incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
Cyber × Network FusionhardInternal CA MITM + C2Critical asset
Scenario

Internal CA key possibly exposed + ARP poisoning + outbound C2 from server VLAN

A hard Cyber × Network Fusion scenario on Internal CA MITM + C2.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 4 templates in this Track + Difficulty pool.

catalog id · fusion-internal-ca-mitm-c2

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Internal-CA trust triage
  • Beaconing pattern recognition over trusted channels
MITRE ATT&CKmitre-attack
  • Adversary-in-the-Middle · Credential AccessT1557 · TA0006
    MappedHigh confidence

    Trains triage when internal trust anchors are abused for redirection.

  • Application Layer Protocol · Command and ControlT1071 · TA0011
    MappedHigh confidence

    Trains scoping of beaconing patterns over trusted channels.

MITRE D3FENDmitre-d3fend
  • Network Traffic AnalysisD3-NTA
    MappedHigh confidence

    Trains TLS-and-DNS-visibility reasoning.

  • Service Binary VerificationD3-SBV
    PartialLow confidence

    Trains broader integrity-verification posture across endpoints.

NIST CSF 2.0nist-csf-2
  • Data Security · ProtectPR.DS · PR
    MappedHigh confidence

    Trains the data-security baseline behind TLS trust.

  • Continuous Monitoring · DetectDE.CM · DE
    MappedHigh confidence

    Trains the monitoring discipline on the egress plane.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains triage of trust-anchor abuse signals.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains trust-rotation and revocation workflow.

CISA Cybersecurity Performance Goalscisa-cpg
  • Strong and Agile Encryption2.H
    MappedHigh confidence

    Trains the trust-and-encryption baseline.

  • Detecting Relevant Threats and TTPs3.A
    MappedHigh confidence

    Trains the detection baseline for beaconing patterns.

CIS Controls v8cis-controls
  • Data ProtectionControl 3
    MappedHigh confidence

    Trains the data-protection control.

  • Network Monitoring and DefenseControl 13
    MappedHigh confidence

    Trains the monitoring control.