Case catalog
Investigation labs
10 open · 10 total · filter by service as the catalog grows
- AWS-WAF-001WAF
AWS WAF SQL Injection Attack Investigation
Cloud Detection & Response·Investigate a SQL injection campaign against a fictional e-commerce site using AWS WAF and ALB logs.
Intermediate45 min
→
- AWS-WAF-002WAF
AWS WAF Cross-Site Scripting (XSS) Attack Investigation
Incident Response·Investigate a reflected XSS campaign against shop.lumenbay.io using CloudFront/WAF, ALB, and application logs.
Intermediate25 min
→
- AWS-EC2-001EC2
EC2 Port Scanning Investigation
Incident Response·Investigate a GuardDuty port-probe finding against a fictional EC2 instance using VPC Flow Logs, security groups, and CloudTrail.
Intermediate25 min
→
- AWS-EC2-002EC2
EC2 Suspicious DNS Communication Investigation
Incident Response·Investigate a GuardDuty Trojan:EC2/DriveBySourceTraffic!DNS finding using DNS query logs, VPC Flow Logs, Apache logs, and Linux process events.
Intermediate30 min
→
- AWS-IAM-001IAM
AWS IAM Credential Compromise Investigation
Incident Response·Investigate a GuardDuty HIGH alert for a compromised IAM access key. Trace the attacker's reconnaissance, failed privilege escalation, and sensitive S3 data exfiltration through CloudTrail.
Intermediate30 min
→
- AWS-IAM-002IAM
IAM Privilege Escalation Investigation
Incident Response·Investigate unusual IAM policy changes and determine whether a low-privileged identity successfully escalated to AdminRole using CloudTrail and GuardDuty.
Intermediate30 min
→
- AWS-RDS-001RDS
RDS Brute Force Attack Investigation
Incident Response·Investigate anomalous RDS authentication failures against a production MySQL instance, determine whether brute force succeeded, and assess post-login database activity.
Intermediate25 min
→
- AWS-S3-001S3
S3 Data Exfiltration Investigation
Incident Response·Investigate a suspected data exfiltration from a production S3 bucket. Correlate CloudTrail data events, object inventory, and bucket transfer metrics to separate a compromised service credential from legitimate high-volume traffic.
Intermediate30 min
→
- AWS-EC2-003EC2
EC2 Web Shell Investigation
Incident Response·Investigate a web-shell compromise on a production EC2 instance. Correlate Apache access logs, Linux process telemetry, file-system events, and DNS logs to reconstruct the full attack chain from initial file upload to post-compromise C2 communication.
Intermediate30 min
→
- AWS-IAM-003IAM
AWS Account Takeover Investigation
Incident Response·A security-administration identity signs in from an unfamiliar network without MFA and, within twenty minutes, holds administrative control of a production AWS account. Correlate console sign-in, CloudTrail, IAM writes, and STS sessions to separate what the operator attempted from what actually succeeded — and find the persistence that outlives the session.
Advanced40 min
→
Showing 10 of 10.