Valid federation tokens with no upstream login + a /32 redirect pulling auth traffic off-path
A extremely-hard Cyber × Network Fusion scenario on Federation Token Theft + Routing Redirect.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 4 templates in this Track + Difficulty pool.
catalog id · fusion-federation-token-routing-redirect
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Forged-token + routing-redirect correlated triage
- Signing-key rotation with scoped network rollback
- Forge Web Credentials · Credential AccessT1606 · TA0006MappedHigh confidence
Trains recognition of valid federation tokens issued with no upstream authentication event.
- Adversary-in-the-Middle · Credential AccessT1557 · TA0006MappedMedium confidence
Trains scoping when a routing/DNS redirect places the token-signing path under interception.
- Network Traffic AnalysisD3-NTAMappedHigh confidence
Trains correlation of the redirect flow with anomalous federated sign-ins.
- Multi-factor AuthenticationD3-MFAPartialLow confidence
Trains why MFA alone does not stop forged assertions, only complements key rotation.
- Continuous Monitoring · DetectDE.CM · DEMappedHigh confidence
Trains detection from the gap between cloud sign-ins and on-prem IdP events.
- Mitigation · RespondRS.MI · RSMappedHigh confidence
Trains signing-key rotation plus scoped route/DNS rollback as paired mitigation.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains correlation of identity, routing, and DNS telemetry into one campaign.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains parallel identity and network containment without a blanket SSO outage.
- Phishing-Resistant MFA2.EPartialLow confidence
Trains the identity-assurance baseline that complements signing-key rotation.
- Detecting Relevant Threats and TTPs3.AMappedMedium confidence
Trains the detection baseline that surfaces forged-token use.
- Access Control ManagementControl 6MappedHigh confidence
Trains federated access-control response under a signing-path compromise.
- Network Infrastructure ManagementControl 12MappedHigh confidence
Trains the route/DNS hygiene that prevents redirect of a trust-critical endpoint.