Skip to main content
OneClik: ClickOnce + AppDomainManager Injection with ETW Patching and AWS-Hidden C2 operation cover
COMING SOONAdvancedPRO

OneClik: ClickOnce + AppDomainManager Injection with ETW Patching and AWS-Hidden C2

A ClickOnce-delivered intrusion at an oil-and-gas operator that mirrors nation-state tradecraft. A spearphishing link served a Microsoft ClickOnce deployment that ran under the trusted dfsvc.exe, sideloaded a signed binary whose tampered .config used .NET AppDomainManager hijacking to load an attacker assembly at CLR startup, patched Event Tracing for Windows to blind the sensor, ran anti-debugging checks, and injected a Golang backdoor (RunnerBeacon) that hid its C2 behind AWS CloudFront and API Gateway. Reconstruct the chain from email, endpoint XDR, and cloud audit telemetry, and classify the key ATT&CK techniques.

1h 25m
8 tasks
150 points
Pro

Launches in 4 days

Aug 11, 2026

Tuesday, August 11, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

EmailXDRCloud

What you'll investigate

8 objectives unlock when this operation goes live.

1Incident brief
2Classify the proxied-execution technique
3Name the sideloaded signed binary
4Classify the runtime injection technique
5Recover the loader assembly hash
6Classify the telemetry-blinding technique
7Identify the cloud-fronted command channel
8Recover the paired C2 task endpoint

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Aug 11, 2026, you can jump straight in.

Get Started Free