Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

Detecting AD Post-Exploitation

Premium room

Discover how to detect Post-Exploitation activity in an AD environment.

medium

90 min

862

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

As a result of a successful domain compromise, a threat actor can proceed with their actual goals - whether it is long-term access for espionage purposes, ransomware deployment and encryption, data theft, or data destruction. In this room, we will review these scenarios from a team perspective and understand why the attacker pursues them and how they can be detected.

Learning Objectives

  • Understand how attackers perform post-exploitation activities
  • Explore long-term techniques in environments
  • Learn how threat actors deploy ransomware in enterprise networks
  • Understand how wiping and data destruction techniques are executed

Prerequisites

It is suggested to complete the following rooms first before proceeding:

Lab Access

Before proceeding, start the lab by clicking the Start Machine button below. You will then have access to the Web Interface. 
To access , please follow this link: https://LAB_WEB_URL.p.thmlabs.com (opens in new tab). Please wait 4-5 minutes for the instance to launch. Use 's All Time range to search. The indexes where logs are stored for each practical exercise are present in each task.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting the Target Machine, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Target machine
Status:Off
Answer the questions below

Let's go!