Skip to main content
Back to all walkthroughs
Room Icon

Detecting AD Post-Exploitation

Max room.

Discover how to detect Post-Exploitation activity in an AD environment.

medium

90 min

1,030

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

As a result of a successful domain compromise, a threat actor can proceed with their actual goals - whether it is long-term access for espionage purposes, ransomware deployment and encryption, data theft, or data destruction. In this room, we will review these scenarios from a team perspective and understand why the attacker pursues them and how they can be detected.

Learning Objectives

  • Understand how attackers perform post-exploitation activities
  • Explore long-term techniques in AD environments
  • Learn how threat actors deploy ransomware in enterprise networks
  • Understand how wiping and data destruction techniques are executed

Prerequisites

It is suggested to complete the following rooms first before proceeding:

Lab Access

Before proceeding, start the lab by clicking the Start Lab Machine button below. You will then have access to the Web Interface. 
To access Splunk, please follow this link: https://LAB_WEB_URL.p.thmlabs.com (opens in new tab). Please wait 4-5 minutes for the Splunk instance to launch. Use Splunk's All Time range to search. The indexes where logs are stored for each practical exercise are present in each task.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting the Lab Machine, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Lab machine
Status:Off
Answer the questions below

Let's go!