Browser LabLD-DFIR-LAB-002Medium
Browser LabLD-DFIR-LAB-002Medium30 min
The Persistence Sweep
After an intrusion on Wadi server WD-APP-02, you must find every mechanism the attacker planted to survive a reboot. You have an autostart sweep (registry + services + tasks) and the Security event log. The eradication plan will contain exactly what you find — miss one and the incident restarts.
What you will be able to do
- Judge autostart entries by creator, timing and target path — not by name.
- Corroborate registry findings with event-log creation records.
- Find ALL mechanisms, not the first one.
Windows SecurityLog AnalysisAnalyst ReportingT1053.005 — Scheduled TaskT1547.001 — Registry Run KeysT1070.001 — Clear Windows Event Logs
Sign in to start this lab.
Sign in