Skip to main content
Medusa RaaS: VPN access to enterprise encryption operation cover
COMING SOONAdvancedPRO

Medusa RaaS: VPN access to enterprise encryption

A regional healthcare provider is breached through its internet-facing SSL-VPN, and within a shift a Medusa affiliate harvests domain credentials, pivots to the domain controller and backup servers, persists with a rogue remote-management agent hidden among the estate's legitimate ones, steals patient data to cloud storage, and deploys ransomware. Work the VPN authentication records, the endpoint process tree, and the perimeter traffic to reconstruct the intrusion end to end and tell the abuse apart from a heavy baseline of normal remote-management activity.

1h 35m
7 tasks
150 points
Pro

Launches in 4 days

Aug 4, 2026

Tuesday, August 4, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

SIEMXDRFirewall

What you'll investigate

7 objectives unlock when this operation goes live.

1Find the account that opened the door
2Pin the entry address
3Catch the credential theft
4Separate the rogue remote-management agent
5Follow the patient data out
6Classify the recovery sabotage
7Read the impact signature

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Aug 4, 2026, you can jump straight in.

Get Started Free