Skip to main content
Zerologon DC takeover → ransomware operation cover
IntermediateSIEMXDRFirewallPRO

Zerologon DC takeover → ransomware

An unprivileged phishing foothold becomes a domain-wide ransomware outbreak in hours. The attacker abuses the Zerologon flaw to reset a domain controller's machine-account password, pivots controller-to-controller, and encrypts the estate after gutting the backups. Work the Windows Security log, the endpoint process tree, and the perimeter traffic to reconstruct the takeover.

55m
5 tasks
50 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Find the foothold

50

A manufacturing domain saw a workstation light up with mail-borne activity this morning before anything touched the servers. Work the endpoint process records and identify the workstation where the intrusion began.

Hint available
2

Identify the controller that was tampered with

60

After enumerating the domain from that foothold, the intruder went straight at the directory's core. Determine which domain controller had its own machine account altered.

Hint available
3

Trace the source of the change

55

The controller's machine account was reset from somewhere on the inside. Pin down the internal address the tampering came from so it can be contained.

Hint available
4

Catch the controller phoning home

60

Once the directory fell, the attacker stood up a beacon on a second controller. Follow the perimeter traffic and name the external destination that a domain controller began contacting.

Hint available
5

Classify the escalation technique

50

Summarize for the incident report how an unprivileged host seized the domain. Map the core escalation to its MITRE ATT&CK technique.

Hint available

5 tasks · 275 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
XDR log analysis
Firewall log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Intermediate

Requires foundational alert triage skills. Multiple data sources to correlate.

Prerequisites

  • Basic understanding of security alerts
  • Familiarity with SIEM concepts
  • Familiarity with XDR concepts
  • Familiarity with Firewall concepts

Ready to investigate?

More Operations

View all