B1G2 Partner Technical Training 2026
EDR Detection & Investigation Challenge — built on ESET PROTECT and ESET Inspect
Welcome
This is a hands-on detection challenge built on ESET PROTECT and ESET Inspect. You'll work through a real intrusion — from the first malicious file to data leaving the network — and use ESET Inspect to piece together what happened at each step.
How it works
Every flag is something you dig out of the telemetry: a process, a command line, a registry value, an IP address, a hash. Read the question, investigate in the console, and submit what you find. Points scale with difficulty. Not everything shows up under Detections — some answers you have to search the raw events for, so get comfortable filtering by host, process, and command line.
The scenario
This is one continuous intrusion, in two phases:
- Phase 1 — Intrusion. A finance workstation is compromised by a malicious "invoice." Follow the chain from execution and persistence through discovery, a credential-access attempt, a downloaded payload, and the command-and-control beacon.
- Phase 2 — Credential attack from the blind spot. A host with no EDR coverage brute-forces a second machine and moves in. You'll only see it from the target side and the network — that's the point.
On the board, challenges are grouped by MITRE ATT&CK tactic (Initial Access, Execution, Persistence, and so on). Solve them in any order.
Rules
- This is an individual assessment.
- Investigate only inside the ESET Inspect console provided. Don't attack this platform or the lab infrastructure — you're here to investigate it, not break it.
- Flags are case-insensitive. Some are wrapped as
ESET{...}; others are literal values (process names, IPs, hashes). Submit them as you find them. - Stuck for more than ~15 minutes? Reach out to the B1G2 Technical team.
Have fun, and pay attention to the process trees. Good hunting.