CND (312-38) Network Defense Simulation

In this simulation, you will analyze SOC alerts and Brand Intelligence reports related to targeted harassment campaigns against organizational personnel. You will learn to map non-technical threat vectors (like cyberstalking) to network defense actions such as DNS sinkholing and Web Proxy filtering.

Network Scenario

The corporate Legal and HR departments have opened a critical incident ticket. The company's Chief Financial Officer (CFO) is the target of a severe cyberstalking campaign. A threat actor has been purchasing domain names that mimic the CFO's name and corporate title to host defamatory content.

As a Network Security Analyst on the Blue Team, you have been provided with indicators of compromise (IoCs) from the Brand Threat Intelligence platform. You need to identify the exact nature of this cyberstalking tactic to correctly classify the incident in the SIEM and update the network's web content filtering and DNS firewalls to prevent internal users from accessing these malicious reputational-damage sites.

Traffic & Logs

Brand Intelligence Alert (SIEM Dashboard):

[ALERT ID: THREAT-INTEL-88912] TIMESTAMP: 2026-04-11T14:22:01Z SOURCE: Brand Protection API CATEGORY: Brand Abuse / Defamation DETAILS: Multiple new domain registrations detected targeting CFO persona. DOMAIN 1: thetruthabout[CFO-NAME]fraud.com (Active - Hosting Blog) DOMAIN 2: [CFO-NAME]-embezzlement-exposed.net (Active - Hosting User Page) [PROXY LOG - FIREWALL-01] 14:25:33 SRC: 10.10.5.55 (Internal Desktop) DST: 198.51.100.42 (thetruthabout[CFO-NAME]fraud.com) PROTO: HTTPS ACTION: ALLOWED CATEGORY: Uncategorized

Note: The internal network proxy currently allows traffic to these newly registered domains because they are not yet classified as malicious by the default vendor feeds.

Question

Which of the following types of cyberstalking damages the reputation of their victim and turns other people against them by setting up their own Websites, blogs, or user pages for this purpose?
Analyst Hint: Look at the logs showing domains like "thetruthabout...fraud.com". The attacker is not gathering data or pretending to be attacked; they are actively projecting fabricated, damaging narratives via dedicated web pages.

Expert Analysis

1. What is happening in the network

A threat actor has registered typosquatted or targeted domains specifically designed to host defamatory content against an organizational leader. The network proxy logs indicate that internal users are successfully navigating to these newly registered, uncategorized domains.

2. Identify attack or behavior

This is a sociological/policy-level attack categorized as Cyberstalking: False Accusation. The attacker relies on public web infrastructure (websites, blogs, user pages) to post unverified, reputation-destroying information.

3. Why the correct answer is correct

A (False accusation) is correct. Setting up dedicated websites, blogs, or user pages to post derogatory, untrue information specifically maps to the "False Accusation" tactic within cyberstalking frameworks. It is designed purely to damage reputation and turn public/internal opinion against the target.

4. Why others are wrong

  • B (Attempts to gather information): This describes reconnaissance, footprinting, or doxing, not the act of publishing defamatory sites.
  • C (Encouraging others to harass): This refers to proxy stalking or swarming (e.g., posting the victim's phone number on a public forum), rather than setting up dedicated false accusation blogs.
  • D (False victimization): This happens when the stalker falsely claims the victim is actually harassing them, reversing the roles to gain sympathy or legal leverage.

5. Defensive action

As a Network Defender, you must immediately bridge the gap between HR/Legal policies and technical controls:

  • DNS Sinkholing / DNS RPZ: Add the identified domains to the internal DNS Response Policy Zone so internal resolution attempts return NXDOMAIN or direct to a safe block page.
  • Web Proxy/Firewall Rules: Add the IPs and URLs to the proxy's custom blocklist. Temporarily restrict access to "Newly Registered Domains (NRD)" if your firewall supports it.
  • Threat Hunting: Query SIEM logs for the domains to see which internal users have already accessed the sites, assisting HR in understanding the internal spread of the disinformation.

6. MINI LESSON: Brand Intelligence & Web Defense

  • Detection vs Prevention: Traditional IDS/IPS will not flag this traffic because there is no malware payload or network exploit occurring over HTTPS. It is technically "clean" web traffic.
  • Brand Monitoring: Modern network defense requires ingesting Threat Intel feeds for brand abuse. Defenders must block malicious infrastructure before it is weaponized for phishing or, as in this case, reputation destruction.
  • Defense-in-Depth: Protecting an organization includes protecting its personnel. Integrating HR incidents with fast-response network layer blocking (DNS/Proxy) mitigates the impact of social engineering and harassment campaigns.

Ready to advance your defensive mindset?

Master real-world network traffic analysis, IDS/IPS tuning, and defensive operations.

Explore more CND simulations