Threat Hunting Workshop: Hunting for Initial Access

Earn Your Threat Hunting - Initial Access (Level 1) Badge!

You’ve signed up for the workshop, you've studied to the data, and you've even gotten your hands dirty. Now is the time to put your knowledge to the ultimate test!

The data you've been provided during the workshop contains several initial access examples that you have had a chance to observe and hunt for. In the data there exists another technique that falls under initial access. Hunt through the data and see if you can find it!

For those that successfully answer the questions, you will be awarded the Intel 471 Threat Hunting badge for Initial Access (Level 1).

How Do You Claim Your Badge?

The data is already imported into your Elastic instance during set up - all you have to do is begin your hunt!

REMEMBER: You can submit as many times as you like!

What was the event code that confirmed the scheduled task was either successfully, or unsuccessfully, created?

Cyborg and Intel 471 Logo - Full Color - Transparent