Skip to content

DamianLee20/phantom-credentials.md

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

7 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Tabletop Exercise: Phantom Credentials – Initial Access & Pivoting Drill

This tabletop cybersecurity exercise simulates a credential theft and lateral movement attack within a professional services organization. Participants will respond to a simulated phishing attack, investigate suspicious activity, and coordinate incident response actions.

🎯 Scenario Summary

A phishing email compromises a user's VPN credentials. The attacker leverages the credentials to gain access to internal systems and escalates privileges using Active Directory tools.

🧠 Learning Objectives

  • Test and validate incident response procedures
  • Enhance team coordination and communication
  • Identify gaps in security tools and policies

πŸ“ Contents

  • phantom-credentials.md: Complete exercise scenario and flow
  • artifacts/: Placeholder for injects, logs, emails (coming soon)
  • instructions.md: (Optional) Guide for facilitators and observers

πŸš€ How to Use

  1. Review the scenario and timeline in phantom-credentials.md
  2. Use logs, emails, or fake alerts from artifacts/ (if added)
  3. Assign roles and walk through each phase
  4. Conduct a debrief using provided reflection questions

πŸ“Ž Reference

Inspired by MITRE ATT&CK techniques:

  • Initial Access (T1078)
  • Lateral Movement (T1021)
  • Credential Access (T1003)

Built by Damian Lee | GitHub Profile

About

tabletop-exercises/phantom-credentials

Resources

License

Stars

Watchers

Forks

Packages

 
 
 

Contributors