Operation Ash Layer

FORENSICS · LINUX · difficulty 5 · ~50 min · 20 steps

The logs were destroyed and the toolkit was shredded. The filesystem kept more than either of them intended.

Briefing

srv-app-02 was rebuilt on Sunday afternoon by someone who is now unavailable. Before it was rebuilt it was imaged, which is the only reason this investigation exists. The journal directory is empty. /var/log is a set of files with the right names and no content in them. The attacker's working directory is gone and at least one binary was shredded rather than deleted. You have 480 gigabytes of E01 and no live system to ask. Everything from here is recovered from the difference between removing a NAME and removing DATA.

Objectives

Return to the range lobby

THREAT FEED ▲ lateral movement via wmiexec up 18% ▲ new loader family 'GHOSTPULSE' staging via DLL search-order hijack ▲ prompt injection in support queues now routine ▲ cron persistence campaign targeting exposed SSH ▲ poisoned model weights on public hubs ▲ remember: trust nothing, hash everything ▲
operator@dojo:~$