Suspected core-switch firmware implant + lateral movement across a segmented fabric
A extremely-hard Cyber × Network Fusion scenario on Network Appliance Firmware Implant + Fabric Pivot.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 4 templates in this Track + Difficulty pool.
catalog id · fusion-firmware-implant-fabric-pivot
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Untrusted-firmware (device implant) triage
- Out-of-band capture and segmentation containment
- Modify System Image · Defense EvasionT1601 · TA0005MappedHigh confidence
Trains triage of a network-device firmware/image integrity mismatch.
- Remote Services · Lateral MovementT1021 · TA0008MappedHigh confidence
Trains scoping of a cross-segment pivot the suspect device should have denied.
- Service Binary VerificationD3-SBVMappedHigh confidence
Trains out-of-band image-integrity verification against vendor known-good.
- Network Traffic AnalysisD3-NTAMappedMedium confidence
Trains external-collector analysis of the unbooked mirror and cross-segment flows.
- Continuous Monitoring · DetectDE.CM · DEMappedHigh confidence
Trains detection of device-integrity drift and segmentation bypass.
- Supply Chain Risk Management · IdentifyID.SC · IDMappedHigh confidence
Trains the supply-chain lens on a vendor-advised firmware implant.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains out-of-band evidence capture when the device's own telemetry is untrusted.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains preserve-then-isolate-then-replace ordering for a compromised core node.
- Vendor/Supplier Cybersecurity Requirements2.RMappedHigh confidence
Trains the vendor-coordination baseline for a known-implant advisory and RMA.
- Document Network Topology2.MMappedMedium confidence
Trains the topology baseline the segmentation reasoning depends on.
- Network Infrastructure ManagementControl 12MappedHigh confidence
Trains the network-management control the incident centers on.
- Network Monitoring and DefenseControl 13MappedHigh confidence
Trains the segmentation-monitoring control that surfaced the pivot.