AA23-108 APT28 Router Exploitation Analysis
Research how APT28 used weak SNMP configuration and a known Cisco vulnerability to enumerate routers, deploy Jaguar Tooth, collect network data, and maintain covert access.
Browse our selection of certification exams and practice tests to validate your knowledge.
Research how APT28 used weak SNMP configuration and a known Cisco vulnerability to enumerate routers, deploy Jaguar Tooth, collect network data, and maintain covert access.
Examine the Snake implant's Windows persistence, encrypted artifacts, Queue structure, modular protocol stack, layered encryption, and global peer-to-peer relay design.
Research BianLian's access, proxying, privilege escalation, discovery, credential theft, defense evasion, and changing extortion model from the joint advisory.
Investigate CL0P's MOVEit Transfer campaign by connecting the exploited SQL injection to LEMURLOOT authentication, database access, privileged-account behavior, and data theft.
Trace Truebot from delivery and environment checks through FlawedGrace execution, in-memory follow-on activity, encoded collection, and Teleport exfiltration.
Use official reporting to distinguish normal Exchange Online access from forged-token activity and choose logging and retention measures that preserve investigative evidence.
Analyze appliance-side webshell, privilege, staging, persistence, and anti-forensic artifacts from exploitation of Citrix NetScaler ADC and Gateway systems.
Investigate a vulnerability chain against Ivanti EPMM and use API, log, user-agent, certificate, and webshell evidence to design defensible hunting conclusions.
Research QakBot's evolution, tiered command-and-control design, registry persistence, and the operational limits of the 2023 disruption.
Reconstruct two nation-state intrusion paths at an aeronautical organization and connect account, malware, credential, and network evidence to the correct phase of the investigation.
Investigate Snatch's RDP entry, bulletproof-hosted command-and-control, long dwell time, service manipulation, Safe Mode boot, shadow-copy removal, filename masquerading, and recovery note.
Analyze BlackTech's subsidiary-to-headquarters pivots, router firmware replacement, ROMMON bypass, unlogged SSH backdoors, EEM output manipulation, and magic-packet activation.
Use NSA and CISA assessment findings to analyze ADCS relay, name-resolution poisoning, unsigned SMB, weak network-share controls, cleartext credential discovery, and unrestricted code execution.
Classify AvosLocker remote administration, tunneling, credential theft, exfiltration, scripting, web-shell persistence, and the NetMonitor reverse-proxy behavior captured by the FBI YARA rule.
Investigate exploitation of Confluence setup state, unauthorized administrator creation, Rclone configuration, observed user agents, product scope, and post-compromise recovery decisions.
Investigate Rhysida's valid-account access, MFT evidence, Windows staging, remote execution, Azure storage utilities, process injection, cryptographic design, and ransom-note artifact.
Trace Scattered Spider from helpdesk impersonation and MFA transfer through legitimate remote tools, credential stealers, AWS discovery, Snowflake collection, response monitoring, and ESXi impact.
Investigate how LockBit affiliates extracted NetScaler session material, bypassed MFA, staged an encoded DLL, required a launch key, and established command-and-control.
Analyze IRGC-affiliated compromise of Unitronics PLCs, including exposed engineering access, ladder-logic replacement, device renaming, version rollback, port changes, and HMI defacement.
Reconstruct two ColdFusion compromises from vulnerable versions and exploit paths through web-shell decoding, credential artifacts, network reconnaissance, and failed exfiltration.
Trace Star Blizzard from open-source persona research and rapport building through Evilginx session theft, personal-email targeting, mailbox collection, and follow-on phishing.
Examine SVR exploitation of TeamCity, software-build risk, EDRSandBlast defense evasion, GraphicalProton's cloud covert channel, registry collection, and server-log evidence.
Compare Play's Windows and ESXi operations, initial-access CVEs, custom discovery tooling, Group Policy distribution, intermittent encryption, and campaign-specific recompilation.
Analyze ALPHV Blackcat's social engineering, remote tooling, adversary-in-the-middle credential theft, Kerberos access, defense evasion, exfiltration, and encryptor artifacts.
Investigate how Androxgh0st finds exposed application secrets, chains PHPUnit and Laravel weaknesses, exploits Apache path traversal, and repurposes stolen cloud credentials.
Reconstruct a state-government intrusion from a retained former-employee account through SharePoint credential exposure, LDAP discovery, CIFS access, and cloud scoping.
Assess how SVR operators target service and dormant accounts, reuse tokens, manipulate MFA enrollment, and hide authentication behind residential proxies.
Trace a Phobos intrusion from exposed RDP and loader behavior through firewall changes, credential access, exfiltration, recovery inhibition, and ransom-note execution.
Evaluate an Ivanti Connect Secure intrusion where web shells, credential exposure, root persistence, and anti-forensic activity challenged normal appliance validation.
Investigate Akira's evolving hypervisor targeting, identity tradecraft, defense evasion, and virtual-disk credential theft using the official joint advisory.
