Skip to main content
PowerShell Download Cradle: Encoded Payload on a Workstation operation cover
COMING SOONBeginner

PowerShell Download Cradle: Encoded Payload on a Workstation

A finance workstation runs an obfuscated PowerShell command with a base64-encoded download cradle that fetches and executes a second-stage payload, which then beacons out to a C2 host. Work through the Sysmon and Windows Security event logs alongside the XDR process tree to trace the encoded launch, the staging fetch, the dropped file, and the recurring beacon.

25m
6 tasks
25 points
Free

Launches in 5 days

Oct 6, 2026

Tuesday, October 6, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops, free.

Training Tools

XDRSIEM

What you'll investigate

6 objectives unlock when this operation goes live.

1Spot the suspicious PowerShell launch
2Identify the parent process
3Trace the staging server
4Name the dropped payload
5Find the C2 beacon destination
6Classify the obfuscation technique

Be first when it launches

Create your free account now. The moment this operation goes live on Oct 6, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free