Skip to main content
Removable Media: USB Autorun Malware on a Workstation operation cover
COMING SOONBeginner

Removable Media: USB Autorun Malware on a Workstation

A USB drive plugged into a Kaldera Systems workstation auto-ran a malicious shortcut that executed a VBScript dropper, planted a persistence Run key, and began beaconing to an external C2 host. Single-host endpoint triage using XDR process-tree and SIEM Sysmon logs.

25m
6 tasks
25 points
Free

Launches in 5 days

Oct 13, 2026

Tuesday, October 13, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops, free.

Training Tools

XDRSIEMQuery

What you'll investigate

6 objectives unlock when this operation goes live.

1Identify the infected workstation
2Name the user who executed the malicious file
3Find the persistence mechanism
4Identify the dropped payload
5Find the C2 domain
6Map the persistence to ATT&CK

Be first when it launches

Create your free account now. The moment this operation goes live on Oct 13, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free