Guided lab: nine hours at Northwind Freight, from lure to scheduled task
A constructed intrusion written as a DFIR report. You get the same artifacts an analyst gets on day one, in the order they arrive, and you build the timeline yourself. The company is fictional; the techniques, event IDs and analytic reasoning are not.
Security Artifacts
9 min read
Constructed scenario. This case is written for practice. The organisation, the people and the events in it are invented, and no real incident is being described. The techniques, artifact locations and analytic reasoning are real, but the evidence is illustrative rather than exported from a live host, so it is tidier than anything you will meet in production.
It is 09:40 on a Tuesday. The IT manager at Northwind Freight, a 200-person
logistics firm, has escalated to you: a finance user reports Outlook "acting
strange" yesterday afternoon, and this morning a domain admin account logged in
from a workstation nobody recognises.
You have Sysmon on the endpoints, Windows Security logs forwarded, and 30 days
of retention. You do not yet have EDR on everything.
Build the timeline. Work each question before opening the hints.
Artifact 1: the mailbox
The finance user, s.okafor, received this at 14:02 on Monday.
What is in this lab
Questions
6
Artifacts
6
Staged hints
16
Sections
The call
Artifact 1: the mailbox
Artifact 2: process creation on FIN-WS-014
Artifact 3: LSASS
Artifact 4: the logon you were called about
Artifact 5: persistence
Build the timeline
What you would do next
The first question, as it appears
Before opening a single log, what does the sender address alone tell you, and
what would you check next to confirm it?
Its hints are staged from a nudge, to the method, to the answer. Members see all three.
[!] members only
The rest of this teardown — the full timeline, the complete IOC list and the detection rule with its tuning notes — is for members. Sign in if you have an account, or start a 7-day trial. No card is charged and none is collected up front.