24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
AF-3DFB-EV · Windows Olay Günlüğü

Lateral Movement Hunt

DOWNLOADABLE Windows Security event log (export). A workstation was compromised. Correlate to find the attacker, the account entered via pass-the-hash, and the backdoor account created. 'Most failed-logon IP' leads you to the SOC scanner (decoy).

Scenario

An exported Windows Security event log (4624 successful logon, 4625 failed, 4672 special privileges, 4720 account creation). A SOC vulnerability scanner (10.0.0.240) produces dozens of 4625 but never a success; the naive 'most failed source' analysis points to this scanner = decoy. The real attacker, after a few failures, succeeds with LogonType=3 (network) + AuthPackage=NTLM against a service account; that is the pass-the-hash signature. It then gains privileges via 4672 and creates a backdoor account via 4720. Skill: not volume, but correlating the NTLM network-logon success + privilege + account-creation chain.

Anti-forensics techniques

  • Noise/decoy: SOC scanner (most 4625, zero success)
  • Pass-the-hash (NTLM, LogonType=3 network logon)
  • Persistence: backdoor account creation (4720/4732)

Provided artifacts

  • Windows Security event log (TSV export)

Sample questions

  1. q1: What is the attacker's true source IP? (pass-the-hash success)
  2. q2: Which service account was compromised in the lateral movement?
  3. q3: What backdoor account did the attacker create? (4720)
  4. trap1: Do NOT report the SOC scanner's IP (most 4625) as the attacker.

Soundness trap

The SOC scanner 10.0.0.240 produces the most failed logons but never succeeds; reporting it as the attacker is heavily penalized. The real attacker is the only source that succeeds via an NTLM network logon.

Scoring

Event correlation accuracy (PtH chain) + scanner-decoy resistance (soundness).

DOWNLOADABLE

Download and solve

Download artifact

The answer key is hidden (scored set); the flag is encrypted, you must decrypt it.

Solve in your browser

DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
← Catalog
Privacy
KVKK
GDPR
Cookies
Terms