A phishing email hits Finance at 8:02 AM. Behind it: an APT group that has been inside your network for eleven days. This is the exact path a top-scoring analyst takes, and why every other road ends worse.
In our Cybersecurity Simulations, every case starts you at 100 points and lets your decisions do the talking. Operation Shadow Ledger is the flagship case, and it’s built around one uncomfortable truth of modern incident response: the alert you’re looking at is almost never the beginning of the story.
What looks like a routine phishing report turns out to be the visible edge of a financially motivated APT campaign with nearly two weeks of quiet pre-positioning behind it. Three decision points separate a clean eviction from a $2M ransomware crisis. Watch the optimal run play out below, then let’s break down why each move is the right one.
The Map: Three Decisions, Four Endings
Before the play-by-play, here’s the full branching structure. The green route is the optimal path. Notice that the wrong turns don’t fail right away. They quietly degrade your position and hand the attacker the one currency an APT needs: time.
Decision 1 โ The Phishing Report (08:02 AM)
A Finance analyst forwards a suspicious email from “IT Support” demanding password verification through an external link. The reporter didn’t click. But the same email was delivered to 34 Finance employees.
Why this is the right call
Scope to the blast radius, not the ticket. The reporter is one of 34 recipients. If you only handle the reported copy, you leave 33 live phishing emails sitting in inboxes. In the simulation, that shortcut costs you: two hours later three users have clicked, one entered credentials, and a VPN login from Kyiv succeeds.
Preserve the IOCs before you destroy the evidence. The sender domain, reply-to address, originating IP, and link URL are the threads you’ll pull during the hunt phase. Quarantining (rather than deleting) keeps the artifacts intact for correlation.
Never engage the attacker. The catastrophic branch here is replying to “verify the message is legitimate.” That confirms your address is live and tells the attacker the SOC is awake. In the sim, they immediately fire a second, better-crafted phish at a VP, who clicks. Now there’s a silent mail-forwarding rule on an executive account.
Even the optimal move comes with a twist, and it’s a deliberate lesson: gateway logs show one user, a Finance manager, clicked and entered credentials 13 minutes before your quarantine landed. Perfect execution doesn’t mean perfect outcomes. One credential is already in the wild.
Decision 2 โ The Live Session (09:14 AM)
The stolen credential has already been used: a successful VPN authentication from an IP in Kyiv, three minutes after the user typed her password into the fake page. The session is still active. Threat intel links the IP to an APT group tracked as GHOST LEDGER.
Why this is the right call
This is the pivotal decision of the entire case, and the gap between the two options is subtle. Both kill the session. Both lock the account. The difference is a single assumption.
The standard credential-theft playbook assumes the attack started this morning. Kill session, reset password, check what the session touched, close ticket. That’s fine for a commodity phish. But the evidence says otherwise: a threat-intel-flagged APT IP, instant credential use, a patient and targeted lure. Advanced actors don’t start working the moment they get a password. They pre-position days or weeks in advance. The phish you caught may be their expansion, not their entry.
Assume breach; hunt backwards. The optimal analyst treats the phishing wave as a symptom and goes hunting through weeks of DNS, process, and network telemetry. In the sim, this is exactly what cracks the case open. The playbook branch handles the immediate threat by the book, then gets blindsided at 12:15 PM when a secondary implant detonates on a workstation nobody was watching.
Decision 3 โ The Eleven-Day Beacon (11:30 AM)
The hunt pays off, and what it finds is chilling. A developer workstation has been resolving a low-reputation domain every four hours โ for eleven days. The process chain shows the classic macro infection signature, dated eleven days back. The attacker was inside long before the phishing email ever landed.
Why this is the right call
Against an APT, eviction is all-or-nothing. The tempting alternative is to isolate the beaconing host first, image it carefully, then work through the remaining footholds one by one. That works for commodity malware. Against a live, attentive adversary it’s a fatal tell. The moment their beacon goes dark, they know they’re caught, and they race you: burning C2 infrastructure, activating backup channels, and grabbing whatever data they can on the way out. In the sim, the sequential branch ends with partial exfiltration and a six-figure cleanup.
Simultaneity denies the attacker a reaction window. One coordinated strike leaves them nothing to pivot to: every implant isolated, every credential rotated, every session revoked in the same moment. Eleven days of patient pre-positioning, erased in one window. That’s the textbook APT eviction doctrine, and it’s why this decision carries the biggest score of the case.
The Ending You’re Playing For
โ APT EVICTED โ OPERATION NEUTRALIZED (final score: 150)
Memory forensics confirms the C2 framework and attribution. Eleven days of dwell time, yet the attacker never reached their staging phase. No data left the network. Regulatory notifications: none required. And the run ends with the quiet, professional flourish that separates good teams from great ones: the IOCs go to the industry ISAC, and three peer firms get early warning of GHOST LEDGER’s campaign.
Where the Other Roads Lead
| Shortcut taken | What it costs | Best ending still reachable |
|---|---|---|
| Block future delivery, ignore the 33 delivered copies | Three clicks, one credential harvested, attacker browses file shares for 17 minutes | Partial โ $180K |
| Reply to the phisher “to verify” | Attacker confirms live target, phishes a VP, plants a forwarding rule on an executive inbox | Partial โ $180K |
| “Monitor the attacker” without deception infrastructure | They spread malware internally while you watch; domain admin falls next | Breach โ $2.4M |
| Standard playbook, no hunt | Secondary implant detonates three hours later on an unwatched host | Partial โ $180K |
| Block one C2 IP + AV scan | Implant rotates channels via domain fronting; credential hashes dumped | Breach โ $2.4M |
| Restore from backup before containing | Attacker re-encrypts instantly, then stages a full deployment overnight | Ransomware โ 47 servers, $2M demand |
The Takeaway
Strip away the terminal windows and the score counter, and Operation Shadow Ledger teaches three habits that transfer directly to real SOC work:
1. Respond to the blast radius, not the report. The ticket in front of you is a sample of the incident, not its boundary. Ask “who else got this?” before you ask anything else.
2. Treat every credential-theft alert as a possible mid-campaign discovery. The cheapest question in incident response is “what if they’ve been here longer than this alert?” The hunt it triggers is the difference between this case’s victory and its breach endings.
3. When you evict an advanced attacker, evict them everywhere at once. Sequential cleanup telegraphs your next move to an adversary who is faster than your change-control process. Plan the eviction fully, then execute it simultaneously.
None of these are exotic. That’s the point. The optimal path through an APT incident isn’t a stroke of genius โ it’s disciplined fundamentals executed under time pressure, three times in a row, while the wrong option looks almost identical to the right one.
Think you’d have caught the eleven-day beacon?
There are four endings. Most first runs don’t find the best one.