Skip to main content
Staged and Gone: Rclone Bulk Upload to MEGA From a File Server operation cover
COMING SOONIntermediatePRO

Staged and Gone: Rclone Bulk Upload to MEGA From a File Server

A pre-ransomware bulk data-exfiltration investigation. After a perimeter foothold and hands-on command and control, the operator pivoted to a Windows file share server, recovered a domain-administrator password from a plaintext file, staged finance data into a single archive, and bulk-uploaded it to a MEGA cloud remote with a renamed rclone client over HTTPS before any encryptor ran. The organization also runs rclone legitimately on its backup server, so the challenge is separating the sanctioned job from the theft. Reconstruct the staging-then-upload chain from SIEM and perimeter firewall telemetry.

55m
7 tasks
50 points
Pro

Launches in 4 days

Aug 4, 2026

Tuesday, August 4, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

SIEMFirewall

What you'll investigate

7 objectives unlock when this operation goes live.

1Incident brief
2Recover the abused administrator credential
3Find where the data was staged
4Separate the malicious upload tool from the sanctioned one
5Pin the exfiltration destination
6Classify the exfiltration technique
7Recover the exfiltration tool indicator

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Aug 4, 2026, you can jump straight in.

Get Started Free