Skip to main content
Room Icon

The Clean Exit

THM Security Services has been engaged for a Digital Forensics activity for GlobalTech Manufacturing.

medium

60 min

36

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Score updated
Score updated

Few Traces.

You have been brought on at Security Services (TSS). Click the card below to reveal your role on this case.

Your case briefing is waiting in the TSS Operations Hub. Head to the Active Case tab for everything you need before you begin. The other tabs are there if you want to explore the company, the team, or previous cases.

Prerequisites

Answer the questions below

I have reviewed the active case briefing and I am ready to begin.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Lab Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine
Status:Off

Now that you have reviewed the case details on the TSS Operations Hub, it is time to begin your investigation.

A forensic workstation has been attached to this task, equipped with all the tools required for the investigation. Start the machine by clicking the Start Lab Machine button below.

Target Machine card placeholder

The machine will open in a split-screen. Give it 2-3 minutes to initialise, and then you can start the investigation. If the is not visible, use the blue Show Split View button at the top of the page. You can also connect to the machine via using the credentials below.

Credentials

Only needed if you are using your own machine.

Username
 
DFIRUser
 
Password
 
TryH@cKMe1!433

 
IP address
 
MACHINE_IP
 
Connection via
 
RDP

The details of the tools and artefacts are given below:

Forensic Tools: C:\Users\DFIRUser\DFIR Tools\

KAPE Artefacts: C:\Users\DFIRUser\Kape-Collection

Your job is to examine the evidence and answer the questions below.

Answer the questions below

A storage device was connected to Turner's workstation on the day of the incident. What is its serial number?

What was the name of the storage device Turner connected with the workstation?

An executable was run on Turner's workstation on the same day. Its name clearly reflects the intent behind running it. What is its name?

The first attempt failed. Turner then used a Windows-native background transfer mechanism to try again. What domain was he targeting?

What was the name of the archive Turner prepared to send to that domain?

Both direct transfer attempts from the workstation failed. Turner then accessed another internal system before moving the data. What is the name of that system?

The client reported that vendor contracts are missing. Turner browsed the finance directory locally before removing it. What was the name of the folder containing those contracts?

What was the last interaction time of that restricted folder that Turner accessed? (Format: HH:MM:SS)

Turner successfully moved the archive to the internal system he accessed. What was the full path of the location he copied it to?

Turner deleted several files to cover his tracks. When was the firewall log deleted? (Format: HH:MM:SS AM/PM)