
Spring4Shell: Class-Loader RCE to Webshell (CVE-2022-22965)
An internet-facing Java Spring MVC application is compromised through CVE-2022-22965 (Spring4Shell), a class-loader manipulation flaw that turns Tomcat's own logging system into a webshell writer. Working from the Tomcat access logs and the perimeter firewall, trace the exploit request, identify what landed on disk, follow the operator's command sessions, and catch the pivot to an internal backend service.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Trace the exploit source
20Multiple external addresses touched the Spring application. One of them sent a POST request whose parameters manipulated internal framework properties in a way no legitimate API client would. Identify the source address behind that exploitation request.
Identify the dropped webshell
20The class-loader exploit did not execute code directly; it abused the Tomcat logging system to write a file to disk. Identify the filename of the JSP that was written to the web application root.
Name the service account behind the commands
15The webshell runs commands on the operating system, but it does not choose who those commands run as. The OS account is whatever account the Tomcat process itself uses. Identify the service account that executed the shell commands.
Determine the operator source address
20The IP that planted the webshell and the IP that drove commands through it are distinct. Identify the address that acted as the hands-on operator after the webshell was established.
Spot the lateral probe
25Shortly after gaining command execution, the attacker pivoted from the compromised application server to probe a backend service that is only reachable from inside the network. Identify the internal destination IP the compromised host connected to.
Classify the persistence technique
20The attacker gained durable access to the compromised server not by adding a system service or a crontab entry but by planting a file inside the web application itself. Identify the MITRE ATT&CK technique that describes using a server-side web file for persistent access.
6 tasks · 120 points total
Training Tools
Skills You'll Build
Requires foundational alert triage skills. Multiple data sources to correlate.
Prerequisites
- Basic understanding of security alerts
- Familiarity with SIEM concepts
- Familiarity with Firewall concepts
Ready to investigate?
More Operations
View allLLMNR and NBT-NS Poisoning: NTLM Relay to SMB
A workstation on the Vantara Solutions network mistyped a file server name. DNS had no answer. Windows broadcast the query over LLMNR -- and something on the network answered. Reconstruct the poisoning, the credential capture, and the relay that followed using SIEM events, endpoint telemetry, and a raw packet capture.
Cisco IOS XE Web UI: Implant and Rogue Admin (CVE-2023-20198)
The Cisco IOS XE Web UI management interface on AXFORD-RTR-01 was inadvertently exposed to the internet. An attacker exploited CVE-2023-20198 to create an unauthenticated privilege-15 local account, then chained CVE-2023-20273 to drop a Lua implant on the device flash filesystem. The implant hooked the HTTP server and beaconed to an external C2 address. Reconstruct the full compromise chain from the router syslog and the perimeter firewall.
Golden Ticket: Forged Kerberos TGT Persistence
A threat actor who already extracted the krbtgt hash from a domain workstation forged Kerberos TGTs offline and used them to access any domain resource without re-touching the domain controller. The telltale signs are RC4-encrypted TGS requests with no preceding AS-REQ and a domain controller that starts beaconing outbound. Reconstruct the full chain from LSASS extraction to C2 beacon using Windows Security events and XDR process telemetry.