Federated sign-in with no upstream login, a route that should not exist, and a cloud admin role assumed across the gap
A hard Cyber × Network Fusion scenario on Tri-Domain: Identity → Routing → Cloud Pivot.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 4 templates in this Track + Difficulty pool.
catalog id · fusion-tri-domain-identity-routing-cloud-pivot
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Identity→routing→cloud correlated triage
- Cross-domain containment without a blanket SSO or network outage
- Forge Web Credentials · Credential AccessT1606 · TA0006MappedHigh confidence
Trains recognition of a federated session valid downstream with no matching upstream identity-provider login.
- Remote Services · Lateral MovementT1021 · TA0008MappedMedium confidence
Trains scoping a cross-segment pivot that a routing/segmentation gap should have prevented.
- Valid Accounts: Cloud Accounts · Privilege EscalationT1078.004 · TA0004MappedHigh confidence
Trains response to a federated identity assuming a higher-privilege cloud control-plane role.
- Network Traffic AnalysisD3-NTAMappedHigh confidence
Trains correlating the unexpected route and cross-segment flow with the anomalous federated sign-in.
- User Account ContainmentD3-UACMappedHigh confidence
Trains revoking the federated session and the assumed-role session to stop the pivot.
- User Account PermissionsD3-UAPMappedMedium confidence
Trains scoping the role and route so the identity can no longer reach the management path.
- Continuous Monitoring · DetectDE.CM · DEMappedHigh confidence
Trains detection from the gap between downstream sign-ins and the on-prem identity-provider log.
- Mitigation · RespondRS.MI · RSMappedHigh confidence
Trains paired identity and routing containment without a blanket SSO or network outage.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains correlating identity, routing, and cloud telemetry into one campaign timeline.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains scoped session revocation, route removal, and role containment together.
- Phishing-Resistant MFA2.EPartialLow confidence
Trains the identity-assurance baseline that complements short-lived credentials.
- Detecting Relevant Threats and TTPs3.AMappedMedium confidence
Trains the detection baseline that surfaces a sign-in with no upstream login.
- Access Control ManagementControl 6MappedHigh confidence
Trains federated access-control response when a session reaches cloud roles without an upstream login.
- Network Infrastructure ManagementControl 12MappedHigh confidence
Trains the routing and segmentation hygiene the unexpected route violated.