incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
Cyber × Network FusionhardBGP Hijack + DNS ExfilCritical asset
Scenario

Customer prefix hijack + abnormal DNS volume from internal resolver to attacker AS

A hard Cyber × Network Fusion scenario on BGP Hijack + DNS Exfil.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 4 templates in this Track + Difficulty pool.

catalog id · fusion-bgp-hijack-dns-exfil

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • DNS-and-routing correlated triage
  • Layered egress containment discipline
MITRE ATT&CKmitre-attack
  • Application Layer Protocol · Command and ControlT1071 · TA0011
    MappedHigh confidence

    Trains correlated triage of DNS-channel egress and routing anomalies.

  • Data Manipulation · ImpactT1565 · TA0040
    PartialMedium confidence

    Trains scoping when routing manipulation enables data redirection.

MITRE D3FENDmitre-d3fend
  • Network Traffic AnalysisD3-NTA
    MappedHigh confidence

    Trains the visibility posture across the DNS plane and routing tiers.

  • Network Traffic FilteringD3-NTF
    MappedMedium confidence

    Trains the outbound-filtering control once the channel is scoped.

NIST CSF 2.0nist-csf-2
  • Anomalies and Events · DetectDE.AE · DE
    MappedHigh confidence

    Trains anomaly-detection reasoning across DNS and routing telemetry.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains correlated DNS-and-routing triage.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains layered containment across egress and routing tiers.

CISA Cybersecurity Performance Goalscisa-cpg
  • Detecting Relevant Threats and TTPs3.A
    MappedHigh confidence

    Trains the detection-engineering baseline.

  • Document Network Topology2.M
    MappedHigh confidence

    Trains the topology baseline.

CIS Controls v8cis-controls
  • Network Monitoring and DefenseControl 13
    MappedHigh confidence

    Trains the monitoring control across multiple planes.

  • Network Infrastructure ManagementControl 12
    MappedHigh confidence

    Trains the network-management control.