Trusted MSP's RMM agent pushing unexpected commands across managed hosts — pivot from a compromised provider, ambiguous legit-maintenance vs malicious, cross-org coordination
A extremely-hard Cybersecurity scenario on Third-Party Vendor Breach Pivot.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 5 templates in this Track + Difficulty pool.
catalog id · vendor-rmm-pivot-msp-compromise
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Trusted-vendor (MSP) pivot containment
- Cross-org coordination without over-trusting the partner
- Trusted Relationship · Initial AccessT1199 · TA0001MappedHigh confidence
Trains triage of a pivot arriving through a trusted MSP channel.
- Remote Access Software · Command and ControlT1219 · TA0011MappedHigh confidence
Trains reasoning about abuse of a legitimate RMM agent.
- Network Traffic AnalysisD3-NTAMappedMedium confidence
Trains scoping of what the RMM channel reached, including backups.
- User Account ContainmentD3-UACMappedHigh confidence
Trains constraint of the MSP technician account and rogue admins.
- Continuous Monitoring · DetectDE.CM · DEMappedHigh confidence
Trains detection of vendor-driven recon and admin creation.
- Supply Chain Risk Management · IdentifyID.SC · IDMappedHigh confidence
Trains the third-party-risk lens on the MSP relationship.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains legit-maintenance-vs-malicious disambiguation across orgs.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains targeted, coordinated containment of a trusted channel.
- Vendor/Supplier Cybersecurity Requirements2.RMappedHigh confidence
Trains the third-party security-requirements baseline for MSP access.
- Detecting Relevant Threats and TTPs3.AMappedMedium confidence
Trains detection of vendor-channel recon and admin creation.
- Service Provider ManagementControl 15MappedHigh confidence
Trains the service-provider control the incident exercises.
- Network Monitoring and DefenseControl 13MappedMedium confidence
Trains the segmentation that keeps the vendor channel off backups.