Skip to main content

DiskFiltration

Test your Windows investigation skills on a critical data exfiltration case.

Room Icon

DiskFiltration

Max room.

Test your Windows investigation skills on a critical data exfiltration case.

hard

120 min

2,657

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

An overview of the attack chain is provided in the table below:

Tactic TechniqueActivity
Initial Access

T1078 - Valid Accounts: Local Accounts

Liam used his valid credentials to log into his workstation.
Discovery

T1083 - File and Directory Discovery

Liam searches for critical files in the file explorer.
Collection

T1560 - Archive Collected Data: Archive via Utility

Liam copies the zip file from the USB to his workstation and unzips it.

Exfiltration

T1048 Exfiltration Over Alternative Protocol

Liam executes a file responsible for uploading any future data in the Documents folder to the external entity.
Defense EvasionT1070.004 - File DeletionLiam deletes the extracted zip folder after performing the exfiltration.
ExecutionT1059.001 - Command and Scripting Interpreter: Liam executes a PowerShell command to get some information about the system as per the plan provided by the external entity helping him.
Answer the questions below
Ready for the challenge?