
COMING SOONIntermediatePRO
NetSupport RAT: Phishing ZIP to Domain Compromise
A finance coordinator opened a ZIP that posed as an overdue invoice. Inside was an obfuscated JavaScript dropper that spawned PowerShell, downloaded a NetSupport Manager remote-control client, and ran it as a RAT from AppData. The operator enumerated the domain, reused a domain admin credential to RDP into the domain controller, dumped the NTDS.dit database, and tunneled it out. Trace the kill chain from the phishing email to full domain compromise.
1h
8 tasks
50 points
ProLaunches in 5 days
Oct 13, 2026
View Pro plansTuesday, October 13, 2026 at 9:00 AM
Pro unlocks this operation at launch.
Training Tools
SIEMEmailXDRFirewallQuery
What you'll investigate
8 objectives unlock when this operation goes live.
1Scope the intrusion
2Identify the phishing sender
3Trace the script execution
4Recover the delivery host
5Pin the command-and-control gateway
6Identify the credential dumped from the domain controller
7Find the exfiltration endpoint
8Classify the remote-access tradecraft
Be first when it launches
Create your account and grab Pro before launch. The moment this operation goes live on Oct 13, 2026, you can jump straight in.
Get Started Free