About this interactive
Triage is the skill that separates a security operations centre that works from one that is buried, and it is almost never taught directly. Modules list indicators of compromise — IP addresses, file hashes, domain names, registry keys — and students learn to recognise the categories. What they do not learn is that the category tells you almost nothing about severity. A registry Run key write is the most cited persistence indicator there is, and most Run key writes in a real environment are software installing itself. A changed system-binary hash is the classic file-integrity alarm, and most changed system binaries are patches. A first-seen external destination is a genuine detection primitive, and most first-seen destinations are somebody visiting a website for the first time. An analyst who grades the artifact instead of the evidence will page the on-call engineer for a vendor update and let a beacon sit in the queue behind it. This set is thirty-two indicators, each presented with the context an analyst would actually have, graded against a rubric stated in the instructions so the answer is defensible rather than a matter of taste: High is evidence of an active compromise, Medium is suspicious and unexplained with a benign reading still available, Low is a real but weak signal, and False Positive is an indicator with a verified benign cause. The pool is built in deliberate pairs. The Run key that launches encoded PowerShell thirty seconds after an attachment opened is High; the Run key that launches a vendor-signed EDR updater at the change-ticket timestamp is a false positive. The changed DLL hash that matches the vendor published hash for this month patch is a false positive; the changed cmd.exe whose Authenticode signature fails to validate is High. The unsigned zero-prevalence binary in a developer %APPDATA% that has never executed is Medium; the intelligence-matched loader dropped by a macro onto seven hosts is High. Facing a student with the same artifact twice and a different answer each time is the whole design, because it makes the mistake diagnosable: whoever gets one of a pair wrong skipped a specific clue, and the clue has a name. The technical grounding is deliberate rather than decorative. Every address that stands in for attacker infrastructure comes from the RFC 5737 documentation ranges, which cannot route and therefore cannot point at a real host, and one question makes that fact the answer — a vendor example rule firing on TEST-NET-1 is a false positive by definition. Link-local addressing under RFC 3927 appears as a DHCP failure rather than as an intrusion. Domain generation algorithms appear as a burst of NXDOMAIN with one success; DNS tunneling appears as thousands of TXT queries with long base32 labels; beaconing appears as a fixed interval and a constant payload size rather than as a word in the stem. Impossible travel is graded Medium on the geography alone and High only once the second session creates an external forwarding rule, because a VPN produces the first and nothing benign produces the second. Malicious domains are written defanged with bracketed dots, which is the convention analysts use and one more thing a student picks up by seeing it. Because quiz-game samples at random, the teaching has to survive whichever twelve are drawn: every stem contains the clue that decides it, and the four answer options never change, so the exercise is always reading evidence rather than reading options. The explanation naming that clue is shown to the student as soon as the answer is graded, so a miss says which piece of evidence was skipped rather than only that the bucket was wrong. Run it after the module lessons on Alerts, Logs and Beaconing, and again after the wrap; twelve of thirty-two means two consecutive rounds overlap without repeating, and the indicators that fooled you the first time come back.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →