SIMULATION
-
A company recently experienced a security incident. The security team has determined a user clicked on a link embedded in a phishing email that was sent to the entire company. The link resulted in a malware download, which was subsequently installed and run.
INSTRUCTIONS
-
Part 1
-
Review the artifacts associated with the security Incident. Identify the name of the malware, the malicious IP address, and the date and time when the malware executable entered the organization.
Part 2
-
Review the kill chain items and select an appropriate control for each that would improve the security posture of the organization and would have helped to prevent this incident from occurring. Each control may only be used once, and not all controls will be used.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Alarming_Subject
Highly Voted 3 months, 2 weeks agocf83993
Most Recent 2 months, 2 weeks agocy_analyst
2 months, 3 weeks ago78f9a0a
3 weeks, 1 day agoIE17
2 months, 1 week agothisguyfucks
2 months, 3 weeks agocy_analyst
2 months, 3 weeks agoID77
2 months, 3 weeks agobinogamer12
4 months agoalialzehhawi
3 months, 2 weeks agopendekarsuling
2 months, 4 weeks agoFreshly
2 months agojdlrosa
1 month agovoiddraco
4 months, 3 weeks ago