
COMING SOONIntermediatePRO
Zerologon DC takeover → ransomware
An unprivileged phishing foothold becomes a domain-wide ransomware outbreak in hours. The attacker abuses the Zerologon flaw to reset a domain controller's machine-account password, pivots controller-to-controller, and encrypts the estate after gutting the backups. Work the Windows Security log, the endpoint process tree, and the perimeter traffic to reconstruct the takeover.
55m
5 tasks
50 points
ProLaunches in 3 days
Aug 18, 2026
View Pro plansTuesday, August 18, 2026 at 9:00 AM
Pro unlocks this operation at launch.
Training Tools
SIEMXDRFirewall
What you'll investigate
5 objectives unlock when this operation goes live.
1Find the foothold
2Identify the controller that was tampered with
3Trace the source of the change
4Catch the controller phoning home
5Classify the escalation technique
Be first when it launches
Create your account and grab Pro before launch. The moment this operation goes live on Aug 18, 2026, you can jump straight in.
Get Started Free