Semester ends with Cyber Crisis
This lab simulates a real-world incident response scenario where a university lecturer's device has been compromised during end-of-semester activities. Students will conduct forensic analysis to uncover malicious startup files, trace the attack chain, identify exploited vulnerabilities, discover rogue administrative accounts, analyze authentication logs, investigate scheduled tasks and backdoors, and compile threat intelligence for firewall blocking. The investigation covers the full attack lifecycle from initial compromise through persistence mechanisms.
By CyberTask ยท Medium level
14
Tasks
1
Sections
280
Points
1 hr
Duration
What You'll Learn
- Enumerate administrative accounts on compromised system
- Identify and analyze malicious persistence mechanisms
- Trace attack chain to initial infection vector
- Investigate suspicious user accounts and logon activity
- Analyze scheduled tasks and backdoor configurations
- Compile threat intelligence for network defense
Prerequisites
- Windows system administration fundamentals
- Basic digital forensics concepts
- Understanding of user account management
- Familiarity with Windows event logs
- Knowledge of common attack techniques
Tools & Technologies
Event Viewer
PowerShell
Registry Editor
Task Scheduler
Windows Management Instrumentation
Ready to Begin?
Sign in or create an account to start this lab and earn points.