Operation Hollow Crown

LONG · WINDOWS · difficulty 5 · ~90 min · 50 steps

A nation-state-grade domain compromise. Work it to first contact and find out who really opened the door.

Briefing

06:00. Every domain controller at Meridian Logistics is compromised. The adversary holds a forged Kerberos ticket, has replicated the entire directory, and issued themselves a certificate that authenticates as any user they choose. Three separate vendors have already told the board this is a state actor. It may be. But nobody has yet answered the only question that closes an incident: how did they get the FIRST credential. Everything above is what an attacker does once they are already inside. You have the domain, the certificate authority, exported host artifacts, and the badge and VPN records. Work it backwards to first contact, and be prepared for the answer to be less exotic and far more uncomfortable than the board expects. When a name appears, you stop and hand over — that is part of the job, not an interruption to it.

Objectives

Return to the range lobby

THREAT FEED ▲ lateral movement via wmiexec up 18% ▲ new loader family 'GHOSTPULSE' staging via DLL search-order hijack ▲ prompt injection in support queues now routine ▲ cron persistence campaign targeting exposed SSH ▲ poisoned model weights on public hubs ▲ remember: trust nothing, hash everything ▲
operator@dojo:~$