
COMING SOONBeginner
PowerShell Download Cradle: Encoded Payload on a Workstation
A finance workstation runs an obfuscated PowerShell command with a base64-encoded download cradle that fetches and executes a second-stage payload, which then beacons out to a C2 host. Work through the Sysmon and Windows Security event logs alongside the XDR process tree to trace the encoded launch, the staging fetch, the dropped file, and the recurring beacon.
25m
6 tasks
25 points
FreeLaunches in 5 days
Oct 6, 2026
Create your free accountTuesday, October 6, 2026 at 9:00 AM
Be ready the moment it drops, free.
Training Tools
XDRSIEM
What you'll investigate
6 objectives unlock when this operation goes live.
1Spot the suspicious PowerShell launch
2Identify the parent process
3Trace the staging server
4Name the dropped payload
5Find the C2 beacon destination
6Classify the obfuscation technique
Be first when it launches
Create your free account now. The moment this operation goes live on Oct 6, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.
Get Started Free