Labs
TA0001 Initial Access
ClickOnce Abuse
Detect ClickOnce abuse and AppDomainManager injection using ClickOnceBlobber. Covers dfsvc.exe process telemetry, ClickOnce cache artifacts, Zeek logs, Sysmon unsigned module loads, and Suricata TLS fingerprints. Includes KQL detection queries.
Windows Screensaver Files and RMM Persistence
This is a simple emulation of a campaign documented by ReliaQuest, 'New Campaign Uses Screensavers for RMM-Based Persistence'. LimeWire.com is used to deliver a self-extracting archive masquerading as a Windows screensaver file that installs ScreenConnect.
ClickFix, Electron Script-jacking, and Mandatory User Profiles
This attack simulation is inspired by Seqrite Lab's Operation HanKook Phantom: North Korean APT37 targeting South Korea and Praetorian's Corrupting the Hive Mind: Persistence Through Forgotten Windows Internals. It relies on a simple ClickFix attack to launch a PowerShell script that drops a Loki C2 payload, which is in turn used to establish persistence with a Mandatory User Profile.
TA0002 Execution
ClickOnce Abuse
Detect ClickOnce abuse and AppDomainManager injection using ClickOnceBlobber. Covers dfsvc.exe process telemetry, ClickOnce cache artifacts, Zeek logs, Sysmon unsigned module loads, and Suricata TLS fingerprints. Includes KQL detection queries.
Windows Screensaver Files and RMM Persistence
This is a simple emulation of a campaign documented by ReliaQuest, 'New Campaign Uses Screensavers for RMM-Based Persistence'. LimeWire.com is used to deliver a self-extracting archive masquerading as a Windows screensaver file that installs ScreenConnect.
Python Persistence via .pth Files
Abuse of Python .pth files to establish persistence on Windows. The lab demonstrates how code embedded in site-packages path files executes automatically when Python starts.
ClickFix, Electron Script-jacking, and Mandatory User Profiles
This attack simulation is inspired by Seqrite Lab's Operation HanKook Phantom: North Korean APT37 targeting South Korea and Praetorian's Corrupting the Hive Mind: Persistence Through Forgotten Windows Internals. It relies on a simple ClickFix attack to launch a PowerShell script that drops a Loki C2 payload, which is in turn used to establish persistence with a Mandatory User Profile.
TA0003 Persistence
ClickOnce Abuse
Detect ClickOnce abuse and AppDomainManager injection using ClickOnceBlobber. Covers dfsvc.exe process telemetry, ClickOnce cache artifacts, Zeek logs, Sysmon unsigned module loads, and Suricata TLS fingerprints. Includes KQL detection queries.
Windows Screensaver Files and RMM Persistence
This is a simple emulation of a campaign documented by ReliaQuest, 'New Campaign Uses Screensavers for RMM-Based Persistence'. LimeWire.com is used to deliver a self-extracting archive masquerading as a Windows screensaver file that installs ScreenConnect.
Python Persistence via .pth Files
Abuse of Python .pth files to establish persistence on Windows. The lab demonstrates how code embedded in site-packages path files executes automatically when Python starts.
DLL Sideloading with the Windows Bluetooth File Transfer Wizard
KQL analysis lab of malicious DLL sideloading via the Windows Bluetooth File Transfer Wizard. Demonstrates loading from a user dir and how to detect the behavior using MDE telemetry.
ClickFix, Electron Script-jacking, and Mandatory User Profiles
This attack simulation is inspired by Seqrite Lab's Operation HanKook Phantom: North Korean APT37 targeting South Korea and Praetorian's Corrupting the Hive Mind: Persistence Through Forgotten Windows Internals. It relies on a simple ClickFix attack to launch a PowerShell script that drops a Loki C2 payload, which is in turn used to establish persistence with a Mandatory User Profile.
TA0011 Command and Control
ClickOnce Abuse
Detect ClickOnce abuse and AppDomainManager injection using ClickOnceBlobber. Covers dfsvc.exe process telemetry, ClickOnce cache artifacts, Zeek logs, Sysmon unsigned module loads, and Suricata TLS fingerprints. Includes KQL detection queries.
Windows Screensaver Files and RMM Persistence
This is a simple emulation of a campaign documented by ReliaQuest, 'New Campaign Uses Screensavers for RMM-Based Persistence'. LimeWire.com is used to deliver a self-extracting archive masquerading as a Windows screensaver file that installs ScreenConnect.
Python Persistence via .pth Files
Abuse of Python .pth files to establish persistence on Windows. The lab demonstrates how code embedded in site-packages path files executes automatically when Python starts.
