Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

Supplemental Memory

Premium room

Investigate lateral movement, credential theft, and additional adversary actions in a memory dump.

medium

60 min

1,766

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

As a team member in this room, you are tasked with conducting a memory analysis of a Windows workstation image suspected to have been compromised by a threat actor.

This room is designed for team members, Threat Hunters, and L2/L3 analysts who want to improve and reinforce their skills in memory analysis during a potential incident in order to understand better the value that memory dump investigation can provide in such scenarios.

Learning Objectives

  • Uncover the TryHatMe breach with just a memory dump.
  • Identify suspicious processes and network connections.
  • Explore traces of execution and discovery actions.
  • Detect signs of potential lateral movement and credential dumping.

Room Prerequisites

It is suggested to clear the following rooms first before proceeding:

Answer the questions below

Let's start!