Skip to main content
Zerologon DC takeover → ransomware operation cover
COMING SOONIntermediatePRO

Zerologon DC takeover → ransomware

An unprivileged phishing foothold becomes a domain-wide ransomware outbreak in hours. The attacker abuses the Zerologon flaw to reset a domain controller's machine-account password, pivots controller-to-controller, and encrypts the estate after gutting the backups. Work the Windows Security log, the endpoint process tree, and the perimeter traffic to reconstruct the takeover.

55m
5 tasks
50 points
Pro

Launches in 3 days

Aug 18, 2026

Tuesday, August 18, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

SIEMXDRFirewall

What you'll investigate

5 objectives unlock when this operation goes live.

1Find the foothold
2Identify the controller that was tampered with
3Trace the source of the change
4Catch the controller phoning home
5Classify the escalation technique

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Aug 18, 2026, you can jump straight in.

Get Started Free