Skip to main content
Qilin: Veeam credential abuse to ESXi hypervisor encryption operation cover
AdvancedSIEMXDRFirewallPRO

Qilin: Veeam credential abuse to ESXi hypervisor encryption

A Qilin operator exploits a manufacturing firm's SSL-VPN edge, recovers stored credentials from an internet-facing backup server, steals a domain-admin token, self-propagates over SMB to vCenter, exfiltrates data over an encrypted tunnel, clears the Windows logs, and encrypts the ESXi datastores after mass-powering-off the guests. Work the FortiGate and Windows logs, the endpoint process tree, the perimeter traffic, and the vCenter/ESXi records to reconstruct the path from the edge to the hypervisor.

1h 35m
7 tasks
150 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Find the way in

50

A manufacturing network with an internet-facing SSL-VPN edge saw a run of malformed remote-access requests this morning, immediately before an outsider established a session. Work the perimeter records and identify the external address that exploited the edge device.

Hint available
2

Identify the looted server

55

Once inside, the operator went straight for a server that stores credentials it could reuse. Determine which host had its stored credentials read out of a product configuration database.

Hint available
3

Pin the operator's address

55

The hands-on operator worked through the VPN to reach that server over RDP. Identify the external address the operator used so it can be blocked and hunted across the estate.

Hint available
4

Catch the reach to the hypervisor

60

From the looted server the operator self-propagated and reached the virtualization management plane. Identify the management host the propagation routine deliberately targeted.

Hint available
5

Follow the data out

55

Before the hypervisor was touched, engineering data was copied out of the network. Identify the external host the stolen data was transferred to.

Hint available
6

Confirm the hypervisor impact

60

Late in the day the virtualization layer was encrypted. Determine the file extension that was appended to the encrypted virtual-machine disk files on the datastores.

Hint available
7

Classify the recovery sabotage

50

Just before encryption, the operator made sure the victim could not simply restart the affected workloads. Map that anti-recovery activity at the hypervisor to the MITRE ATT&CK technique it represents.

Hint available

7 tasks · 385 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
XDR log analysis
Firewall log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Advanced

Complex multi-stage investigations. Realistic noise, ambiguous indicators, lateral movement.

Prerequisites

  • Basic understanding of security alerts
  • Experience with log analysis tools
  • Familiarity with SIEM concepts
  • Familiarity with XDR concepts
  • Familiarity with Firewall concepts

Ready to investigate?

More Operations

View all
AdvancedSIEMXDR

Medusa RaaS: VPN access to enterprise encryption

A regional healthcare provider is breached through its internet-facing SSL-VPN, and within a shift a Medusa affiliate harvests domain credentials, pivots to the domain controller and backup servers, persists with a rogue remote-management agent hidden among the estate's legitimate ones, steals patient data to cloud storage, and deploys ransomware. Work the VPN authentication records, the endpoint process tree, and the perimeter traffic to reconstruct the intrusion end to end and tell the abuse apart from a heavy baseline of normal remote-management activity.

1h 35m150 pts
AdvancedSIEMXDR

Play (Playcrypt): FortiOS + Exchange to Double Extortion

Operators consistent with the Play ransomware group abuse a valid SSL-VPN account and exploit a published Exchange server, run AdFind and Grixba, disable the endpoint defenses, beacon out with Cobalt Strike and SystemBC, move laterally over RDP, archive Finance and HR data with WinRAR, and upload roughly 9.6 GB to a file-sharing service before deleting shadow copies and running an intermittent-encryption impact stage. Work the FortiGate edge, Exchange web logs, the endpoint process tree, the perimeter egress, and the extortion email to reconstruct the full double-extortion intrusion.

1h 45m150 pts
AdvancedSIEMXDR

BianLian: Exfiltration-Based Extortion

A threat actor with a valid domain account and no MFA to stop them lands on an internet-facing RDP jump host, spends the morning living off the land, dumps credentials from LSASS, and spends the afternoon moving approximately 47 GB of engineering documents out of the network through a cloud-sync utility pointed at storage they control. No files are encrypted; the leverage is the stolen data itself. Reconstruct the full chain from initial RDP spray to log wipe.

1h 55m150 pts