Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-DFIR-LAB-002Medium
Browser LabLD-DFIR-LAB-002Medium30 min

The Persistence Sweep

After an intrusion on Wadi server WD-APP-02, you must find every mechanism the attacker planted to survive a reboot. You have an autostart sweep (registry + services + tasks) and the Security event log. The eradication plan will contain exactly what you find — miss one and the incident restarts.

What you will be able to do

  • Judge autostart entries by creator, timing and target path — not by name.
  • Corroborate registry findings with event-log creation records.
  • Find ALL mechanisms, not the first one.
Windows SecurityLog AnalysisAnalyst ReportingT1053.005Scheduled TaskT1547.001Registry Run KeysT1070.001Clear Windows Event Logs

Sign in to start this lab.

Sign in