top of page

Defend The City Challenge-Protect the Hospital

  • 5 Days
  • 20 Steps
Get a certificate by completing the program.
Everyone who has completed all steps in the program will get a badge.

About

The Challenge Scenario: Hospital Malware Investigation A hospital security team has received an alert about suspicious activity on a workstation used by clinical staff. The activity began when a suspicious file named invoice_update.exe was opened on NURSE-STATION-03. The file started PowerShell, created an unusual outbound connection, and was followed by similar activity on another hospital device, ER-WS-02. Threat intelligence shows that some of the observed behavior is similar to activity associated with the Red Raven threat profile, but the evidence does not confirm who is responsible. As a Defender, your job is to review the available evidence, determine how serious the incident may be, understand whether the activity has spread, and recommend the safest next response. Your Mission Use the Defender SOC to: Review the security alert Prioritize the incident Investigate the affected hospital devices Compare the evidence with known threat behavior Recommend the appropriate response Enter the Challenge Room and make your final decisions What You Need to Determine By the end of the investigation, you should be able to answer: What happened? Which systems may be affected? What evidence suggests the activity spread? How does the threat intelligence help explain the activity? What should the defender recommend doing next? Mission Objective Protect hospital operations by identifying the suspicious activity, understanding its possible impact, and recommending the safest response based on the evidence.

Overview

Instructors

Cyber Defender Free Access, Free
bottom of page