incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
Cyber × Network FusionhardIoT Botnet DDoSCritical asset
Scenario

Internal IoT segment compromised — outbound DDoS to external target, ISP abuse complaints

A hard Cyber × Network Fusion scenario on IoT Botnet DDoS.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 4 templates in this Track + Difficulty pool.

catalog id · fusion-iot-botnet-ddos

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • IoT botnet DDoS triage
  • Availability-first containment discipline
MITRE ATT&CKmitre-attack
  • Network Denial of Service · ImpactT1498 · TA0040
    MappedHigh confidence

    Trains triage of availability-impacting traffic floods.

  • Application Layer Protocol · Command and ControlT1071 · TA0011
    PartialMedium confidence

    Trains scoping of remote-access channels on IoT segments.

MITRE D3FENDmitre-d3fend
  • Network Traffic FilteringD3-NTF
    MappedHigh confidence

    Trains the traffic-filtering response under DDoS pressure.

  • Network Traffic AnalysisD3-NTA
    MappedHigh confidence

    Trains the traffic-analysis posture for source attribution.

NIST CSF 2.0nist-csf-2
  • Anomalies and Events · DetectDE.AE · DE
    MappedHigh confidence

    Trains anomaly-detection reasoning under volumetric pressure.

  • Recovery Planning · RecoverRC.RP · RC
    MappedHigh confidence

    Trains availability-recovery decision making.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains structured triage of volumetric anomalies.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains scrubbing, isolation, and recovery workflow.

CISA Cybersecurity Performance Goalscisa-cpg
  • Asset Inventory1.A
    MappedHigh confidence

    Trains IoT asset-inventory reasoning.

  • Changing Default Passwords2.A
    MappedHigh confidence

    Trains the default-password baseline for IoT gear.

CIS Controls v8cis-controls
  • Inventory and Control of Enterprise AssetsControl 1
    MappedHigh confidence

    Trains the asset-inventory control.

  • Network Monitoring and DefenseControl 13
    MappedHigh confidence

    Trains the network-monitoring control.