Welcome to the Volt Typhoon challenge! In this challenge, you will encounter a simulated incident that draws inspiration from the Volt Typhoon's infamous tactics. As a member of the incident response team, your mission is to meticulously investigate the breach, piece together the puzzle of the attack, and assess the extent of the damage caused.
Volt Typhoon primarily targets critical infrastructure for espionage purposes. They gain access to target networks by exploiting vulnerabilities in edge devices. Once a foothold is established, they use a variety of living-off-the-land techniques combined with valid credentials to evade traditional detection.
Remember, each decision you make, every clue you discover, and all the evidence you gather will contribute to the overall assessment of the breach. Your ability to connect the dots and draw accurate conclusions will determine your success in this challenge. Good luck!
The events in your SIEM can be found in the following timespan: 21 June 2023 - 22 June 2023.
/mo
Explore realistic pre-recorded attacks
Master full-featured defensive platforms
Browser-based challenges and modules
Extended attack videos
Grants access to Analyst content. You can cancel any time by returning to this page and following the cancellation steps.
/mo
Instant fully interactive labs
Hands-on prevention and detection
Master offensive techniques
Security engineering exercises
Highly realistic and dynamic scenarios
Access to all Analyst-level content
Grants access to all Defender content, Analyst content and interactive lab environments. You can cancel any time by returning to this page and following the cancellation steps.