Skip to main content
LockBit 3.0: Affiliate Full Kill Chain operation cover
COMING SOONAdvancedPRO

LockBit 3.0: Affiliate Full Kill Chain

A LockBit 3.0 affiliate gained entry through a ProxyShell-class exploit on an internet-facing Exchange server, dropped a webshell as SYSTEM, harvested domain-admin credentials from LSASS on the domain controller, spread laterally across every high-value server, exfiltrated the primary data share with rclone, deleted all shadow copies and backup catalogs, and deployed the encryptor as a Windows service. Trace the complete kill chain from initial foothold to ransomware impact across SIEM event logs, XDR process telemetry, and perimeter firewall records.

1h 40m
9 tasks
150 points
Pro

Launches in 5 days

Jul 28, 2026

Tuesday, July 28, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

SIEMXDRFirewall

What you'll investigate

9 objectives unlock when this operation goes live.

1Identify the initial foothold on the Exchange server
2Confirm the credential theft on the domain controller
3Identify the account used to spread across the estate
4Locate where the attacker erased the audit trail
5Confirm the pre-encryption exfiltration destination
6Map the shadow-copy deletion to its ATT&CK technique
7Reconstruct the initial-access technique
8Name the credential-access sub-technique used on the DC
9Classify the final-stage ransomware technique

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Jul 28, 2026, you can jump straight in.

Get Started Free