incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
CybersecurityhardWeb Shell + Lateral MovementCritical asset
Scenario

Public-facing IIS server hosting unfamiliar .aspx — w3wp spawned cmd.exe + net use to internal file server

A hard Cybersecurity scenario on Web Shell + Lateral Movement.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 5 templates in this Track + Difficulty pool.

catalog id · web-shell-lateral-iis-fileserver

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Web-server persistence triage
  • Lateral-movement scoping discipline
MITRE ATT&CKmitre-attack
  • Server Software Component · PersistenceT1505 · TA0003
    MappedHigh confidence

    Trains web-server persistence triage on a public-facing host.

  • Remote Services · Lateral MovementT1021 · TA0008
    MappedHigh confidence

    Trains defensive scoping of lateral movement from the compromised host.

MITRE D3FENDmitre-d3fend
  • File AnalysisD3-FA
    MappedHigh confidence

    Trains file-analysis triage on web directories.

  • Process Activity AnalysisD3-PAU
    MappedHigh confidence

    Trains process-activity review on the web host.

  • Network Traffic AnalysisD3-NTA
    MappedMedium confidence

    Trains east-west visibility scoping.

NIST CSF 2.0nist-csf-2
  • Continuous Monitoring · DetectDE.CM · DE
    MappedHigh confidence

    Trains detection reasoning on web-server posture.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains scoped containment of a compromised web host.

CISA Cybersecurity Performance Goalscisa-cpg
  • Mitigating Known Vulnerabilities1.E
    MappedHigh confidence

    Trains the vuln-mitigation baseline behind web-server hardening.

  • Detecting Relevant Threats and TTPs3.A
    MappedHigh confidence

    Trains the detection baseline the scenario depends on.

CIS Controls v8cis-controls
  • Application Software SecurityControl 16
    MappedHigh confidence

    Trains the application-software control the scenario exercises.

  • Network Monitoring and DefenseControl 13
    MappedMedium confidence

    Trains the east-west monitoring control.