Trace Black Basta's email-bombing support scam, RMM deployment, ConnectWise exploitation, masqueraded discovery, EDR disabling, exfiltration, and cryptographic impact.
Compare two APT40 incident-response case studies involving a custom web application, service-account compromise, Secure Socket Funnelling, remote-access appliances, MFA artifacts, and session tokens.
Use the SILENTSHIELD report to analyze parallel access paths, long dwell time, diversified implants, timestamp tampering, Sysmon visibility, and organizational response failures.
Investigate the DPRK RGB 3rd Bureau's defense collection requirements, ransomware funding, web-server exploitation, custom RAT inventory, command habits, and packed tooling.
Investigate how an Iran-linked group turns edge-device exploitation into credential capture, durable access, ransomware partnerships, and separate state-aligned collection.
Research RansomHub's affiliate model, exploit set, exfiltration separation, Curve25519 encryption, intermittent block processing, and encrypted-file trailer structure.
Research Unit 29155's scanning, vulnerability exploitation, IP-camera access, tunneling, post-exploitation tools, and destructive mission using the joint advisory.
Trace an Iranian access operation from password spraying and MFA registration through Kerberos discovery, living-off-the-land reconnaissance, and probable resale of network access.
Use the multinational report to compare zero-day prevalence, exploitation windows, affected products, weakness classes, and exploit consequences among 2023's top vulnerabilities.
Reconstruct how a CISA red team moved from a forgotten webshell through Linux credential stores and Kerberos delegation to domain compromise, then evaluate the defender response.
Trace two Ivanti Cloud Service Appliance exploit chains from access-control bypass through credential theft, command execution, webshell attempts, and lateral movement.
Investigate Ghost's opportunistic exploitation, short dwell time, Cobalt Strike execution, encoded lateral movement, limited exfiltration, and recovery inhibition.
Research Medusa's broker model, discovery ports, PowerShell evasion, lateral movement, encryption artifacts, and extortion process from documented investigations.
Research fast-flux infrastructure as a CTI collection problem, distinguish single from double flux, and evaluate DNS evidence without misclassifying legitimate CDNs.
Analyze LummaC2's delivery, host checks, command configuration, browser theft, download execution, and memory-resident behavior using the FBI and CISA report.
Trace GRU Unit 26165's credential attacks, vulnerability use, Active Directory collection, logistics intelligence requirements, and IP-camera reconnaissance.
Investigate how an unpatched remote-management component exposed a software provider's downstream customers and determine the correct discovery and response steps.
Reconstruct Interlock's unusual initial access, persistence, credential theft, Azure exfiltration, and virtual-machine encryption from the joint advisory.
Use the CISA and U.S. Coast Guard hunt report to decide which observed configuration and logging gaps would prevent defensible incident analysis in an IT/OT environment.
Investigate the joint government report on PRC-linked compromises of telecommunications and edge infrastructure, then distinguish vulnerable-device activity from normal router behavior.
Research official YARA rule syntax to interpret string types, modifiers, hex wildcards and jumps, Boolean conditions, occurrence counts, identifiers, and output behavior for malware-focused collection.
Research Sigma's official rule format to interpret log sources, detection selections, conditions, field modifiers, status, severity, false positives, and portable rule intent.
Research IETF Certificate Transparency v2 to interpret signed certificate timestamps, tree heads, inclusion and consistency proofs, monitor behavior, and the evidentiary limits of public certificate logs.
Research IETF RDAP JSON to interpret domain, network, autonomous-system, entity, event, status, notice, remark, and extension data without overclaiming what registration records prove.
Research GitHub's official APIs to retrieve security advisories, apply vulnerability filters, export dependency evidence, and interpret SPDX package and relationship data for supply-chain decisions.
Research Kubernetes auditing to identify event stages, select policy levels, understand first-match evaluation, configure the API server, and balance investigative detail with sensitive-data exposure.
Research Google Cloud's official audit-log structure to identify log classes, principals, services, methods, resources, policy denials, and the correct filters for security investigations.
Research AWS CloudTrail's official event schema to attribute API activity, interpret assumed-role sessions, preserve source identity, and distinguish reliable event fields from contextual clues.
Use Microsoft Defender XDR's official advanced-hunting schema to select event tables, interpret process and network fields, correlate unique events, and retrieve trustworthy signing evidence.
Research Microsoft Entra and Microsoft Graph documentation to distinguish sign-in types, interpret risk and Conditional Access fields, understand aggregation, and avoid misreading identity evidence.
Research CISA joint advisory AA24-038A to extract exact living-off-the-land commands, artifacts, ATT&CK mappings, persistence observations, and investigative implications from reported victim evidence.
Extract vulnerability, product, impact, weakness, scoring, and affected-version evidence from a specific CISA industrial control systems advisory without substituting assumptions about operational exposure.
Research the OASIS TAXII 2.1 standard to discover servers, interpret API roots and collection permissions, retrieve manifests, filter STIX objects, and handle protocol pagination correctly.
