Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

Detecting AD Initial Access

Premium room

Detect AD initial access attacks by analyzing IIS, NPS, and Windows Security logs.

medium

60 min

1,325

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

In an environment, every internet-facing service that authenticates against the domain is a potential entry point. This room teaches how to detect initial access attacks against three of the most common ones: web applications, Exchange , and gateways. 

Each scenario uses a different application log source, but they share a common principle:

  • The attack is visible in the application logs first
  • Then, correlating with other log sources (e.g., and Windows Security logs) to reveal the full scope

Learning Objectives

  • Analyze logs to detect web application attacks and web shell activity
  • Correlate Exchange/ authentication events with Windows Security logs
  • Investigate credential attacks using event logs
  • Investigate post-authentication activity to determine the impact of a breach
  • Build investigation timelines by correlating application logs with Windows Security logs

Prerequisites

Machine Access

Start the machine by clicking the Start Machine button below. Give the instance about 4-5 minutes to launch, then access it using the link below. Feel free to continue reading the next tasks while it boots:

Info: This instance is used throughout Tasks 2-7. A separate instance with different data is provided for the Task 8 challenge.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting the Target Machine, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Target machine - Task 1
Status:Off
Answer the questions below

I have successfully started my Splunk instance.