Skip to main content
Operation Lunar Peek: PAN-OS Mgmt Interface Takeover operation cover
COMING SOONAdvanced

Operation Lunar Peek: PAN-OS Mgmt Interface Takeover

An internet-exposed PAN-OS firewall management interface was taken over in a single night. An unauthenticated attacker bypassed authentication on the management web interface to gain PAN-OS administrator privileges, chained an authenticated command injection to run commands as root, created a rogue administrator for persistence, and wrote a PHP web shell under the appliance web root that a separate host returned to drive interactively. Reconstruct the full management-plane chain from the firewall and SIEM telemetry and classify the key ATT&CK techniques.

1h 15m
8 tasks
150 points
Free

Launches in 5 days

Oct 13, 2026

Tuesday, October 13, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops, free.

Training Tools

FirewallSIEM

What you'll investigate

8 objectives unlock when this operation goes live.

1Incident brief
2Find where the firewall was reachable from the internet
3Catch the authentication bypass
4Identify the host that ran the exploit chain
5Find the persistence account
6Recover the web shell indicator
7Separate the operator who returned to use the web shell
8Classify the implant the operator left behind

Be first when it launches

Create your free account now. The moment this operation goes live on Oct 13, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free