Skip to main content
PAN-OS GlobalProtect: Command Injection (CVE-2024-3400) operation cover
COMING SOONIntermediate

PAN-OS GlobalProtect: Command Injection (CVE-2024-3400)

An internet-facing Palo Alto Networks firewall published its GlobalProtect VPN portal to the world, and an unauthenticated command-injection flaw turned a single crafted request into code execution on the appliance. The attacker validated the bug with a zero-byte canary, stole the firewall's running configuration, dropped a python implant that takes commands from the device's own error log, and pivoted off the box into the domain controller. Reconstruct the chain from the firewall system, GlobalProtect, and perimeter traffic logs.

45m
6 tasks
50 points
Free

Launches in 5 days

Oct 13, 2026

Tuesday, October 13, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops, free.

Training Tools

SIEMFirewall

What you'll investigate

6 objectives unlock when this operation goes live.

1Find the way in
2Spot the dry run
3Catch the execution
4Recover what was stolen
5Trace the command channel
6Name the pivot

Be first when it launches

Create your free account now. The moment this operation goes live on Oct 13, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free