incident-response-trainer
Incident response training · Rule-based scoring
DemoCatalogHistoryDashboard
← Back to catalog
Cyber × Network Fusionextremely-hardTri-Domain: Workload → Interconnect → Detection CrisisCritical asset
Scenario

A compromised cloud workload, a rogue route into on-prem, and a security agent going quiet — all at once

A extremely-hard Cyber × Network Fusion scenario on Tri-Domain: Workload → Interconnect → Detection Crisis.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 6 templates in this Track + Difficulty pool.

catalog id · fusion-tri-domain-workload-interconnect-detection-crisis

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Tri-domain workload-to-on-prem pivot triage under degraded detection
  • Evidence-preserving containment without a full interconnect outage
MITRE ATT&CKmitre-attack
  • Unsecured Credentials: Cloud Instance Metadata API · Credential AccessT1552.005 · TA0006
    MappedHigh confidence

    Trains response to theft and off-node use of the workload's instance metadata role token.

  • Remote Services · Lateral MovementT1021 · TA0008
    PartialMedium confidence

    Trains scoping the cloud-to-on-prem pivot that a rogue route and a widened security group enabled toward the management jump host.

  • Impair Defenses: Disable or Modify Cloud Logs · Defense EvasionT1562.008 · TA0005
    PartialMedium confidence

    Trains the defender side: reconstructing activity after node detection and cloud log forwarding were degraded.

MITRE D3FENDmitre-d3fend
  • Network Traffic AnalysisD3-NTA
    MappedHigh confidence

    Trains using off-node and cloud-provider telemetry to detect the rogue interconnect route and the cloud-to-on-prem probing.

  • User Account ContainmentD3-UAC
    MappedHigh confidence

    Trains revoking the workload instance-role session so the stolen metadata token can no longer call cloud APIs.

  • Service Binary VerificationD3-SBV
    MappedMedium confidence

    Trains verifying the pulled container image against a known-good source before any rebuild.

NIST CSF 2.0nist-csf-2
  • Adverse Event Analysis · DetectDE.AE · DE
    MappedHigh confidence

    Trains separating a genuine workload fault from adversary activity while node detection is degraded.

  • Mitigation · RespondRS.MI · RS
    MappedHigh confidence

    Trains isolating the node and removing the rogue route without a full interconnect outage.

  • Incident Recovery Plan Execution · RecoverRC.RP · RC
    MappedMedium confidence

    Trains recovery that rebuilds the node from a signed known-good image only after evidence capture.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains fault-vs-adversary triage across workload, cloud network, and detection on one timeline.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains evidence-preserving isolation instead of terminating the node or tearing down the interconnect.

  • IR lifecycle phasePost-Incident Activity
    MappedMedium confidence

    Trains hardening instance identities, route change-control, and tamper-evident logging so the crisis cannot recur.

CISA Cybersecurity Performance Goalscisa-cpg
  • Detecting Relevant Threats and TTPs3.A
    MappedHigh confidence

    Trains the detection baseline that surfaces off-node use of a workload metadata token.

  • Document Network Topology2.M
    MappedMedium confidence

    Trains the topology baseline the cloud-to-on-prem route reasoning depends on.

CIS Controls v8cis-controls
  • Access Control ManagementControl 6
    MappedHigh confidence

    Trains workload-identity containment and least privilege when an instance metadata token is stolen.

  • Network Infrastructure ManagementControl 12
    MappedHigh confidence

    Trains safe handling of a rogue cloud route and a widened security group without a full interconnect outage.

  • Audit Log ManagementControl 8
    MappedMedium confidence

    Trains reasoning about the cloud log-forwarding gap and restoring tamper-evident logging.