
Zerologon DC takeover → ransomware
An unprivileged phishing foothold becomes a domain-wide ransomware outbreak in hours. The attacker abuses the Zerologon flaw to reset a domain controller's machine-account password, pivots controller-to-controller, and encrypts the estate after gutting the backups. Work the Windows Security log, the endpoint process tree, and the perimeter traffic to reconstruct the takeover.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Find the foothold
50A manufacturing domain saw a workstation light up with mail-borne activity this morning before anything touched the servers. Work the endpoint process records and identify the workstation where the intrusion began.
Identify the controller that was tampered with
60After enumerating the domain from that foothold, the intruder went straight at the directory's core. Determine which domain controller had its own machine account altered.
Trace the source of the change
55The controller's machine account was reset from somewhere on the inside. Pin down the internal address the tampering came from so it can be contained.
Catch the controller phoning home
60Once the directory fell, the attacker stood up a beacon on a second controller. Follow the perimeter traffic and name the external destination that a domain controller began contacting.
Classify the escalation technique
50Summarize for the incident report how an unprivileged host seized the domain. Map the core escalation to its MITRE ATT&CK technique.
5 tasks · 275 points total
Training Tools
Skills You'll Build
Requires foundational alert triage skills. Multiple data sources to correlate.
Prerequisites
- Basic understanding of security alerts
- Familiarity with SIEM concepts
- Familiarity with XDR concepts
- Familiarity with Firewall concepts
Ready to investigate?
More Operations
View allFrozen Assets: The Snowflake Tenant Heist
A retailer's Snowflake tenant is accessed with a contractor credential lifted from an infostealer log. With no MFA and no network policy to stop it, the actor logs in from VPN-exit IPs, recons with anomalous tooling, and bulk-exfiltrates an entire customer table. Work the Snowflake audit trail to reconstruct the theft.
Exchange ProxyShell: Domain-Wide Ransomware
An internet-facing Exchange server falls to ProxyShell, dropping ASPX web shells that run as SYSTEM. The attacker re-enables a built-in account, dumps LSASS with a Windows DLL, tunnels out with Plink and FRP, moves laterally over RDP, and encrypts the domain with its own BitLocker and DiskCryptor, no ransomware binary in sight. Work the Exchange logs, the endpoint process tree, and the perimeter traffic to reconstruct the intrusion.
Hide Your RDP
An internet-facing RDP server at a logistics firm is password-sprayed into, and within hours a RansomHub affiliate dumps credentials, pivots to the domain controller and backup servers, steals finance data over SFTP, and deploys ransomware. Work the authentication records, the endpoint process tree, and the perimeter traffic to reconstruct the intrusion end to end.