ClickFix, Electron Script-jacking, and Mandatory User Profiles
This attack simulation is inspired by Seqrite Lab's Operation HanKook Phantom: North Korean APT37 targeting South Korea and Praetorian's Corrupting the Hive Mind: Persistence Through Forgotten Windows Internals. It relies on a simple ClickFix attack to launch a PowerShell script that drops a Loki C2 payload, which is in turn used to establish persistence with a Mandatory User Profile.
TA0005 Defense Evasion
Windows Screensaver Files and RMM Persistence
This is a simple emulation of a campaign documented by ReliaQuest, 'New Campaign Uses Screensavers for RMM-Based Persistence'. LimeWire.com is used to deliver a self-extracting archive masquerading as a Windows screensaver file that installs ScreenConnect.
Python Persistence via .pth Files
Abuse of Python .pth files to establish persistence on Windows. The lab demonstrates how code embedded in site-packages path files executes automatically when Python starts.
DLL Sideloading with the Windows Bluetooth File Transfer Wizard
KQL analysis lab of malicious DLL sideloading via the Windows Bluetooth File Transfer Wizard. Demonstrates loading from a user dir and how to detect the behavior using MDE telemetry.
T1204.001 User Execution: Malicious Link
T1127.002 Trusted Developer Utilities Proxy Execution: ClickOnce
T1574.014 Hijack Execution Flow: AppDomainManager
T1071.001 Application Layer Protocol: Web Protocols
T1204.002 User Execution: Malicious File
T1059.003 Command and Scripting Interpreter: Windows Command Shell
T1218.007 System Binary Proxy Execution: Msiexec
T1546 Event Triggered Execution
Python Persistence via .pth Files
Abuse of Python .pth files to establish persistence on Windows. The lab demonstrates how code embedded in site-packages path files executes automatically when Python starts.
ClickFix, Electron Script-jacking, and Mandatory User Profiles
This attack simulation is inspired by Seqrite Lab's Operation HanKook Phantom: North Korean APT37 targeting South Korea and Praetorian's Corrupting the Hive Mind: Persistence Through Forgotten Windows Internals. It relies on a simple ClickFix attack to launch a PowerShell script that drops a Loki C2 payload, which is in turn used to establish persistence with a Mandatory User Profile.
T1059 Command and Scripting Interpreter
Python Persistence via .pth Files
Abuse of Python .pth files to establish persistence on Windows. The lab demonstrates how code embedded in site-packages path files executes automatically when Python starts.
ClickFix, Electron Script-jacking, and Mandatory User Profiles
This attack simulation is inspired by Seqrite Lab's Operation HanKook Phantom: North Korean APT37 targeting South Korea and Praetorian's Corrupting the Hive Mind: Persistence Through Forgotten Windows Internals. It relies on a simple ClickFix attack to launch a PowerShell script that drops a Loki C2 payload, which is in turn used to establish persistence with a Mandatory User Profile.
T1071 Application Layer Protocol
T1562.004 Disable or Modify System Firewall
T1218 Signed Binary Proxy Execution
T1574.002 Hijack Execution Flow: DLL Side-Loading
ClickOnce Abuse
Detect ClickOnce abuse and AppDomainManager injection using ClickOnceBlobber. Covers dfsvc.exe process telemetry, ClickOnce cache artifacts, Zeek logs, Sysmon unsigned module loads, and Suricata TLS fingerprints. Includes KQL detection queries.
Windows Screensaver Files and RMM Persistence
This is a simple emulation of a campaign documented by ReliaQuest, 'New Campaign Uses Screensavers for RMM-Based Persistence'. LimeWire.com is used to deliver a self-extracting archive masquerading as a Windows screensaver file that installs ScreenConnect.
Python Persistence via .pth Files
Abuse of Python .pth files to establish persistence on Windows. The lab demonstrates how code embedded in site-packages path files executes automatically when Python starts.
BYOVD and KslD.sys
Hands-on lab demonstrating a BYOVD technique using Microsoft's KslD.sys driver to extract domain credentials from LSASS. Explore detection gaps in Windows telemetry, learn how to implement controls using WDAC, and see how attackers evade monitoring.
DLL Sideloading with the Windows Bluetooth File Transfer Wizard
KQL analysis lab of malicious DLL sideloading via the Windows Bluetooth File Transfer Wizard. Demonstrates loading from a user dir and how to detect the behavior using MDE telemetry.
ClickFix, Electron Script-jacking, and Mandatory User Profiles
This attack simulation is inspired by Seqrite Lab's Operation HanKook Phantom: North Korean APT37 targeting South Korea and Praetorian's Corrupting the Hive Mind: Persistence Through Forgotten Windows Internals. It relies on a simple ClickFix attack to launch a PowerShell script that drops a Loki C2 payload, which is in turn used to establish persistence with a Mandatory User Profile.