved, classification True positive, threat type Multi-staged activity, tags, four-element note.
Escalation. Pick the correct clocks and owners. Then export your evidence pack if you want a record.
Marking
How points are awarded
Objective
Points
Pass condition
Intake & priority
10
Accepted at the gate; priority judgement recorded
Queue filter + ownership
15
Correct row selected, correct filters, assignee and status, non-trivial justification
Attack story
20
Exactly the five supported techniques, correct initial access, pivot and beacon reading
Advanced hunting
15
Query executes and returns exactly the three affected devices, bounded window
Objectives are gated: containment requires the hunt, resolution requires containment. A failed submit costs nothing and can be retried; violations are logged, not penalised.
Data protection & ethics
Standing rules of this lab
1
Synthetic identifiers onlyDomains use RFC 2606 reserved names (.example, contoso); network addresses use RFC 5737 documentation ranges (192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24); hashes shown are truncated or obviously fake.
2
Redaction on exportAnything that looks like a real UPN, GUID, IP or long hash is masked when the audit trail or evidence pack is written.
3
Local-only statelocalStorage in your browser. No sign-in, no upload, no lab telemetry. Site analytics run only under your saved consent choice and never see your answers.
4
No live-action instructionsThe lab describes console actions but never tells you to run them outside a training tenant. Destructive steps are always framed as decisions with owners and approvals.
5
AccessibilityKeyboard-operable queue and grids, ARIA live regions for validation and query results, focus trapping in the authorisation dialog, WCAG 2.2 AA contrast, reduced-motion and forced-colors support.
MITRE ATT&CK — technique IDs are referenced for education; ATT&CK is a registered trademark of MITRE RE®.
i
UI drift is normal
Microsoft ships the Defender portal continuously; labels, menu order and preview features move. Where this replica and your tenant differ, your tenant is right — the workflow and the controls being taught are the point.