4.8 GB outbound from production web server to low-reputation IP overnight
A hard Cybersecurity scenario on Suspicious Outbound.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 5 templates in this Track + Difficulty pool.
catalog id · suspicious-outbound-exfil
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Outbound-anomaly recognition
- Network-level containment under uncertainty
- Exfiltration Over C2 Channel · ExfiltrationT1041 · TA0010MappedHigh confidence
Trains defensive recognition of anomalous outbound data flows.
- Network Traffic AnalysisD3-NTAMappedHigh confidence
Trains the traffic-analysis posture the scenario exercises.
- Network Traffic FilteringD3-NTFMappedMedium confidence
Trains the outbound-filtering response once the destination is scoped.
- Anomalies and Events · DetectDE.AE · DEMappedHigh confidence
Trains anomaly-detection reasoning on outbound flows.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains anomaly triage on traffic baselines.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedMedium confidence
Trains network-level containment of suspected exfil endpoints.
- Detecting Relevant Threats and TTPs3.AMappedHigh confidence
Trains the detection-engineering baseline for outbound anomalies.
- Network Monitoring and DefenseControl 13MappedHigh confidence
Trains the network-monitoring control the scenario exercises.
- Network Infrastructure ManagementControl 12MappedMedium confidence
Trains the network-management discipline behind safe blocks.