To access material, start machines and answer questions login.
Gaining a foothold is only the beginning. Once an attacker has access to a target system, they must pivot to the execution phase, where they attempt to run their tools while blending in with legitimate system traffic. Whether they use common utilities, exploit trusted binaries, or execute their own uploaded tools, the goal is to remain undetectable. In this room, we will examine the forensic trail left by malicious executables.
Learning Objectives
- Examine why attackers use malicious executables
- Identify key indicators of malicious executable activity
- Identify malicious executable execution within event logs
- Evaluate forensic artifacts to detect the use of malicious executables
- Explore containment, prevention, and mitigation strategies
Prerequisites
Some familiarity with Windows Event Logs and is recommended for this walkthrough. A solid understanding of Windows forensic techniques and artifacts will also be beneficial.
- Check out Windows Event Logs for an overview of important event
- Go over Sysmon to learn about event IDs and key fields related to process execution
- Cover Expediting Registry Analysis to learn about Windows registry acquisition and analysis
Machine Access
Click the Start Machine button below. The machine will start in Split-Screen mode. Once you gain access, all necessary tools and files will be available on the machine's desktop.
Set up your virtual environment
If you prefer to connect using your own -connected machine, please use the credentials below to in:
Credentials
Only needed if you are using your own machine.
I understand the room objectives and am ready to learn how to detect malicious executables!
Ready to learn Cyber Security?
The Investigating Executables Evidence room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in
