Skip to main content
Akira Ransomware: Full Kill Chain IR operation cover
AdvancedSIEMXDRFirewallPRO

Akira Ransomware: Full Kill Chain IR

The intrusion began with a search engine advertisement and ended with the deployment of Akira ransomware. This scenario covers the full 2025 threat landscape, emphasizing identity-based compromise, MFA bypass via AiTM kits, and rapid lateral movement toward Active Directory. Analysts must navigate a complex environment of Windows workstations, Domain Controllers, and Cisco VPN infrastructure to reconstruct the timeline from initial access to data exfiltration and final encryption.

2h
10 tasks
150 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Identify the Ransomware Payload

10

CORP-FS-01 went dark overnight: files across the share were renamed to an unfamiliar extension and a ransom note appeared. The host that drove the encryption is corp-wks-102. Working from the impact backward, identify the executable that carried out the mass-encryption stage on that host.

Hint available
2

Recover the Encryption Key Argument

10

Akira's operators pass their per-victim encryption key on the command line when they launch the encryptor. Having identified the payload on corp-wks-102, examine how it was invoked and recover the key value the operator supplied at runtime.

Hint available
3

Trace the Pre-Encryption Data Staging

10

Before detonating the ransomware, the actor staged data for theft: a 14 GB transfer left CORP-FS-01 for an external host the night before encryption. On corp-wks-102 a burst of process activity preceded that transfer. Determine which legitimate-looking third-party utility the actor used to compress and bundle the data for exfiltration.

Hint available
4

Identify the Command-and-Control Channel

10

The operator needed an interactive channel to drive corp-wks-102 between initial access and impact. Shortly after the loader executed on the host, it began beaconing outbound to an external server. Identify the command-and-control destination the host was reaching out to.

Hint available
5

Uncover the Lateral Movement Mechanism

10

From corp-wks-102 the actor pivoted toward the Domain Controller, installing a service on the remote host to run commands with SYSTEM privileges. Identify the service binary that carried out this remote-execution-based lateral movement.

Hint available
6

Identify the Attacker-Created Privileged Account

10

To move freely and reach the Domain Controller, the actor needed privileges beyond the compromised user benjamin.smith. Investigate the net.exe activity on corp-wks-102 and the related account-management events to identify the high-privilege account the actor created and then reused to run the encryptor.

Hint available
7

Determine the Targeted Active Directory Artifact

10

With a privileged account in hand, the actor went after Active Directory's credential store wholesale. Review the file-system activity in XDR on corp-wks-102 and identify the critical Active Directory database file the actor accessed to harvest every domain credential at once.

Hint available
8

Reconstruct the Credential Harvesting Technique

10

The privileged account did not appear from nowhere: earlier in the intrusion the actor harvested credentials directly from memory on corp-wks-102. Examine the process-execution chain and credential-access behavior in XDR to determine which signed system DLL was abused, alongside rundll32.exe, to dump LSASS memory.

Hint available
9

Identify the Alternate Execution Interpreter

10

Tracing further back toward the foothold: after the malicious installer ran on corp-wks-102, the actor sidestepped PowerShell controls by running their logic through a different scripting interpreter. Review the execution events that follow the msiexec.exe activity and identify the interpreter the actor used.

Hint available
10

Pinpoint the Initial Access Foothold

10

Closing the loop on root cause: the entire intrusion began with user benjamin.smith on corp-wks-102, where a file was dropped into a user temp directory after slipping past standard filtering. Analyze the XDR file-system artifacts for that user and identify the document written to disk as the initial-access foothold.

Hint available

10 tasks · 100 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
XDR log analysis
Firewall log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Advanced

Complex multi-stage investigations. Realistic noise, ambiguous indicators, lateral movement.

Prerequisites

  • Basic understanding of security alerts
  • Experience with log analysis tools
  • Familiarity with SIEM concepts
  • Familiarity with XDR concepts
  • Familiarity with Firewall concepts

Ready to investigate?

More Operations

View all
BeginnerSIEMFirewall

The Template That Read the Disk

The file-transfer portal that Tideglow Logistics' partners upload to spent a morning returning host files it was never meant to publish, and finished it running an administrator session nobody had logged into. The root cause is CVE-2024-4040 in CrushFTP 10.6.0. Walk the access logs and firewall traffic step by step to trace how a client holding no credentials turned a request parameter into a read of the host, and that read into a takeover.

25m25 pts
BeginnerEmailXDR

OneNote Attachment to RAT: A Guided First Investigation

A logistics contracts employee at Glacierline Freight opens an attachment that arrived in her inbox and clicks a button inside it. Minutes later her workstation is running something that appears on no software inventory and is talking to a host that no business process uses. Walk the email gateway records, the file artifacts and the endpoint process tree one step at a time, and work out for yourself which message carried the delivery, what landed on disk, and what ran.

15m25 pts
BeginnerSIEMFirewall

Hijacked Discord Invite to ClickFix Loader: Tracing the Lure

A finance analyst at Halcyon Wealth Partners followed a recycled Discord invite that quietly redirected the browser to a fake verification page. They did what the page asked, and inside the hour the workstation was running a remote-access trojan alongside an info-stealer that shipped browser data straight out of the building. Walk the proxy, endpoint and firewall evidence step by step to trace the lure, the loader, the C2 beacon and the data theft.

15m25 pts