Skip to main content
Room Banner
Back to all walkthroughs
Room Icon

Threat Hunting: Endgame

Max room.

Learn how to hunt and discover suspicious activities indicating actions on objectives.

medium

60 min

8,491

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Can your organisation detect when attackers accomplish their final objectives on compromised systems? Can you identify data exfiltration, system disruption, or data destruction before critical assets are compromised? Can you use threat hunting to uncover the attacker's endgame before it causes irreversible damage?

These are essential questions when considering the Actions on Objectives phase of the Cyber Kill Chain. By the time attackers reach this phase, they have already established , escalated privileges, and moved laterally across your network. Now they are ready to accomplish their true objectives, whether stealing data, destroying systems, or disrupting operations. As a security team, you are responsible for detecting these final attack stages and stopping them before they succeed. Understanding how attackers accomplish their objectives is critical for effective threat hunting.

Learning Objectives

In this room, we will learn to hunt malicious activities in the "Actions on Objectives" phase of the attack chain. By the end of this room, you will be able to:

  • Gain hands-on threat hunting investigation skills in real-world scenarios
  • Understand the Actions on Objectives phase and its significance in the Cyber Kill Chain
  • Correlate and evaluate artefacts to develop and test threat hunting hypotheses
  • Hunt for collection, exfiltration, and impact activities using ATT&CK techniques
  • Identify attacker objectives and the techniques used to accomplish them

Prerequisites

It's recommended you complete the following rooms before proceeding with this room:

Answer the questions below

I am ready to start hunting!