incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
Cyber × Network FusionmediumVPN Brute + OSPF PivotCritical asset
Scenario

VPN admin compromised — attacker added a static route + redistributed it into OSPF

A medium Cyber × Network Fusion scenario on VPN Brute + OSPF Pivot.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 3 templates in this Track + Difficulty pool.

catalog id · fusion-vpn-brute-ospf-pivot

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Perimeter-to-internal correlated triage
  • Layered access-control containment
MITRE ATT&CKmitre-attack
  • Brute Force · Credential AccessT1110 · TA0006
    MappedHigh confidence

    Trains triage of brute-force pressure against perimeter VPN.

  • Remote Services · Lateral MovementT1021 · TA0008
    MappedMedium confidence

    Trains scoping of internal pivots once VPN access is obtained.

MITRE D3FENDmitre-d3fend
  • Multi-factor AuthenticationD3-MFA
    MappedHigh confidence

    Trains MFA-backed defense at the perimeter.

  • Network Traffic AnalysisD3-NTA
    MappedHigh confidence

    Trains east-west visibility for pivot scoping.

NIST CSF 2.0nist-csf-2
  • Access Control · ProtectPR.AC · PR
    MappedHigh confidence

    Trains the access-control baseline at the VPN tier.

  • Continuous Monitoring · DetectDE.CM · DE
    MappedHigh confidence

    Trains the monitoring discipline across perimeter and internal tiers.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains correlated VPN-and-internal triage.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains layered containment across perimeter and internal segments.

CISA Cybersecurity Performance Goalscisa-cpg
  • Phishing-Resistant MFA2.E
    MappedHigh confidence

    Trains the MFA baseline.

  • Detection of Unsuccessful Logins2.Q
    MappedHigh confidence

    Trains the failed-login detection baseline.

CIS Controls v8cis-controls
  • Access Control ManagementControl 6
    MappedHigh confidence

    Trains the access-management control.

  • Network Monitoring and DefenseControl 13
    MappedHigh confidence

    Trains the network-monitoring control.