Operation 01: SOC Case 001 — Password Spray to Persistence is ready in the Classroom. Access is individual and is not granted automatically by this announcement. How to get access If you are new to North Star—or you have not received an individual invitation and assigned Case 001 link—send me a private Skool DM that says: Operation 01 access request Do not include a password, TOTP code, recovery code, token, cookie, or other authentication material. Do not use or request another learner’s invitation or link. Wait for me to confirm that your individual access is ready before entering the investigation. If you already have a working individual invitation and assigned Case 001 link, you may begin with Start Here: Scope & Downloads. In this guided, fully synthetic investigation, you will: • review authentication and endpoint evidence; • reconstruct a chronological timeline; • distinguish confirmed facts from supported assessments and unknowns; • recommend defensible response actions; • produce an investigation worksheet and incident report. Estimated time: 60–90 minutes. Before you begin 1. Confirm that you have received your individual invitation and assigned Case 001 link. 2. Open Start Here: Scope & Downloads. 3. Download the Quick Start Guide and Investigation Worksheet. 4. Read the authorized scope and privacy boundaries. 5. Use only your individual North Star invitation and assigned Case 001 link. 6. Complete central password-plus-TOTP authentication. Wazuh should open through federated SSO without requesting a second password. If Wazuh presents a local username/password form, stop and send me a private Skool DM. Your evidence view should contain exactly 15 synthetic events from 2026-07-26 00:00:00 to 00:12:00 UTC. Stop and request private support if the count, time window, learner identity, cohort visibility, or available permissions differ. Submission Submit exactly two editable DOCX files in one private Skool DM thread to me: 1. Completed OP-001 Investigation Worksheet