Guided lab: nine hours at Northwind Freight, from lure to scheduled task

A constructed intrusion written as a DFIR report. You get the same artifacts an analyst gets on day one, in the order they arrive, and you build the timeline yourself. The company is fictional; the techniques, event IDs and analytic reasoning are not.

The call

It is 09:40 on a Tuesday. The IT manager at Northwind Freight, a 200-person logistics firm, has escalated to you: a finance user reports Outlook "acting strange" yesterday afternoon, and this morning a domain admin account logged in from a workstation nobody recognises.

You have Sysmon on the endpoints, Windows Security logs forwarded, and 30 days of retention. You do not yet have EDR on everything.

Build the timeline. Work each question before opening the hints.

Artifact 1: the mailbox

The finance user, s.okafor, received this at 14:02 on Monday.

What is in this lab

Questions
6
Artifacts
6
Staged hints
16

Sections

  1. The call
  2. Artifact 1: the mailbox
  3. Artifact 2: process creation on FIN-WS-014
  4. Artifact 3: LSASS
  5. Artifact 4: the logon you were called about
  6. Artifact 5: persistence
  7. Build the timeline
  8. What you would do next

The first question, as it appears

Before opening a single log, what does the sender address alone tell you, and what would you check next to confirm it?

Its hints are staged from a nudge, to the method, to the answer. Members see all three.

[!] members only

The rest of this teardown — the full timeline, the complete IOC list and the detection rule with its tuning notes — is for members. Sign in if you have an account, or start a 7-day trial. No card is charged and none is collected up front.

sign insee what is included