Phishing Triage
The attacker sent an urgent message to finance. Inspect the email and identify the suspicious domain used in one of the below sender addresses.
Enter your name and the email address where the completion notification should be sent.
A simulated cyberattack is underway. Complete four cybersecurity missions, investigate the evidence, and stop the breach before the attacker escapes.
Complete all four missions to fully contain the breach and restore system integrity.
Work through the evidence. Each challenge is designed to be approachable, fast, and memorable while still feeling like a real cyber investigation.
The attacker sent an urgent message to finance. Inspect the email and identify the suspicious domain used in one of the below sender addresses.
Four logins occurred overnight. One account authenticated from a suspicious location and then accessed the vault admin panel.
A breached employee reused a predictable seasonal password pattern. Investigators recovered the following intelligence from the attacker’s notes.
> recovered_hints.txt Employee initial password setup (unchanged by employee): - Uses one of the seasons in password - Typically adds the current year - Always includes a special character Password policy: Minimum 10 characters Maximum 14 characters Detected partial and fragmented hash: *******0***
A USB device containing vault credentials was plugged into a secure workstation. Match the evidence to identify the employee responsible.