In this simulation, you will analyze SOC alerts and Brand Intelligence reports related to targeted harassment campaigns against organizational personnel. You will learn to map non-technical threat vectors (like cyberstalking) to network defense actions such as DNS sinkholing and Web Proxy filtering.
The corporate Legal and HR departments have opened a critical incident ticket. The company's Chief Financial Officer (CFO) is the target of a severe cyberstalking campaign. A threat actor has been purchasing domain names that mimic the CFO's name and corporate title to host defamatory content.
As a Network Security Analyst on the Blue Team, you have been provided with indicators of compromise (IoCs) from the Brand Threat Intelligence platform. You need to identify the exact nature of this cyberstalking tactic to correctly classify the incident in the SIEM and update the network's web content filtering and DNS firewalls to prevent internal users from accessing these malicious reputational-damage sites.
Brand Intelligence Alert (SIEM Dashboard):
Note: The internal network proxy currently allows traffic to these newly registered domains because they are not yet classified as malicious by the default vendor feeds.
A threat actor has registered typosquatted or targeted domains specifically designed to host defamatory content against an organizational leader. The network proxy logs indicate that internal users are successfully navigating to these newly registered, uncategorized domains.
This is a sociological/policy-level attack categorized as Cyberstalking: False Accusation. The attacker relies on public web infrastructure (websites, blogs, user pages) to post unverified, reputation-destroying information.
A (False accusation) is correct. Setting up dedicated websites, blogs, or user pages to post derogatory, untrue information specifically maps to the "False Accusation" tactic within cyberstalking frameworks. It is designed purely to damage reputation and turn public/internal opinion against the target.
As a Network Defender, you must immediately bridge the gap between HR/Legal policies and technical controls:
Master real-world network traffic analysis, IDS/IPS tuning, and defensive operations.
Explore more CND simulations