Eye House - Threat Actor Profiling Lab

Week 7 - Incident Response Capstone Back to Week 7

Analysis Objectives

Threat Intelligence Terminal

INCIDENT BRIEFING

Date: 2026-02-10

Organization: GlobalFinance Corp

Incident Type: Advanced Persistent Threat

Initial Detection: Suspicious PowerShell execution detected by EDR

Observed Activity:

- Phishing email with malicious attachment

- Lateral movement via RDP and WMI

- Scheduled task creation for persistence

- Data exfiltration via DNS tunneling

Your Mission: Map the TTPs to MITRE ATT&CK and profile the threat actor.

==========================================
MITRE ATT&CK LOOKUP SYSTEM
==========================================
Available Commands:
search [tactic/technique] - Search ATT&CK framework
describe [TID] - Get detailed info on technique
groups - List known threat groups
match-ttps - Match TTPs to threat groups
System Ready.
intel@mitre:~$

ANALYSIS COMPLETE!

You successfully profiled the threat actor using MITRE ATT&CK.

+25 XP