Research the OASIS STIX 2.1 specification to model indicators, observed data, relationships, sightings, bundles, and object properties without confusing transport containers with intelligence assertions.
Investigate a live ATT&CK group record to connect aliases, techniques, procedure evidence, software, commands, vulnerabilities, and infrastructure into a sourced actor profile.
Navigate live MITRE ATT&CK technique pages to identify tactics, platforms, parent-child relationships, procedure evidence, and the difference between behavior categories and observed implementations.
Research NIST's official NVD developer documentation to distinguish CVE publication from NVD enrichment, navigate CVE API responses, and build precise CPE and pagination queries.
Navigate FIRST's CVSS v4 specification and data representations to interpret metric groups, vector nomenclature, impact separation, and the role of supplemental context.
Use FIRST's official EPSS documentation, API, and data guidance to retrieve exploitation probabilities, interpret percentiles, choose filters, and avoid treating EPSS as a complete risk score.
Research the authoritative CISA Known Exploited Vulnerabilities catalog, interpret its machine-readable fields, and turn catalog evidence into defensible vulnerability-prioritization decisions.
Test your ability to evaluate and govern a CTI program through outcome metrics, stakeholder value, service levels, source portfolios, quality review, ethical controls, sharing governance, capability maturity, and investment decisions.
Test your ability to fuse incident evidence with external intelligence, build defensible timelines, separate observations from hypotheses, reconstruct campaign scope, generate intelligence leads, and feed lessons back into response and analysis.
Test your ability to analyze phishing and social-engineering campaigns through lure themes, delivery chains, sender infrastructure, credential capture, payload staging, audience targeting, campaign clustering, and defensive intelligence.
Test your ability to analyze credential theft, session hijacking, MFA abuse, identity-provider compromise, privileged access, credential marketplaces, authentication telemetry, and identity-centered adversary tradecraft.
Test your ability to assess software, service-provider, dependency, and vendor compromise scenarios using relationship mapping, upstream evidence, blast-radius analysis, trust paths, prioritization, and third-party intelligence requirements.
Test your ability to produce threat intelligence for cloud and SaaS environments, including identity-centric intrusion paths, control-plane activity, tenant context, exposed credentials, shared responsibility, cloud-native telemetry, and cross-tenant campaigns.
Test your ability to analyze ransomware ecosystems, distinguish operator and affiliate roles, interpret leak sites and negotiations, assess initial access, track rebrands, and produce decision-relevant extortion intelligence.
Test your ability to assess how geopolitical events shape state-sponsored cyber activity while separating context from evidence, identifying strategic objectives, building indicators, and avoiding deterministic attribution.
Test your ability to build and maintain defensible threat actor profiles using motivation, intent, capability, constraints, victimology, behavioral patterns, naming discipline, and confidence-aware attribution.
Test your ability to turn threat developments into decision-relevant strategic intelligence, including horizon scanning, business impact, scenarios, warning indicators, estimative language, and executive communication.
This comprehensive exam assesses foundational knowledge in cybersecurity as of 2026, covering emerging threats like AI-driven attacks, quantum computing risks, post-quantum cryptography, zero-trust architecture, supply chain security, cloud-native vulnerabilities, and regulatory updates (e.g., NIS2, DORA). It includes 15 multiple-choice and true/false questions designed for professionals seeking to validate their understanding of modern cyber defense strategies.
Test your ability to analyze malware-related intelligence, distinguish families from samples, connect technical evidence to campaigns, evaluate behavioral and code similarities, interpret configuration and infrastructure relationships, track campaign evolution, and communicate confidence without overstating attribution in Cyber Threat Intelligence.
Test your ability to analyze adversary infrastructure, interpret passive DNS and historical registration data, assess infrastructure overlap, account for shared hosting and temporal context, validate investigative pivots, evaluate clustering confidence, and avoid unsupported attribution in Cyber Threat Intelligence.
Test your ability to define and manage Cyber Threat Intelligence requirements, plan collection, select and evaluate sources, identify collection gaps, process incoming information, align reporting with stakeholder needs, and use feedback to improve the intelligence cycle.
Test your ability to apply Cyber Threat Intelligence to detection engineering and threat hunting, including hypothesis development, telemetry selection, indicator use, behavioral detection, ATT&CK mapping, detection gaps, hunt prioritization, and translating intelligence into operational security actions.
Test your ability to work with structured Cyber Threat Intelligence concepts, including STIX object types, relationships, indicators, sightings, markings, TAXII API Roots and Collections, and the exchange and modeling of threat intelligence.
Test your ability to apply Cyber Threat Intelligence analytic tradecraft, including evidence evaluation, assumptions, confidence, alternative hypotheses, source assessment, attribution, collection bias, adversary behavior mapping, and structured analytic reasoning.
Test your understanding of foundational Cyber Threat Intelligence concepts, terminology, analytical thinking, threat information sharing, indicators, adversary behavior, and structured intelligence standards.
A beginner level exam on the fundamentals of the Go programming language.