Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-TH-LAB-001Medium
Browser LabLD-TH-LAB-001Medium30 min

Hunt the Qasr Finance Endpoint

Intelligence describes a campaign that delivers macro documents to finance staff. You are hunting Qasr's finance workstations with a hypothesis: an office document spawned a shell chain and established persistence. You have process-creation telemetry and a scheduled-task export. Read the lineage — do not judge by process name.

What you will be able to do

  • Identify the malicious process lineage, not the scary-sounding process.
  • Decode intent from the command line.
  • Find the persistence mechanism the intrusion established.
Threat HuntingWindows SecurityDetection EngineeringT1566PhishingT1059.001PowerShellT1053.005Scheduled Task

Sign in to start this lab.

Sign in