Skip to main content

Investigating Executables Evidence

Learn to detect, prevent, and mitigate malicious executables through log data and DFIR artifacts.

Back to all walkthroughs
Room Icon

Investigating Executables Evidence

Max room.

Learn to detect, prevent, and mitigate malicious executables through log data and DFIR artifacts.

medium

60 min

98

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Gaining a foothold is only the beginning. Once an attacker has access to a target system, they must pivot to the execution phase, where they attempt to run their tools while blending in with legitimate system traffic. Whether they use common utilities, exploit trusted binaries, or execute their own uploaded tools, the goal is to remain undetectable. In this room, we will examine the forensic trail left by malicious executables.

Learning Objectives

  • Examine why attackers use malicious executables
  • Identify key indicators of malicious executable activity
  • Identify malicious executable execution within event logs
  • Evaluate forensic artifacts to detect the use of malicious executables
  • Explore containment, prevention, and mitigation strategies

Prerequisites

Some familiarity with Windows Event Logs and is recommended for this walkthrough. A solid understanding of Windows forensic techniques and artifacts will also be beneficial.

Machine Access

Click the Start Machine button below. The machine will start in Split-Screen mode. Once you gain access, all necessary tools and files will be available on the machine's desktop.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting the Lab Machine, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Lab machine
Status:Off

If you prefer to connect using your own -connected machine, please use the credentials below to in: 

Credentials

Only needed if you are using your own machine.

Username
 
DFIRUser
 
Password
 
TryHackMe!
 
IP address
 
MACHINE_IP
 
Connection via
 
RDP
 
Answer the questions below

I understand the room objectives and am ready to learn how to detect malicious executables!