
Critical Compromise (ICS)
Earned by sechow1 on June 14, 2025
This analyst completed the Critical Compromise in Chicago module, demonstrating their ability to investigate a malware-based attack on a SCADA system. Through their use of Kusto Query Language (KQL), they uncovered the deployment of malicious software that disrupted the power grid. Their investigation helped identify the attack's origin and provided insights into the attackersâ methods, ultimately contributing to the restoration of normal operations and improving defenses for critical infrastructure.
About this Investigation
In this KC7 cybersecurity game, youâll dive into a major power outage in Chicago, caused by a sophisticated attack targeting the city's SCADA systems. As you track down malicious activity, youâll uncover phishing attacks that compromised employees, leading to destructive malware being deployed . Youâll follow evidence of lateral movement, credential theft, and system sabotage, all while uncovering how the attackerâmodeled after a real-world threat actorâgained control and shut down the power grid . Are you ready for the challenge?
Play this investigation.png)