Operation Borrowed Blade

LOCKOUT · WINDOWS · difficulty 5 · ~45 min · 19 steps

The endpoint agent did not crash and did not alert. It was terminated from kernel space by a driver with a valid signature.

Briefing

The file server encrypted between 03:12 and 04:40 and your endpoint agent has no detections in that window. Not a blocked one, not a suppressed one — none. Its service shows Stopped, there is no crash dump, and the last log line it wrote was at 03:09, ordinary and unremarkable. Something switched it off from underneath. User-mode protection cannot stop code running in the kernel, and getting code into the kernel no longer takes an exploit — it takes a driver that somebody legitimately signed years ago and never got revoked. Find the driver. Then find out why this machine was willing to load it.

Objectives

Return to the range lobby

THREAT FEED ▲ lateral movement via wmiexec up 18% ▲ new loader family 'GHOSTPULSE' staging via DLL search-order hijack ▲ prompt injection in support queues now routine ▲ cron persistence campaign targeting exposed SSH ▲ poisoned model weights on public hubs ▲ remember: trust nothing, hash everything ▲
operator@dojo:~$