To access material, start machines and answer questions login.
Few Traces.
You have been brought on at Security Services (TSS). Click the card below to reveal your role on this case.
Your case briefing is waiting in the TSS Operations Hub. Head to the Active Case tab for everything you need before you begin. The other tabs are there if you want to explore the company, the team, or previous cases.
Prerequisites
I have reviewed the active case briefing and I am ready to begin.
Set up your virtual environment
Now that you have reviewed the case details on the TSS Operations Hub, it is time to begin your investigation.
A forensic workstation has been attached to this task, equipped with all the tools required for the investigation. Start the machine by clicking the Start Lab Machine button below.
The machine will open in a split-screen. Give it 2-3 minutes to initialise, and then you can start the investigation. If the is not visible, use the blue Show Split View button at the top of the page. You can also connect to the machine via using the credentials below.
Credentials
Only needed if you are using your own machine.
The details of the tools and artefacts are given below:
Forensic Tools: C:\Users\DFIRUser\DFIR Tools\
KAPE Artefacts: C:\Users\DFIRUser\Kape-Collection
Your job is to examine the evidence and answer the questions below.
A storage device was connected to Turner's workstation on the day of the incident. What is its serial number?
What was the name of the storage device Turner connected with the workstation?
An executable was run on Turner's workstation on the same day. Its name clearly reflects the intent behind running it. What is its name?
The first attempt failed. Turner then used a Windows-native background transfer mechanism to try again. What domain was he targeting?
What was the name of the archive Turner prepared to send to that domain?
Both direct transfer attempts from the workstation failed. Turner then accessed another internal system before moving the data. What is the name of that system?
The client reported that vendor contracts are missing. Turner browsed the finance directory locally before removing it. What was the name of the folder containing those contracts?
What was the last interaction time of that restricted folder that Turner accessed? (Format: HH:MM:SS)
Turner successfully moved the archive to the internal system he accessed. What was the full path of the location he copied it to?
Turner deleted several files to cover his tracks. When was the firewall log deleted? (Format: HH:MM:SS AM/PM)
Ready to learn Cyber Security?
TryHackMe provides free online cyber security training to secure jobs & upskill through a fun, interactive learning environment.
Already have an account? Log in